Using and Disclosing PHI Flashcards
The uses and disclosures of PHI allowed and not allowed under HIPAA
1
Q
Permissible Uses and Disclosures of PHI
A
TPO: <ul> <li>Treatment</li> <li>Payment</li> <li>Operations</li> </ul> covered entities: for any disclosure outside TPO, must obtain explicit authorization from individual whose information is to be disclosed business associates: only allowed to disclose for specific intended stated purpose in the BA contract. Cannot use/disclose PHI which violates contract (including when provided by CO or BA), or in violation of the law
2
Q
Sharing or Disclosing PHI with Third Parties
A
due diligence with questions to confirm HIPAA compliant before signing BA.
3
Q
Minimum Necessary Standard
A
BA must perform reasonable efforts to not use/disclose more than minimum PHI for intended purpose
4
Q
for CE or BA to disclose outside of TPO, …
A
- get explicit permission from patient with a signed authorization
- “de-identify” the information by deleting all individually identifying information
5
Q
Individually Identifiable Information
A
name, address, email, phone number, any other unique identifiers or codes
6
Q
breach
A
when PHI is improperly used or disclosed
7
Q
breach response
A
investigate, mitigate, document, and notify the CE whose information was affected, and potentially notify the Office of Civil Rights at the Department of Health and Human Services.