Basics
Definitions
Duties
Breach Notifications
Authorizations
100

What is the acronym for Protected Health Information?


PHI

100

Information which can lead to the identification of an individual such as name, date of birth, social security number, diagnosis, medical record number, or any other clearly identifying documentation in a health record are examples of _______.


Protected Health Information (PHI)

100

All healthcare providers are required by law to maintain and distribute a notice that describes their HIPAA ________ practices.

Privacy

100

If a breach of privacy actually took place, notice of breach must be provided to the individuals whose _____________ was released.

Protected Health Information (PHI)

100

An _______________ is required by the Privacy Rule for uses and disclosures of protected health information (PHI) not otherwise allowed by the Rule.

Authorization

200

What is the acronym for Health Insurance Portability and Accountability Act?

HIPAA

200

The Privacy Rule set national standards for the protection of individually identifiable health information by three types of _________ entities: health plans, healthcare clearinghouses, and healthcare providers who conduct the standard healthcare transactions electronically.  

Covered

200

Documents containing Protected Health Information (PHI) must be _________ when discarded.

Destroyed

200

No breach notice is necessary if there is a ______ probability that the PHI was received or viewed.

Low

200

Where the Privacy Rule requires patient authorization, voluntary ___________ is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization.

Consent

300

You may not discuss or disclose any _______ that you learn in performing your job with anyone who does not need to know the information (co-workers not caring for the resident, friends, family, etc.).

PHI (Protected Health Information)

300

"Impermissible use or disclosure" is always presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a ______ probability that the PHI has been compromised.

Low

300

Documentation containing Protected Health Information (PHI) must be covered or out of ________ of casual observers.

Sight

300

Notice to the news media can be done by issuing a timely _________ release.  

Press

300

An authorization must specify a number of elements, including a description of the protected health information to be used and disclosed, the person authorized to make the use or disclosure, the person to whom the covered entity may make the disclosure, an _____________ date, and, in some cases, the purpose for which the information may be used or disclosed.

Expiration

400

HIPAA places an obligation on all healthcare providers to use “appropriate ____________” to protect PHI.

Safeguards

400

An expansion of the HIPAA Privacy Rule which extends the same confidentiality requirements to all contractors or other business associates of a healthcare provider who might have access to Protected Health Information (PHI) is known as the ________ Rule. Such associates can include, for example, billing services, payment handlers, or medical staff contracted from outside.

HITECH

400

A facility must ensure that all partner companies have a business associate agreement that addresses all the ________ Rules.

Privacy

400

When any breach occurs, the healthcare provider must conduct a risk assessment within ____ days to determine the exact nature of the data released, who received or used it, and if the data was viewed by unauthorized persons.

30

400

The Privacy Rule gives individuals the right to revoke, at any time, an Authorization they have given. The revocation must be in writing, and is not effective until the covered entity ____________ it.

Receives

500

All patients of healthcare providers have the right to check the _____________ rights of any individual requesting their protected health information (PHI).

Authorization

500

An ____________ is a detailed document that gives covered entities permission to use protected health information (PHI) for specified purposes, which are generally other than treatment, payment, or healthcare operations, or to disclose protected health information to a third party specified by the individual.

Authorization

500

Remain up-to-date on laws, rules, and regulations regarding data privacy and update policies and _____________ as necessary.

Procedures

500

Business associate agreements must stipulate that associates notify the healthcare provider as soon as reasonable, but no later than ____ days, after a breach.

60

500

Under the Privacy Rule, a covered entity may use or disclose protected health information pursuant to a copy of a valid and signed Authorization, including a copy that is received by facsimile or electronically ______________.

Transmitted

Click to zoom
M
e
n
u