Deck 2: Privacy Issues Explained

Full screen (f)
exit full mode
Question
In HIPAA usage, TPO stands for treatment, payment, and optional care.
Use Space or
up arrow
down arrow
to flip the card.
Question
Consent as defined by HIPAA is for

A) permission to reveal PHI for payment of services provided to a patient.
B) permission to reveal PHI for comprehensive treatment of a patient.
C) permission to reveal PHI for normal business operations of the provider's facility.
D) all of the above.
E) both A and B.
Question
The HIPAA Privacy Rule gives patients assurance that their personal health information will be treated the same no matter which state or organization receives their medical information.
Question
During an investigation by the Office for Civil Rights, the inspector will depend upon the HIPAA Officer to know the details of the written policies of the organization.
Question
Protected health information is an association between a(n)

A) diagnosis and a payer.
B) individual and a physician.
C) health care provider and a patient or two businesses.
D) diagnosis and an individual.
Question
The Privacy Rule

A) applies only to protected health information (PHI).
B) establishes policies for covered entities.
C) details when authorization to release PHI is needed.
D) none of the above.
E) both answers A and C.
Question
An emancipated minor is

A) a person younger than 21 who lives independently and is self-supporting.
B) a person younger than 18 who is married or divorced and possesses decision-making rights.
C) a person younger than 16 who lives independently and is self-supporting.
D) a person younger than 18 who is totally self-supporting and possesses decision-making rights.
Question
Financial records fall outside the scope of HIPAA law.
Question
Nursing notes are not considered PHI since they are not physician's notes and therefore are not protected by HIPAA law.
Question
If a medical office does not use electronic means to send its insurance claims, it is considered a covered entity .
Question
Who in the health care organization is responsible to know where the written policies are located regarding HIPAA compliance?

A) Only the HIPAA Officer
B) Office workers who send electronic PHI
C) All staff members, paid or not paid
D) All clinical staff members
Question
The response "She was taken to ICU because her diabetes became acute" is an example of HIPAA-compliant disclosure of information.
Question
Any covered entity does not have to disclose PHI to the Office for Civil Rights if they come to investigate a complaint. That is not allowed by HIPAA law.
Question
A signed receipt of the facility's Notice of Privacy Practices (NOPP) is mandated by the Privacy Rule in order for a patient to receive services from a health care provider.
Question
Insurance companies who provide automobile and life insurance come under the HIPAA ruling as covered entities?
Question
Use and disclosure of PHI is permitted without authorization with the EXCEPTION of which of the following?

A) When incidental to a permitted use and disclosure
B) When releasing process or psychotherapy notes
C) For public interest and to benefit the public
D) When releasing to the individual whose health information it is
Question
A refusal by patient to sign a receipt of the NOPP allows the physician to refuse treatment to that patient.
Question
What specific government agency receives complaints about the HIPAA Privacy ruling?

A) Centers for Medicare and Medicaid Services
B) Department of Health and Human Services
C) Department of Justice
D) Office for Civil Rights
Question
The Regional Offices of the Centers for Medicare and Medicaid Services (CMS) is the only way to contact the government about HIPAA questions and complaints.
Question
It is possible for a first name and zip code to be considered individually identifiable health information (IIHI).
Question
Match between columns
Title II
Persons with legal authority to act on behalf of minor children
Title II
PHI that excludes direct identifiers for research purposes
Title II
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
Title II
Written permission allowing disclosure of PHI for purposes other than TPO
Title II
Permission granted to disclose PHI for purposes of TPO
Title II
Administrative Simplification
limited data set
Persons with legal authority to act on behalf of minor children
limited data set
PHI that excludes direct identifiers for research purposes
limited data set
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
limited data set
Written permission allowing disclosure of PHI for purposes other than TPO
limited data set
Permission granted to disclose PHI for purposes of TPO
limited data set
Administrative Simplification
in loco parentis
Persons with legal authority to act on behalf of minor children
in loco parentis
PHI that excludes direct identifiers for research purposes
in loco parentis
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
in loco parentis
Written permission allowing disclosure of PHI for purposes other than TPO
in loco parentis
Permission granted to disclose PHI for purposes of TPO
in loco parentis
Administrative Simplification
authorization
Persons with legal authority to act on behalf of minor children
authorization
PHI that excludes direct identifiers for research purposes
authorization
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
authorization
Written permission allowing disclosure of PHI for purposes other than TPO
authorization
Permission granted to disclose PHI for purposes of TPO
authorization
Administrative Simplification
minimum necessary
Persons with legal authority to act on behalf of minor children
minimum necessary
PHI that excludes direct identifiers for research purposes
minimum necessary
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
minimum necessary
Written permission allowing disclosure of PHI for purposes other than TPO
minimum necessary
Permission granted to disclose PHI for purposes of TPO
minimum necessary
Administrative Simplification
consent
Persons with legal authority to act on behalf of minor children
consent
PHI that excludes direct identifiers for research purposes
consent
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
consent
Written permission allowing disclosure of PHI for purposes other than TPO
consent
Permission granted to disclose PHI for purposes of TPO
consent
Administrative Simplification
Question
The minimum penalty per incidence for violations that Office for Civil Rights finds for noncompliance to the Privacy Rule is

