RHIA Exam: Rapid Facts for Success - Domain 2: Compliace with Access, Use and Disclosure of HI

0.0(0)
Studied by 6 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/77

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:49 PM on 4/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

78 Terms

1
New cards

What does HIPAA stands for?

Health Insurance Portability and Accountability Act

2
New cards

What is HIPAA

Landmark legislation designed to safeguard individuals’ health information and ensure its confidentiality, integrity, and availability. It applies to healthcare providers, health plans, and healthcare clearinghouses (covered entities), as well as BAs who handle PHI

3
New cards

What is the Security Rule?

Under HIPAA, it outlines specific safeguards that covered entites and their BAs must implement to protect ePHI. It includes administrative, physical and technical safeguards to ensure the confidentiality, integrity and security of ePHI

4
New cards

How long does a CE following a data breach under 500 impacted have to provide notification of the breach to the secretary of the Department of HHS

60 days after the end of the calendar year in which the braech occurred

This is known as HIPAA’s Breach Notification Rule

5
New cards

How many days does an entity have to respond to PHI copy request?

30 days

6
New cards

What is required when someone is collecting medical records on behalf of the patient?

written authorization from the patient

7
New cards

Is it a villation of HIPAa to call a patient’s name in the waiting room?

No

8
New cards

What is a responsibility a HIM professional have?

determining when an individual or entity has the right to access healthcare information in a hospital setting

9
New cards

How long does a patient have a right of access to inspect and obtain a copy of their PHI?

for as long as it is maintained

10
New cards

What is a custodian of health records

an individual within a healthcare entity who is responsible for testifying to the authenticity of records

11
New cards

What type of PHI requires a specific authorization for disclosure, must be explicity identified in the authorization and includes sensitive details?

psychotherapy notes

12
New cards

What is priviledged communication?

the confidential interactions between a patient and a healthcare provider are legallly protected from disclosure without the patiet’s consent. This includes conversations, medical records, and any other information shared furing the course of treatment

13
New cards

What does the minimum necessary rule states?

healthcare providers and other entities should only access, use or disclose minimum amount of PHI necessary to access a specific task

14
New cards

What type of information should be provided to individuals whose PHI las been breached

the types of unsecured PHI that was involved

15
New cards

What does a Professional Code of Ethics do for a pateint?

it holds the provider responsible for keeping health information private

16
New cards

What does security audits do?

records and examines the activity in information systems

17
New cards

What are access controls?

security measures used to regulate who can view, use, or modify info resources within a system

18
New cards

What are firewalls?

security devices situated between the routers of a private network and a public network to protect the private network from authorized users. They control external access to a network

19
New cards

What does Administrative Safeguards protect?

the management, policy, and procedural aspects of information security, ensuring that appropiate actions are taken to prevent, detect, contain, and correct security violations

20
New cards

What does Physical Safeguards protect?

the physical access to buildings, equipment and other physical resources to store or process sensitive information, preventing unauthorized physical tampering and theft

21
New cards

What does Technical Safeguards protect?

electronic HI should be ensured that only authorized users access it. These include measures like encryption, secure access controls, and audit controls

22
New cards

What does Security Safeguards protect?

overall integrity, confidentiality, and availability of information systemsand the data they contain, encompassing administrative, physical and technical measures

23
New cards

List identifiers under the Privacy Rule

Names

Geographic data smaller than a state (address, zip code)

alll elements of dates related to an individual (except year)

telephone numbers

fax numbers

email address

social security numbers

medical numbers

health plan beneficiary numbers

accont numbers

certificate/license numbers

vehicle identifiers and serial numbers

device numbers and serial numbers

web URLs

IP addresses

biometric identifiers (eye scan, face scan, fingerprints)

full face photographic images

24
New cards

What is Role-Based Access?

a security mechanism that grants system access based on an user’s role within a n organization, ensuring that individuals can only access information necessary for their job functions

25
New cards

What is Facility Access

the control measures inplemented to ensure that only authorized personnel can physically enter facilities where sensitive information is stored or processed, safe-guarding against unauthorized access and breaches

26
New cards

List examples of Facility Access:

a visitor sign-in sheet

27
New cards

What is confidentiality?

the obligation to PHI from unauthorized access and disclosure, ensuring that it is only available to those who have permission to view or use it

28
New cards

What is privacy?

