HIPAA Lesson 4 Flashcards
The ________ Rule lays the foundation—or floor—for standardized, national protections. These protections attempt to reduce the risks of inappropriate disclosures and uses of individuals’ health information.
Privacy
A privacy breach of PHI in electronic form is a ________.
Security Breach
Name the Four Core Areas of the Privacy Rule
- Individual control of health information
- Boundaries on use and release of health information by covered entities
- Establishment of policies, procedures, and appropriate safeguards to protect privacy
- Accountability for violations with civil and criminal penalties
The Privacy Rule creates national standards for the protection of healthcare information. Its basic intent is to _______ individuals’ medical records and other identifiable health information.
Protect
This core area of the Privacy Rule outlines how covered entities can use and disclose an individual’s protected health information.
Individual control of health information
This core area of the Privacy Rule outlines in detail what information is protected, how and when entities can release it, and under what circumstances they may disclose it. This includes any information in any form: electronic, paper-based, or verbal.
Boundaries on use and release of health information by covered entities
This core area of the Security Rule lays out the technical requirements to comply with the policies, procedures, and safeguards that the Privacy Rule establishes.
Establishment of policies, procedures, and appropriate safeguards to protect privacy
This core area of the Privacy Rule establishes the civil and criminal penalties for violations of the Privacy and the Security Rules and designates which organizations must oversee compliance.
Accountability for violations with civil and criminal penalties
If a healthcare entity maintains any health information that identifies an individual in any possible way, it’s ________.
PHI
The Privacy Rule regulates how institutions must protect PHI, and it establishes penalties for _________.
Noncompliance
The ________ Rule supports the protections that the Privacy Rule requires.
Security
It’s important to point out that the Privacy Rule represents the _______ level of protection.
Floor or Minimum
_______ laws can require covered entities to implement more stringent privacy practices. If the _______ laws are more stringent, then the _______ law can supersede HIPAA’s Privacy Rule.
State
List the Privacy Rule Requirements
- Adopt Written Privacy Policies, Procedures, and Contract Provisions
- Designate a Privacy Officer or a Compliance Officer
- Train Employees and Other Workforce Members
- Establish Privacy Safeguards
- Ensure that Health Information Is Not Used for Non health Purposes
- Establish Clear, Strong Protections Against Marketing
- Provide the Minimum Amount of Information Necessary
- Support Individual Privacy Rights
- Obey Authorization Policies
Covered entities must develop ________ to describe how they will use and disclose PHI, protect individual rights, including BAs.
Policies, Procedures, and Provisions
Each covered entity must have one named person in its organization who is ultimately accountable for the CE’s Privacy Rule compliance. The buck stops with that person!
Designate a Privacy Officer or a Compliance Officer
Covered entities must ________ all employees on privacy policies and procedures, including volunteers, part-time employees, and contractors.
Train
_______ can be a combination of procedures, practices, and physical and technical solutions. Privacy ________ enforce the CE’s policies and procedures about the appropriate use of protected health information.
Common ________ include things like locking or shutting doors, or keeping your voice down when talking. Other ________ might include using privacy screens on computer monitors or having a clear desk policy (no paper with PHI left in the open).
Safeguards
Unless an individual gives explicit written permission, health information is for ________ purposes only.
Health
The Privacy Rule has explicit requirements for that covered entities must first obtain the individual’s written authorization before sending any ______ materials. Only under very limited circumstances can they send _______ without authorization.
Marketing
Advertising
What are these? Right to Inspect or Copy Right to Request Amendments Right to Receive a Notice of Privacy Practices Right to Request Restrictions Right to Request Alternate Communications Right to Accounting of Disclosures Right to File a Complaint
Individual Privacy Rights
The Privacy Rule requires an individual’s ________ to use or disclose PHI for purposes not explicitly stated.
Written Permission or Authorization
Sometimes individual states enact laws that provide greater privacy protections than HIPAA provides. These laws ________ the HIPAA Privacy Rule.
Preempt (replace)
If part of the state rule supersedes HIPAA, then the covered entity must comply with ________ the state’s and HIPAA’s requirements.
Both