1/17
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
A Privacy Officer is one of HIPAA's Administrative Requirements.
true
True
Role-Based Access is a helpful tool that assists employees with compliance related to using the Minimum Necessary.
True
The privacy act is part of HIPAA
False
What type of information is not considered PHI?
Deidentified information.
Under the Privacy Rule, all types of health information are treated equally, regardless of their nature.
True
Which Title of HIPAA is most relevant for Health Information Management (HIM)?
Title 2 is the most relevant to HIM
The 2 Goals of the HIPAA Privacy Rule are also used in the Legal Doctrine of Preemption. They are used in order to decide if one requirement is stricter than another requirement.
True
A CE's Workforce is defined as those who receive a paycheck.
False
Which of the following is an example of a situation in which a disclosure is permitted without patient authorization, but the patient has the opportunity to informally agree or object?
Facility directory.
On what basis are Business Associates (BAs) obligated to comply with the law?
Based on the nature of the relationship and the nature of the work (using PHI).
How does the Privacy Rule refer to patients?
As individuals.
When using the Safe Harbor Method, which data element does not need to be removed to deidentify PHI?
Diagnoses.
What is an example of a Covered Entity (CE)?
A health plan.
What does mitigation refer to in the context of PHI?
The lessening of effects of a wrongful use or disclosure of PHI.
TPO
Functions of a CE that are necessary for the CE to successfully conduct business.
What does consent (per HIPAA) mean?
Obtaining patient permission to use or disclose PHI for TPO purposes (obtaining consent for TPO purposes is optional)
What is the difference between use and disclosure of PHI?
Use is sharing within a healthcare organization, while disclosure is the release of information outside of it.
What does NPP stand for and what does it explain?
NPP stands for Notice of Privacy Practices, which explains a patient's rights and the CE's legal duties with respect to PHI.