HIPPA/MEDICAL RECORDS and Terminology Flashcards
Who sets the HIPAA rules?
US Dept. of Health and Human Services
What does HIPAA stand for?
Health Insurance Portability Accountability Act
What year was it founded in?
1996
What issue does HIPAA address?
Addresses use and disclosure of health info of individuals and the use by organizations
Who is responsible for implementing and enforcing the Privacy Rule?
Office for Civil Rights is responsible for implementing and enforcing the Privacy Rule
what is the goal of HIPAA?
Goal of HIPAA is to assure health info is protected while info that is shared promotes high quality health care
What does HIPAA law specifically protect?
Protects all identifiable health info held or transmitted by a covered entity or business associate
o All demographic data related to a pt or individuals past/present or future mental health condition
o Provision of health care to that individual
o Past, present, or future payment for health care; identifiers include name, address, birth date and SSN.
are these identifiable or de-identified info?
identifiable info
what is not protected under HIPAA?
de-identified info
what is de-identified info?
Limited Data Set: protected health info from which certain specified direct identifiers of individuals and their relatives, household members, and employers have been removed
o This may be disclosed for research or public health purposes
The Privacy Rule permits the use and disclosure of protected information in how many national priority purposes?
12
name the reasons the privacy rule permits the use and disclosure of protected information.
Required by law, Public health activities, victims of neglect or abuse, health oversight activities such as audits, judicial proceedings, law enforcement purposes, to determine cause of death, facilitation of donation and transplantation of organs, research, serious threat to Health of Safety to public, essential government functions, worker’s compensation
When must written authorization be obtained?
Written authorization must be obtained for:
1) any use of protected health info that is not used for treatment,
2) payment,
3) health care operations
4) marketing (communications and referrals are not marketing)
Name what a Privacy Practices Notice must state.
Privacy Practices Notice must state:
1) how the covered entity may disclose the protected health info,
2) state the duty to protect privacy,
3) provide notice and abide by it and must be delivered no later than the first service encounter
4) should be posted prominently in the office
Must be a “good faith effort” to obtain acknowledgement of receipt of the privacy practices.
True or False
True
Documentation about privacy notices, disposition, complaints and other actions must be kept for how long?
6 years
Individuals do not have the right to review and obtain a copy of their records.
True or False
False
The maximum necessary protected information should be disclosed
true or false
false. the minimum necessary info should be disclosed.
Release of information may occur for national priority purposes.
true or false.
true
as an extern are you bound by HIPAA rules?
yes
what are the ONLY reasons that you can access patient info?
payment, patient care or treatment
what is considered to be anterior?
everything before the iris.
what is considered posterior?
vitreous, choroid, retina, etc.
Disc diameter is used to describe the distance of what?
Disc diameter used to describe the distance of lesions on the retina. ONH is approx. 1.5mm
what is the size of the normal disc? it increases until when?
Normal disc is 1/3 or .3 and increases until .1 and disc is gone
what does a patient learn during lid hygiene/maintenance?
Lid hygiene/ lid maintenance= procedure where patient is taught how to clean lids and put warm compresses on lids.
what is dry eye?
if any of the 3 layers of the tears are affected.
ptosis
droopy lid