A) $100.
B) $500.
C) $1000.
D) $5000.
Question
Match between columns
outside the entity
Disclosure of PHI is for releasing IIHI
outside the entity
Use of PHI is for sharing, examination, or analysis of IIHI
within the entity
Disclosure of PHI is for releasing IIHI
within the entity
Use of PHI is for sharing, examination, or analysis of IIHI
Question
A HIPAA investigator seeks to find willingness in each organization to comply with what is ____________________ for their particular situation.
Question
A hospital or other inpatient facility may include patients in their published directory

A) for any advertising purpose.
B) only when the patient or family has not chosen to "opt-out" of the published directory.
C) to announce on a radio station who has been admitted.
D) so that pharmaceutical organizations may offer the patients special offers on their drugs.
Question
Research organizations are permitted to receive

A) limited data set that has been de-identified for research purposes.
B) IIHI without withholding any information.
C) only IIHI when patients have given written authorization.
D) any PHI a covered entity may choose to send them in relation to the diagnoses they are researching.
Question
During an investigation by the Office for Civil Rights, each provider is expected to have the following EXCEPT

A) business associate contracts with vendors to protect privacy of PHI.
B) written policy and procedures.
C) a designated privacy official.
D) a workforce trained in state law.
Question
According to AHIMA report, the most common problem that health care providers face in relation to PHI is

A) complying with BA provisions.
B) confusion about the NOPP provisions.
C) releasing information to relatives of patients.
D) lack of a standardized process to release PHI.
Question
Another name for the Title II portion of HIPAA law is ___________________________________.
Question
Psychotherapy notes or process notes include

A) the treatment plan for the patient.
B) a summary of medications the patient is prescribed.
C) the therapist's impressions of the patient.
D) the current state of the patient, medications prescribed, and their side effects.
Question
For individuals requesting to amend their medical record

A) the replaced portion of the record is destroyed.
B) the provider has the option to reject the amendment.
C) there is a new file made just for the amendment.
D) it is not possible without a court order.
Question
When policies for a facility are in both written and electronic form, the Office for Civil Rights will assume the ____________________ policies are the most trustworthy.
Question
Typical Business Associate individuals are

A) in-house lab technicians, transcriptionists, and billing specialists.
B) health plan agents, in-house transcriptionists, and office billing specialists.
C) biometric device repairman, legal counsel to a clinic, and outside coding service.
D) nonclinical staff such as the hospital billing office, housekeeping staff, and maintenance workers.
Question
Requesting to amend a medical record was a feature included in HIPAA because

A) increase in theft of medical information for criminal purposes.
B) possible difference in opinion between patient and physician regarding the diagnosis and treatment.
C) ease of human entry error when posting patient information.
D) all of the above.
E) both B and C.
Question
Written policies and procedures relating to the HIPAA Privacy Rule:

A) are kept by the HIPAA officer only.
B) must be only in electronic format.
C) are not necessary.
D) must be available to all employees.
Question
When there is an alleged violation to HIPAA Privacy Rule

A) an individual may sue the offending health care provider.
B) an individual may join a class action lawsuit against the provider.
C) the individual should report them to the local county sheriff.
D) there is no option to sue a health care provider for HIPAA violations.
Question
The Office for Civil Rights receives complaints regarding the Privacy Rule. About what percentage of these complaints have been ruled either no violation or the entity is working toward compliance?

