โ† All HIPAA Flashcard Decks

Compliance Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance flashcards as text
  1. Under HIPAA, a covered entity must designate a Privacy Officer responsible for which primary duty?

    Answer: Developing and implementing privacy policies and procedures

    HIPAA's Privacy Rule requires covered entities to designate a Privacy Official responsible for developing and implementing the entity's privacy policies and procedures.

  2. A Business Associate Agreement (BAA) must be executed before a vendor can:

    Answer: Receive or create PHI on behalf of the covered entity

    A BAA is required whenever a vendor (business associate) will create, receive, maintain, or transmit PHI on behalf of a covered entity.

  3. How long must a covered entity retain its HIPAA policies, procedures, and related documentation?

    Answer: 6 years from the date of creation or last effective date

    HIPAA requires covered entities to retain documentation of policies and procedures for 6 years from the date of creation or the date it was last in effect, whichever is later.

  4. Which of the following is the correct standard for a covered entity to use PHI for marketing purposes under HIPAA?

    Answer: Marketing using PHI generally requires individual written authorization

    HIPAA generally requires individual written authorization before a covered entity can use or disclose PHI for marketing communications.

  5. A hospital employee accesses the medical records of a famous patient out of curiosity, without a treatment need. This is a violation of which HIPAA principle?

    Answer: The Minimum Necessary standard

    The Minimum Necessary standard requires workforce members to access only the PHI needed to perform their job duties; accessing records out of curiosity violates this principle.

  6. Under the HIPAA Security Rule, which category of safeguards includes policies for workforce supervision and information access management?

    Answer: Administrative safeguards

    Administrative safeguards are administrative actions and policies designed to manage workforce conduct and protect electronic PHI, including access management and workforce training.

  7. Which entity has primary enforcement authority over HIPAA compliance?

    Answer: The Office for Civil Rights (OCR) within HHS

    The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.

Compliance Flashcards โ€” HIPAA Study Cards with Answers