HIT-001 Chapter 3 Flashcards
The divisions of the _____ involved in healthcare are the _____, the _____,
and the _____.
HHS, CMS, ONC, OCR
The new standard of medical diagnosis and inpatient procedure coding, called _____, is required to be adopted by October 1, 2013, by ______-compliant facilities.
ICD-10, HIPAA
The _____ tests and certifies all _____ solutions to be _____-compliant.
ONC, EMR/EHR, HIPAA
The _____ enforces ______ rules to protect ______.
OCR, HIPAA, e-PHI
An _____ is used to establish how information is shared and to set expectations for service provided.
SLA
Which branch of the HHS controls the electronic standards of transaction for an insurance claim? And what is the current standard?
CMS (Centers for Medicare & Medicaid Services). The current standard is
Version 5010.
Which HHS division is responsible for enforcing HIPAA rules?
OCR (Office of Civil Rights)
Do federal or state agencies administrate Medicare? Medicaid?
Medicare is administrated at the federal level. Medicaid is administrated by states.
What does the HIPAA Enforcement Rule determine?
The Enforcement Rule establishes penalties for violations to HIPAA rules and procedures following a violation, such as investigations and hearings.
What are the goals of the meaningful use of technology in healthcare?
The goals of meaningful use are to help healthcare providers know more about their patients, make better decisions, and save money.
Why would an eligible provider want to demonstrate the meaningful use of
technology?
Eligible providers who demonstrate meaningful use receive monetary incentives.
What are possible breaches of e-PHI?
A breach can be theft, unauthorized access or disclosure, loss, or improper disposal of e-PHI.
What is the purpose of a public health record?
A public health record is used for the collection of public health data to be analyzed by researchers.
What is the basic rule of thumb of record disposal?
The basic rule of thumb is to make sure the data on an electronic device is unreadable, indecipherable, and cannot be reconstructed.
Why are SLAs important and what do they establish?
SLAs establish how e-PHI is shared and used, and an SLA establishes expectations of service provided.
The .gov websites are a great resource for HIT professionals. Suppose your boss asks you to develop a contract to be used to establish the SLA with a software vendor to support the software and provide fixes to bugs discovered. Rather than reinventing the wheel by making up your own contract, use an Internet search engine to find templates for contracts and checklists. Find a template on the http://www.hhs.gov website for an SLA/MOU document. Write down the websites where you found the documents.
Answers may vary. The link for the example on the http://www hhs.gov web- site is http://www.hhs.gov/ocio/eplc/Enterprise%20Performance%20Life- cycle%20Artifacts/eplc_artifacts.htmlSimilar.
Search online for two case examples and resolution agreements to HIPAA violations. You can find several in news articles, and the http://www.hhs.gov website gives some examples where acceptable resolutions agreements were reached. What was the cause of the breach? What were the consequences of the breach? What was the resolution agreement reached? Were policies implemented to prevent the violation from happening again?
Answers may vary. However, the link to the hhs.gov examples is http://www.
hhs.gov/ocr/privacy/hipaa/enforcement/examples/index.html.
While in the waiting room at the free clinic with three other patients, Nurse Jack calls out, “Patti Patient.” Patti Patient begins to walk to Nurse Jack. Before leaving the waiting room, Nurse Jack asks Patti Patient, “Has the herpes cleared up yet?” Is this a HIPAA violation? Why?
Yes, this is a HIPAA violation because Patti Patient’s name and medical condi-
tion were spoken to be heard by anyone in the waiting room
breach notification rule
Requires covered entities to notify affected individuals, the HHS secretary, and possibly the media when protected health information (PHI) has been breached.