A) About 25%
B) About 50%
C) About 75%
D) About 90%
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/37
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 2: Privacy Issues Explained
1
In HIPAA usage, TPO stands for treatment, payment, and optional care.
False
2
Consent as defined by HIPAA is for

A) permission to reveal PHI for payment of services provided to a patient.
B) permission to reveal PHI for comprehensive treatment of a patient.
C) permission to reveal PHI for normal business operations of the provider's facility.
D) all of the above.
E) both A and B.
all of the above.
3
The HIPAA Privacy Rule gives patients assurance that their personal health information will be treated the same no matter which state or organization receives their medical information.
True
4
During an investigation by the Office for Civil Rights, the inspector will depend upon the HIPAA Officer to know the details of the written policies of the organization.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
5
Protected health information is an association between a(n)

A) diagnosis and a payer.
B) individual and a physician.
C) health care provider and a patient or two businesses.
D) diagnosis and an individual.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
6
The Privacy Rule

A) applies only to protected health information (PHI).
B) establishes policies for covered entities.
C) details when authorization to release PHI is needed.
D) none of the above.
E) both answers A and C.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
7
An emancipated minor is

A) a person younger than 21 who lives independently and is self-supporting.
B) a person younger than 18 who is married or divorced and possesses decision-making rights.
C) a person younger than 16 who lives independently and is self-supporting.
D) a person younger than 18 who is totally self-supporting and possesses decision-making rights.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
8
Financial records fall outside the scope of HIPAA law.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
9
Nursing notes are not considered PHI since they are not physician's notes and therefore are not protected by HIPAA law.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
10
If a medical office does not use electronic means to send its insurance claims, it is considered a covered entity .
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
11
Who in the health care organization is responsible to know where the written policies are located regarding HIPAA compliance?

A) Only the HIPAA Officer
B) Office workers who send electronic PHI
C) All staff members, paid or not paid
D) All clinical staff members
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
12
The response "She was taken to ICU because her diabetes became acute" is an example of HIPAA-compliant disclosure of information.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
13
Any covered entity does not have to disclose PHI to the Office for Civil Rights if they come to investigate a complaint. That is not allowed by HIPAA law.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
14
A signed receipt of the facility's Notice of Privacy Practices (NOPP) is mandated by the Privacy Rule in order for a patient to receive services from a health care provider.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
15
Insurance companies who provide automobile and life insurance come under the HIPAA ruling as covered entities?
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
16
Use and disclosure of PHI is permitted without authorization with the EXCEPTION of which of the following?

A) When incidental to a permitted use and disclosure
B) When releasing process or psychotherapy notes
C) For public interest and to benefit the public
D) When releasing to the individual whose health information it is
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
17
A refusal by patient to sign a receipt of the NOPP allows the physician to refuse treatment to that patient.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
18
What specific government agency receives complaints about the HIPAA Privacy ruling?

A) Centers for Medicare and Medicaid Services
B) Department of Health and Human Services
C) Department of Justice
D) Office for Civil Rights
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
19
The Regional Offices of the Centers for Medicare and Medicaid Services (CMS) is the only way to contact the government about HIPAA questions and complaints.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
20
It is possible for a first name and zip code to be considered individually identifiable health information (IIHI).
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
21
Match between columns
Title II
Persons with legal authority to act on behalf of minor children
Title II
PHI that excludes direct identifiers for research purposes
Title II
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
Title II
Written permission allowing disclosure of PHI for purposes other than TPO
Title II
Permission granted to disclose PHI for purposes of TPO
Title II
Administrative Simplification
limited data set
Persons with legal authority to act on behalf of minor children
limited data set
PHI that excludes direct identifiers for research purposes
limited data set
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
limited data set
Written permission allowing disclosure of PHI for purposes other than TPO
limited data set
Permission granted to disclose PHI for purposes of TPO
limited data set
Administrative Simplification
in loco parentis
Persons with legal authority to act on behalf of minor children
in loco parentis
PHI that excludes direct identifiers for research purposes
in loco parentis
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
in loco parentis
Written permission allowing disclosure of PHI for purposes other than TPO
in loco parentis
Permission granted to disclose PHI for purposes of TPO
in loco parentis
Administrative Simplification
authorization
Persons with legal authority to act on behalf of minor children
authorization
PHI that excludes direct identifiers for research purposes
authorization
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
authorization
Written permission allowing disclosure of PHI for purposes other than TPO
authorization
Permission granted to disclose PHI for purposes of TPO
authorization
Administrative Simplification
minimum necessary
Persons with legal authority to act on behalf of minor children
minimum necessary
PHI that excludes direct identifiers for research purposes
minimum necessary
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
minimum necessary
Written permission allowing disclosure of PHI for purposes other than TPO
minimum necessary
Permission granted to disclose PHI for purposes of TPO
minimum necessary
Administrative Simplification
consent
Persons with legal authority to act on behalf of minor children
consent
PHI that excludes direct identifiers for research purposes
consent
Reasonable effort to limit PHI to only that which is necessary to accomplish intended purpose
consent
Written permission allowing disclosure of PHI for purposes other than TPO
consent
Permission granted to disclose PHI for purposes of TPO
consent
Administrative Simplification
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
22
The minimum penalty per incidence for violations that Office for Civil Rights finds for noncompliance to the Privacy Rule is

