HIPAA and Privacy Act Training (1.5 hrs) (DHA-US001)
Study online at https://quizlet.com/_hxbavm
1. Select all that apply: In which of the following circumstances must an individ-
ual be given the opportunity to agree or object to the use and disclosure of
their PHI?: Both A and C
-Before PHI directly relevant to a person's involvement with the individual's care or payment of health care is shared
with that person
- Before their information is included in a facility directory
2. Which of the following statements about the HIPAA Security Rule are true?: Al
of the above
3. A covered entity (CE) must have an established complaint process.: True
4. The e-Government Act promotes the use of electronic government services
by the public and improves the use of information technology in the govern-
ment.: True
5. When must a breach be reported to the U.S. Computer Emergency Readiness
Team?: Within 1 hour of discovery
6. Which of the following statements about the Privacy Act are true?: All of the above
7. What of the following are categories for punishing violations of federal health
care laws?: All of the above
8. Which of the following are common causes of breaches?: All of the above
9. Which of the following are fundamental objectives of information security?: Al
of the above
10. If an individual believes that a DoD covered entity (CE) is not complying with
HIPAA, he or she may file a complaint with the:: All of the above
11. Technical safeguards are:: Information technology and the associated policies and procedures that
are used to protect and control access to ePHI
12. A Privacy Impact Assessment (PIA) is an analysis of how information is
handled:: All of the above
13. A breach as defined by the DoD is broader than a HIPAA breach (or breach
defined by HHS).: True
14. Which of the following are breach prevention best practices?: All of the above
1/3
Study online at https://quizlet.com/_hxbavm
1. Select all that apply: In which of the following circumstances must an individ-
ual be given the opportunity to agree or object to the use and disclosure of
their PHI?: Both A and C
-Before PHI directly relevant to a person's involvement with the individual's care or payment of health care is shared
with that person
- Before their information is included in a facility directory
2. Which of the following statements about the HIPAA Security Rule are true?: Al
of the above
3. A covered entity (CE) must have an established complaint process.: True
4. The e-Government Act promotes the use of electronic government services
by the public and improves the use of information technology in the govern-
ment.: True
5. When must a breach be reported to the U.S. Computer Emergency Readiness
Team?: Within 1 hour of discovery
6. Which of the following statements about the Privacy Act are true?: All of the above
7. What of the following are categories for punishing violations of federal health
care laws?: All of the above
8. Which of the following are common causes of breaches?: All of the above
9. Which of the following are fundamental objectives of information security?: Al
of the above
10. If an individual believes that a DoD covered entity (CE) is not complying with
HIPAA, he or she may file a complaint with the:: All of the above
11. Technical safeguards are:: Information technology and the associated policies and procedures that
are used to protect and control access to ePHI
12. A Privacy Impact Assessment (PIA) is an analysis of how information is
handled:: All of the above
13. A breach as defined by the DoD is broader than a HIPAA breach (or breach
defined by HHS).: True
14. Which of the following are breach prevention best practices?: All of the above
1/3