Healthcare Provider Obligations and Covered Entities Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Healthcare Provider Obligations and Covered Entities flashcards as text
A covered entity discovers that a business associate has experienced a breach of PHI. Who is primarily responsible for notifying affected individuals?
Answer: The covered entity is responsible for notifying affected individuals
Under the HIPAA Breach Notification Rule, the covered entity bears primary responsibility for notifying affected individuals, even when the breach occurred at a business associate.
A covered healthcare provider may share PHI with another provider for treatment purposes without patient authorization. This is an example of which type of HIPAA disclosure?
Answer: Permitted disclosure
Treatment disclosures between providers are permitted disclosures under HIPAA and do not require patient authorization.
Under HIPAA, what is the minimum necessary standard?
Answer: Covered entities must limit PHI access to the minimum necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to what is needed for the intended purpose.
Which of the following is an example of a covered entity's 'healthcare operations' that permits PHI use without patient authorization?
Answer: Conducting quality assessment and improvement activities
Quality assessment and improvement activities are specifically listed as healthcare operations under HIPAA, permitting PHI use without authorization.
A nurse accesses the medical records of a celebrity patient out of curiosity without a treatment need. This violates which HIPAA principle?
Answer: The minimum necessary standard and authorized access controls
Accessing PHI without a legitimate purpose violates the minimum necessary standard and workforce access control requirements under HIPAA.
How long must covered entities retain HIPAA-related documentation, such as policies and procedures?
Answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain documentation of policies, procedures, and actions for 6 years from the date of creation or the date it was last in effect.
A covered entity that operates both HIPAA-covered and non-covered components is known as what type of entity?
Answer: A hybrid entity
A hybrid entity is a single legal entity that performs both covered and non-covered functions and must designate its healthcare components for HIPAA compliance purposes.