1/77
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What does HIPAA stands for?
Health Insurance Portability and Accountability Act
What is HIPAA
Landmark legislation designed to safeguard individuals’ health information and ensure its confidentiality, integrity, and availability. It applies to healthcare providers, health plans, and healthcare clearinghouses (covered entities), as well as BAs who handle PHI
What is the Security Rule?
Under HIPAA, it outlines specific safeguards that covered entites and their BAs must implement to protect ePHI. It includes administrative, physical and technical safeguards to ensure the confidentiality, integrity and security of ePHI
How long does a CE following a data breach under 500 impacted have to provide notification of the breach to the secretary of the Department of HHS
60 days after the end of the calendar year in which the braech occurred
This is known as HIPAA’s Breach Notification Rule
How many days does an entity have to respond to PHI copy request?
30 days
What is required when someone is collecting medical records on behalf of the patient?
written authorization from the patient
Is it a villation of HIPAa to call a patient’s name in the waiting room?
No
What is a responsibility a HIM professional have?
determining when an individual or entity has the right to access healthcare information in a hospital setting
How long does a patient have a right of access to inspect and obtain a copy of their PHI?
for as long as it is maintained
What is a custodian of health records
an individual within a healthcare entity who is responsible for testifying to the authenticity of records
What type of PHI requires a specific authorization for disclosure, must be explicity identified in the authorization and includes sensitive details?
psychotherapy notes
What is priviledged communication?
the confidential interactions between a patient and a healthcare provider are legallly protected from disclosure without the patiet’s consent. This includes conversations, medical records, and any other information shared furing the course of treatment
What does the minimum necessary rule states?
healthcare providers and other entities should only access, use or disclose minimum amount of PHI necessary to access a specific task
What type of information should be provided to individuals whose PHI las been breached
the types of unsecured PHI that was involved
What does a Professional Code of Ethics do for a pateint?
it holds the provider responsible for keeping health information private
What does security audits do?
records and examines the activity in information systems
What are access controls?
security measures used to regulate who can view, use, or modify info resources within a system
What are firewalls?
security devices situated between the routers of a private network and a public network to protect the private network from authorized users. They control external access to a network
What does Administrative Safeguards protect?
the management, policy, and procedural aspects of information security, ensuring that appropiate actions are taken to prevent, detect, contain, and correct security violations
What does Physical Safeguards protect?
the physical access to buildings, equipment and other physical resources to store or process sensitive information, preventing unauthorized physical tampering and theft
What does Technical Safeguards protect?
electronic HI should be ensured that only authorized users access it. These include measures like encryption, secure access controls, and audit controls
What does Security Safeguards protect?
overall integrity, confidentiality, and availability of information systemsand the data they contain, encompassing administrative, physical and technical measures
List identifiers under the Privacy Rule
Names
Geographic data smaller than a state (address, zip code)
alll elements of dates related to an individual (except year)
telephone numbers
fax numbers
email address
social security numbers
medical numbers
health plan beneficiary numbers
accont numbers
certificate/license numbers
vehicle identifiers and serial numbers
device numbers and serial numbers
web URLs
IP addresses
biometric identifiers (eye scan, face scan, fingerprints)
full face photographic images
What is Role-Based Access?
a security mechanism that grants system access based on an user’s role within a n organization, ensuring that individuals can only access information necessary for their job functions
What is Facility Access
the control measures inplemented to ensure that only authorized personnel can physically enter facilities where sensitive information is stored or processed, safe-guarding against unauthorized access and breaches
List examples of Facility Access:
a visitor sign-in sheet
What is confidentiality?
the obligation to PHI from unauthorized access and disclosure, ensuring that it is only available to those who have permission to view or use it
What is privacy?
