Which of the following are common causes of breaches? - Technical safeguards are: - ANSWER -Information
ANSWER -All of the above technology and the associated policies and procedures that are
used to protect and control access to ePHI
Breaches are commonly associated with human error at the
hands of a workforce member. Improper disposal of electronic
media devices containing PHI or PII is also a common cause of
breaches. Theft and intentional unauthorized access to PHI and An incidental use or disclosure is not a violation of the HIPAA
PII are also among the most common causes of privacy and Privacy Rule if the covered entity (CE) has: - ANSWER -All
security breaches. Another common cause of a breach includes of the above
lost or stolen electronic media devices containing PHI and PII
such as laptop computers, smartphones and USB storage -Implemented the minimum necessary standard
drives. Lost or stolen paper records containing PHI or PII also - Established appropriate administrative safeguards
are a common cause of breaches. - Established appropriate physical and technical safeguards
A Privacy Impact Assessment (PIA) is an analysis of how A covered entity (CE) must have an established complaint
information is handled: - ANSWER -All of the above process. - ANSWER -True
-To ensure handling conforms to applicable legal, regulatory,
and policy requirements regarding privacy
-To determine the risks and effects of collecting, maintaining The HIPAA Security Rule applies to which of the following: -
and disseminating information in identifiable form in an ANSWER -PHI transmitted electronically
electronic information system
-To examine and evaluate protections and alternative
processes
Which of the following are breach prevention best practices? -
ANSWER -All of the above
Under the Privacy Act, individuals have the right to request
You can help prevent a breach by accessing only the minimum
amendments of their records contained in a system of records. -
amount of PHI/PII necessary and by promptly retrieving
ANSWER -True documents containing PHI/PII from the printer. You should
always logoff or lock your workstation when it is unattended for
any length of time.
Under HIPAA, a covered entity (CE) is defined as: -
ANSWER -All of the above
Which of the following are examples of personally identifiable
Under HIPAA, a CE is a health plan, a health care information (PII)? - ANSWER -All of the above
clearinghouse, or a health care provider engaged in standard
electronic transactions covered by HIPAA. Social Security Number; DoD identification number; home
address; home telephone; date of birth (year included); personal
medical information; or personal/private information (e.g., an
individual's financial data).
The e-Government Act promotes the use of electronic
government services by the public and improves the use of
information technology in the government. - ANSWER -
True HIPAA provides individuals with the right to request an
accounting of disclosures of their PHI. - ANSWER -True
What of the following are categories for punishing violations of
federal health care laws? - ANSWER -All of the above If an individual believes that a DoD covered entity (CE) is not
complying with HIPAA, he or she may file a complaint with the: -
The three main categories of punishment for violating federal ANSWER -All of the above
health care laws include: criminal penalties, civil money
penalties, and sanctions. DHA Privacy Office, HHS Secretary, and/or the MTF HIPAA
Privacy Officer.
1/2