Deck 3: Accreditation, Regulation, and Hipaa

Full screen (f)
exit full mode
Question
The ________ accredits medical laboratories.

A) College of American Pathologists
B) Commission on Accreditation of Rehabilitation Facilities
C) American Hospital Association
D) American Medical Association
E) All of the above
Use Space or
up arrow
down arrow
to flip the card.
Question
A laboratory with CAP accreditation is deemed to have complied with:

A) COP standards.
B) AHA standards.
C) AMA standards.
D) state law.
E) All of the above
Question
Which of the following organizations has the power to enforce HIPAA security standards?

A) CMS
B) AHA
C) AMA
D) AHIMA
E) None of the above
Question
Which of the following refers to rules and standards of care developed by Medicare in which healthcare organizations must comply?

A) Conditions of participation
B) Contracts for participation
C) Accreditation for participation
D) Standards of participation
E) All of the above
Question
When a facility meets the requirements of the Joint Commission, Medicare may deem that it has also met the COP requirements, thereby granting ________ status.

A) incorporated
B) deemed
C) recognized
D) accreditation
E) conditional
Question
Healthcare facilities are required to report certain incidents such as:

A) routine surgical procedures.
B) gunshot wounds.
C) child abuse.
D) Both A and B
E) Both B and C
Question
The name given to the initiative that integrates performance and outcome measures into the accreditation process is:

A) JCAHO.
B) ORYX.
C) HIPAA.
D) CMS.
E) AHA.
Question
Licenses are required for:

A) providers who prescribe drugs.
B) operation of a hospital pharmacy.
C) pharmacists who dispense drugs.
D) caregivers who administer drugs.
E) All of the above
Question
State laws regulate:

A) nursing staff requirements.
B) facility operation.
C) patient records.
D) medical staff requirements.
E) All of the above
Question
Medicare and Medicaid are both governed by the American Medical Association.
Question
People who are poor, blind, or pregnant may be eligible for help from Medicaid.
Question
Medicare and Medicaid began in:

A) 1950.
B) 1955.
C) 1960.
D) 1965.
E) 1970.
Question
The abbreviation for Centers for Medicare and Medicaid Services is:

A) CMS.
B) CMMS.
C) CMSS.
D) CCMS.
E) CCMs.
Question
JCAHO stands for:

A) Joint Commission on Accreditation of Healthcare Organizations.
B) Joint Committee on Accrediting of Health Organizations.
C) Joint Committee on Accredited Homes.
D) Joint Commission on Accredited Health Professionals.
E) None of the above
Question
Which of the following is a system developed to pay a fixed amount for inpatient stays based on the type of case rather than the length of the stay?

A) Discharge payment system
B) Provider payment system
C) Prospective discharge system
D) Patient payment system
E) Prospective payment system
Question
Companies that have a contract to handle claims for Medicare and Medicaid for a state or region are called:

A) insurance companies.
B) fiscal intermediaries.
C) consultants.
D) government offices.
E) healthcare contractors.
Question
Healthcare coverage is provided by Medicare for those:

A) 55 and older.
B) with kidney failure.
C) with disabilities.
D) All of the above
E) None of the above
Question
All states require healthcare facilities to be:

A) registered.
B) accredited.
C) licensed.
D) bonded.
E) regulated.
Question
Benefits of accreditation by the Joint Commission include:

A) enhanced staff development and recruitment.
B) improved risk management.
C) competitive edge in the marketplace.
D) strengthening of community confidence in the healthcare organization.
E) All of the above
Question
Politics can influence decisions regarding healthcare facility licensing.
Question
All of the following are privacy activities in a medical office that would comply with the law EXCEPT:

A) providing a copy of the office privacy policy informing patients of their privacy rights and how their information may be used.
B) training employees to understand privacy procedures.
C) having individually identifiable patient information available to all hospital employees.
D) adopting clear privacy procedures.
E) asking patients to acknowledge receiving a copy of the office privacy policy.
Question
HIPAA established the ________ Identifier to identify employer sponsored health insurance.

A) National Provider
B) Employer
C) National Health Plan
D) All of the above
E) None of the above
Question
This Privacy Rule standard limits unnecessary or inappropriate access to and disclosure of PHI beyond what is necessary.

A) Incidental disclosure
B) Health information
C) Access
D) Minimum necessary
E) PHI
Question
A(n) ________ requires the patient's permission to disclose PHI.

