HIPAA Lesson 2 Flashcards

1
Q

CE is an acronym for?

A

Covered Entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name the three types of CE.

A
  1. Healthcare Providers
  2. Health Plans
  3. Healthcare Clearinghouses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A _________ is any person or organization that diagnoses or treats a patient.

A

Healthcare Provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A ________ is the covered entity that pays the cost of medical care.

A

Health Plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A company that owns, administers, and maintains a health plan for fewer than _____ employees isn’t a CE.

A

50

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An entity that translates nonstandard information into a standard format.

A

Healthcare Clearinghouses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

List two other names used for clearinghouses.

A
  1. Value-added Networks

2. Switches - Works like a bus station.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What questions should be asked to figure out if an organization is a CE?

A
  1. Does the person, business, or agency furnish, bill for, or receive payment for healthcare in the normal course of business? If Yes, then go to the next question.
  2. Is it possible to transmit the information electronically? If Yes, go to the next question.
  3. Then the organization is a CE.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Name the six agreements and relationships available for healthcare entities.

A
  1. Affiliated Covered Entity (ACE)
  2. Business Associate Contract/Agreement (BAA)
  3. Chain of Trust Agreement
  4. Data Use Agreement
  5. Organized Healthcare Arrangement (OHCA)
  6. Trading Partner Agreement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What two forms of organization relationships does the Administrative Simplification allow to help reduce costs to organizations.

A
  1. ACE

2. OHCA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Legally separate entities that are under common ownership or control may designate themselves an __________.

A

Affiliated Covered Entity (ACE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

An ACE has two responsibilities.

A
  1. It must state that it will operate as an ACE.

2. It must comply with all HIPAA rqmts when it creates, receive, maintains, or transmits PHI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Affiliated entities may have ___________in charge of HIPAA compliance.

A

One person or team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Multiple healthcare providers (like a hospital and a group of physicians) that typically provide healthcare to a common set of patients may designate themselves as a ____________.

A

Organized Healthcare Arrangement (OHCA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In an OHCA, there’s a relationship between legally _______ organizations.

A

Separate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The difference between an OHCA and an ACE is that OHCA doesn’t have _________ owership.

A

Common

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

OHCA’s can disclose PHI among themselves as needed, and allows _________ of compliance activities.

A

Centralization and Sharing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Members of OHCA must _________ develop privacy policies, procedures, and practices.

A

Jointly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

For a CE to be a ________ entity, one part of the organization must provide healthcare, pay for healthcare, or act as a healthcare clearinghouse, while the rest of the organization must not provide any of these services.

A

Hybrid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

_______ are people or entities who aren’t employees of a CE, and perform certain activities on the CE’s behalf that use PHI.

A

Business Associates (BA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

One CE can be a ____________ of another CE.

A

BA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

BA’s can use ____________ only to help providers and health plans carry out their healthcare functions.

A

PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Disclosures to BA’s must be the ____________ to perform the services required.

A

Minimum Necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

List eight types of services that BA’s perform.

A
  1. Legal
  2. Actuarial
  3. Accounting
  4. Consulting
  5. Data Aggregation
  6. Management
  7. Administrative
  8. Accreditation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Entities that pass along or transport PHI, but usually don’t have access to it. They don’t require PHI to perform their work.

A

Conduits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Give examples of conduits.

A

USPS, FedEx, UPS, Internet Service Providers, AT&T, Comcast

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

_________ are firms that process consumer-related financial transactions and not a BA.

A

Financial Institutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What are the clues that you could be a BA?

A
  1. You perform services on behalf of a CE (health plan, health provider, healthcare clearinghouse.
  2. You are not a member of the CE’s workforce.
  3. The services you proved involve the use of IIHI (PHI).
  4. You aren’t a bank.
  5. You aren’t a conduit, such as UPS/Internet Provider.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

___________ perform clinical, medical, and health services and exchange electronic transactions with each other rather than going through a clearinghouse.

A

Trading Partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

An organization that performs financial transactions (billing, claims processing, or audits) for a covered entity.

A

BA

31
Q

USPS is considered what type of organization.

A

Conduit

32
Q

A provider, health plan, or clearinghouse

A

Covered Entity

33
Q

A financial institution that performs collection activities for a covered entity.

A

Possible BA

34
Q

A hospital billing company that sends claims directly to a health plan.

A

Trading Partner

35
Q

An organization made up of legally separate entities that are under common ownership or control.

A

ACE

36
Q

A clinical integrated care setting in which individuals typically receive care from more than one

A

OHCA

37
Q

A business that conducts covered and non-covered activities.

