Chapter 4 and 5 Flashcards
Being free from unwanted intrusion
Privacy
the disclosing of private facts without the consent of the individual
invasion of privacy
who enforces HIPPA?
the HHS office for civil rights
what does HHS stand for?
department of health and human services
what does OCR stand for?
office for civil rghts
10 digit number given to covered healthcare providers and used for financial and administrative transactions
national provider identifier - NPI
There are how many standards of HIPPA..
four
created national standards that protect health records and other patient information. Main purpose is to define and limit situations in which a patient’s info can be used or disclosed. Also describes patients’ rights over their information
The HIPPA privacy rule
According to the HIPPA privacy rule, patients have the right to do the following three things:
- examine their health information
- obtain a copy of their health records
- request corrections to be made if the information is incorrect
When a provider is treating a patient for emotional or mental conditions, the provider can exercise professional judgement to determine if the records should be released to the patient. This as known as the..
doctrine of professional discretion
under HIPPA, which notes are treated to a higher level of confidentiality?
psychotherapy notes
these include the patient-provider details from mental health treatment, either from a private, group, or family therapy. They include what the patient stated during the session and the provider’s analysis of the patient’s statements and the situation
psychotherapy notes
substance abuse and ( ) content are also held at a higher level of confidentiality
HIV
What does GINA stand for and what did it do?
genetic information nondiscrimination act. It modified HIPAA by clarifying that genetic info is health info and prohibited the use and disclosure of genetic info by covered health plans
the security officer is responsible for creating and carrying out security policies and procedures. Potential risks to the ePHI must be identified. Cyber attacks pose a huge risk to network security
administrative safeguards
Facility, workstation, and device security must be implemented. A security officer must create procedures
Physical Safeguards
Only authorized employees should have access to ePHI. Safeguards include audits and encryption of data, among other things.
technical safeguards
Who is the HITECH Act enforced by?
OCR
what does HITECH stand for?
health information technology for economic and clinical health
contains provisions that increase the enforcement of the privacy and security of electronic transmission and health information.
the HITECH Act
The HITECH Act made business associates directly liable for compliance with..
HIPAA
The greater the violation, the greater the ( )
penalty amount
When HIPAA was modified through the HITECH act, ( ) notification requirements were increased.
breach
In 1938, the food and drug act was replaced by the ( ), which is still enforced today.
food, drug and cosmetic act
The ( ) is responsible for the afety, effectiveness, security, and quality of food, drugs, and cosmetics.
FDA
The controlled substances act has ( ) schedules of medications.
five