The right of individuals to control the use, collection, and disclosure of their personal information, ensuring that it is kept secure and only shared with consent
What is security?
the practice of protecting information and IS from authorized access, use, disclosure, disruption, modification, or destruction to ensure confidentiality, integrity and availability
PHI does not require patient authorization to allow providers access, use or disclosure when:
it is used for the purpose of treatment, payment or operation
List situations where PHI can be disclosed without patient authorization:
treatment, payment and healthcare operations
public health activities
health oversight activities
judicial and administrative proceedings
law enforcement purposes
emergencies
research under certain conditions
worker’s compensation
What is the HITECH Act
Health Information Technology for Economic and Clinical Health (HITECH)
is part of the American Recovery and Reinvestment Act of 2009; it promotes the adoption and meaningful use of EHRs and strengthens the privacy and security protections or HI est. under HIPAA. HITECH also introduces provisions for breach notification requirements and increased penalties for HIPAA violations
According to HITECH, an accounting of disclosures may include disclosures made during the previous ____ years
3 years
What is phising
a cybercrime tactic where fraudulent emails, messages, or websites are used to trick individuals into revealing sensitive information such as usernames, passwords, or financial details
What is ransomware?
Malicious software that encrypts a user’s data and demands payment (a ransom) in exchange for decrypting it. It can severely disrupt operations and cause loss if not mitigated promptly
What is a virus?
a type of malicious software that replicates itself by inserting copies of its code into ther computer programs, files, or systems, often causing damage to data, disrupting normal operations
What is a bot?
a software that performs automated tasks on the internet, often human interaction. Bots ca n be used for legit purposes (search engine crawling) or malicious activities (lauching DDoS attacks)
What is a trojan horse?
a type of malware disguised as legit software. Once installed, it can perform various harmful attacks, such as stealing data, spying on users, or providing unauthorized access to the system
What information can be given out when a patient is part of the facility directory?
general condition and acknowledgment of admission
Are the most common security threats internal or external to the healthcare entity?
Internal (threats or breaches caused in house)
What is a utilization review?
a process used by healthcare organizations to evaluate the necessity, appropriateness, and efficiency of medical services and treatments provided to patients
it involves reviewing medical records, treatment plans, and outcomes to ensure healthcare resources are used effectively and in accordance with established standards of care
A utilization review is an example of:
use
What is Workforce security awareness training do for employees?
it educates about cybersecurity risks, best practices, and organizational policies. it aims to enhance understanding of potential threats such as phising, malware, social engineering and data breaches`
What is a local area network?
a network that connects computers and devices within a limited geographic ares (home, school, office), allowing them to communicate and share resources
What is a virtual private network (VPN)?
a secure connection over the internet that encrypts data, providing privacy and security for online activities by creating a private network from a public internet connection
What is intranet?
a private network accessible only to an organization’s staff often used to share internal information and applications securely
What is extranet?
a network made accessible to trusted individuals outside of the facility
What is wide area network (WAN)?
telecommunications network that spans a large geographical area, connecting multiple local networks or devices
What are disclosures?
the act of revealing, releasing, transferring, providing access to, or divulging PHI to another party outside of the entity holding the information
What is verification?
the process of ensuring that something is true, accurate, or compliant with established criteria, standards, or requirements
How is verification useful in HIM?
verification plays a crucial role in ensuring the integrity, accuracy, security of HI
What is Res judicata?
a legal principle that prevents the same parties from litigating the same causes of action or claim that has already been decided by a final judgement; means “a matter judged”
What is Respondeat superior
a legal doctrine that holds an employer or principal legally responsible for the wrongful acts of omissions committed by an employee or agent during the course of employment or agency. It means “let the master answer” in Latin
What is Restitutio in integrum
a legal principle that aims to restore an injurred party to tjhe condition they were in before suffering harm or loss, typically through compensation or restitution.
it means “restoration to original condition” in Latin
What is redisclosure
the sharing of HI by an entity that received it from another source.
it involves passing on the data to a third party, often requiring patient consent and adherence to privacy regulations
True of False:
Under HIPAA, written authorizatino from a patient is required whenever it is being used for reasons unrelated to treatment, payment, and operations
True
What is a legal hold?
special, tracked handling of patient records involved in litigation to ensure no changes can be made
What is a designated record set?
a group of records maintained by or for a healthcare provider that includes medical and billing records about individuals and any other records used to make decisions about patients
What is e-Discovery?