A) authorization
B) consent
C) requirement
D) disclosure
E) None of the above
Question
Under HIPAA Privacy Rule, a healthcare provider may disclose PHI without patient authorization in all of the following situations EXCEPT:

A) as part of a claim for payment from a health plan.
B) to a nursing home a patient is being transferred to.
C) when consulted to provide healthcare to a patient.
D) to a specialist a patient is being referred to.
E) to any family members.
Question
Each of the following are specific transaction standards for types of electronic data interchange EXCEPT:

A) claims status.
B) employment status.
C) enrollment and deenrollment in a health plan.
D) first report of injury.
E) premium payments.
Question
HIPAA was passed in 1996 by:

A) Congress.
B) state law.
C) American Hospital Association.
D) American Medical Association.
E) American Health Information Management Association.
Question
Accreditation for organizations providing behavioral health, occupational, and physical therapy services is granted by the:

A) American Medical Association.
B) American Hospital Association.
C) College of American Pathologists.
D) Commission on Accreditation of Rehabilitation Facilities.
E) None of the above
Question
Which of the following is NOT an example of safeguarding a patient's privacy?

A) Discussing a patient case in the cafeteria
B) Avoiding use of patient names in public areas
C) Speaking quietly when discussing patient information
D) Using passwords to protect information on computers
E) Locking record rooms
Question
A patient agreement to receive medical treatment after having been provided with benefits and risks is known as:

A) consent.
B) commitment.
C) authorization.
D) informed consent.
E) acknowledgement.
Question
The HIPAA Privacy Rule replaces any federal, state, or other laws that might grant individuals greater privacy.
Question
PHI refers to:

A) personal health information.
B) professional health information.
C) patient health information.
D) purposeful health information.
E) protected health information.
Question
Health plans, clearinghouses, and healthcare provider entities are covered by which part of HIPAA law?

A) Security Rule
B) Privacy Rule
C) Administrative Simplification Subsection
D) All of the above
E) None of the above
Question
It is important for everyone working with patient information to have a clear understanding of confidentiality.
Question
Which of the following are required on an authorization form?

A) Expiration date
B) What can be disclosed
C) Date signed
D) Who the information may be disclosed to
E) All of the above
Question
Healthcare providers, insurance companies, and clearinghouses are referred to by HIPAA documents as:

A) covered entities.
B) providers.
C) contractors.
D) affiliates.
E) partners.
Question
Which of the following is a component of the Administrative Simplification Subsection?

A) Privacy
B) Uniform identifiers
C) Security
D) Transactions and code sets
E) All of the above
Question
Which HIPAA identifier has NOT yet been implemented?

A) National Provider Identifier
B) Employer Identifier
C) National Health Plan Identifier
D) All of the above
E) None of the above
Question
Under the HIPAA Privacy Rule, consent refers specifically to:

A) surgical procedures.
B) use of the patient's information.
C) medication administration.
D) general medical care.
E) All of the above
Question
According to the Privacy Rule, a person authorized to act on behalf of an individual to make healthcare related decisions is a(n):

A) personal representative.
B) guardian.
C) legal representative.
D) benefactor.
E) emergency contact.
Question
The HIPAA Security Rule is enforced by the:

A) OCR.
B) AMA.
C) AHIMA.
D) HIPAA.
E) CMS.
Question
The HIPAA Security Rule covers:

A) protected health information in paper form.
B) protected health information that is stored electronically.
C) insurance information in paper form.
D) insurance information stored in paper format.
E) All of the above
Question
The Documentation standard includes which of the following implementation specifications?

A) Updates
B) Availability
C) Time limit
D) All of the above
E) None of the above
Question
The primary goal of the Security Rule is to protect the integrity of the:

A) healthcare providers.
B) EPHI.
C) healthcare facility.
D) PHI.
E) rules and regulations.
Question
The ________ Standard includes authorization and/or supervision, workforce clearance procedures, and termination procedures.

A) Policies and Procedures
B) Documentation
C) Workforce Security
D) Organizational Requirements
E) Access Control
Question
A patient has the right to know if his or her information was disclosed by a healthcare facility.
Question
Patients may request to see and obtain copies of their medical records in addition to requesting corrections. Healthcare facilities must provide access to the medical record within how many days of a request?

A) 5
B)10
C) 14
D) 30
E) 60
Question
Personal health information that is stored electronically is referred to as:

A) EPHI.
B) PHI.
C) PHIE.
D) ERPHI.
E) None of the above
Question
Which of the following standards outlines the procedures for limited access to only those persons or software programs that have been granted access rights by the Information Access Management administrative standard?

A) Access Control
B) Transmission Security
C) Policies and Procedures
D) Organizational Requirements
E) Person or Entity Authentication
Question
All of the following are implementation specifications in the Security Management Process EXCEPT:

A) Risk Management.
B) Patient Information Review.
C) Risk Analysis.
D) Sanction Policy.
E) Information System Activity Review.
Question
The HIPAA security standards include:

A) physical safeguards.
B) administrative safeguards.
C) technical safeguards.
D) All of the above
E) None of the above
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/51
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 3: Accreditation, Regulation, and Hipaa
1
The ________ accredits medical laboratories.

