Compliance Flashcards
11 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 11 Compliance flashcards as text
What is the primary purpose of the Health Insurance Portability and Accountability Act (HIPAA)?
Answer: To protect the privacy and security of health information
HIPAA is designed to safeguard patient information and ensure privacy and security in the handling of health data.
What does PHI stand for in the context of HIPAA?
Answer: Protected Health Information
PHI stands for Protected Health Information, which includes any information about health status, provision of healthcare, or payment for healthcare that can be linked to an individual.
Which of the following is considered a covered entity under HIPAA?
Answer: All of the above
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
What is a Business Associate Agreement (BAA) in HIPAA compliance?
Answer: A contract that outlines how a business associate will protect PHI
A BAA is a contract between a covered entity and a business associate that details how PHI will be protected.
Which of the following is NOT an example of a business associate under HIPAA?
Answer: A janitorial service that does not have access to PHI
Business associates are entities that perform activities involving the use or disclosure of PHI on behalf of, or provides services to, a covered entity. A janitorial service without access to PHI is not considered a business associate.
What must covered entities provide to patients under the HIPAA Privacy Rule?
Answer: A Notice of Privacy Practices
Covered entities must provide patients with a Notice of Privacy Practices that explains how their PHI will be used and protected.
What should an employee do if they suspect a HIPAA violation?
Answer: Report it to their supervisor or the HIPAA compliance officer
Suspected HIPAA violations should be reported to a supervisor or the HIPAA compliance officer to address the issue appropriately.
Which of the following actions would be a violation of HIPAA?
Answer: Discussing a patient’s medical condition in a public area
Discussing a patient’s medical condition in a public area where others can overhear is a violation of HIPAA privacy rules.
What is the purpose of the HIPAA Security Rule?
Answer: To establish national standards for protecting electronic PHI (ePHI)
The HIPAA Security Rule sets national standards for the protection of electronic PHI (ePHI) to ensure its confidentiality, integrity, and security.
What are the three primary safeguards required by the HIPAA Security Rule?
Answer: Physical, administrative, and technical safeguards
The HIPAA Security Rule requires physical, administrative, and technical safeguards to protect ePHI.
How often should employees receive HIPAA training?
Answer: Annually, or whenever there are significant changes to policies
Employees should receive HIPAA training annually, or whenever there are significant changes to policies, to ensure they remain compliant with current regulations.