HIPAA/PA Refresher TEST
Study online at https://quizlet.com/_1kjxf0
1. Under HIPAA, a All of the above
covered entity
(CE) is defined as: Under HIPAA, a CE is a health plan, a health care clearinghouse, or a health care
provider engaged in standard electronic transactions covered by HIPAA.
2. The minimum All of the above
necessary stan-
dard: The minimum necessary standard limits uses, disclosures, and requests for PHI to
the minimum necessary amount of PHI needed to carry out the intended purposes
of the use or disclosure. The minimum necessary standard does not apply to
disclosures to, or requests by, a health care provider for treatment purposes. It
also does not apply to uses or disclosures made to the individual or pursuant to
the individual's authorization.
3. Which of the fol- An individual's first and last name and the medical diagnosis in a physician's
lowing would be progress report
considered PHI?
4. The HIPAA Priva- All of the above
cy Rule applies to
which of the fol- The HIPAA Privacy Rule applies to PHI that is transmitted or maintained by a covered
lowing? entity or a business associate in any form or medium.
5. Which of the All of the above
following state-
ments about the The HIPAA Security Rule: Established a national set of standards for the protection
HIPAA Security of PHI that is created, received, maintained, or transmitted in electronic media
Rule are true? by a HIPAA CE or BA; protects ePHI; and addresses three types of safeguards -
administrative, technical and physical - that must be in place to secure individuals'
ePHI.
6. The HIPAA Securi- PHI transmitted electronically
ty Rule applies to
, HIPAA-PA Refresher TEST
HIPAA/PA Refresher TEST
Study online at https://quizlet.com/_1kjxf0
which of the fol-
lowing:
7. Which of the fol- All of the above
lowing are fun-
damental objec- Confidentiality, Integrity, and Availability are the fundamental objectives of health
tives of informa- information security and the HIPAA Security Rule requires covered entities and
tion security? business associates to protect against threats and hazards to these objectives.
8. Technical safe- Information technology and the associated policies and procedures that are used
guards are: to protect and control access to ePHI
9. If an individual All of the above
believes that a
DoD covered en- If an individual believes that a DoD CE is not complying with HIPAA he or she may
tity (CE) is not file a complaint with the DHA Privacy Office, HHS Secretary, and/or the MTF HIPAA
complying with Privacy Officer.
HIPAA, he or she
may file a com-
plaint with the:
10. Which of the fol- All of the above
lowing are cate-
gories for pun- The three main categories of punishment for violating federal health care laws
ishing violations include: criminal penalties, civil money penalties, and sanctions.
of federal health
care laws?
11. Which HHS Office Office for Civil Rights (OCR)
is charged with
protecting an in-
dividual patient's
health informa-