CDAP Midterm 1 - HIPAA and HITECH

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/31

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

32 Terms

1
New cards

What is HIPAA

Establishes national standards for the protection of the protected health information and electronic protected health information

2
New cards

HIPAA Privacy act

National standards for the protection of medical records and other personal health information

3
New cards

Purpose of HIPAA privacy act

strike a balance between the need to share information for the provision of quality healthcare and the need to protect patient privacy

4
New cards

Covered entities

Health plan, healthcare clearing houses, and health care providers who transmit health information electronically

5
New cards

Protected health information (PHI)

Encompasses all identifiable health information held or covered by a covered entity

6
New cards

What must the HIPAA privacy act do

Implement reasonable safeguards to protect the privacy of PHI

7
New cards

What are patient’s rights

They have the right to access their PHI, request corrections, and obtain disclosures of info

8
New cards

HIPAA security rule

Designed to protect electronic protected health information

9
New cards

Administrative safeguard

Policies and procedures to protect electronic PHI and ensure compliance with HIPAA regulations.

10
New cards

What are the three safeguards for the HIPAA security act

Administrative, physical, and technical

11
New cards

Physical safeguard

measures to protect electronic PHI by controlling physical access to facilities and equipment.

12
New cards

technical safeguard

Allow only authorized individuals to access PHI

13
New cards

Risk control

Allow an organization to recognize and minimize vulnerabilities and threats to EPHI

14
New cards

ePHI standards

Identify where your oganization comes into contact with PHI and develop clear step by step orcedures that comply with HIPAA

15
New cards

Implementation

bringing these policies and procedures to life using training or monitoring

16
New cards

What does every member of an organization need to understand?

policies and procedures and potential consequences of violations

17
New cards

Sanctions

Enforcing compliance when violations to HIPAA occur and for deterring future violations

18
New cards

HITECH Act

Enhances the existing regulations and sanctions with increased penalties for non-compliance. Also covers HIPAA to more health care providers

19
New cards

Tiered penalty system

Based on the level of willfulness of violation. Penalties increase with level of negligence

20
New cards

Breach notification rule

Requires covered entities and business associates to notify individuals and the government of any breach of unsecured protected health information.

21
New cards

Purpose of breach notification rule?

To promote transparency and accountability in case of a breach of phi

22
New cards

What is the purpose of risk analysis and risk assessment

To identify and mitigate potential risks to PHI and ePHI, ensuring compliance with HIPAA regulations.

23
New cards

Risk analysis

process of identifying potential threats and vulnerabilities that could negatively impact the integrity, availability, and confidentiality of PHI and ePHI

24
New cards

Risk assessment

Evaluates the likelihood and impact of potential risks, helping you prioritize your resources and efforts in safeguarding data

25
New cards

Steps in risk assessment

Gather and document all data, identify potential threats, assess potential vulnerabiliites, determine the likelhihood, prioritize them, develop a risk management plan

26
New cards

Why is it important to monitor and report

It’s important to look out for vulnerabilities and potential threats as technology advances

27
New cards

Compliance monitoring

Process of routinely reviewing and checking to ensure that the standards and procedures of the compliance program are being followed

28
New cards

Purpose of compliance monitoring

Ensures ongoing adherence to regulations and identify areas of improvement

29
New cards

Compliance reporting

documenting and communicating results of compliance monitoring activities

30
New cards

Purpose of compliance reporting

maintains transparency and provides a record of efforts, helps organizations understand effectiveness

31
New cards

PHI

protected health information

32
New cards

ePHI

electronic protected health information