Healthcare Provider Obligations and Covered Entities Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Healthcare Provider Obligations and Covered Entities flashcards as text
A covered entity that fails to enter into a BAA with a known business associate and a breach occurs may face penalties under which category?
Answer: Willful neglect — not corrected
Failing to obtain a required BAA while knowing the obligation exists constitutes willful neglect, and if uncorrected, the highest penalty tier applies.
Under HIPAA, which of the following scenarios requires a covered entity to obtain written patient authorization before using or disclosing PHI?
Answer: Using PHI for the covered entity's own fundraising activities
Using PHI for fundraising requires patient authorization unless the covered entity limits the information disclosed and provides an opt-out mechanism.
A covered healthcare provider wants to share PHI with a patient's family member who is present during a visit. What is required under HIPAA?
Answer: The provider may share relevant information if the patient does not object
Covered entities may share PHI with persons involved in a patient's care when the patient is present and does not object, or when it is reasonably inferred that the patient would not object.
Which of the following must be included in a covered entity's Notice of Privacy Practices (NPP)?
Answer: A description of the types of uses and disclosures the entity may make
The NPP must describe the types of uses and disclosures the covered entity may make of PHI, as well as patient rights and the entity's legal duties.
A hospital's workforce member discloses PHI by accidentally faxing records to the wrong physician's office. This may qualify as what type of event under HIPAA?
Answer: A breach subject to the Breach Notification Rule unless an exception applies
A misdirected fax containing PHI is a potential breach; the covered entity must perform a risk assessment to determine if notification is required.
Under HIPAA, which of the following is considered a 'covered transaction' that triggers compliance requirements?
Answer: An electronic submission of a health care claim to an insurance plan
Electronic submission of health care claims (Transaction 837) is one of the standard HIPAA-covered transactions that triggers compliance obligations.
A covered entity that is also a hybrid entity must ensure that its designated healthcare components comply with HIPAA. What must the entity do with its non-healthcare components?
Answer: Erect firewalls to prevent non-covered components from accessing PHI held by the healthcare components
Hybrid entities must erect appropriate firewalls between covered healthcare components and non-covered components to prevent unauthorized PHI flows.