HIPAA Breaches And Penalties Flashcards
HITECH Act of 2009 was enacted as part of the American Recovery and ___ reinvestment Act (ARRA), the stimulus package.
Reinvestment
What does HITECH stand for?
Health Information Technology of Economic and Clinical Health
What is Obamacare also to referred to as?
Patient Protection and Affordable Care Act (PPACA
Data is considered breached if…
- it is sold to a personal injury attorney
- it is hacked and published on a website
- it is stored on an unencrypted hard drive that is lost or stolen
HITECH exempts a breach from being reported if the lost data was ___
Encrypted
The HITECH Act requires breaches to be reported within ___ days
60
You must notify the Office of Civil Rights within 60 days of a breach of more than ___ patient records
500
True or False: State laws may require stricter reporting and privacy standards than federal law. Business associates must comply with both state and federal laws, meeting the ____ standard.
True, stricter
The OCR investigates approximately ___ potential HIPAA violations a year.
9,000
Reports of HIPAA violations typically come from breach reports, patient complaints, and ___ complaints.
Whistleblower
Civil penalties for data breaches may not exceed
$1,500,000
The HIPAA Omnibus Final Rule of 2013 somewhat relaxed the data breach reporting requirements of HIPAA.
False
A business associate that becomes aware of the breach must report it to who?
The covered entity with which they are contracted
The HITECH Act was part of the ___
American Recovery and Reinvestment Act of 2009
Actions for civil violations of HIPAA may be brought by___
The DHHS Office of Civil Rights