HIPAA and Patient Privacy Rights Flashcards
6 cards from real NCMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 HIPAA and Patient Privacy Rights flashcards as text
Under HIPAA, what is a 'Business Associate Agreement' (BAA) and when is it required?
Answer: A contract required when a covered entity shares PHI with a third-party vendor or service provider that performs functions on its behalf
A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity and any business associate (third party) that creates, receives, maintains, or transmits PHI on behalf of the covered entity. Examples include EHR vendors, billing companies, and shredding services.
What are the three HIPAA safeguard categories under the Security Rule, which applies specifically to electronic PHI (ePHI)?
Answer: Administrative, physical, and technical safeguards
HIPAA's Security Rule requires covered entities to implement three types of safeguards for ePHI: Administrative (policies, training, risk analysis), Physical (facility access controls, workstation security, device controls), and Technical (access controls, audit controls, encryption).
A medical assistant overhears a colleague discussing a patient's HIV status in the hospital cafeteria with another colleague. What is the appropriate action?
Answer: Politely remind the colleagues that discussing PHI in public areas violates HIPAA and report the incident to the privacy officer if necessary
Discussing identifiable patient information in public spaces (cafeteria, elevators, hallways) violates HIPAA even among healthcare workers. The minimum necessary standard and incidental disclosure rules prohibit unnecessary sharing of PHI in public areas.
Under HIPAA, what must a covered entity do when a data breach affects 500 or more individuals?
Answer: Notify affected individuals, provide notice to prominent media outlets in affected states, and report to HHS (OCR) within 60 days of breach discovery
HIPAA's Breach Notification Rule for breaches affecting 500+ individuals requires: notification to affected individuals within 60 days, notice to prominent media outlets in affected states, and immediate notification to HHS OCR (which posts breaches publicly on the 'Wall of Shame').
A patient requests that the medical office NOT share their PHI with their health insurance plan for a specific service they paid for entirely out of of-pocket. Under HIPAA, what must the covered entity do?
Answer: Honor the restriction request — this is a mandatory restriction covered entities must comply with under the HITECH Act
The HITECH Act (2009) amended HIPAA to mandate that covered entities must honor a patient's request to restrict disclosure to a health plan when: (1) the restriction applies to a specific item or service, AND (2) the patient has paid for the service in full out-of-pocket.
Which federal law supplements HIPAA by providing additional privacy protections specifically for substance use disorder (SUD) treatment records?
Answer: 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records)
42 CFR Part 2 provides stricter privacy protections for records of patients treated in federally assisted substance use disorder (SUD) programs. It generally requires patient consent even for disclosures permitted under HIPAA (e.g., for treatment purposes to other providers).