Electronic Health Records (EHR) Compliance Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Electronic Health Records (EHR) Compliance flashcards as text
Under HIPAA, which of the following EHR data exchanges does NOT require a patient's authorization?
Answer: Disclosing records for public health reporting to state authorities
HIPAA permits covered entities to disclose ePHI to public health authorities for authorized public health activities without patient authorization.
A hospital implements a new EHR module. Under HIPAA's Security Rule, what process must be conducted before go-live?
Answer: Security risk analysis of the new module
HIPAA requires covered entities to conduct a security risk analysis before implementing any new system or module that handles ePHI.
What is the maximum civil monetary penalty per violation category under HIPAA for a covered entity that demonstrates willful neglect and does not correct the violation?
Answer: $1,900,000 (adjusted for inflation, annually)
For willful neglect not corrected, HIPAA penalties can reach $1.9 million per violation category per calendar year under the tiered penalty structure.
An EHR system sends an appointment reminder via text message that includes the patient's diagnosis. Which HIPAA principle does this violate?
Answer: Minimum necessary standard
Including a diagnosis in a text reminder violates the minimum necessary standard because only the appointment time and location are needed for a reminder.
Which of the following best describes a contingency plan requirement under HIPAA's Security Rule for EHR systems?
Answer: A documented data backup plan and disaster recovery procedure
HIPAA's contingency plan standard requires covered entities to have documented data backup plans and disaster recovery procedures to ensure ePHI availability during emergencies.
A patient requests that their EHR be amended to correct an error in their medical history. Under HIPAA, when may a covered entity deny this request?
Answer: When the record was not created by the covered entity
A covered entity may deny an amendment request if the ePHI was not created by that entity, as they typically cannot verify or change records created elsewhere.
Under the HITECH Act's EHR Meaningful Use requirements, what additional HIPAA obligation was strengthened regarding business associates?
Answer: Business associates became directly liable for HIPAA Security Rule compliance
The HITECH Act extended direct HIPAA Security Rule liability to business associates, meaning they can be penalized directly by OCR for violations.