the process of identifying, collecting and producing electronically stored information (ESI) in response to a legal request or investigation. This includes emails, documents, databases, voicemails, and other digital data that could be relevant to legal proceedings
What is a trigger flag?
an alret or indicator in an IS that signals the occurrence of a specific event or condition, prompting a predefined response or action
it can be used to alert providers to potential issues such as medication interactions, abnormal lab results, or conditions requiring immediate attention
What is a subpoena?
a direct command that requires an individual or a representative of a healthcare entity to appear in court or to present an object to the court
What is a judicial decision?
a formal ruling or judgement made by a court of law or judicial authority in a legal case or matter. It outlines the court’s findings, conclusions and orders based on the interpretation and application of laws and evidence presented during legal proceedings
What does it mean for a state law to be stringent?
the law is strict, rigorious, or demanding in its requirements, regulations, or penalties
What is a patient portal?
a securre method of communicating between a provider and the patient; available for 24 hours online adn provides patient’s PHI
Clinician web portals are used by physicians to ____
access multiple sources to patient information within the healthcare organization’s network
What is a workforce member?
anyone who performs work for a healthcare entity, including employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a CE or BA, is under the direct control of such entity or associate
OCR HIPAA Civil Monetary Penalty
Tier 1 (A) Did not know
Each Violation: $100
Annual Cap: $25,000
Tier 2 (B) Reasonable cause
Each Violation: $1,000
Annual Cap: $100,000
Tier 3 (C)(i) Willful neglect - corrected
Each Violation: $10,000
Annual Cap: $250,000
Tier 4 (C)(ii) Willful neglect - not corrected
Each Violation: $10,000
Annual Cap: 1.5 million
What is reasonable cause?
an act or omission in which a CE or BA knew, orby exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the CE or BA did not act with willful neglect
What is willful neglect?
conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated
What is the Omnibus Rule
first enacted in 2003; it strengthens teh privacy and security of patient HI, modifies the Breach Notification Rule, strengthen privacy protections for genetic information by prohibiting health plans from using or disclosig such information for underwriting, makes BAs of HIPAA-covered entities liable for compliance, strengthens limitations on the use and disclosure of PHI for marketing, research and fundraising, and allows patients increased restriction rights
What is a breach?
an acquisition, access, use, or disclosure of PHI in a manner not permitted
A risk assessment should be conducted to determine if a breach has occurred. The risk assessment should address what factors?
the nature and extent of the PHI involved in the breach, including the types of identifiers and likelihood of hte reidentification
the unauthorized person/people who used the PHI or whom it was disclosed
whether the PHI was viewed, acquired, or redisclosed
the extent to which the risk to the PHI has been mitigated
What are the three exceptions to the Breach Notification Rule?
the PHI disclosure was not intentional and the individuals that received the information have the requirement to keep the information confidential
access to the PHI was unintentional by a workforce member and the person receiving the information has a right by the person receiving it
The healthcare organization believes in good faith that the PHI could not have been retained by the person receiving it
List examples how authorizations may be considered defective under the HIPAA Privacy Rule
the expiration date has passed or occurred
the authorization was not completely filled out
the authorization has been revoked
any required elements defined here are missing
the authorization is combined with any other documentation to create a compound authorization except where permitted
the facility knows that the material information included is false
What are accounting of disclosures
information that describes a CE’s disclosures of PHI other than TPO (treatment, payment, and healthcare operations), disclosures with authorizations, and certain other limited disclosures
What is deidentification?
HI that has had identifiers removed so there is not the capability to reasonably identify the person to which the information belongs
What are the two methods of deidentification?
Expert Determination Method - data elements that could identify an individual are removed from the data and then an expert the organization hires applies scientific methodology to determine the likelihood of identification of the individual and provides documentation of the probability that the information would be identified
a low probability means the data has been deidentified
a high probability means more data elements needs to be removed
Safe Harbor Method - requires the CE/BA to remove 18 data elements from the HI. This can include demographic data, geographical data, and any identifierslisted in the Privacy Rule
What is reidentification
the process of reidentifying information by applying a specific code other means