Safety & Infection Control Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Safety & Infection Control flashcards as text
During a public health emergency involving an infectious disease outbreak, a covered entity wants to share patient PHI with public health authorities without patient authorization. Which HIPAA provision permits this?
Answer: The Public Health Activities exception allows disclosure to public health authorities authorized by law to collect data
HIPAA's Public Health Activities exception (45 CFR § 164.512(b)) permits covered entities to disclose PHI to authorized public health authorities for activities such as disease surveillance and outbreak response.
A nurse accidentally sticks herself with a needle used on an HIV-positive patient. The hospital's occupational health team requests the patient's HIV status. What does HIPAA permit in this scenario?
Answer: HIPAA permits disclosure of the patient's HIV status to the source patient's treating provider and the exposed worker's healthcare provider for treatment purposes
HIPAA's treatment exception and workforce safety provisions allow disclosure of the source patient's relevant PHI to facilitate occupational exposure management.
Which OSHA standard works in conjunction with HIPAA to protect healthcare workers from bloodborne pathogen exposure risks?
Answer: OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030)
OSHA's Bloodborne Pathogens Standard requires employers to protect workers from exposure to blood and other potentially infectious materials, complementing HIPAA's privacy protections for patient information related to these exposures.
A covered entity's security policy requires that all workstations be logged off or locked when unattended. This requirement primarily addresses which HIPAA Security Rule implementation specification?
Answer: Automatic Logoff
The Automatic Logoff implementation specification (addressable) under the Access Control standard requires entities to implement electronic procedures that terminate sessions after a predetermined period of inactivity.
A hospital emergency department uses a shared 'break-the-glass' override procedure to access ePHI during a mass casualty event. Under HIPAA, this is best characterized as:
Answer: A permissible emergency access procedure that must be documented and reviewed after the event
HIPAA permits emergency access procedures and requires covered entities to establish them; however, all emergency access events must be logged and reviewed to detect inappropriate use.
Which practice BEST supports both infection control and HIPAA compliance when healthcare staff use mobile devices to document patient care?
Answer: Implementing a mobile device management (MDM) solution with remote wipe, encryption, and device hygiene guidelines
An MDM solution addresses HIPAA requirements for encryption, access control, and remote wipe while device hygiene guidelines address infection control concerns in clinical environments.
Under HIPAA, when a covered entity discovers a breach involving PHI on paper records contaminated with biohazardous material, what is the CORRECT sequence of priorities?
Answer: Safely contain and manage the biohazard following infection control protocols, then conduct breach analysis and notifications per HIPAA Breach Notification Rule
Life safety and infection control always take precedence; once the biohazard is controlled, the organization must conduct a breach risk assessment and follow the HIPAA Breach Notification Rule timeline.