AHIMA ROI Microcredential Exam
Questions And Answers
Security Rule - - -
correct answer ✅establishes national standards to protect
individuals' electronic personal health information that is created,
received, used, or maintained by a covered entity
What is another name for the Security Rule? - - -
correct answer ✅The Security Standards for the Protection of
Electronic Protected Health Information
Who enforces the Security Rule? - - -
correct answer ✅the Office for Civil Rights (OCR)
Who does the Security Rule apply to? - - -
correct answer ✅health plans, health care clearinghouses, and to
any health care provider who transmits HI in electronic form in
connection with a transaction for which the Secretary of HHS has
adopted standards under HIPAA (the CEs) and to their BAs
Administrative Safeguards provision in the Security Rule - - -
correct answer ✅requires covered entities to perform risk analysis
as part of their security management processes
,AHIMA ROI Microcredential Exam
Questions And Answers
Administrative safeguard examples - - -
correct answer ✅security management process, security
personnel, information access management, workforce training and
management, and evaluation
Physical safeguard examples - - -
correct answer ✅facility access and control, and workstation and
device security
Technical safeguard examples - - -
correct answer ✅access control, audit controls, integrity controls,
and transmission security
Minimum Necessary standard - - -
correct answer ✅practice that protected health information
should not be used or disclosed when it is not necessary to satisfy a
particular purpose or carry out a function
Can an entire medical record be disclosed? - - -
correct answer ✅A CE may not use, disclose, or request the entire
medical record for a particular purpose, unless it can specifically
justify the whole record as the amount reasonably needed for the
purpose
,AHIMA ROI Microcredential Exam
Questions And Answers
Final Omnibus Rule - - -
correct answer ✅implements a number of provisions of the
HITECH Act, enacted as part of the American Recovery and
Reinvestment Act of 2009, to strengthen the privacy and security
protections for health information established under HIPAA
The four final rules of the Omnibus Rule - - -
correct answer ✅modifications to the HIPAA Privacy, Security, and
Enforcement Rules mandated by the HITECH Act, and certain other
modifications to improve the Rules
adopting changes to the HIPAA Enforcement Rule to incorporate
the increased and tiered civil penalty structure provided by the
HITECH Act
Breach Notification for Unsecured PHI under the HITECH Act, which
replaces the breach notification rule's ''harm'' threshold with a
more objective standard
modifying the HIPAA Privacy Rule as required by the Genetic
Information Nondiscrimination Act (GINA) to prohibit most health
, AHIMA ROI Microcredential Exam
Questions And Answers
plans from using or disclosing genetic information for underwriting
purposes
What must happen before a provider can respond to a subpoena? -
--
correct answer ✅the provider must receive satisfactory assurance
from the requesting party that reasonable efforts have been made
by the requesting party to ensure that the patient who is the
subject of the PHI has been given notice of the request
When can a disclosure of pHI in response to a subpoena occur? - - -
correct answer ✅The information may be disclosed if the
subpoena is accompanied by a proper written authorization. The
authorization form must include all of the elements described in
HIPAA's authorization rule and must be signed by the appropriate
person (the patient himself, or the patient's personal
representative)
The information may be disclosed without the individual's
authorization if it is accompanied by a court order for the
information
Questions And Answers
Security Rule - - -
correct answer ✅establishes national standards to protect
individuals' electronic personal health information that is created,
received, used, or maintained by a covered entity
What is another name for the Security Rule? - - -
correct answer ✅The Security Standards for the Protection of
Electronic Protected Health Information
Who enforces the Security Rule? - - -
correct answer ✅the Office for Civil Rights (OCR)
Who does the Security Rule apply to? - - -
correct answer ✅health plans, health care clearinghouses, and to
any health care provider who transmits HI in electronic form in
connection with a transaction for which the Secretary of HHS has
adopted standards under HIPAA (the CEs) and to their BAs
Administrative Safeguards provision in the Security Rule - - -
correct answer ✅requires covered entities to perform risk analysis
as part of their security management processes
,AHIMA ROI Microcredential Exam
Questions And Answers
Administrative safeguard examples - - -
correct answer ✅security management process, security
personnel, information access management, workforce training and
management, and evaluation
Physical safeguard examples - - -
correct answer ✅facility access and control, and workstation and
device security
Technical safeguard examples - - -
correct answer ✅access control, audit controls, integrity controls,
and transmission security
Minimum Necessary standard - - -
correct answer ✅practice that protected health information
should not be used or disclosed when it is not necessary to satisfy a
particular purpose or carry out a function
Can an entire medical record be disclosed? - - -
correct answer ✅A CE may not use, disclose, or request the entire
medical record for a particular purpose, unless it can specifically
justify the whole record as the amount reasonably needed for the
purpose
,AHIMA ROI Microcredential Exam
Questions And Answers
Final Omnibus Rule - - -
correct answer ✅implements a number of provisions of the
HITECH Act, enacted as part of the American Recovery and
Reinvestment Act of 2009, to strengthen the privacy and security
protections for health information established under HIPAA
The four final rules of the Omnibus Rule - - -
correct answer ✅modifications to the HIPAA Privacy, Security, and
Enforcement Rules mandated by the HITECH Act, and certain other
modifications to improve the Rules
adopting changes to the HIPAA Enforcement Rule to incorporate
the increased and tiered civil penalty structure provided by the
HITECH Act
Breach Notification for Unsecured PHI under the HITECH Act, which
replaces the breach notification rule's ''harm'' threshold with a
more objective standard
modifying the HIPAA Privacy Rule as required by the Genetic
Information Nondiscrimination Act (GINA) to prohibit most health
, AHIMA ROI Microcredential Exam
Questions And Answers
plans from using or disclosing genetic information for underwriting
purposes
What must happen before a provider can respond to a subpoena? -
--
correct answer ✅the provider must receive satisfactory assurance
from the requesting party that reasonable efforts have been made
by the requesting party to ensure that the patient who is the
subject of the PHI has been given notice of the request
When can a disclosure of pHI in response to a subpoena occur? - - -
correct answer ✅The information may be disclosed if the
subpoena is accompanied by a proper written authorization. The
authorization form must include all of the elements described in
HIPAA's authorization rule and must be signed by the appropriate
person (the patient himself, or the patient's personal
representative)
The information may be disclosed without the individual's
authorization if it is accompanied by a court order for the
information