Module 6 - HIPAA and other healthcare Flashcards

1
Q

what is Title XIII of american recovery and reinvestment act (ARRA)

A

Health Information Technology for Economic and Clinical health (HITECH) act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Health Information Technology for Economic and Clinical health (HITECH) imposes data breach notification requirements for unauthorized uses and disclosures of unsecured PHI - what are these for businesses

A
  • Business Associates must report privacy and
    security breaches.
  • Subject to the same civil and criminal
    penalties as Covered Entities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Health Information Technology for Economic and Clinical health (HITECH) imposes data breach notification requirements for unauthorized uses and disclosures of unsecured PHI - what are privacy and secruity breach notifications to individuals

A
  • Notices sent without delay.
  • No later than 60 calendar days after
    discovery

$5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what is an HIE and what must they sign

A

Health Information Exchanges (HIE) are Business Associates and must enter into a BAA with the Covered Entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HIPAA and HITECH penalty tier A is what

A

Tier A – if the offender did not know
* $100 for each violation, total for all violations of an identical requirement during a calendar year cannot exceed $25,000.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

HIPAA and HITECH penalty tier A is what

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

HIPAA and HITECH penalty tier D is what

A

Tier D – violation due to willful neglect, but was NOT corrected
* $50,000 for each violation, total for all violations of an identical requirement during a calendar year cannot exceed $1,500,000.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

HIPAA and HITECH penalty tier B is what

A

Tier B – violation due to reasonable cause, not willful neglect
* $1,000 for each violation, total for all violations of an identical requirement during a calendar year cannot exceed $100,000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

HIPAA and HITECH penalty tier C is what

A

Tier C – violation due to willful neglect, but was corrected
* $10,000 for each violation, total for all violations of an identical requirement during a calendar year cannot exceed $250,000.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

HIPAA Final Rule: Key Facts

A
  • Final Rule introduced Jan 17, 2013
  • Modifies the following Rules:
  • —- HIPAA Privacy Rule
  • ———– ➢ HIPAA Privacy Rule modified as required by the
  • —- Genetic Information Nondiscrimination Act (GINA).
  • —- HIPAA Security Rule
  • —- HIPAA Enforcement Rule
  • —- HITECH Breach Notification for Unsecured PHI
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Business Associates (BA)
3 rules that apply to a BA

A
  • The changes announced expand many of the privacy
    and security requirements to BAs that receive PHI,
    such as contractors and subcontractors.
  • BAs may also be liable for the increased penalties for
    noncompliance based on the level of negligence up to
    a maximum penalty of $1.5 million.
  • The definition of a BA is expanded to include entities or
    individuals that maintain PHI on behalf of a CE, even if
    such entities or individuals never access PHI.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The Business Associate definition now reflects the following updates:
what 4 definitions

A
  • Inclusion of Patient Safety Organizations (PSO).
  • Inclusion of Health Information Organizations (HIO), e-prescribing gateways, and other persons that facilitate data transmission services with respect to PHI to a Covered Entity and that requires access to such PHI on a routine basis.
  • Inclusion of vendors of Personal Health Records (PHR) that require routine access to such PHI.
  • Inclusion of subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what forms of medium is included when talking about PHI that is covered by HIPAA

A
  • oral
  • paper
  • electronic

all forms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what does HIPAA stand for

A

Health Insurance Portability and Accountability Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HIPAA security focuses on what

A

ePHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is ePHI

A

electronic protected health information

17
Q

The HIPAA Security Rule Sections (Categories or Domains) are: -in order-

A
  1. administrative safeguards
  2. phyiscal safeguards
  3. technical safeguards
18
Q

what items make up a category of HIPAA security

A
  • Each category is composed of “standards” and one or more “implementation specifications”.
  • All standards must be met!