Midterm Flashcards
What 3 covered entities must comply w/ HIPAA?
- ) All health care plans
- ) All health care clearing houses
- ) A health care provider transmitting any health information in electronic form
Refers to the rights of an individual to limit the use and disclosure of ALL protected health information.
Privacy
Refers to the obligations of covered entities to safeguard protected health info from improper use of disclosure, especially electronically transmitted or stored information
Security
Release, transfer, provision of access to, or divulging of info outside the entity holding the info.
Disclosure
Sharing, employment, application, utilization, examination, or analysis of individually identifiable info w/in an entity
Use
Employees, volunteers, trainees, and other persons whose conduct, in the performance of work, is under the direct control of such entity.
Workforce
A person or entity that performs a function that requires the creation, use or disclosure of PHI on behalf of a CE but is not considered part of the workforce
Business associate
The physical premises and interior and exterior of a building.
Facility
The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference w/ system operations in an information system.
Security incident
An electronic computing device; for example, a laptop or desktop computer, or any other device that performs similar functions, and environment
Workstation
Software designed to damage or disrupt a system; for example, a virus or a worm
Malicious software
Any information, including demographic info, collected from an individual that:
- -A.) is created or received by a healthcare provider
- -B.) relates to the past, present or future health conditions
Protected health information
Are employment records of covered entity or FERPA covered by Protected Health Information?
No
Information which does not identify the individual or that which the covered entity has no reasonable basis to believe can be used to identify the individual
De-identified PHI
Minimum necessary to accomplish the intended purpose of the use, disclosure, or request.
Minimum necessary
Can an individual request an accounting of health info disclosures?
Yes
Can an individual request an amendment to health info?
Yes
Can an individual request to inspect and copy health info?
Yes
Can an individual request restrictions on disclosures?
Yes
Can an individual complain to the covered entity and to DHHS?
Yes