The right of individuals to control the use, collection, and disclosure of their personal information, ensuring that it is kept secure and only shared with consent

29
New cards

What is security?

the practice of protecting information and IS from authorized access, use, disclosure, disruption, modification, or destruction to ensure confidentiality, integrity and availability

30
New cards

PHI does not require patient authorization to allow providers access, use or disclosure when:

it is used for the purpose of treatment, payment or operation

31
New cards

List situations where PHI can be disclosed without patient authorization:

treatment, payment and healthcare operations

public health activities

health oversight activities

judicial and administrative proceedings

law enforcement purposes

emergencies

research under certain conditions

worker’s compensation

32
New cards

What is the HITECH Act

Health Information Technology for Economic and Clinical Health (HITECH)

is part of the American Recovery and Reinvestment Act of 2009; it promotes the adoption and meaningful use of EHRs and strengthens the privacy and security protections or HI est. under HIPAA. HITECH also introduces provisions for breach notification requirements and increased penalties for HIPAA violations

33
New cards

According to HITECH, an accounting of disclosures may include disclosures made during the previous ____ years

3 years

34
New cards

What is phising

a cybercrime tactic where fraudulent emails, messages, or websites are used to trick individuals into revealing sensitive information such as usernames, passwords, or financial details

35
New cards

What is ransomware?

Malicious software that encrypts a user’s data and demands payment (a ransom) in exchange for decrypting it. It can severely disrupt operations and cause loss if not mitigated promptly

36
New cards

What is a virus?

a type of malicious software that replicates itself by inserting copies of its code into ther computer programs, files, or systems, often causing damage to data, disrupting normal operations

37
New cards

What is a bot?

a software that performs automated tasks on the internet, often human interaction. Bots ca n be used for legit purposes (search engine crawling) or malicious activities (lauching DDoS attacks)

38
New cards

What is a trojan horse?

a type of malware disguised as legit software. Once installed, it can perform various harmful attacks, such as stealing data, spying on users, or providing unauthorized access to the system

39
New cards

What information can be given out when a patient is part of the facility directory?

general condition and acknowledgment of admission

40
New cards

Are the most common security threats internal or external to the healthcare entity?

Internal (threats or breaches caused in house)

41
New cards

What is a utilization review?

a process used by healthcare organizations to evaluate the necessity, appropriateness, and efficiency of medical services and treatments provided to patients

it involves reviewing medical records, treatment plans, and outcomes to ensure healthcare resources are used effectively and in accordance with established standards of care

42
New cards

A utilization review is an example of:

use

43
New cards

What is Workforce security awareness training do for employees?

it educates about cybersecurity risks, best practices, and organizational policies. it aims to enhance understanding of potential threats such as phising, malware, social engineering and data breaches`

44
New cards

What is a local area network?

a network that connects computers and devices within a limited geographic ares (home, school, office), allowing them to communicate and share resources

45
New cards

What is a virtual private network (VPN)?

a secure connection over the internet that encrypts data, providing privacy and security for online activities by creating a private network from a public internet connection

46
New cards

What is intranet?

a private network accessible only to an organization’s staff often used to share internal information and applications securely

47
New cards

What is extranet?

a network made accessible to trusted individuals outside of the facility

48
New cards

What is wide area network (WAN)?

telecommunications network that spans a large geographical area, connecting multiple local networks or devices

49
New cards

What are disclosures?

the act of revealing, releasing, transferring, providing access to, or divulging PHI to another party outside of the entity holding the information

50
New cards

What is verification?

the process of ensuring that something is true, accurate, or compliant with established criteria, standards, or requirements

51
New cards

How is verification useful in HIM?

verification plays a crucial role in ensuring the integrity, accuracy, security of HI

52
New cards

What is Res judicata?

a legal principle that prevents the same parties from litigating the same causes of action or claim that has already been decided by a final judgement; means “a matter judged”

53
New cards

What is Respondeat superior

a legal doctrine that holds an employer or principal legally responsible for the wrongful acts of omissions committed by an employee or agent during the course of employment or agency. It means “let the master answer” in Latin

54
New cards

What is Restitutio in integrum

a legal principle that aims to restore an injurred party to tjhe condition they were in before suffering harm or loss, typically through compensation or restitution.

it means “restoration to original condition” in Latin

55
New cards

What is redisclosure

the sharing of HI by an entity that received it from another source.

it involves passing on the data to a third party, often requiring patient consent and adherence to privacy regulations


56
New cards

True of False:

Under HIPAA, written authorizatino from a patient is required whenever it is being used for reasons unrelated to treatment, payment, and operations

True

57
New cards

What is a legal hold?

special, tracked handling of patient records involved in litigation to ensure no changes can be made

58
New cards

What is a designated record set?

a group of records maintained by or for a healthcare provider that includes medical and billing records about individuals and any other records used to make decisions about patients

