JKO HIPAA and Privacy Act Training (1.5 hours)

¡Supera tus tareas y exámenes ahora con Quizwiz!

Which of the following statements about the Privacy act are true?

All of the above

Abigail Adams is a TRICARE beneficiary and patient at Valley Forge MTF and is applying for Sun Life Insurance. Sun Life has requested some of Abigail's medical records in order to evaluate her application. Which of the following is required?

An authorization is required.

The HIPAA Security Rule applies to which of the following:

PHI transmitted electronically

Physical safeguards are:

Physical measures, including policies and procedures that are used to protect electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion

A covered entity (CE) must have an established complaint process.

TRUE

When must a breach be reported to the U.S. Computer Emergency Readiness Team?

Within 1 hour of discovery

Was this a violation of HIPAA security safeguards?

Yes

Do Betty's actions in this scenario constitute a HIPAA Privacy Rule violation?

Yes, because John is not a physician and therefore is not entitled to review any medical files.

How should John respond?

Yes. Privacy Act Statements and a SORN should both be considered prior to initiating the research project.

What of the following are categories for punishing violations of federal health care laws?

criminal penalties, civil money penalties, and sanctions

A System of Records Notice (SORN) serves as a notice to the public about a system of records and must:

All of the Above

If an individual believes that a DOD covered entity (CE) is not complying with HIPAA, he or she may file a complaint with the:

All of the above

Which of the following are common causes of breach?

All of the above

Which of the following are breach prevention best practices?

All of the above -Access only the minimum amount of PHI/ PII necessary -Logoff or lock your workstation when it is unattended -Promptly retrieve documents containing PHI/PII from the printer

Which of the following are examples of personally identifiable information (PII)?

All of the above Social Security Number Home Address Telephone

The HIPAA Privacy Rule applies to which of the following?

All of the above The HIPAA Privacy Rule applies to PHI that is transmitted or maintained by a covered entity or a business associate in any form or medium.

What enforcement actions may occur based on Janet's conduct?

All of the above.

How should John advise the staff member to proceed?

Both B and C

Which of the following are fundamental objectives of information security?

Confidentiality, Integrity, and Availability

Which HHS Office is charged with protecting an individual patient's health information privacy and security through the enforcement of HIPAA?

Office for Civil Rights (OCR) ​

T or F. Under HIPAA, a person or entity that provides services to a CE that do not involve the use or disclosure of PHI would be considered a BA.

False

True or False? "Use" is defined under HIPAA as the release of information containing PHI outside of the covered entity (CE).

False

Which of the following is NOT electronic PHI (ePHI)?

Health information stored on paper in a file cabinet

Technical safeguards are:

Information technology and the associated policies and procedures that are used to protect and control access to ePHI

Dr Jefferson sends a patient's medical record to the surgeon's office in support of a referral for treatment he made for the patient. Which of the following is required?

Neither an authorization nor an opportunity to agree or object is required.

Valley Forge MTF discloses a patient's information in response to a request from his HHS in the investigation of a patient complaint. Which of the following is required?

Neither an authorization nor an opportunity to agree or object is required.

The Chief Medical Officer for Valley Forge MTF utilizing PHI is conducting monthly physician peer review operations exercise. Which of the following is required?

Neither an authorization not an opportunity to agree or object is required.

A friend of Phillip Livingston, a military service member who is being treated for a broken leg at Valley Forge MTF, asked what room Phillip is in so that he can visit. Which of the following is required?

The patient must be given the opportunity to agree or object to the use or disclosure.

A breach as defined by the DoD is broader than a HIPAA breach (or breach defined by HHS).

True

HIPAA provides individuals with the right to request an accounting of disclosures of their PHI.

True

The e-Government Act promotes the use of electronic government services by the public and improves the use of information technology in the government.

True


Conjuntos de estudio relacionados

Hardware and Buying a Computer Quizzes for Exam 1- CGS 2060

View Set

Physiology 1.2. - Cardiovascular System

View Set

urinary test zoom + PPT questions

View Set

Standard Form of a Linear Equation

View Set

Chapter 13 - Modems and Tranceivers

View Set

Chapter 6: The Call for Church Reform

View Set

APCSP BI 2- Data - Binary Numbers and Other

View Set