CRIS ACTUAL TEST PAPER COMPLETE
QUESTIONS AND ANSWERS FULL
SOLUTION
●● HIPAA Security Rule
Answer: Federal rule requiring safeguards for electronic PHI.
●● Protected Health Information (PHI)
Answer: Individually identifiable health information protected by
HIPAA.
●● Designated Record Set
Answer: Records used to make decisions regarding a patient's care or
payment.
●● Minimum Necessary Standard
Answer: Principle requiring disclosure of only the least amount of PHI
needed.
●● Business Associate
Answer: Person or company performing services involving PHI on
behalf of a covered entity.
,●● Business Associate Agreement (BAA)
Answer: Written agreement outlining responsibilities of vendors
handling PHI.
●● Office for Civil Rights (OCR)
Answer: Organization responsible for enforcing HIPAA.
●● Patient Directive
Answer: Written request from a patient directing release of their own
records.
●● HIPAA Authorization
Answer: Required when PHI is disclosed outside permitted HIPAA uses.
●● Treatment, Payment & Healthcare Operations (TPO)
Answer: Healthcare activities that generally do not require patient
authorization.
●● Notice of Privacy Practices (NPP)
Answer: Document explaining how PHI may be used and patient rights.
●● Accounting of Disclosures
, Answer: Documentation describing certain disclosures made during the
previous six years.
●● 21st Century Cures Act
Answer: Federal law designed to improve interoperability and patient
access to electronic health information.
●● Information Blocking
Answer: Practices that improperly interfere with access to electronic
health information.
●● Peer Review Organization (PRO)
Answer: Organization reviewing quality of Medicare services.
●● Quality Improvement Organization (QIO)
Answer: Organization focused on improving Medicare healthcare
quality.
●● Medical Records Custodian
Answer: Person responsible for maintaining medical records.
●● Personal Representative
QUESTIONS AND ANSWERS FULL
SOLUTION
●● HIPAA Security Rule
Answer: Federal rule requiring safeguards for electronic PHI.
●● Protected Health Information (PHI)
Answer: Individually identifiable health information protected by
HIPAA.
●● Designated Record Set
Answer: Records used to make decisions regarding a patient's care or
payment.
●● Minimum Necessary Standard
Answer: Principle requiring disclosure of only the least amount of PHI
needed.
●● Business Associate
Answer: Person or company performing services involving PHI on
behalf of a covered entity.
,●● Business Associate Agreement (BAA)
Answer: Written agreement outlining responsibilities of vendors
handling PHI.
●● Office for Civil Rights (OCR)
Answer: Organization responsible for enforcing HIPAA.
●● Patient Directive
Answer: Written request from a patient directing release of their own
records.
●● HIPAA Authorization
Answer: Required when PHI is disclosed outside permitted HIPAA uses.
●● Treatment, Payment & Healthcare Operations (TPO)
Answer: Healthcare activities that generally do not require patient
authorization.
●● Notice of Privacy Practices (NPP)
Answer: Document explaining how PHI may be used and patient rights.
●● Accounting of Disclosures
, Answer: Documentation describing certain disclosures made during the
previous six years.
●● 21st Century Cures Act
Answer: Federal law designed to improve interoperability and patient
access to electronic health information.
●● Information Blocking
Answer: Practices that improperly interfere with access to electronic
health information.
●● Peer Review Organization (PRO)
Answer: Organization reviewing quality of Medicare services.
●● Quality Improvement Organization (QIO)
Answer: Organization focused on improving Medicare healthcare
quality.
●● Medical Records Custodian
Answer: Person responsible for maintaining medical records.
●● Personal Representative