Chapter 6: Health Insurance Portability and Accountability Act (HIPAA) Exam 1 Flashcards

1
Q

What does HIPAA stand for?

A

Health Insurance Portability & Accountability Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Origin of HIPAA

A

-1996
-Enacted by Congress
-Signed by President Bill Clinton
-Within Dpt. of Health & Human Survices
-Office for Civil Rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is HIPAA

A
  1. Establishes nationwide protection for patient confidentiality, electronic system security, & transmission of electronic health information
  2. Guarantees patients the right to access their information
  3. Outlines penalties for violations that occur
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why do we care about HIPAA?

A

-Required to comply w/ these policies & procedures when dealing with health information
-Clients/patients trust their personal health information will be protected
-Committing HIPAA violations puts you & your employer at risk (Fines, civil/criminal penalties, bad reputation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HIPAA states that health information is required to be protected when created, stored, or transmitted in which ways?

A
  1. Verbal Discussions
  2. Written
  3. Stored in Computers
  4. Transfer of Data through Electronic Devices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Protected Health Information (PHI) ?

A

Any individually identifiable health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Examples of Protected Health Information (PHI)

A

-Medical Records
-Photos & Videos
-Communications between providers
-Billing & Payment Records
-Health Plan Claims Records
-Health Insurance Policy Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Minimum Necessary Rule

A

Use or disclose only the minimum necessary to accomplish an intended purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When does the minimum necessary rule not apply?

A

Treatment Purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What instances can PHI be used/disclosed without authorization from client/patient?

A

-Treatment
-Payment
-Health Care Operations
-Public Policy Exception

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Treatment is during, coordinating, & managing health care for an individual. What does this include?

A
  1. Direct treatment
  2. Consultation among health care providers
  3. Indirect treatment (lab testing)
  4. Referrals from one provider to another
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Payment is activities by a health care provider to obtain payment for health care services. What does this include?

A
  1. Billing
  2. Eligibility/Coverage Determination
  3. Medical Necessity Determination
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Health Care Operations

A
  1. Activities directly related to treatment & payment (credentialing, auditing, & quality assessment)
  2. Administrative & Managerial Activities (business planning, resolving complaints, HIPAA compliance checks)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When dealing with PHI paperwork…

A
  1. Don’t print or copy unless necessary
  2. Keep in protected locations
  3. Use fax cover pages
  4. Properly dispose (shred, dispose in separate bins)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

When storing PHI in computers or electronic data…

A
  1. Follow safe practices (strong passwords, keep logins confidential, no access to others of ID)
  2. Do not leave computer unattended without locking it
  3. Avoid risky practices (use of electronics in public/unsecure locations, opening suspicious emails, etc.)
  4. Implement workstation certified for HIPAA access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Type I Privacy Violation - Inadvertent or Unintentional (Negligent) Disclosure

A

-May or may not result in disclosure of PHI
-Possible disciplinary actions (verbal warning, re-education, review & signing of confidentiality agreement)
-Disciplinary actions determined by Privacy Officer, director of Human Resources, etc.

17
Q

Type II Privacy Violation - Intentional Disclosure

A

-May or may not result in disclosure of PHI
-Disciplinary actions (civil & criminals penalties can be enforced, loss of job)