U.S. Law: Health Insurance Portability and Accountability Act (HIPAA) Flashcards
What does Healthcare Providers HIPAA category include?
doctors, hospitals, mental health professionals, dentists, long-term care facilities, farmacies, etc.
Who is a HIPAA business associate?
any third-party individiual or organization that works with a covered entity to fulfill healthcare-related functions and that has access to PHI or ePHI
What organization provides the rules and standards for organizations that are subjects to HIPAA?
HHS Centers for Medicare and Medicaid Services (CMS)
Who is subject to the HIPAA Privacy Rule?
HIPAA covered entities and business associates
What organization is responsible for implementing and enforcing the HIPAA Privacy Rule?
HHS Office for Civil Rights
What authority does HHS Office for Civil Rights has for imposing the Privacy Rule?
can issue monetary penalties for violations
What category of law best describes the HIPAA Privacy Rule?
administrative law; HIPAA Privacy Rule and HIPAA Security Rule did not go through the legislative process
What are the main two componetns (rules) of HIPAA?
- Privacy Rule
- establishes standards for safeguarding protected health information (PHI)
- Security Rule
- focuses on the security of electronic protected health information (ePHI)
Who does HIPAA apply to?
healthcare providers, health plans, and healthcare clearinghouses and their business associates who handle PHI or ePHI
What’s Business Associates Agreement (BAA) in HIPAA?
HIPAA requires that anyone working with personal health information on behalf of a HIPAA-covered entity be subject to the terms of a business associates agreement (BAA)
HIPAA covered entities fall into three broad categories. What are they?
- Healthcare Insurance Plans
- Healthcare Clearinghouses
- Healthcare providers
What does Health Insurance Plans HIPAA category include?
health insurance companies, government plans (Medicare), HMOs, employer health plans
What does Healthcare Clearinghouses HIPAA category include?
organizations that help to manage the sharing of healthcare information by converting healthcare data into formats that can be read by different health information systems