RES: HIPAA Flashcards

1
Q

what does HIPAA stand for?

A

Health Insurance Portability and Accountability Act t

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

when and where was HIPAA passed by the congress?

A

1996 & USA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does HIPAA do?

A
  1. provides the ability to transfer and continue health insurance coverage for millions of American workers and their families when they change or lose their jobs;
  2. reduces health care fraud and abuse;
  3. mandates industry-wide standards for health care information on electronic billing
  4. requires the protection and confidential handling of protected health information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what is the major role of the privacy rule?

A

To assure that individuals’ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public’s health and well-being.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

this rule applies to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form in connection with transactions for which the Secretary of HHS has adopted standards under HIPAA

A

the privacy rule and administrative simplification rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

protects all “individually identifiable health information”

A

The Privacy Rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

information that includes demographic data,

A

Individually identifiable health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Individually identifiable health information i relates to:

A
  • the individual’s past, present or future physical or mental health or condition,
  • the provision of health care to the individua
  • the past, present, or future payment for the provision of health care to the individual,
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

This rule excludes from protected health information employment records that a covered entity maintains in its capacity as an employer and education and certain other records subject to, or defined in, the Family Educational Rights and Privacy Act, 20

A

privacy rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual.

A

Individually identifiable health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

because the HIPAA is a law in that applies only to healthcare in the USA, a law has been passed in the Philippines, this law was created in the philippines

A

Republic Act 10173 – Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

refers to an individual whose personal, sensitive personal, or privileged information is processed;

A

Data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

refers to the structure and procedure by which personal data is collected and further processed in an information and communications system or relevant filing system, including the purpose and intended output of the processing;

A

Data processing systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

This act protecting individual personal information in information and communications systems in the government and the private sector, creating for this purpose a national privacy commission, and for other purposes.

A

Republic Act 10173 – Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

refers to communication by whatever means of any advertising or marketing material which is directed to particular individuals

A

Direct marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

is the disclosure or transfer to a third party of personal data under the custody of a personal information controller or personal information processor.

A

“Data sharing”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

refers to any set of information relating to natural or juridical persons to the extent that, although the information is not processed by equipment operating automatically in response to instructions given for that purpose, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular individual is readily accessible

A

Filing system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

refers to a system for generating, sending, receiving, storing, or otherwise processing electronic data messages or electronic documents, and includes the computer system

A

Information and communications system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

refers to all types of personal information

A

Personal data

17
Q

refers to Republic Act No. 10173, also known as the Data Privacy Act of 2012;

A

ACT

18
Q

refers to the National Privacy Commission

A

COMMISSION

19
Q

any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of his or her personal, sensitive personal, or privileged information.

A

“Consent of the data subject”

20
Q

refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed

A

Personal data breach

21
Q

refers to any information, whether recorded in a material form or not, from which the identity of an individual

A

Personal information

21
Q

refers to a natural or juridical person, or any other body who controls the processing of personal data, or instructs another to process personal data on its behalf.

A

Personal information controller

21
Q

refers to any natural or juridical person or any other body to whom a personal information controller may outsource or instruct the processing of personal data pertaining to a data subject

A

Personal information processor

22
Q

refers to any operation or any set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.

A

Processing

23
Q

refers to any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects

A

Profiling

23
Q

refers to any government entity created by the Constitution or law, and vested with law enforcement or regulatory authority and functions

A

Public authority

23
Q

refers to any and all forms of data, which, under the Rules of Court and other pertinent laws constitute privileged communication

A

Privileged information

23
Q

is an event or occurrence that affects or tends to affect data protection, or may compromise the availability, integrity and confidentiality of personal data. It includes incidents that would result to a personal data breach, if not for safeguards that have been put in place

A

Security incident

24
Q

Penalty: Unauthorized Processing of Personal Information and Sensitive Personal Information.

A
  1. imprisonment 1 yr to 3 yrs
  2. fine of not less than 500k but not more than 2M
  3. imprisonment 3 to 6 yrs and a fine of not less than 500k but not more than 4M
25
Q

Penalty: Accessing Personal Information and Sensitive Personal Information Due to Negligence.

A

1.imprisonment 1-3 yrs and a fine of not less than 500k but not more than 2M

  1. imprisonment 3-6 yrs and a fine of not less than 500k but more not more than 4M
26
Q

Penalty: Improper Disposal of Personal Information and Sensitive Personal Information.

A
  1. imprisonment: (6) mts to2 years and a fine of not less than 100k but not more than 500k
  2. imprisonment :1 to 3 yrs and a fine of not less than 100k but not more than 1M
27
Q

Unauthorized Access or Intentional Breach

A

imprisonment 1 to 3 yrs and a fine of not less than 500k but not more than 2M

27
Q

Processing of Personal Information and Sensitive Personal Information for Unauthorized Purposes.

A
  1. imprisonment 1yr and six 6 months to 5 yrs and a fine of not less than 500k but not more than 1M
  2. imprisonment: 2-7 yrs and a fine of not less than 500k but not more than 2M
28
Q

Concealment of Security Breaches Involving Sensitive Personal Information

A

imprisonment 1 yr to 6 months to 5 yrs and a fine of not less than 500k but not more than 1M.

29
Q

Malicious Disclosure

A

imprisonment 1 yr to 6 months to 5 yrs and a fine of not less than 500k but not more than 1M.

30
Q

Unauthorized Disclosure.

A

1-3 yrs and a fine of not less than500k but not more than 1M
3-5 yrs and a fine of not less than 500k but not more than 2m

31
Q

Combination or Series of Acts.

A

3-6 YRS and a fine of not less than 1M but not more than 5M

32
Q

Extent of Liability.

A
32
Q

Large-Scale

A

maximum penalty in the corresponding scale of penalties provided for the preceding offenses shall be imposed when the personal data of at least one hundred (100) persons are harmed, affected, or involved, as the result of any of the above-mentioned offenses.

33
Q

what is the difference of privacy and confidentiality

A

privacy is the right of an individual to keep his or her health information private.

confidentiality- refers to the duty of anyone entrusted with health information to keep that information

34
Q

refers to the duty of anyone entrusted with health information to keep that information

A

confidentiality

35
Q

the right of an individual to keep his or her health information private.

A

privacy