A) $100.
B) $500.
C) $1000.
D) $5000.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
23
Match between columns
outside the entity
Disclosure of PHI is for releasing IIHI
outside the entity
Use of PHI is for sharing, examination, or analysis of IIHI
within the entity
Disclosure of PHI is for releasing IIHI
within the entity
Use of PHI is for sharing, examination, or analysis of IIHI
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
24
A HIPAA investigator seeks to find willingness in each organization to comply with what is ____________________ for their particular situation.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
25
A hospital or other inpatient facility may include patients in their published directory

A) for any advertising purpose.
B) only when the patient or family has not chosen to "opt-out" of the published directory.
C) to announce on a radio station who has been admitted.
D) so that pharmaceutical organizations may offer the patients special offers on their drugs.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
26
Research organizations are permitted to receive

A) limited data set that has been de-identified for research purposes.
B) IIHI without withholding any information.
C) only IIHI when patients have given written authorization.
D) any PHI a covered entity may choose to send them in relation to the diagnoses they are researching.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
27
During an investigation by the Office for Civil Rights, each provider is expected to have the following EXCEPT

A) business associate contracts with vendors to protect privacy of PHI.
B) written policy and procedures.
C) a designated privacy official.
D) a workforce trained in state law.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
28
According to AHIMA report, the most common problem that health care providers face in relation to PHI is

A) complying with BA provisions.
B) confusion about the NOPP provisions.
C) releasing information to relatives of patients.
D) lack of a standardized process to release PHI.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
29
Another name for the Title II portion of HIPAA law is ___________________________________.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
30
Psychotherapy notes or process notes include

A) the treatment plan for the patient.
B) a summary of medications the patient is prescribed.
C) the therapist's impressions of the patient.
D) the current state of the patient, medications prescribed, and their side effects.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
31
For individuals requesting to amend their medical record

A) the replaced portion of the record is destroyed.
B) the provider has the option to reject the amendment.
C) there is a new file made just for the amendment.
D) it is not possible without a court order.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
32
When policies for a facility are in both written and electronic form, the Office for Civil Rights will assume the ____________________ policies are the most trustworthy.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
33
Typical Business Associate individuals are

A) in-house lab technicians, transcriptionists, and billing specialists.
B) health plan agents, in-house transcriptionists, and office billing specialists.
C) biometric device repairman, legal counsel to a clinic, and outside coding service.
D) nonclinical staff such as the hospital billing office, housekeeping staff, and maintenance workers.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
34
Requesting to amend a medical record was a feature included in HIPAA because

A) increase in theft of medical information for criminal purposes.
B) possible difference in opinion between patient and physician regarding the diagnosis and treatment.
C) ease of human entry error when posting patient information.
D) all of the above.
E) both B and C.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
35
Written policies and procedures relating to the HIPAA Privacy Rule:

A) are kept by the HIPAA officer only.
B) must be only in electronic format.
C) are not necessary.
D) must be available to all employees.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
36
When there is an alleged violation to HIPAA Privacy Rule

A) an individual may sue the offending health care provider.
B) an individual may join a class action lawsuit against the provider.
C) the individual should report them to the local county sheriff.
D) there is no option to sue a health care provider for HIPAA violations.
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
37
The Office for Civil Rights receives complaints regarding the Privacy Rule. About what percentage of these complaints have been ruled either no violation or the entity is working toward compliance?

A) About 25%
B) About 50%
C) About 75%
D) About 90%
Unlock Deck
Unlock for access to all 37 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 37 flashcards in this deck.