← All CMAA Flashcard Decks

HIPAA and Patient Confidentiality Flashcards

7 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA and Patient Confidentiality flashcards as text
  1. Under HIPAA, which of the following is considered a 'covered entity'?

    Answer: A health insurance plan that pays for medical services

    Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.

  2. A patient requests an amendment to their medical record because they believe information is incorrect. Under HIPAA, the covered entity must respond within:

    Answer: 60 days, with one possible 30-day extension

    HIPAA requires covered entities to act on a request for amendment within 60 days, with one 30-day extension if needed and notice is provided.

  3. Which of the following best describes a 'limited data set' under HIPAA?

    Answer: PHI with most direct identifiers removed but may include dates and geographic data

    A limited data set has most direct identifiers removed but may still include dates (e.g., admission, discharge) and geographic subdivisions, and requires a data use agreement.

  4. A medical administrative assistant receives a subpoena for a patient's records. What is the correct first step?

    Answer: Notify the patient and consult the facility's legal counsel or privacy officer

    Before releasing records pursuant to a subpoena, the facility should notify the patient and seek legal guidance to ensure HIPAA compliance.

  5. Under the HIPAA Privacy Rule, which of the following uses of PHI does NOT require patient authorization?

    Answer: Sharing PHI with a public health authority to report a communicable disease

    Public health activities, such as reporting communicable diseases to authorized public health authorities, are permitted disclosures under HIPAA without patient authorization.

  6. What is the purpose of a Notice of Privacy Practices (NPP)?

    Answer: To inform patients of how their PHI may be used and their rights regarding that information

    The NPP informs patients about how the covered entity may use and disclose their PHI and describes the patient's rights under HIPAA.

  7. Which HIPAA rule specifically addresses the security of electronic protected health information (ePHI)?

    Answer: The Security Rule

    The HIPAA Security Rule establishes national standards to protect individuals' electronic personal health information that is created, received, used, or maintained by a covered entity.