Under HIPAA, a covered entity (CE) is defined as: - Rule requires covered entities and business associates to
ANSWER -All of the above protect against threats and hazards to these objectives.
Under HIPAA, a CE is a health plan, a health care
clearinghouse, or a health care provider engaged in standard
electronic transactions covered by HIPAA. Technical safeguards are: - ANSWER -Information
technology and the associated policies and procedures that are
used to protect and control access to ePHI
The minimum necessary standard: - ANSWER -All of the
above
If an individual believes that a DoD covered entity (CE) is not
The minimum necessary standard limits uses, disclosures, and complying with HIPAA, he or she may file a complaint with the: -
requests for PHI to the minimum necessary amount of PHI ANSWER -All of the above
needed to carry out the intended purposes of the use or
disclosure. The minimum necessary standard does not apply to If an individual believes that a DoD CE is not complying with
disclosures to, or requests by, a health care provider for HIPAA he or she may file a complaint with the DHA Privacy
treatment purposes. It also does not apply to uses or Office, HHS Secretary, and/or the MTF HIPAA Privacy Officer.
disclosures made to the individual or pursuant to the individual's
authorization.
Which of the following are categories for punishing violations of
federal health care laws? - ANSWER -All of the above
Which of the following would be considered PHI? -
ANSWER -An individual's first and last name and the The three main categories of punishment for violating federal
medical diagnosis in a physician's progress report health care laws include: criminal penalties, civil money
penalties, and sanctions.
The HIPAA Privacy Rule applies to which of the following? -
ANSWER -All of the above Which HHS Office is charged with protecting an individual
patient's health information privacy and security through the
The HIPAA Privacy Rule applies to PHI that is transmitted or enforcement of HIPAA? - ANSWER -Office for Civil Rights
maintained by a covered entity or a business associate in any (OCR)
form or medium.
A covered entity (CE) must have an established complaint
Which of the following statements about the HIPAA Security process. - ANSWER -True
Rule are true? - ANSWER -All of the above
The HIPAA Security Rule: Established a national set of
standards for the protection of PHI that is created, received, Which of the following are examples of personally identifiable
maintained, or transmitted in electronic media by a HIPAA CE information (PII)? - ANSWER -All of the above
or BA; protects ePHI; and addresses three types of safeguards
- administrative, technical and physical - that must be in place to PII means information that can be linked to a specific individual
secure individuals' ePHI. and may include the following: Social Security Number; DoD
identification number; home address; home telephone; date of
birth (year included); personal medical information; or
personal/private information (e.g., an individual's financial data).
The HIPAA Security Rule applies to which of the following: -
ANSWER -PHI transmitted electronically
The e-Government Act promotes the use of electronic
government services by the public and improves the use of
Which of the following are fundamental objectives of information information technology in the government. - ANSWER -
security? - ANSWER -All of the above True
Confidentiality, Integrity, and Availability are the fundamental
objectives of health information security and the HIPAA Security
1/4