• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 80 pages
Exam (elaborations)

Cpss Test- Ophthalmology Actual Exam With Complete Questions And Well Detailed Answers

Document preview thumbnail
Preview 4 out of 80 pages

HIPAA stands for a. Health Information Portability and Accountability Act b. Health Insurance Portability and Accountability Act c. Health Insurance Protection and Activity Act d. Home Information Protection and Accountability Act. - CORRECT ANSWER -b. Health Insurance Portability and Accountability Act One primary change included in the HIPAA Omnibus Final Rule of 2013 requires a business associate of the covered entity (physician practice) to sign a Business Associate Agreement with: a. Subcontractors of professional associations b. Subcontractors of business associates c. Subcontractors of optometrists d. Subcontractors of affiliated hospitals - CORRECT ANSWER -b. Subcontractors of business associates Page 2 of 80 T/F. According to the regulations contained in the Omnibus Final Rule of 2013, a patient has the right to receive a copy of his or her medical record in an electronic format if the associated provider utilizes electronic health records. - CORRECT ANSWER -True Covered entities under HIPAA include: a. Lawyers b. Health care providers c. Health care facilities d. Librarians e. a and d. f. b and c. - CORRECT ANSWER -b and c. Health care providers and Health care facilities Protected Health Information (PHI) includes: a. Demographic information on individuals b. Insurance eligibility and coverage information c. Billing records, claims data, referral authorizations d. Medical records, diagnosis, genetic information, and testing e. c and d f. All of the above. - CORRECT ANSWER -f. All of the above. T/F. Entities covered under HIPAA are required to develop a Notice of Privacy Practices (NPP) and must make these available to individuals accessing services through the entity. - CORRECT ANSWER -True Page 3 of 80 Which of the following disclosures require signed permission from the individual whose PHI is being requested? a. Referrals to physicians b. Consultations between physicians treating individuals c. Information requested by an attorney without a subpoena d. Information requested by insurance companies for payment purposes. - CORRECT ANSWER -c. Information requested by an attorney without a subpoena T/F. Patient names on a sign-in form are considered an intentional breach of PHI. - CORRECT ANSWER -False; incidental breach T/F. Under the HITECH Act, the Breach Notification Act does NOT require notification to HHS of the intentional or unintentional disclosure of PHI to unapproved entities on an annual basis unless the breach has affected more than 500 individuals. - CORRECT ANSWER -False Notice of Privacy Practices (NPP) must be updated in 2013 to include which of the following? a. Names of the owners of the covered entity b. Names of companies that have access to PHI c. Patient's right to restrict disclosures of PHI to a health plan when the patient pays out of pocket and in full for the health care item or service. Page 4 of 80 d. Profitability of the covered entity. - CORRECT ANSWER -c. Patient's right to restrict disclosures of PHI to a health plan when the patient pays out of pocket and in full for the health care item or service. If an individual or staff member has a complaint regarding the use of PHI, the individual must speak with the facility's: a. Manager b. Owner c. Maintenance coordinator d. Privacy Officer e. Chief Physician - CORRECT ANSWER -d. Privacy officer. Which of the following is NOT an administrative safeguard requirement? a. Designating a privacy officer b. Developing a cost analysis of HIPAA requirements. c. Obtaining HIPAA-compliant business associate agreements for subcontractors d. Establishing procedures to prevent terminated employees from obtaining access to confidential information after termination - CORRECT ANSWER -b. Developing a cost analysis of HIPAA requirements. Physical safeguards do NOT include which of the following? a. Posting PHI on a white board in the facility b. Storage of PHI in a secure place c. Shredding of PHI

Content preview

Page 1 of 80


CPSS TEST- OPHTHALMOLOGY 2025-2026 ACTUAL EXAM
WITH COMPLETE QUESTIONS AND WELL DETAILED
ANSWERS




HIPAA stands for

a. Health Information Portability and Accountability Act
b. Health Insurance Portability and Accountability Act
c. Health Insurance Protection and Activity Act

d. Home Information Protection and Accountability Act. - CORRECT
ANSWER -b. Health Insurance Portability and Accountability Act


One primary change included in the HIPAA Omnibus Final Rule of 2013
requires a business associate of the covered entity (physician practice) to sign
a Business Associate Agreement with:
a. Subcontractors of professional associations
b. Subcontractors of business associates
c. Subcontractors of optometrists

d. Subcontractors of affiliated hospitals - CORRECT ANSWER -b.
Subcontractors of business associates

, Page 2 of 80


T/F. According to the regulations contained in the Omnibus Final Rule of 2013,
a patient has the right to receive a copy of his or her medical record in an
electronic format if the associated provider utilizes electronic health records. -
CORRECT ANSWER -True


Covered entities under HIPAA include:
a. Lawyers
b. Health care providers
c. Health care facilities
d. Librarians
e. a and d.

f. b and c. - CORRECT ANSWER -b and c.
Health care providers and Health care facilities


Protected Health Information (PHI) includes:
a. Demographic information on individuals
b. Insurance eligibility and coverage information
c. Billing records, claims data, referral authorizations
d. Medical records, diagnosis, genetic information, and testing
e. c and d

f. All of the above. - CORRECT ANSWER -f. All of the above.


T/F. Entities covered under HIPAA are required to develop a Notice of Privacy
Practices (NPP) and must make these available to individuals accessing
services through the entity. - CORRECT ANSWER -True

, Page 3 of 80




Which of the following disclosures require signed permission from the
individual whose PHI is being requested?
a. Referrals to physicians
b. Consultations between physicians treating individuals
c. Information requested by an attorney without a subpoena
d. Information requested by insurance companies for payment purposes. -
CORRECT ANSWER -c. Information requested by an attorney
without a subpoena


T/F. Patient names on a sign-in form are considered an intentional breach of
PHI. - CORRECT ANSWER -False; incidental breach


T/F. Under the HITECH Act, the Breach Notification Act does NOT require
notification to HHS of the intentional or unintentional disclosure of PHI to
unapproved entities on an annual basis unless the breach has affected more
than 500 individuals. - CORRECT ANSWER -False


Notice of Privacy Practices (NPP) must be updated in 2013 to include which of
the following?
a. Names of the owners of the covered entity
b. Names of companies that have access to PHI
c. Patient's right to restrict disclosures of PHI to a health plan when the patient
pays out of pocket and in full for the health care item or service.

, Page 4 of 80


d. Profitability of the covered entity. - CORRECT ANSWER -c.
Patient's right to restrict disclosures of PHI to a health plan when the patient
pays out of pocket and in full for the health care item or service.


If an individual or staff member has a complaint regarding the use of PHI, the
individual must speak with the facility's:
a. Manager
b. Owner
c. Maintenance coordinator
d. Privacy Officer

e. Chief Physician - CORRECT ANSWER -d. Privacy officer.


Which of the following is NOT an administrative safeguard requirement?
a. Designating a privacy officer
b. Developing a cost analysis of HIPAA requirements.
c. Obtaining HIPAA-compliant business associate agreements for
subcontractors
d. Establishing procedures to prevent terminated employees from obtaining
access to confidential information after termination - CORRECT
ANSWER -b. Developing a cost analysis of HIPAA requirements.


Physical safeguards do NOT include which of the following?
a. Posting PHI on a white board in the facility
b. Storage of PHI in a secure place
c. Shredding of PHI

Document information

Uploaded on
August 14, 2025
Number of pages
80
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
CA$23.51

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
258
Followers
29
Items
8482
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions