← All CMAA Flashcard Decks

HIPAA and Patient Confidentiality Flashcards

7 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA and Patient Confidentiality flashcards as text
  1. A patient calls the office asking for their test results to be left on their home answering machine. The medical administrative assistant should:

    Answer: Honor the request by leaving only the minimum necessary information and a callback number

    HIPAA allows covered entities to communicate with patients by their preferred method, including voicemail, but only the minimum necessary information should be left.

  2. Under HIPAA, a 'business associate' is best described as:

    Answer: A person or entity that performs functions involving PHI on behalf of a covered entity

    A business associate is a person or organization that performs certain functions or activities that involve the use or disclosure of PHI on behalf of, or in service to, a covered entity.

  3. Which of the following represents an appropriate 'minimum necessary' practice when sharing PHI?

    Answer: Providing only the specific information needed to fulfill a request for treatment purposes

    The minimum necessary standard requires that covered entities limit the PHI disclosed to only what is needed to accomplish the intended purpose.

  4. If a HIPAA breach is discovered, the covered entity must notify affected individuals within:

    Answer: 60 days of discovery

    HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.

  5. A patient's 16-year-old child calls to ask about a parent's medical records. Under HIPAA, the administrative assistant should:

    Answer: Verify whether the minor child is listed as an authorized representative before releasing any information

    HIPAA requires verification that an individual is an authorized personal representative before disclosing a patient's PHI to a third party, including family members.

  6. Which of the following is an example of a physical safeguard required under the HIPAA Security Rule?

    Answer: Using locked cabinets or restricted-access areas for workstations containing ePHI

    Physical safeguards include facility access controls, workstation security, and device and media controls — such as locked areas — to protect ePHI from unauthorized physical access.

  7. An employee shares a patient's diagnosis with a coworker out of curiosity. This is a violation of which HIPAA principle?

    Answer: The minimum necessary standard and Privacy Rule prohibitions on unauthorized disclosure

    Sharing a patient's diagnosis without a legitimate treatment, payment, or operations purpose violates the Privacy Rule's minimum necessary standard and prohibition on unauthorized PHI disclosures.