QUESTIONS WITH COMPLETE
ANSWERS
How soon are practices or medical organizations required to process a patient's
request for medical records when the information is maintained or accessible on-
site?
The timeframes are per state law
As soon as possible
Within 30 days
Within 60 days - ANSWER-Within 30 days
The covered entity must act upon the request within 30 days of its receipt if the
information is maintained or accessible on-site.
HIPAA requires national standards for code sets. Which of the following is NOT one
of the standards required?
HCPCS Level II codes
ICD-10-CM codes
CPT® codes
ISO 9001 codes - ANSWER-ISO 9001 codes
To improve the efficiency and effectiveness of the healthcare system, HIPAA, Public
Law 104-191, included Administrative Simplification provisions that required HHS to
adopt national standards for electronic healthcare transactions (ASC X12N or
NCPDP) and code sets (CPT®, HCPCS, ICD-10-CM/PCS, CDT®, NDC), unique
health identifiers, and security.
Privacy rules are designed for what reason?
To protect physicians
To protect personal health information
To protect mid-level providers
To protect employees - ANSWER-To protect personal health information
Privacy and security rules are designed to protect personal health information (PHI).
Can an individual provide a verbal authorization to release PHI?
Yes, in certain states
No, all authorizations must be in writing
Yes, in the state of California
Yes, only in New York - ANSWER-No, all authorizations must be in writing
All valid authorizations for disclosure must be in writing.
What is the main purpose of the HIPAA Omnibus Rule?
Provides employee with better education
Provides providers with the ability to correct PHI
Provides individuals new rights with regard to their health information
Provides safeguards for attorneys when handling PHI - ANSWER-Provides
individuals new rights with regard to their health information
, The final omnibus rule greatly enhances a patient's privacy protections, provides
individuals new rights to their health information, and strengthens the government's
ability to enforce the law.
How did HIPAA change health care?
It made employees more accountable.
It improved efficiency of the health care system
It helped create electronic health record templates.
It changed medical authorization forms. - ANSWER-It improved efficiency of the
health care system
The Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law
104-191, improved efficiency and effectiveness of the health care system.
Tim is a patient at ABC Internal Medicine Group. Tim is HIV positive. John, the
Compliance Officer explains to Tim that the medical group:
will keep all information confidential on Tim.
will only release information if Tim has signed a release form.
will need to release the information because that is the state's law to require that
information.
will only release information when they see a need to. - ANSWER-will need to
release the information because that is the state's law to require that information.
If the patient lives in a state that requires providers to report information when a
patient has certain communicable diseases, even if the patient doesn't want the
information reported.
What safeguard is defined as a measure to protect electronic systems?
Physical safeguards
Technical safeguards
Administrative safeguards
Facility safeguards - ANSWER-Physical safeguards
Physical safeguards are defined as measures to protect a covered entity's electronic
information systems and related buildings and equipment, from natural and
environmental hazards, and unauthorized intrusion.
What safeguard is defined as a measure to protect ePHI?
Facility safeguards
Administrative safeguards
Physical safeguards
Technical safeguards - ANSWER-Technical safeguards
Technical safeguards are defined as measures that protect electronic protected
health information and control access to it.
Did the HIPAA Omnibus Rule affect Business Associates?
Yes; they are more accountable for their client's PHI
No; everything stayed the same
Yes; they can no longer get PHI without patient consent
No; Business Associates are excluded from PHI - ANSWER-Yes; they are more
accountable for their client's PHI
The HIPAA Omnibus Rule makes Business Associates more accountable for PHI. If
they have a HIPAA breach, they are now required to report the breach to the client.