Ch. 4 Legal and Ethical Aspects of Cancer Registry Data (2)

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/36

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

37 Terms

1
New cards

Family Educational Rights and Privacy Act (FERPA)

One of the first federal laws to provide specific, statutory protection for patient privacy

2
New cards

Family Educational Rights and Privacy Act (FERPA)

Protects individual privacy from misuse of federal records

3
New cards

Family Educational Rights and Privacy Act (FERPA)

Allows persons to access their records

4
New cards

Family Educational Rights and Privacy Act (FERPA)

Allows federal agencies to collect, maintain, use, or disseminate any educational record containing personal information

5
New cards

FERPA established

The Privacy Protection Study Commission

6
New cards

The Privacy Protection Study Commission

Allows individuals to find out what information is collected, correct inaccurate information, and control disclosure of their information

7
New cards

Private Health Information (PHI)

Individually identifiable health information subject to regulatory protections of the Privacy Rule

8
New cards

Private Health Information (PHI)

eg. names, addresses, birthdates, SSN, phone numbers

9
New cards

Health Insurance Portability and Accountability Act (HIPAA)

Signed into law in 1996

10
New cards

Health Insurance Portability and Accountability Act (HIPAA)

Governs how PHI is used, who may use it, and the purpose for using it

11
New cards

Health Insurance Portability and Accountability Act (HIPAA)

Allows a covered entity to use or disclose PHI for various public health activities and purposes

12
New cards

Through HIPAA, the U.S. Department of Health and Human Services established

HIPAA Privacy Rule

13
New cards

HIPAA Privacy Rule

Protects all individually identifiable health information held or transmitted by a covered entity of its business associate

14
New cards

HIPAA Privacy Rule

Establishes national standards and allows the flow of health information

15
New cards

HIPAA Privacy Rule

Requires safeguards for PHI

16
New cards

HIPAA Privacy Rule

Sets limits and conditions on uses and disclosures made without an individuals authorization

17
New cards

HIPAA Privacy Rule

Gives patients the right to look at and obtain a copy of their health records

18
New cards

HIPAA Privacy Rule

PHI shall not be disclosed by covered entities without written, informed consent

19
New cards

HIPAA Privacy Rule

Applies to all PHI regardless of form

20
New cards

Health Information

Any information pertaining to the health or condition of an individual

21
New cards

Individually identifiable health information

Information that pertains to the provision of health care or demographic information

22
New cards

Covered entity

A healthcare plan, clearinghouse, or healthcare provider

23
New cards

Business Associate (BA)

A person or organization, not part of a covered entities workforce that performs functions involving PHI

24
New cards

Business Associate (BA)

eg. outside consultants, outside law firm, outside transcription service, “vendor” cancer registry staff

25
New cards

BA Agreement

Written agreement that identifies tasks for BA that involve PHI

26
New cards

BA Agreement

A hospital using non-employee vendors

27
New cards

HIPAA Security Rule

Establishes national standards to protect individual ePHI that is created, used, or maintained by a covered entity

28
New cards

HIPAA Security Rule

Specifies safeguards that covered entities and their business associates must implement

29
New cards

HIPAA Security Rule

Safeguards through administrative, physical, and technical

30
New cards

HIPAA Security Rule

Applies to electronic PHI

31
New cards

Encryption

Means of scrambling information that can only be unencrypted through an appropriate key or secure receiving app

32
New cards

Aggregate data

Data that do not contain any elements of PHI

33
New cards

Health Information Technology for Economic and Clinical Health (HITECH) Act

Promotes widespread adoption and interoperability of health information technology

34
New cards

HITECH Final Rule

Makes BA’s directly liable for compliance with certain aspects of HIPAA Rules

35
New cards

HITECH Final Rule

Increases limitations of use of PHI for fundraising and marketing

36
New cards

HITECH Final Rule

Gives authority to the Office of Civil Rights (OCR) to increase enforcement of HIPAA privacy violations

37
New cards

Breach

An impermissible use of disclosure under the Privacy Rule compromising the security or privacy of PHI