A

Hybrid

38
Q

Name the three Government HIPAA organizations

A
  1. HHS
  2. CMS
  3. OCR
39
Q

HHS named six organizations to maintain the Administrative Simplification standards. They develop, maintain, and modify HIPAA transactions, code sets, and EDI standards.

A

Designated Standard Maintenance Organizations (DSMOs)

40
Q

List the six DSMOs.

A
  1. The American National Standards Institute’s Accredited Standards Committee X12
  2. Health Level Seven (HL7)
  3. National Council for Prescription Drug Programs
  4. Dental Content Committee of the American Dental Association
  5. National Uniform Billing Committee
  6. National Uniform Claim Committee
41
Q

This committee developed the transaction standards for EDI.

A

Accredited Standards Committee X12 (ASC)

42
Q

Allows organizations to standardize systems and improve communication between systems. It cannot transmit images, graphics, or the special reports that sometimes accompany insurance claims.

A

Health Level Seven (HL7)

43
Q

The ________ develops standards for prescription drug program. It works with pharmacy chains like CVS and Walgreens, pharmaceutical manufacturers, wholesale drug distributors, and pharmacy insurance plans.

A

National Council for Prescription Drug Programs (NCPDP)

44
Q

This association sets the standards required for electronic transmission of transactions for dental treatment and diagnosing.

A

Dental Content Committee of the American Dental Association

45
Q

This association sets the standards required for electronic transmission of transactions for billing transactions.

A

National Uniform Billing Committee

46
Q

This association sets the standards required for electronic transmission of insurance claim transactions.

A

National Uniform Claims Committee

47
Q

________ specializes in managing and distributing EDI information and produces documentation for organizations that develop, maintain, and implement EDI standards.

A

Washington Publishing Company

48
Q

Congress established this committee to advise HHS on health data, statistics, and national health information policy.

A

National Committee on Vital and Health Statistics

49
Q

______ is an advisory group to HHS. Its original mission was to address administrative costs in the nation’s healthcare system. It streamlines healthcare administration by standardizing electronic communication. It’s members solve some of the issues that prevent organizations from easily exchanging information. In addition, it publishes educational papers that help organizations understand how to comply with HIPAA.

A

Workgroup for Electronic Data Interchange (WEDI)

50
Q

Can my organization be both a hybrid covered entity (HCE) and an affiliated covered entity (ACE)?

A

Yes. In fact, a hybrid covered entity can also be an organized healthcare arrangement (OHCA). Essentially, an HCE performs covered and non-covered HIPAA functions in the same building. The part of the HCE that performs HIPAA-covered functions (and therefore must comply with HIPAA) can be a simple covered entity, an ACE, or an OHCA.

51
Q

In order for an organization to be a covered entity, it must send healthcare data electronically. What if a provider doesn’t perform transactions like charting and insurance billing electronically?

A

Before 2003, healthcare providers used paper charts, and they printed and mailed paper copies of insurance claims. Many of these providers considered themselves exempt from HIPAA.

52
Q

Which type of covered entity receives data, standardizes that data, and sends it on to other organizations, such as health plans and government agencies?

A

Clearinghouse

53
Q

What’s the name of the group of six organizations that the federal Department of Health and Human Services put in charge of developing HIPAA standards?

A

Designated Standard Maintenance Organizations (DSMO).

54
Q

What’s the correct name for an organization that treats and diagnoses patients, submits electronic bills for healthcare services, and receives payment?

A

Covered entity (CE).

55
Q

What is the Accredited Standards Committee X12’s role in HIPAA

A

That group developed the transaction standards that organizations use for electronic data interchange.

56
Q

What’s the correct name for an organization that handles protected health information and performs services on behalf of a health plan, provider, or clearinghouse, but isn’t a member of that entity’s workforce?

A

Business associate (BA)

57
Q

CMS

A

Centers for Medicare and Medicaid Services

58
Q

OCR

A

Office for Civil Rights

59
Q

ANSI

A

American National Standards Institute, 5010 Transaction standard

60
Q

WPC

A

Washington Publishing Company

61
Q

ACE

A

Affiliated Covered Entity

62
Q

OHCA

A

Organized Healthcare Arrangement

63
Q

BAC

A

Business Associate Contract

64
Q

HHS

A

Department of Health and Human Services

65
Q

DSMO

A

Designated Standard Maintenance Organizations

66
Q

ASC

A

American Standards Committee

67
Q

HL7

A

Health Level 7

68
Q

NCPDP

A

National Council for Prescription Drug Programs

69
Q

EDI

A

Electronic Data Interchange

70
Q

WEDI

A

Workgroup for Electronic Data Interchange

71
Q

HCE

A

Hybrid Covered Entity

72
Q

TCS

A

Transactions and Code Sets

73
Q

NCVHS

A

National Committee on Vital and Health Statistics