Protected Health Information (PHI) Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Protected Health Information (PHI) flashcards as text
Under HIPAA's Safe Harbor de-identification method, geographic data must be limited to:
Answer: State level or larger
The Safe Harbor method requires geographic subdivisions to be no smaller than a state, except that the first three digits of a ZIP code may be retained if the geographic unit contains more than 20,000 people.
Which of the following is an example of PHI in a non-electronic format covered by the HIPAA Privacy Rule?
Answer: A paper prescription with a patient's name and medication
A paper prescription containing a patient's name (an identifier) linked to medication information (health-related data) constitutes PHI subject to the HIPAA Privacy Rule.
A patient's right to request an amendment to their PHI under HIPAA applies when:
Answer: They believe the information is inaccurate or incomplete
HIPAA gives patients the right to request amendments to their PHI when they believe the record is inaccurate or incomplete, though covered entities may deny the request under certain conditions.
Which HIPAA concept describes a patient's right to receive a list of certain disclosures of their PHI made by a covered entity?
Answer: Accounting of disclosures
The accounting of disclosures provision gives patients the right to receive a list of certain disclosures of their PHI made without their authorization, covering the prior six years.
A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
Answer: No later than the date of first service delivery
Covered entities must provide patients with the NPP no later than the date of first service delivery, and must make a good-faith effort to obtain written acknowledgment of receipt.
Under HIPAA, which of the following is true about deceased individuals' PHI?
Answer: PHI of deceased individuals is protected for 50 years after death
HIPAA protects the PHI of deceased individuals for 50 years following the date of death, after which it is no longer considered protected health information.
A covered entity that discovers a breach of unsecured PHI must notify affected individuals within:
Answer: 60 calendar days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.