โ† All CHP Flashcard Decks

Regulatory Compliance & Standards Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Standards flashcards as text
  1. Under HIPAA, which of the following is considered a 'hybrid entity'?

    Answer: A company that operates both as a covered entity and a non-covered business

    A hybrid entity is an organization whose business activities include both HIPAA-covered functions and non-covered functions, and it may designate its healthcare component separately.

  2. The HIPAA Privacy Rule's 'Right of Access' requires covered entities to provide individuals with access to their PHI within how many days?

    Answer: 30 days, with one 30-day extension

    Covered entities must act on access requests within 30 days, with a one-time 30-day extension if they notify the individual in writing.

  3. Which of the following is a 'required' implementation specification under the HIPAA Security Rule?

    Answer: Risk analysis and risk management

    Risk analysis and risk management are 'required' implementation specifications โ€” covered entities must perform them regardless of size or resources.

  4. A covered entity's subcontractor improperly disposes of PHI. Under HIPAA post-HITECH, who bears direct liability?

    Answer: The subcontractor directly, as a business associate of a business associate

    Post-HITECH, subcontractors who handle PHI on behalf of business associates are themselves treated as business associates and bear direct HIPAA liability.

  5. Which of the following disclosures is explicitly permitted under HIPAA without patient authorization for public health activities?

    Answer: Reporting communicable disease data to public health authorities

    HIPAA explicitly permits disclosure of PHI to public health authorities (like the CDC or state health departments) authorized to collect data for disease control.

  6. What is the primary purpose of the HIPAA transaction standards (ASC X12 and NCPDP)?

    Answer: To standardize the electronic formats used for healthcare administrative transactions

    HIPAA transaction standards (like ASC X12 837 for claims) standardize electronic data interchange formats to improve efficiency in healthcare administrative transactions.

  7. A researcher wants to use PHI for a study. Which of the following is NOT an acceptable basis for waiving individual authorization under HIPAA?

    Answer: The researcher's institution holds a Certificate of Confidentiality from NIH

    An NIH Certificate of Confidentiality protects researchers from compelled disclosure but is not a HIPAA mechanism that waives the authorization requirement for PHI use.

Regulatory Compliance & Standards Flashcards โ€” CHP Study Cards with Answers