Healthcare Provider Obligations and Covered Entities Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Healthcare Provider Obligations and Covered Entities flashcards as text
A small solo-practice physician transmits claims electronically to Medicare. Under HIPAA, this physician is classified as:
Answer: A covered entity
Any healthcare provider that transmits health information electronically in connection with HIPAA-covered transactions is a covered entity.
Which of the following healthcare providers is NOT required to comply with HIPAA because they do not conduct covered electronic transactions?
Answer: A cash-only psychiatrist who never files insurance claims
A provider that conducts no HIPAA-covered electronic transactions is not a covered entity and has no HIPAA compliance obligation.
Under the HIPAA Privacy Rule, a covered entity must provide patients with a Notice of Privacy Practices (NPP) at what point?
Answer: No later than the date of first service delivery
Covered entities must provide the NPP no later than the date of first service delivery to a patient.
A hospital outsources its medical transcription to a company that will create and store PHI. What agreement must the hospital obtain before sharing PHI with this company?
Answer: A business associate agreement (BAA)
Covered entities must execute a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on their behalf.
Which entity type may voluntarily choose to be treated as a covered entity under HIPAA even if not strictly required?
Answer: A non-covered provider
A non-covered provider may voluntarily comply with HIPAA, often to facilitate electronic transactions with covered entities.
A health plan that is self-administered and has fewer than how many participants is exempt from the HIPAA Privacy Rule?
Answer: 50
Self-administered health plans with fewer than 50 participants are exempt from the HIPAA Privacy Rule.
When a covered entity undergoes a merger with another covered entity, what happens to their HIPAA obligations regarding existing BAAs?
Answer: The surviving entity assumes responsibility for existing BAAs
The surviving entity in a merger assumes the HIPAA obligations, including existing Business Associate Agreements, of both predecessor entities.