HIPAA Training and Compliance

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/22

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:14 PM on 9/4/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

23 Terms

1
New cards

HIPAA

Health Insurance Portability and Accountability Act

2
New cards

Four Components of HIPAA

standardized electronic data transactions, data security standards, privacy protections, and standard national identifiers

<p>standardized electronic data transactions, data security standards, privacy protections, and standard national identifiers</p>
3
New cards

Privacy (HIPAA Definition)

the state of being concealed or secret

4
New cards

Confidentiality (HIPAA Definition)

containing private information, such as a patient’s medical record

5
New cards

Authorization (HIPAA)

a written document granting permission to use or disclose PHI for specific purposes

6
New cards

Disclosure vs. Use

disclosure is sharing PHI outside an entity; Use is handling PHI within an entity

7
New cards

Protected Health Information (PHI)

individually identifiable health data created or received by a covered entity

8
New cards

Examples of PHI

name, SSN, address, medical records, medical diagnoses, account numbers, and photos

9
New cards

Covered Entities (CE)

health plans, health care clearinghouses, and health care providers conducting electronic transactions

10
New cards

TPO

Treatment, Payment, and Health Care Operations (uses of PHI not requiring authorization)

11
New cards

Notice of Privacy Practice (NPP)

notice given to patients explaining how their PHI will be used and disclosed

12
New cards

Patient rights under HIPAA

rights to NPP, timely access/copies, amendment, restriction, disclosure accounting, and authorization revocation

13
New cards

HIPAA Privacy Rule Effective Date

April 14, 2003

14
New cards

Request for Amendment

patient’s written request to alter health records; CE can accept or deny

15
New cards

Accounting of Disclosures Timeline

a covered entity must respond to a written request within 60 days

16
New cards

Minimum Necessary Standard

requirement to disclose only the minimum amount of PHI needed to perform a job

17
New cards

Exceptions to Minimum Necessary Standard

treatment, disclosures to the patient, authorized disclosures, and disclosures required by law

18
New cards

Business Associate (BA)

a non-workforce person or entity performing functions involving PHI on behalf of a CE

19
New cards

Examples of Business Associates

third-party claims processors, CPA firms, medical transcriptionists, and pharmacy benefit managers

20
New cards

Incidental Disclosure

a secondary, unpreventable PHI disclosure occurring as a by-product of permitted use

21
New cards

HITECH Act (2009)

legislation adding privacy/security rules, breach reporting requirements, and increased non-compliance penalties

<p>legislation adding privacy/security rules, breach reporting requirements, and increased non-compliance penalties</p>
22
New cards

HITECH Breach Notification (>500 individuals)

requires reporting to affected individuals, the government, and prominent media outlets

23
New cards

Conflict Between State Law and HIPAA

follow whichever law provides greater privacy rights or protection to the patient