Healthcare Provider Obligations and Covered Entities Flashcards
36 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Healthcare Provider Obligations and Covered Entities flashcards as text
Under HIPAA, which of the following is a 'covered entity'?
Answer: A healthcare clearinghouse that processes health insurance claims electronically
Healthcare clearinghouses that process health information from non-standard to standard formats are one of the three categories of HIPAA covered entities.
A small cash-only family physician practice that has never transmitted any health information electronically is subject to HIPAA under which condition?
Answer: The practice becomes covered if it submits even a single electronic claim or electronic transaction covered by HIPAA standards
Healthcare providers become HIPAA covered entities only when they conduct electronic transactions using HIPAA standard transactions — a single electronic submission triggers covered entity status.
Which of the following healthcare entities is NOT typically a covered entity under HIPAA?
Answer: A workers' compensation insurer
Workers' compensation insurers are specifically excluded from HIPAA's definition of health plans because they provide coverage for work-related injuries, not health coverage per se.
Under HIPAA, what is a 'hybrid entity'?
Answer: An organization that performs both covered and non-covered healthcare functions within the same legal entity
A hybrid entity is a single legal entity that performs both HIPAA-covered healthcare functions and non-healthcare functions within the same organization.
What is the primary HIPAA obligation when a healthcare provider refers a patient to a specialist?
Answer: The provider may share the minimum necessary PHI for treatment purposes without patient authorization
Treatment disclosures between healthcare providers are explicitly permitted under HIPAA's Privacy Rule without individual authorization, subject to the minimum necessary standard.
A hospital employed physician has PHI access as part of her clinical role. The same physician's practice is also employed in a non-clinical administrative role at the hospital. Under HIPAA, when she accesses PHI for administrative purposes, what standard applies?
Answer: Access for administrative purposes must be limited to the minimum necessary for the administrative function
Even when a clinician performs administrative functions, PHI access for those functions must comply with the minimum necessary standard for administrative purposes.
Under HIPAA, what is an 'affiliated covered entity'?
Answer: Two or more legally separate covered entities under common ownership that may designate themselves as a single covered entity for HIPAA purposes
Affiliated covered entities are legally separate HIPAA-covered organizations under common ownership/control that may elect to be treated as a single covered entity, simplifying PHI sharing among affiliates.
Which of the following represents a covered entity's obligation under HIPAA when receiving a request for PHI from law enforcement?
Answer: Covered entities may only disclose PHI to law enforcement under specific circumstances without authorization and should disclose only what is required
HIPAA permits (but generally does not require) limited PHI disclosures to law enforcement under specific circumstances, and covered entities should disclose only what is specifically required.
A covered entity's employee discovers that a family member is a patient at their organization. Under HIPAA, what is the employee's obligation?
Answer: The employee must not access the family member's records unless they are directly involved in that person's care
Workforce members may not access PHI of patients they are not involved in treating — 'snooping' on family members' records is a HIPAA violation even with good intentions.
Under HIPAA, what must a covered entity provide to patients at first service delivery?
Answer: A Notice of Privacy Practices describing how the covered entity uses and discloses PHI
HIPAA requires covered entities to provide patients with a Notice of Privacy Practices (NPP) at first service delivery, explaining how their PHI will be used and protected.
Under HIPAA, what is a 'workforce member' for compliance purposes?
Answer: Employees, volunteers, trainees, and others whose conduct is under the direct control of the covered entity
HIPAA's definition of workforce includes all individuals under the covered entity's direct control — paid or unpaid, full or part-time, including volunteers and trainees.
A physician wants to share PHI with a patient's family member who is present during an office visit. Under HIPAA, what governs this disclosure?
Answer: The covered entity may share PHI with the family member if the patient is present and does not object, using professional judgment
HIPAA's Privacy Rule allows PHI disclosure to family members present during care when the patient does not object, using professional judgment about the patient's best interest.
What is the significance of HIPAA's 'treatment exception' to the minimum necessary standard?
Answer: Healthcare providers are not required to apply the minimum necessary standard when disclosing PHI to other providers for treatment purposes
HIPAA explicitly exempts disclosures to other healthcare providers for treatment purposes from the minimum necessary standard, recognizing that clinical care requires comprehensive information access.
A hospital patient asks to inspect their own medical records during their admission. Under HIPAA, what is the hospital's obligation?
Answer: The hospital must provide access within a reasonable timeframe, though access during admission may be deferred until after discharge
While HIPAA gives patients the right to access their records, hospitals may use reasonable operational provisions and provide access within 30 days post-request.
Under HIPAA, what are a covered entity's obligations when receiving a written patient request for amendment of PHI?
Answer: The covered entity must act on the amendment request within 60 days, and may deny it with specific required reasoning if the PHI is accurate and complete
HIPAA gives patients the right to request amendment of their PHI, but covered entities may deny requests if the information is accurate and complete, acting within 60 days.
A covered entity discloses PHI for public health activities. Under HIPAA, what activities are considered permissible public health disclosures?
Answer: Reporting communicable diseases, adverse events from products, child abuse, and vital statistics to authorized public health authorities
HIPAA permits PHI disclosure to public health authorities for disease surveillance, adverse event reporting, child abuse reporting, and vital statistics — without patient authorization.
Under HIPAA, what must a covered entity do to comply with the 'accounting of disclosures' requirement?
Answer: Maintain a record of disclosures made outside of treatment, payment, operations, and other exempt categories, available to patients upon request
HIPAA requires covered entities to track certain PHI disclosures (outside treatment/payment/operations and other exempt categories) and provide this accounting to patients upon request.
Under HIPAA, which type of healthcare provider is NOT required to provide a Notice of Privacy Practices to patients?
Answer: A healthcare clearinghouse that only processes data and has no direct patient relationships
Healthcare clearinghouses that process data without direct patient relationships are not required to provide NPPs to individuals because they have no patient-facing relationship.
What HIPAA requirement applies when a covered entity uses a specialized messaging system (like a patient portal) that allows patients to communicate with their providers?
Answer: The portal and its vendor must meet HIPAA security requirements, and the vendor must execute a BAA with the covered entity
Patient portal vendors handle PHI on behalf of the covered entity and are business associates requiring a BAA, with the portal itself needing to meet all HIPAA security requirements.
Under HIPAA, what is the covered entity's obligation when a patient requests their records be sent directly to a third party?
Answer: The covered entity must transmit records directly to the designated third party when the patient directs it, in a timely manner
HIPAA's right of access includes the right for patients to direct covered entities to transmit their PHI directly to a designated third party, which the covered entity must honor.