HIPAA and Privacy Act Training _ Challenge Exam
Study online at https://quizlet.com/_hxdz9t
1. Which of the following are common causes of breaches?: All of the above
- Theft and intentional unauthorized access to PHI and personally identifiable information (PII)
- Human error (e.g. misdirected communication containing PHI or PII)
- Lost or stolen electronic media devices or paper records containing PHI or PII
2. Under HIPAA, a covered entity (CE) is defined as:: All of the above
- A health plan
- A health care clearinghouse
- A health care provider engaged in standard electronic transactions covered by HIPAA
3. The e-Government Act promotes the use of electronic government services
by the public and improves the use of information technology in the govern-
ment.: True
4. Which of the following is NOT electronic PHI (ePHI)?: Health information stored on paper
in a file cabinet
5. When must a breach be reported to the U.S. Computer Emergency Readiness
Team?: Within 1 hours of discovery
6. A breach as defined by the DoD is broader than a HIPAA breach (or breach
defined by HHS).: True
7. Which of the following are breach prevention best practices?: All of the above
- Access only the minimum amount of PHI/personally identifiable information (PII) necessary
- Logoff or lock your workstation when it is unattended
- Promptly retrieve documents containing PHI/PHI from the printer
8. A covered entity (CE) must have an established complaint process.: True
9. The minimum necessary standard:: All of the above
- Limits uses, disclosures, and requests for PHI to the minimum necessary amount of PHI needed to carry out the
intended purposes of the use or disclosure
- Does not apply to exchanges between providers treating a patient
- Does not apply to uses or disclosures made to the individual or pursuant to the individual's authorization
1/3
Study online at https://quizlet.com/_hxdz9t
1. Which of the following are common causes of breaches?: All of the above
- Theft and intentional unauthorized access to PHI and personally identifiable information (PII)
- Human error (e.g. misdirected communication containing PHI or PII)
- Lost or stolen electronic media devices or paper records containing PHI or PII
2. Under HIPAA, a covered entity (CE) is defined as:: All of the above
- A health plan
- A health care clearinghouse
- A health care provider engaged in standard electronic transactions covered by HIPAA
3. The e-Government Act promotes the use of electronic government services
by the public and improves the use of information technology in the govern-
ment.: True
4. Which of the following is NOT electronic PHI (ePHI)?: Health information stored on paper
in a file cabinet
5. When must a breach be reported to the U.S. Computer Emergency Readiness
Team?: Within 1 hours of discovery
6. A breach as defined by the DoD is broader than a HIPAA breach (or breach
defined by HHS).: True
7. Which of the following are breach prevention best practices?: All of the above
- Access only the minimum amount of PHI/personally identifiable information (PII) necessary
- Logoff or lock your workstation when it is unattended
- Promptly retrieve documents containing PHI/PHI from the printer
8. A covered entity (CE) must have an established complaint process.: True
9. The minimum necessary standard:: All of the above
- Limits uses, disclosures, and requests for PHI to the minimum necessary amount of PHI needed to carry out the
intended purposes of the use or disclosure
- Does not apply to exchanges between providers treating a patient
- Does not apply to uses or disclosures made to the individual or pursuant to the individual's authorization
1/3