HIPAA and Patient Confidentiality Flashcards
6 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 HIPAA and Patient Confidentiality flashcards as text
Under HIPAA, which is considered Protected Health Information (PHI)?
Answer: A medical record number linked to a diagnosis
PHI includes any individually identifiable health information, such as a medical record number linked to a diagnosis.
How long must a covered entity retain HIPAA-related documentation?
Answer: 6 years from creation or last effective date
HIPAA requires retaining policies, procedures, and authorization forms for 6 years from creation or last effective date, whichever is later.
A pharmaceutical rep asks for a list of patients on a specific medication. What is the correct response?
Answer: Decline as it violates HIPAA
Sharing medication lists with pharmaceutical reps violates HIPAA as unauthorized disclosure for non-treatment, payment, or operations purposes.
What does the HIPAA Security Rule primarily protect?
Answer: Electronic PHI (ePHI)
The Security Rule specifically addresses electronic PHI through administrative, physical, and technical safeguards.
Which exemplifies the HIPAA minimum necessary standard?
Answer: Giving billing staff only financial data needed for claims
The minimum necessary standard limits PHI access to only what is needed for the intended purpose.
A patient requests an amendment to their record. The provider must respond within what timeframe?
Answer: 60 days with one 30-day extension
Covered entities must respond to amendment requests within 60 days, with one optional 30-day extension with written notice.