HIPPA Flashcards

1
Q

What does HIPAA stand for?

A

H- Health

I- Insurance

P- Portability

A- Accountability

A- Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is HIPAA and what organizations must comply with it?

A

HIPAA = Health Insurance Portability and Accountability Act of 1996 established national standards for protection of patient medical information and health care providers such as (nurses, doctors, hospitals, dentists, etc.) must comply with it. It is a federal law imposed on all healthcare organizations including hospitals, physician offices, home health agencies, nursing homes and other providers, as well as health plans and clearing houses, that protects patient health information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

These organizations MUST comply HIPAA:

A

Hospitals, Physician offices, home health agencies, nursing homes, health plans, clearing houses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

HIPAA covers a broad range of issues. Accountability involves “Administrative simplification” which includes:

A

Privacy, security, uniform transactions, code sets, and identifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The Privacy Rule Protects information known as

A

protected health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

This protects patient information that exists in _______________________, ______________ and____________________________ formats.

A

written, oral, electronic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The Privacy Rule limits the way in which members of the workforce may use and disclose PHI. Workforce members MUST HAVE JOB-RELATED REASONS to use and disclose

A

PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Workforce members who MUST comply with the HIPAA privacy rule include:

A

Employees, volunteers, trainees, and other persons who have a job-related reason to access personal health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The HIPAA Privacy Rule requires that institutions provide all patients with a copy of its:

A

Notice of Privacy Practices (NOPP). Informs patients of patient rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The Notice of Privacy Practices (NOPP) informs patients of their____________. Each patient must ______an acknowledgement after receiving the NOPP.

A

patient rights, sign

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A patient’s privacy rights are communicated to the patient through what notice?

A

Notice of Privacy Practices (NOPP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The Privacy Rule requires that institutions designate a Privacy Officer who is responsible for:

A

The development and implantation of privacy policies, privacy related training education, investigating privacy related complaints, and conducting routine audits ensure compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The ______________is a key component
of the HIPAA Privacy Rule.

A

minimum necessary standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The standard requires covered entities to:

A

Evaluate their practices and enhance safeguards to protect access and disclosure of PHI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

For uses of PHI, the covered entity’s policies and procedures must identify who needs access to the information:

A

To carry out their job duties, the categories or types of PHI needed, and the conditions appropriate to such access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The Privacy Rule permits certain incidental uses and disclosures as long as the covered entity has adhered to the following:

A

Applied reasonable safeguards and implemented the minimum necessary standard.

17
Q

What must covered entities have in place that protect against uses and disclosures nor permitted by the privacy rule?

A

Appropriate administrative, technical, and physical safeguards that protect against uses and disclosures not permitted by the Privacy Rule.

18
Q

What is HITECH?

A

Health Information Technology for Economic and Clinical Health Act

19
Q

HITECH updated the HIPAA Privacy Rule to include:

A

Protections against identity theft

20
Q

Define Business Associate and their job duties:

A

A person or entity that performs certain functions or activities that involves the use or disclosure of PHI on behalf of, or provides services to, a covered entity

21
Q

What is an example of a business associate?

A

Third party administrator that assists with claims

22
Q

What are Treatment, Payment, and Health Care Operations (TPO)?

A

TREATMENT = Means the provision, coordination, or management of health care and related services. Allows covered entities to disclose individuals PHI for treatment, payment, and healthcare operations.

23
Q

In addition to the general definition, the Privacy Rule provides examples of common payment activities which include, but are not limited to:

A

Determining eligibility or coverage under a plan and adjudicating claims, risk adjustments, billing and collection activities

24
Q

What organization is responsible for administering and enforcing HIPAA standards?

A

The department of health and human services, Office for Civil Rights

25
Q

If a covered entity’s workforce members do not follow the rules set by HIPAA, the Government has the right to:

A

Conduct an investigation and impose fines and/or jail sentences

26
Q

Unintentional HIPAA violations may result in:

A

$100 fine per violation, $25,000 for multiple violations of the same standard in a calendar year

27
Q

Knowingly making unauthorized disclosure of PHI may result in:

A

$50,000 fine, imprisonment up to one year, or both

28
Q

Offenses which include false pretenses may result in:

A

$100,000 fine, imprisonment up to 5 years, or both

29
Q

Offenses with intent to sell information may result in:

A

$250,000 fine, imprisonment up to 10 years, or both