Chapter 8 Flashcards
HIPAA rules set forth …. important patient rights that must be explained in privacy notifications
6
Standard 3 privacy rules state
policies and procedures must be in place to protect unauthorized viewers from accessing PHI
Specific right to privacy in what amendment
None of them
Notice of privacy practice is doc that every …
Patient is asked to read & sign
HIPAA now requires that
code sets are uniform throughout the country
Under HIPAA patients can’t receive these directly …
All of these ( Psyc notes, criminal notes, direct lab results)
Person perform disaster relief notification activities ….
may receive PHI from providers unless the patient says no
FDA entitled to PHI when
All of these (safety issues are apparent, adverse events w/ drugs are apparent, recalls)
Law enforcement get PHI when
only in specific circumstances like a gun shot wound or child abuse
Protected psyc notes include
None of these (medical prescriptions, results of clinical tests, start and stop times)
TPO disclosures within facility or consult with another practitioner
may require authorization
Ex of incidental disclosure of PHI is
All of these (leaving limited message, patient sign in sheet, chart outside of exam room)
Person most likely to handle problem of computer hacker is
security officer
Business Associate under HIPAA is
someone outside of medical practice with HIPAA approved reason to see PHI
Could unintentionally expose content - employer by
All of these (shopping on internet, downloading games, sending unsecured emails)
If a patient complains his privacy has been breached what should you ask that he do?
Speak to your privacy officer to try to handle complaint within the office.
Which are privacy officers responsibilities?
All of the above (research privacy rule, help develop privacy notice, training staff on privacy procedures)
Which is not covered by HIPAA’s security rule
The contents of all documents pertaining to patient’s privacy
Not considered marketing under HIPAA provisions
A reminder about mammograms
Not violation of HIPAA privacy rules
All above are violations (dilantin, friend pregnant, insurance person on phone)
Which is true under HIPAA
Patient must submit complaints to Health & Human Services through office of Civil Rights
HIPAA protect PHI only in
All of these forms (electronic, written, spoken forms)
Which is not true of HIPAA
HIPAA requires that practitioners must change medical record if patient complains
Firewalls and encryptions are for …
help ensure privacy of records
Enactment of federal and state laws for gathering personal data
Information collected about person can be checked for accuracy by the person
Act forbids federal agency to release information except for that it was collected
Privacy Act
Following act guarantees change of job can get health insurance
HIPAA
Following administration has enforcement authority for HIPAA standards including encoding
CMS (Center for medicare & medicaid services)
Limited PHI data set is
All of Above (direct identifiers removed, used for research, and used for public health purposes)