1. Security Rule establishes national standards to protect individuals'
electronic
personal health information that is created, received, used, or
maintained by a covered entity
2. What is another name The Security Standards for the Protection of Electronic
for the Security Rule? Protected Health Information
3. Who enforces the the Oflce for Civil Rights (OCR)
Security Rule?
4. Who does the Security Rule health plans, health care clearinghouses, and to any
health care
apply to? provider who transmits HI in electronic form in connection with a
transaction for which the Secretary of HHS has adopted
standards under HIPAA (the CEs) and to their BAs
5. Administrative requires covered entities to perform risk analysis as part of their
Safeguards provision in security management processes
the Security Rule
6. Administrative security management process, security personnel, information ac-
safeguard examples cess management, workforce training and management,
and eval- uation
7. Physical safeguard facility access and control, and workstation and device security
exam- ples
8. Technical safeguard exam- access control, audit controls, integrity controls, and
transmission
ples
9. Minimum Necessary 10.
stan- dard
, AHIMA ROI Microcredential Study Guide Test.
curity
actice that protected health information
should not be used or disclosed when it
is not necessary to satisfy a particular
purpose or carry out a function
, AHIMA ROI Microcredential Study Guide Test.
Can an entire A CE may not use, disclose, or request the entire medical
medical record be record for a particular purpose, unless it can specifically
disclosed? justify the whole record as the amount reasonably needed
for the purpose
11. Final Omnibus Rule implements a number of provisions of the HITECH Act,
enacted as
part of the American Recovery and Reinvestment Act of
2009, to strengthen the privacy and security protections for
health informa- tion established under HIPAA
12. The four final rules of modifications to the HIPAA Privacy, Security, and Enforcement
the Omnibus Rule Rules mandated by the HITECH Act, and certain other
modifications to improve the Rules
adopting changes to the HIPAA Enforcement Rule to
incorporate the increased and tiered civil penalty structure
provided by the HITECH Act
Breach Notification for Unsecured PHI under the HITECH
Act, which replaces the breach notification rule's ''harm''
threshold with a more objective standard
modifying the HIPAA Privacy Rule as required by the
Genetic In- formation Nondiscrimination Act (GINA) to
prohibit most health plans from using or disclosing
genetic information for underwriting purposes
13. What must happen the provider must receive satisfactory assurance from the
before a provider can request- ing party that reasonable ettorts have been made by
respond to a the requesting party to ensure that the patient who is the
subpoena? subject of the PHI has been given notice of the request
, AHIMA ROI Microcredential Study Guide Test.
14. The information may be disclosed if the subpoena is
accompanied by a proper written authorization. The
authorization form must