A) College of American Pathologists
B) Commission on Accreditation of Rehabilitation Facilities
C) American Hospital Association
D) American Medical Association
E) All of the above
College of American Pathologists
2
A laboratory with CAP accreditation is deemed to have complied with:

A) COP standards.
B) AHA standards.
C) AMA standards.
D) state law.
E) All of the above
COP standards.
3
Which of the following organizations has the power to enforce HIPAA security standards?

A) CMS
B) AHA
C) AMA
D) AHIMA
E) None of the above
CMS
4
Which of the following refers to rules and standards of care developed by Medicare in which healthcare organizations must comply?

A) Conditions of participation
B) Contracts for participation
C) Accreditation for participation
D) Standards of participation
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
5
When a facility meets the requirements of the Joint Commission, Medicare may deem that it has also met the COP requirements, thereby granting ________ status.

A) incorporated
B) deemed
C) recognized
D) accreditation
E) conditional
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
6
Healthcare facilities are required to report certain incidents such as:

A) routine surgical procedures.
B) gunshot wounds.
C) child abuse.
D) Both A and B
E) Both B and C
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
7
The name given to the initiative that integrates performance and outcome measures into the accreditation process is:

A) JCAHO.
B) ORYX.
C) HIPAA.
D) CMS.
E) AHA.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
8
Licenses are required for:

A) providers who prescribe drugs.
B) operation of a hospital pharmacy.
C) pharmacists who dispense drugs.
D) caregivers who administer drugs.
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
9
State laws regulate:

A) nursing staff requirements.
B) facility operation.
C) patient records.
D) medical staff requirements.
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
10
Medicare and Medicaid are both governed by the American Medical Association.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
11
People who are poor, blind, or pregnant may be eligible for help from Medicaid.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
12
Medicare and Medicaid began in:

A) 1950.
B) 1955.
C) 1960.
D) 1965.
E) 1970.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
13
The abbreviation for Centers for Medicare and Medicaid Services is:

A) CMS.
B) CMMS.
C) CMSS.
D) CCMS.
E) CCMs.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
14
JCAHO stands for:

A) Joint Commission on Accreditation of Healthcare Organizations.
B) Joint Committee on Accrediting of Health Organizations.
C) Joint Committee on Accredited Homes.
D) Joint Commission on Accredited Health Professionals.
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
15
Which of the following is a system developed to pay a fixed amount for inpatient stays based on the type of case rather than the length of the stay?

A) Discharge payment system
B) Provider payment system
C) Prospective discharge system
D) Patient payment system
E) Prospective payment system
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
16
Companies that have a contract to handle claims for Medicare and Medicaid for a state or region are called:

A) insurance companies.
B) fiscal intermediaries.
C) consultants.
D) government offices.
E) healthcare contractors.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
17
Healthcare coverage is provided by Medicare for those:

A) 55 and older.
B) with kidney failure.
C) with disabilities.
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
18
All states require healthcare facilities to be:

A) registered.
B) accredited.
C) licensed.
D) bonded.
E) regulated.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
19
Benefits of accreditation by the Joint Commission include:

A) enhanced staff development and recruitment.
B) improved risk management.
C) competitive edge in the marketplace.
D) strengthening of community confidence in the healthcare organization.
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
20
Politics can influence decisions regarding healthcare facility licensing.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
21
All of the following are privacy activities in a medical office that would comply with the law EXCEPT:

A) providing a copy of the office privacy policy informing patients of their privacy rights and how their information may be used.
B) training employees to understand privacy procedures.
C) having individually identifiable patient information available to all hospital employees.
D) adopting clear privacy procedures.
E) asking patients to acknowledge receiving a copy of the office privacy policy.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
22
HIPAA established the ________ Identifier to identify employer sponsored health insurance.

A) National Provider
B) Employer
C) National Health Plan
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
23
This Privacy Rule standard limits unnecessary or inappropriate access to and disclosure of PHI beyond what is necessary.

A) Incidental disclosure
B) Health information
C) Access
D) Minimum necessary
E) PHI
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
24
A(n) ________ requires the patient's permission to disclose PHI.

