HIPAA Lesson 6 Flashcards
List the seven fundamental privacy rights that patients have under the Privacy Rule.
- The right to a notice of privacy practices (NPP)
- The right to request access to their own health information
- The right to request amendments to their own designated record sets
- The right to request restrictions to the use and disclosure of information about them
- The right to request an accounting of disclosures (in other words, a list of who has seen and used that person’s health information)
- The right to request the use of alternate communication (email rather than phone calls, for instance)
- The right to authorizations for use and disclosure
The Privacy Rule doesn’t require which CEs to develop a notice:
- Healthcare clearinghouses, if the only protected health information they create or receive is as a business associate of another CE
- A correctional institution that is a CE (for example, one that has a covered healthcare provider component)
- A group health plan that provides benefits only through contracts with health insurance issuers or HMOs (The group health plan must not create or receive protected health information other than summary health information. It also must not handle enrollment or disenrollment information.)
What’s in the Notice of Privacy Practices?
- How the CE may use and disclose protected health information about an individual.
- The individual’s rights concerning that information.
- The CE’s legal duties with respect to the information.
- A contact for further information about the CE’s privacy policies.
What language in the NoPP is required to be capitalized and in bold print as a prominent header?
THIS NOTICE DESCRIBES HOW YOUR PATIENT INFORMATION WILL BE USED AND DISCLOSED. PLEASE REVIEW IT CAREFULLY.
When are Health plans required to provide the NoPP to new enrollees.
At the time of enrollment
Providers who treat patients directly must provide the notice to an individual no later than:
The date of first service delivery.
In an emergency, providers must give the notice _____.
As soon as is reasonably possible.
Health plans also must provide a revised notice to covered individuals within _____ days of the revision. And at least once every _____ years, they must notify covered individuals that the notice is available and tell them how to get it.
- 60
2. Three
CEs must also make a good-faith effort to obtain a _______ that the individual received the notice.
written acknowledgment
If a patient refuses to sign NoPP acknowledgment, the organization must record that it _______receive acknowledgement.
didn’t
When sending an electronic version of the notice automatically, the provider must make a good-faith effort to get a _______ indicating that the individual received the notice.
return receipt
Certain CEs must provide a notice of privacy practices to all patients at the ______.
first encounter.
The NoPP must list all the _______ that will have access to that patient’s PHI, following the legal requirements that the Privacy Rule sets out.
organizations
A CE must respond to an individuals request for medical records within ____ days unless the information is off-site. In that case, the CE has ____ days to respond.
- 30
2. 60
The CE can have a ___-day extension if it notifies the person making the request within 30 days. And in the notification, the CE must include the ______ for the delay and the ______ the patient will get the information. The law permits the CE only ______ extension.
- 30
- 30
- reason
- date
- one
If the CE cannot provide the requested information in the requested format, the CE and individual can agree on a _______ format.
Different
Individuals do not have the right to access records that a CE compiled in anticipation of ________.
Court Action
CLIA
Clinical Laboratory Improvements Amendment