Medical Information Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Medical Information flashcards as text
Which of the following is an example of PHI in electronic form (ePHI) that must be protected under HIPAA's Security Rule?
Answer: A patient's diagnosis stored in an electronic health record system
ePHI is protected health information that is created, stored, transmitted, or received in electronic form, such as data in an EHR system.
A covered entity discovers a breach of unsecured PHI. Under the Breach Notification Rule, when must affected individuals be notified?
Answer: Without unreasonable delay and no later than 60 calendar days after discovery
The Breach Notification Rule requires notification to affected individuals without unreasonable delay and within no more than 60 calendar days of discovery.
A large breach affecting more than 500 residents of a state must also be reported to:
Answer: Prominent media outlets serving the affected area
Breaches affecting more than 500 residents of a state or jurisdiction must be reported to prominent media outlets in that area in addition to HHS and affected individuals.
Which of the following is NOT one of the 18 identifiers that must be removed for health information to be considered de-identified under the HIPAA Safe Harbor method?
Answer: A patient's blood type
Blood type is not one of the 18 identifiers listed in the HIPAA Safe Harbor method; it is a clinical data element, not a direct identifier.
Under HIPAA, a covered entity may use or disclose PHI without patient authorization for which of the following purposes?
Answer: Conducting health care operations such as quality improvement activities
Healthcare operations, including quality improvement, training, and accreditation, are permissible uses of PHI that do not require patient authorization.
A patient has the right under HIPAA to request a restriction on PHI use or disclosure. When is a covered entity REQUIRED to honor such a restriction?
Answer: When the patient requests that information not be disclosed to a health plan and the service was paid out-of-pocket in full
Covered entities must honor a restriction request when the patient asks that information about a service not be shared with a health plan and the patient paid for the service out-of-pocket in full.
Which HIPAA provision allows a covered entity to disclose PHI to a correctional institution for a patient who is an inmate?
Answer: The correction and law enforcement provision within the Privacy Rule
The Privacy Rule includes a specific provision permitting disclosure of inmate PHI to correctional institutions or law enforcement officials for health and safety purposes.