578 quizes Flashcards

1
Q

The Freedom of Information Act (FOIA) applies to:

A

Federal agency records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following accreditation organizations focuses on health and human service providers?

A

The Commission on Accreditation of Rehabilitation Facilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Changes to HIPAA are included in:

A

HITECH

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The Medicare Conditions of Participation:

A

Regulate only providers who receive Medicare and Medicaid reimbursement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The Drug Abuse Prevention, Treatment, and Rehabilitation Act of 1972:

A

Is a federal law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The Federal Register:

A

Is a daily publication of the federal government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A notice of proposed rulemaking (NPRM) is:

A

Publication of a proposed rule in the Federal Register

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An administrative rule:

A

Is created from a statute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The Office of the National Coordinator for Health Information Technology (ONC) was formed in 2004 to:

A

Guide the federal government’s promotion of health information technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vital statistics are compiled nationally by:

A

The National Center for Health Statistics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Two legally separate covered entities share a common ownership. For purposes of HIPAA, they may refer to themselves as a single covered entity. These two entities are:

A

Affiliated covered entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Administrative simplification refers to:

A

Standardizing the healthcare industry’s non-uniform business practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Barbie is completing her required high school community service hours by serving as a volunteer at the local hospital. Barbie is a(n):

A

Workforce member

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

St. Vincent Hospital has a contract with a local cleaning company that comes into the hospital to pick up all of the facility’s linens for off-site laundering. The cleaning company is:

A

A business associate because St. Vincent has a contract with it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A limited data set:

A

Does not completely deidentify an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The minimum necessary requirement does not apply to:

A

Disclosures to healthcare providers for treatment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Generally, an individual acting in loco parentis of a minor is:

A

Not the minor’s personal representative if the minor consented to his own treatment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A designated record set:

A

Consists of records used in whole or in part to make decisions about an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

General Hospital’s health record department delivers a group of patient records to the quality improvement department for its monthly review. This constitutes:

A

Use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

The highest penalty tier available under HITECH is:

A

Willful neglect, uncorrected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The accounting of disclosures requirement:

A

Includes the 12 public interest and benefit circumstances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

The concept of preemption:

A

Gives legal precedence to federal law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

HITECH granted power to bring civil actions in federal district court based on alleged HIPAA violations to:

A

State attorneys general

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

The Notice of Privacy Practices:

A

Informs individuals about how their PHI is used or disclosed

25
Q

Public interest and benefit disclosures:

A

Do not require the patient’s written authorization or verbal agreement

26
Q

HIPAA enforcement:

A

Includes audits

27
Q

Kay Denton wrote to Mercy Hospital, requesting an amendment to her PHI. She informed them that her record incorrectly states she is 180 lbs. instead of her actual 150 lbs., and that correcting it would look better on her record. The information is present on a copy of a History & Physical that General Hospital sent to Mercy Hospital. Mercy Hospital may decline to grant her request based on which privacy rule provision?

A

The History & Physical was not created by Mercy Hospital

28
Q

To place a patient in a facility directory, a covered entity:

A

Must obtain the patient’s verbal agreement

29
Q

Which of the following is a goal of the HIPAA Privacy Rule?

A

Provide an individual with greater rights regarding his or her health information

30
Q

An addressable implementation specification:

A

May be implemented as written if it is reasonable and appropriate

31
Q

An audit trail:

A

Is a retrospective audit control

32
Q

Which of the following is the most stringent access control mechanism?

A

Context-based

33
Q

The HIPAA Security Rule defines facility as:

A

The interior and exterior of buildings and physical premises

34
Q

Private key infrastructure:

A

Is less secure than public key infrastructure

35
Q

Media reuse:

A

Keeps costs down

36
Q

Erasing or deleting an electronic file:

A

Removes the pathway that leads to the data

37
Q

“Break the glass” functionality:

A

Is prohibited by the Security Rule

38
Q

The HIPAA Security Rule is scalable. This means:

A

It applies to entities of any size

39
Q

Which of the following presents the greatest risk of large-scale health information breaches?

A

Laptop theft

40
Q

What is the most constant threat to health information integrity?

A

Humans

41
Q

The most commonly anticipated reason for health information exchanges is:

A

Treatment

42
Q

Which of the following describes continued organizational functions despite an event?

A

Emergency mode operations

43
Q

Risk determination considers the factors of:

A

Likelihood and impact

44
Q

Which of the following restores critical services as quickly as possible after an event?

A

Disaster recovery plan

45
Q

Which of the following is the best practice for protecting information that is text messaged?

A

Encrypt text messages during transmission

46
Q

If electronic data is backed up consistently, which of the following will be minimized?

A

Data recovery

47
Q

Which of the following is not included in the Red Flags Rule’s definition of “creditor”?

A

Obtains or uses consumer reports in connection with a credit transaction

48
Q

Personal health records (PHRs):

A

Are created by patients

49
Q

Which step of risk analysis identifies information assets that need protection?

A

System characterization

50
Q

Spyware:

A

Is primarily designed to attach to the host computer

51
Q

The Cybersecurity Act of 2015 resulted in:

A

Formation of the health care industry cybersecurity task force

52
Q

Persistent cookies:

A

Remain stored on a computer to allow retention of personal information

53
Q

Middlecross Hospital has an EHR vendor that just learned about a vulnerability in the EHR system. The vendor has not yet been able to warn Middlecross Hospital about the vulnerability or fix it before an attacker hacks into the system. Middlecross Hospital has just experienced a:

A

Zero day exploit

54
Q

Attackers who exploit computer systems:

A

Violate the intended use of the systems

55
Q

Cybersecurity protects information systems against:

A

Threats that exploit a system’s vulnerabilities

56
Q

A computer virus:

A

Is able to replicate itself

57
Q

Whaling is:

A

Spearphishing aimed at an organization’s executive

58
Q

Joe is on the first month of his job in a hospital IT department when the hospital’s network is flooded with traffic. It becomes unusable for users trying to access information. What has occurred is:

A

Denial of service

59
Q

Data backup:

A

Cannot prevent ransomware from blocking a computer’s functionality