Week 7 Flashcards
How many title statues HIPAA has?
5
What is title one?
Portability: preventation of discrimination in health care insurance enrollment and premiums. Health insurance coverage and protecting individuals and their dependence from losing coverage when they leave or otherwise change jobs
What is title two?
Administrative Simplification: Efforts by HIPAA to standardize the healthcare industry’s capricious and inefficient business practices. Prevention of abuse and healthcare fraud
Are all providers covered entities?
No, not all providers are cover. Per definition, a health care provider who transmits any information pertain a certain transaction in electronic form.
Security Rule
Defines a facility as the physical premises and the interior and exterior building
Role- Based Access Control
Gives access to users based on their roles as member of the organization and users are aligned to a preestablished group with it with certain access priviledge based on the groups need to access the information
Based on the US department of Health and Human Services, how many people are effect by laptop theft resulting to a health information breach?
500 or more individuals
True or False: Erasing or deleting a file does not sufficiently remove EPI.
True
Encryption
scrambles or encodes data, protecting it from being comprehend by unauthorized individuals
Public Key Infrastructure
is a more secure method of encryption technology because it use two keys encrypt transmit and send message
Audit Control
Requires installation of hardware, software, or manual mechanism to examine and record activity in systems that contain ePHI
Firewall
is a buffer between an organization internal trusted network and the internet which is considered an untrusted network
Risk Management
Applies to all aspects of an organization’s operational and focuses on identifying, evaluating, and controlling risk that can expose the organization to financial liability,
HIPAA has three primary documents to inform patients and give them control over their PHI
Notice of Privacy Practice, Authorization, and Consent
Notice of privacy practices written in________ and explains how a covered entity will use his or her PHI
Plain Language
Use and disclosure permitted with authorization
Facility Directory
Disclosure of Relevant
Facility Directory
If a patient agrees to disclose to those who ask to for the individual by name
Emergencies
Clergy of individual’s religious affiliation may receive list
Disclosure of Relevant PHI
To family members, relatives, or close friends involved in individual care or payment
If individual unable to agree or object covered entity may use professional judgment to decide if it is in the individuals best interest
True or False: 16 circumstances where written authorization and verbal agreement or objection are not required
True
What are the first 12 of the use and disclosure permitted without authorization is referred as?
Public interest and benefit
Public health activities
No written authorization is required for disclosure of student immunization records from cover entity
Decedents
HIPAA privacy act protection survive as individual’s per HITECH for 50 years after death
Business Associate
A person or organization not a part of the cover entity’s workforce, that performs a function or activities on behalf of or affecting a covered entity involving use or disclosure of individual identifies health information
Business Associate Agreement
Under HIPAA, as originally written business associates as business associates once they were identify as covered entity business associate through a contracted
- even without a contract
-allows covered entity to lawfully disclose protected health information to business associate
Workforce
is any individual working under the covered entity’s direct control regardless of whether they are paid by the covered entity or not
PHI three part test
Identify the person
Future present and past
it held or transmitted by a covered entity or its business associate in any form of medium
Limited Dataset
is PHI that does not completely de-identified individual but excludes most direct identifiers of the individual and individual’s relative employers or household members