A) authorization
B) consent
C) requirement
D) disclosure
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
25
Under HIPAA Privacy Rule, a healthcare provider may disclose PHI without patient authorization in all of the following situations EXCEPT:

A) as part of a claim for payment from a health plan.
B) to a nursing home a patient is being transferred to.
C) when consulted to provide healthcare to a patient.
D) to a specialist a patient is being referred to.
E) to any family members.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
26
Each of the following are specific transaction standards for types of electronic data interchange EXCEPT:

A) claims status.
B) employment status.
C) enrollment and deenrollment in a health plan.
D) first report of injury.
E) premium payments.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
27
HIPAA was passed in 1996 by:

A) Congress.
B) state law.
C) American Hospital Association.
D) American Medical Association.
E) American Health Information Management Association.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
28
Accreditation for organizations providing behavioral health, occupational, and physical therapy services is granted by the:

A) American Medical Association.
B) American Hospital Association.
C) College of American Pathologists.
D) Commission on Accreditation of Rehabilitation Facilities.
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
29
Which of the following is NOT an example of safeguarding a patient's privacy?

A) Discussing a patient case in the cafeteria
B) Avoiding use of patient names in public areas
C) Speaking quietly when discussing patient information
D) Using passwords to protect information on computers
E) Locking record rooms
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
30
A patient agreement to receive medical treatment after having been provided with benefits and risks is known as:

A) consent.
B) commitment.
C) authorization.
D) informed consent.
E) acknowledgement.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
31
The HIPAA Privacy Rule replaces any federal, state, or other laws that might grant individuals greater privacy.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
32
PHI refers to:

A) personal health information.
B) professional health information.
C) patient health information.
D) purposeful health information.
E) protected health information.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
33
Health plans, clearinghouses, and healthcare provider entities are covered by which part of HIPAA law?

A) Security Rule
B) Privacy Rule
C) Administrative Simplification Subsection
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
34
It is important for everyone working with patient information to have a clear understanding of confidentiality.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
35
Which of the following are required on an authorization form?

A) Expiration date
B) What can be disclosed
C) Date signed
D) Who the information may be disclosed to
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
36
Healthcare providers, insurance companies, and clearinghouses are referred to by HIPAA documents as:

A) covered entities.
B) providers.
C) contractors.
D) affiliates.
E) partners.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
37
Which of the following is a component of the Administrative Simplification Subsection?

A) Privacy
B) Uniform identifiers
C) Security
D) Transactions and code sets
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
38
Which HIPAA identifier has NOT yet been implemented?

A) National Provider Identifier
B) Employer Identifier
C) National Health Plan Identifier
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
39
Under the HIPAA Privacy Rule, consent refers specifically to:

A) surgical procedures.
B) use of the patient's information.
C) medication administration.
D) general medical care.
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
40
According to the Privacy Rule, a person authorized to act on behalf of an individual to make healthcare related decisions is a(n):

A) personal representative.
B) guardian.
C) legal representative.
D) benefactor.
E) emergency contact.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
41
The HIPAA Security Rule is enforced by the:

A) OCR.
B) AMA.
C) AHIMA.
D) HIPAA.
E) CMS.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
42
The HIPAA Security Rule covers:

A) protected health information in paper form.
B) protected health information that is stored electronically.
C) insurance information in paper form.
D) insurance information stored in paper format.
E) All of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
43
The Documentation standard includes which of the following implementation specifications?

A) Updates
B) Availability
C) Time limit
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
44
The primary goal of the Security Rule is to protect the integrity of the:

A) healthcare providers.
B) EPHI.
C) healthcare facility.
D) PHI.
E) rules and regulations.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
45
The ________ Standard includes authorization and/or supervision, workforce clearance procedures, and termination procedures.

A) Policies and Procedures
B) Documentation
C) Workforce Security
D) Organizational Requirements
E) Access Control
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
46
A patient has the right to know if his or her information was disclosed by a healthcare facility.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
47
Patients may request to see and obtain copies of their medical records in addition to requesting corrections. Healthcare facilities must provide access to the medical record within how many days of a request?

A) 5
B)10
C) 14
D) 30
E) 60
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
48
Personal health information that is stored electronically is referred to as:

A) EPHI.
B) PHI.
C) PHIE.
D) ERPHI.
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
49
Which of the following standards outlines the procedures for limited access to only those persons or software programs that have been granted access rights by the Information Access Management administrative standard?

A) Access Control
B) Transmission Security
C) Policies and Procedures
D) Organizational Requirements
E) Person or Entity Authentication
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
50
All of the following are implementation specifications in the Security Management Process EXCEPT:

A) Risk Management.
B) Patient Information Review.
C) Risk Analysis.
D) Sanction Policy.
E) Information System Activity Review.
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
51
The HIPAA security standards include:

A) physical safeguards.
B) administrative safeguards.
C) technical safeguards.
D) All of the above
E) None of the above
Unlock Deck
Unlock for access to all 51 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 51 flashcards in this deck.