59
New cards

What is e-Discovery?

the process of identifying, collecting and producing electronically stored information (ESI) in response to a legal request or investigation. This includes emails, documents, databases, voicemails, and other digital data that could be relevant to legal proceedings

60
New cards

What is a trigger flag?

an alret or indicator in an IS that signals the occurrence of a specific event or condition, prompting a predefined response or action

it can be used to alert providers to potential issues such as medication interactions, abnormal lab results, or conditions requiring immediate attention

61
New cards

What is a subpoena?

a direct command that requires an individual or a representative of a healthcare entity to appear in court or to present an object to the court

62
New cards

What is a judicial decision?

a formal ruling or judgement made by a court of law or judicial authority in a legal case or matter. It outlines the court’s findings, conclusions and orders based on the interpretation and application of laws and evidence presented during legal proceedings

63
New cards

What does it mean for a state law to be stringent?

the law is strict, rigorious, or demanding in its requirements, regulations, or penalties

64
New cards

What is a patient portal?

a securre method of communicating between a provider and the patient; available for 24 hours online adn provides patient’s PHI

65
New cards

Clinician web portals are used by physicians to ____

access multiple sources to patient information within the healthcare organization’s network

66
New cards

What is a workforce member?

anyone who performs work for a healthcare entity, including employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a CE or BA, is under the direct control of such entity or associate

67
New cards

OCR HIPAA Civil Monetary Penalty

Tier 1 (A) Did not know

  • Each Violation: $100

  • Annual Cap: $25,000


Tier 2 (B) Reasonable cause

  • Each Violation: $1,000

  • Annual Cap: $100,000


Tier 3 (C)(i) Willful neglect - corrected

  • Each Violation: $10,000

  • Annual Cap: $250,000


Tier 4 (C)(ii) Willful neglect - not corrected

  • Each Violation: $10,000

  • Annual Cap: 1.5 million


68
New cards

What is reasonable cause?

an act or omission in which a CE or BA knew, orby exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the CE or BA did not act with willful neglect

69
New cards

What is willful neglect?

conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated

70
New cards

What is the Omnibus Rule

first enacted in 2003; it strengthens teh privacy and security of patient HI, modifies the Breach Notification Rule, strengthen privacy protections for genetic information by prohibiting health plans from using or disclosig such information for underwriting, makes BAs of HIPAA-covered entities liable for compliance, strengthens limitations on the use and disclosure of PHI for marketing, research and fundraising, and allows patients increased restriction rights

71
New cards

What is a breach?

an acquisition, access, use, or disclosure of PHI in a manner not permitted

72
New cards

A risk assessment should be conducted to determine if a breach has occurred. The risk assessment should address what factors?

  1. the nature and extent of the PHI involved in the breach, including the types of identifiers and likelihood of hte reidentification

  2. the unauthorized person/people who used the PHI or whom it was disclosed

  3. whether the PHI was viewed, acquired, or redisclosed

  4. the extent to which the risk to the PHI has been mitigated


73
New cards

What are the three exceptions to the Breach Notification Rule?

  1. the PHI disclosure was not intentional and the individuals that received the information have the requirement to keep the information confidential

  2. access to the PHI was unintentional by a workforce member and the person receiving the information has a right by the person receiving it

  3. The healthcare organization believes in good faith that the PHI could not have been retained by the person receiving it


74
New cards

List examples how authorizations may be considered defective under the HIPAA Privacy Rule

the expiration date has passed or occurred

the authorization was not completely filled out

the authorization has been revoked

any required elements defined here are missing

the authorization is combined with any other documentation to create a compound authorization except where permitted

the facility knows that the material information included is false

75
New cards

What are accounting of disclosures

information that describes a CE’s disclosures of PHI other than TPO (treatment, payment, and healthcare operations), disclosures with authorizations, and certain other limited disclosures

76
New cards

What is deidentification?

HI that has had identifiers removed so there is not the capability to reasonably identify the person to which the information belongs

77
New cards

What are the two methods of deidentification?

Expert Determination Method - data elements that could identify an individual are removed from the data and then an expert the organization hires applies scientific methodology to determine the likelihood of identification of the individual and provides documentation of the probability that the information would be identified

  • a low probability means the data has been deidentified

  • a high probability means more data elements needs to be removed


Safe Harbor Method - requires the CE/BA to remove 18 data elements from the HI. This can include demographic data, geographical data, and any identifierslisted in the Privacy Rule

78
New cards

What is reidentification

the process of reidentifying information by applying a specific code other means