Data Privacy Flashcards

1
Q

→ official health document of an individual shared among multiple facilities and agencies
→ demographic info, diagnosis, prescriptions, lab tests, contact info, visitation info, allergies, insurance info, family history, etc.

A

Electronic Medical Records (EMRs) or Electronic Health Records (EHRs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

→ hospital discharge data reported to a government agency
→ data that organizations collect about their operations such as status reports on their routine operations

A

Administrative Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

→ billed interactions between insured patients and healthcare systems (inpatient, outpatient, pharmacy, and enrollment)
→ collects information across a wide range of medical professionals
→ comes directly from the notes of physicians as info is recorded at the time of the appointment
→ allows researchers to analyze patients with rare conditions

A

Claims Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

→ tracks a narrow range of key data for chronic conditions
→ uses observational study methods to collect uniform data to evaluate specified outcomes for a population
→ observes the course of the disease and the variations of treatment

A

Patient/Disease Registries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

→ conducted to provide prevalence rates of certain diseases
→ includes the measures of risk factors, health behaviors, and non-health determinants or correlations (e.g. socioeconomic status)

A

Health Surveys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

→ registry and results database hosted by government agencies or the WHO
→ clinical research data made available only through national or discipline-specific organizations
→ studies new tests and treatments that evaluate their effects on human health outcomes
→ data collected are variables relevant to the research hypotheses

A

Clinical Trials Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Documents used for study implementation (acronym is CRF)

A

Case Report Forms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

→ (acc. to the dictionary)—facts and statistics collected for reference
→ (acc. to philosophy)—things known or assumed as facts which shapes the basis of reasoning
→ (acc. to computing)—quantities, characters, or symbols where operations are performed by a computer that transmits electrical signals to record on various media platforms

A

Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

→ ensures that data are not accessed by unauthorized entities

A

Data Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

HIPAA stands for?

A

Health Insurance Portability and Accountability Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

RA 10173

A

Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RA 10713 Chapter 1

A

General Provisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

RA 10173 Section 1

A

Short Title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RA 10173 Section 2

A

Declaration of Policy

  • the state shall protect the human fundamental right of privacy and communication while ensuring a free flow of information
  • the state recognizes the vital role of information and communications technology in nation-building and ensures that personal info is secured and protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

RA 10173 Section 3

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Freely given permission evidenced by written, electronic, or recorded means

A

Consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Race, ethnic origin, marital status, age, color, religion, sex, etc.

A

Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

RA 10173 Section 4

A

Scope; applies to to any natural or juridical person involved in information processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

RA 10173 Section 5

A

Journalist Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

RA 10173 Section 6

A

Extraterritorial Application; countries are obliged to deport foreign criminals running away from their country of origin if found guilty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

RA 10173 Chapter 2

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

RA 10173 Section 7

A

Function of the NPC; administer, implement, monitor, and ensure compliance of the country to international standards of data protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

RA 10173 Section 8

A

Confidentiality

24
Q

RA 10173 Section 9

A

Organizational Structure of the Commission

25
Q

T or F: The NPC is attached to the DICT

A

True

26
Q

DICT stands for?

A

Department of Information and Communications Technology

27
Q

T or F: The DICT Chairman acts as the Privacy Commissioner of the NPC

A

True

28
Q

The current DICT Secretary

A

Sec. Gringo Honasan

29
Q

The three agencies attached to the DICT

A
  • NTC
  • NPC
  • CICC
30
Q

NTC stands for?

A

National Telecommunications Commission

31
Q

CICC stands for?

A

Cybercrime Investigation and Coordinating Center

32
Q

RA 10173 Section 10

A

The Secretariat

33
Q

RA 10173 Chapter 3

A

Processing of Personal Information

34
Q

RA 10173 Section 11

A

General Data Privacy Principles

35
Q

RA 10173 Section 12

A

Criteria for Lawful Processing of Personal Information; consent must be given and the information is necessary as supported by the law

36
Q

RA 10173 Section 13

A

Sensitive and Privileged Information; prohibited by law but with the following exceptions:

  • consent is given
  • supported by law (legal purposes)
  • to protect life and health
  • there is lawful and non-commercial objective of public organizations
  • medical treatment
37
Q

RA 10173 Section 14

A

Subcontract of Personal Information (third-party processing)

38
Q

RA 10173 Section 15

A

Extension of Privileged Communication (between doctor and patient)

39
Q

RA 10173 Chapter 4

A

Rights of the Data Subject

40
Q

RA 10173 Section 16

A

Data Subject Rights

41
Q

RA 10173 Section 17

A

Transmissibility of Rights of the Data Subjects

42
Q

RA 10173 Section 18

A

Right to Data Portability

43
Q

RA 10173 Section 19

A

Non-Applicability

44
Q

RA 10173 Chapter 5

A

Security of Personal Information

45
Q

RA 10173 Section 20

A

Personal Information Security

  • accidental or unlawful destruction, alteration, and disclosure
  • accidental loss, human dangers, unlawful access, fraudulent misuse, and contamination
  • level of protection is dependent on the kind of information present
  • monitoring of 3rd party processors
46
Q

RA 10173 Chapter 6

A

Accountability for Transfer of Personal Information

47
Q

RA 10173 Section 21

A

Principle of Accountability; the information controller is responsible and accountable for any personal information under their control or custody—including those transferred to a 3rd party whether domestic or international

48
Q

RA 10173 Chapter 7

A

Security of Sensitive Personal Information in Government

49
Q

RA 10173 Section 22

A

Responsibility of the Heads of Agencies

50
Q

RA 10173 Section 23

A

Requirements relating to Access by Agency Personnel to Sensitive Personal Information

51
Q

Type of access wherein security clearance is required

A

Onsite and Online Access

52
Q

Type of access approved by the head of the agency but with a limit of 1000 records only with encryptions required

A

Offsite Access

53
Q

RA 10173 Section 24

A

Applicability to Government Contractors

54
Q

International Data Laws:

→ Europe (2016)
→ gives control to the individual over their personal data and to simplify the regulatory environment

A

General Data Protection Regulation (GDPR)

55
Q

International Data Laws:

→ USA (1996)
→ stipulates how healthcare information should be protected from fraud and theft
→ addresses limitations on healthcare insurance coverage

A

Health Insurance Portability and Accountability Act (HIPAA)