HIPAA Flashcards
What does HIPAA stand for?
Health Insurance Portability and Accountability Act
True or False: HIPAA is a United States federal law.
True
What is the primary goal of HIPAA?
To protect the privacy and security of health information
What are the two main rules under HIPAA?
Privacy Rule and Security Rule
Which entity enforces the HIPAA regulations?
Office for Civil Rights (OCR)
What is considered protected health information (PHI) under HIPAA?
Any information that can be used to identify an individual’s health status or history
True or False: Covered entities under HIPAA include healthcare providers, health plans, and healthcare clearinghouses.
True
What is the minimum necessary rule under HIPAA?
Requires covered entities to only use or disclose the minimum necessary PHI
What is the penalty for HIPAA violations?
Fines ranging from $100 to $50,000 per violation, up to $1.5 million per year
What is a Business Associate Agreement (BAA) under HIPAA?
A contract between a covered entity and a business associate outlining how PHI will be protected
What is the purpose of the HIPAA Breach Notification Rule?
To require covered entities to notify individuals affected by a breach of their PHI
What is the deadline for reporting a breach of PHI under the HIPAA Breach Notification Rule?
Within 60 days of discovering the breach
What are the three key elements of the Security Rule under HIPAA?
Administrative safeguards, physical safeguards, and technical safeguards
True or False: The HIPAA Privacy Rule applies to all forms of PHI, regardless of the medium.
True
What is the purpose of the HIPAA Security Rule?
To establish national standards for the protection of electronic PHI
What is the difference between the HIPAA Privacy Rule and the HIPAA Security Rule?
Privacy Rule focuses on protecting the privacy of PHI, while Security Rule focuses on the security of electronic PHI
What is the role of the HIPAA Privacy Officer within a covered entity?
To oversee the development and implementation of HIPAA privacy policies and procedures
What is the purpose of the HIPAA Omnibus Rule?
To strengthen privacy and security protections for PHI under HIPAA
What is the Safe Harbor method for de-identifying PHI under HIPAA?
Removing 18 specified identifiers from the health information
What is the HIPAA Security Rule’s requirement for access controls?
Implement technical policies and procedures that allow only authorized persons to access electronic PHI
What is the purpose of the HIPAA HITECH Act?
To promote the adoption and meaningful use of health information technology
What is the HIPAA Privacy Rule’s requirement for individual rights?
To provide individuals with rights over their health information, including the right to access and amend their records
What is the HIPAA Security Rule’s requirement for audit controls?
Implement hardware, software, and procedural mechanisms that record and examine activity in information systems
What is the purpose of the HIPAA Enforcement Rule?
To establish procedures for investigations and hearings for HIPAA violations