← All HIPAA Flashcard Decks

Compliance Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance flashcards as text
  1. Which of the following HIPAA Security Rule safeguards requires covered entities to implement automatic logoff on workstations?

    Answer: Technical safeguards — automatic logoff

    Automatic logoff is an addressable implementation specification under the Technical Safeguards section of the HIPAA Security Rule (45 CFR § 164.312).

  2. What does the HIPAA 'Safe Harbor' de-identification method require?

    Answer: Removal of 17 specific categories of identifiers and no actual knowledge of re-identification

    The Safe Harbor method requires removing all 18 categories of specified identifiers (one category covers geographic data down to three-digit ZIP codes) and that the covered entity has no actual knowledge that the remaining information could re-identify an individual.

  3. A subcontractor of a business associate handles ePHI as part of its work. Under HIPAA, the subcontractor is:

    Answer: Considered a business associate and must comply with the Security Rule directly

    The HITECH Act extended direct HIPAA liability to subcontractors of business associates; they are treated as business associates and must comply with applicable HIPAA Rules.

  4. A patient requests access to their PHI in an electronic format. If the covered entity maintains the records electronically, it must:

    Answer: Provide the records in the electronic format requested by the individual if readily producible

    Under HIPAA and HITECH, if a covered entity maintains PHI electronically, it must provide that PHI in the electronic format requested by the individual if it is readily producible in that format.

  5. Which of the following is NOT a permissible disclosure of PHI without individual authorization under the HIPAA Privacy Rule?

    Answer: Disclosure to a marketing firm for a drug manufacturer's campaign

    HIPAA does not permit disclosure of PHI to marketing firms for commercial purposes without individual authorization; the other listed disclosures are recognized exceptions.

  6. Under HIPAA, the term 'incidental disclosure' refers to:

    Answer: A secondary disclosure that occurs as a byproduct of a permissible use or disclosure, when reasonable safeguards are in place

    An incidental disclosure is a secondary disclosure that cannot be reasonably prevented, is limited in nature, and occurs as a by-product of an otherwise permissible use or disclosure; it is not a violation when reasonable safeguards are in place.

  7. A covered entity wants to use PHI for a research study. Which of the following satisfies HIPAA requirements for this use?

    Answer: An IRB waiver of authorization or individual written authorization from each subject

    Research use of PHI requires either individual written authorization or an IRB (Institutional Review Board) waiver/alteration of authorization, or the PHI must be de-identified.