• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 18 pages
Exam (elaborations)

CITI Training question & answers 100% correct

Document preview thumbnail
Preview 3 out of 18 pages

CITI Training question & answers 100% correctPrivacy, in the health information context, refers to: The rules about who can access health information, and under what circumstances. In the U.S., privacy protections for health information come from: Federal, state, local, and private certification organizations' requirements With respect to permissions for uses and disclosures, HIPAA divides health information into three categories. Into which category do discussions with family members go? Uses or disclosures that generally require oral agreement only. Under HIPAA, an organization is required to do which of the following? Appoint a Privacy Officer to administer HIPAA rules. When patients receive a copy of an organization's privacy notice, why are they asked to sign an acknowledgment? It shows they received it. Which of these is not a right under HIPAA? To control all disclosures of information in the health record. HIPAA's "incidental uses and disclosures" provision excuses deviations from the minimum necessary standard. What is excused? Truly accidental "excess" uses and disclosures, where reasonable caution was otherwise used and there was no negligence. When a privacy problem is discovered, which of the following is true? Healthcare workers and patients are protected from intimidation or retaliation for reporting. What kinds of persons and organizations are affected by HIPAA's requirements? Healthcare providers, health plans, and health information clearinghouses, as well as their business associates and by extension the workers for those organizations. With respect to permissions for uses and disclosures, HIPAA divides health information into three categories. Into which category does information related to research, marketing, and fundraising go? Uses or disclosures that generally require specific written authorization. With respect to permissions for uses and disclosures, HIPAA divides health information into three categories. Into which category does information related to "treatment, payment and health care operations" go? Uses or disclosures that can generally occur without any specific permission from the patient. HIPAA privacy protections cover identifiable personal information about the "past, present or future physical or mental health condition." What does that include? Health information in any form or medium, as long as it is identified (or identifiable) as a particular person's information. Under the federal HIPAA regulations, state health privacy laws: Can remain in force if "more stringent" than HIPAA, complementing HIPAA's foundation of protections, provided there is no direct conflict in requirements. What does HIPAA's "minimum necessary" and related standards require of healthcare workers? Use or disclose only the minimum necessary amount of health information to accomplish a task. HIPAA includes in its definition of "research," activities related to: Development of generalizable knowledge. If you're unsure about the particulars of HIPAA research requirements at your organization or have questions, you can usually consult with: An organizational IRB or Privacy Board, privacy official ("Privacy Officer"), or security official ("Security Officer"), depending on the issue. Recruiting into research ... Can qualify as an activity "preparatory to research," at least for the initial contact, but data should not leave the covered entity. Under HIPAA, a "disclosure accounting" is required: For all human subjects research that uses PHI without an authorization from the data subject, except for limited data sets. HIPAA's protections for health information used for research purposes... Supplement those of the Common Rule and FDA. Under HIPAA, "retrospective research" (a.k.a., data mining) on collections of PHI generally ... Is research, and so requires either an authorization or meeting one of the criteria for a waiver of authorization. When required, the information provided to the data subject in a HIPAA disclosure accounting ... must be more detailed for disclosures that involve fewer than 50 subject records. The HIPAA "minimum necessary" standard applies... To all human subjects research that uses PHI without an authorization from the data subject. A HIPAA authorization has which of the following characteristics: Uses "plain language" that the data subject can understand, similar to the requirement for an informed consent document. A covered entity may use or disclose PHI without an authorization, or documentation of a waiver or an alteration of authorization, for all of the following EXCEPT: Data that does not cross state lines when disclosed by the covered entity. HIPAA protects a category of information known as protected health information (PHI). PHI covered under HIPAA includes: Identifiable health information that is created or held by covered entities and their business associates. Which of these is not generally a good practice for fax machine use? Sensitive faxes -- inbound or outbound -- are left sitting in or around the machine. Which of these is not a good practice for physical security? To preserve good customer relations, visitors are generally allowed access to all areas of a facility unless it appears they are doing something suspicious. Which of these is generally not a good practice with respect to oral communications (that is, talking) in organizations like healthcare facilities? Use of full names in public areas or on intercom/paging systems, because there is no security issue with identifying persons in public areas and using full names helps avoid misidentification. Which of the following is a correct statement about the balance among prevention, detection, and response (PDR)? The greater the sensitivity and quantity of the data at issue, the more carefully the balance among these three must be evaluated. Which of these is not generally a good practice for telephone use? Using voicemail systems and answering machines that do not require a password or PIN for access. Fines and jail time (occasionally) for information security failures are: Generally, only applied for serious, deliberate misuse, where someone intentionally accesses data in order to do harm or for personal gain. Information security's goals are sometimes described by the letters "CIA." Which of the following is correct definition of C, I, or A? All of the above Security measures are sometimes described as a combination of physical, technical, and administrative (PTA) safeguards. Which of these would be considered a technical safeguard? Measures including device data encryption, anti-malware software, and communications encryption. Which of the following is a good practice if one wishes to avoid "social engineering" attacks? All of the above Which of these is not a good practice for protecting computing devices? Login and screen-saver passwords, or token or biometric mechanisms, are disabled to make it easier to use the device quickly. Which of these is not a good security practice for email? Sending sensitive information in email messages or in attachments to such messages, as long as a legally-binding confidentiality notice is included. Which of these is not a good security practice for web browsing? Browsing to sites using links sent in emails without taking steps to assure the destination is safe. Which of these is not a good security practice for portable devices? Disabling any remote-locate, remote-shutdown, and remote-erase capabilities because these can accidentally erase data. Which of the following are important for protecting computing devices and systems? All of the above Which of the following is generally allowed in most organizations? Social networking if done for approved business-related purposes. Which of these is not a good practice for controlling computer access? Logging into systems with a shared user-ID or password. Unless the subject matter is considered common knowledge, citations are necessary when writing about: Ideas, methodologies, or data from other authors and also your own previously published ideas, methodologies, or data. Which one of the following situations is most likely to constitute an act of plagiarism? Copying someone else's text word-for-word without using quotation marks and adding a citation at the end of the material.


Document information

Uploaded on
January 10, 2023
Number of pages
18
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BravelRadon
3.5
(165)
Sold
968
Followers
541
Items
54075
Last sold
3 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.