Protected Health Information (PHI) Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Protected Health Information (PHI) flashcards as text
Which of the following best describes 'incidental disclosures' of PHI under HIPAA?
Answer: Secondary disclosures that occur as a byproduct of permitted disclosures
Incidental disclosures are unintended secondary disclosures that occur as a result of a permitted disclosure, and they do not violate HIPAA if the covered entity has implemented reasonable safeguards.
A health plan is permitted to use PHI for underwriting purposes under HIPAA when:
Answer: Underwriting is a permitted healthcare operation for health plans
Health plans may use PHI for underwriting, premium rating, and related functions as part of permitted healthcare operations, though GINA and ACA have placed additional restrictions on this practice.
Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
Answer: Employers who sponsor self-insured health plans
Employers who sponsor self-insured health plans are not themselves covered entities; however, the plan itself may be a covered entity, and employers must separate plan functions from employment functions.
IP addresses are considered PHI under HIPAA when they:
Answer: Are linked or linkable to an individual's health information
IP addresses are one of the 18 HIPAA identifiers and constitute PHI when they are associated with or could be linked to a person's health information.
A hospital uses patient data to conduct internal quality improvement studies. Under HIPAA, this activity is classified as:
Answer: A healthcare operation permitted without patient authorization
Quality assessment and improvement activities are explicitly listed as healthcare operations under HIPAA, allowing covered entities to use PHI for these purposes without patient authorization.
Which HIPAA provision allows a covered entity to disclose PHI to prevent a serious and imminent threat to the health or safety of a person or the public?
Answer: The serious threat exception
HIPAA's serious threat exception permits covered entities to disclose PHI to law enforcement or others who can prevent or lessen a serious and imminent threat to the health or safety of a person or the public.
A HIPAA violation is considered 'willful neglect' when the covered entity:
Answer: Consciously and intentionally fails to comply with HIPAA requirements
Willful neglect under HIPAA means conscious, intentional failure to comply, or reckless indifference to the obligation to comply, and carries the highest civil monetary penalties.