SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. EPHI
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
Limited data set
Electronic Protected Health Information
Electronic data interchange
2. Protected Health Information (PHI)
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Patient
3. Patient records are _____________ so not all staff will have access.
Privacy
Regulations
improper performance of an otherwise lawful act. civil
need to know
4. OIG - Office of the Inspector General
Permission
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
concerns noncriminal disputes between private parties
5. Business Associate Agreements applies to...
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
6. PII
addresses portability of insurance coverage when employees change or lose their jobs
false charges and malicious oral statements about someone
law concerned with public wrongs against society
Patient Identifiable Information
7. De-Identified Information
located in a secured and private space
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
De-Identified Information
8. What are the 3 purposes of HIPAA?
Insurance portability - administrative simplification - privacy and security
located in a secured and private space
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
U.S. goverment
9. TPO
treatment - payment - & healthcare operations
Encryption
Notice of Privacy Practices
same legal standards apply to all patient records whether on paper or computer
10. Name - address - date of birth - phone/fax numbers - social security number - medical record number - and photographs - nursing and physician notes - billing and other treatment records used during a patient's visit in a hospital or office.
Verification
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
Examples of PHI
A written set of questions requiring written answers from a plaintiff or defendant under oath
11. 4d's of negligence
Code sets
De-Identified Information
Electronic Protected Health Information
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
12. Document that includes the standards
Rule
Invasion of Privacy Publishing
Treatment - payment and health care operations (TPO)
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
13. Some state laws specifically protect __________. A patient would need to sign a specific request.
A written set of questions requiring written answers from a plaintiff or defendant under oath
must be reported to authorities by law
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
14. All persons who will have access are required to...
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
have a unique password and it should be changed frequently
Covered entities
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
15. Gunshot wound - child abuse - infectious diseases - required by law - law enforcement purposes.
concerns noncriminal disputes between private parties
should never be released w/o a patient's signed consent or court order
Covered entities
What types of disclosures do not require patient permission?
16. Battery
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
generally only patient can auth release of own medical record - there are a few exceptions
illegal touching of another person
improper performance of an otherwise lawful act. civil
17. The ability to control access and protect information from accidental or intentional disclosure to unauthorized persons and from altercation - destruction - or loss
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
security rule
The body of laws made by states is their own statutory laws
Limited data set
18. NPP
Notice of Privacy Practices
What types of disclosures do not require patient permission?
Verification
Health Information
19. Good samaritan law
Notice of Privacy Practices (NPP)
same legal standards apply to all patient records whether on paper or computer
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
comes on after a few idle seconds and the use of a privacy screen should be mandatory
20. Misfeasance
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
improper performance of an otherwise lawful act. civil
false and malicious writing about another
U.S. goverment
21. See & Copy their health records - update health records - obtain a list of the institution's disclosures - other than for payment & healthcare operations - request a restriction on a certain uses or disclosures - choose how to receive their health in
A written set of questions requiring written answers from a plaintiff or defendant under oath
improper performance of an otherwise lawful act. civil
Patient rights under HIPAA
Privacy
22. Ethics
the philosophical study of moral values and rules - conducts
law that permits a person w/ a legal age and sound mind to give their body to donation
law concerned with public wrongs against society
need to know
23. HIPAA
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Regulations
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
24. A written document detailing a health care provider's privacy practices.
Invasion of Privacy Publishing
Notice of Privacy Practices (NPP)
law concerned with public wrongs against society
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
25. Treatment means that a health care provider can provide care; payment means that a provider can disclose PHI to be reimbursed; health care operations refers to HIPAA approved activities and transactions.
Regulations
comes on after a few idle seconds and the use of a privacy screen should be mandatory
Encryption
Treatment - payment and health care operations (TPO)
26. DII
De-Identified Information
Permission
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
27. Conforming to proper professional behavior
false charges and malicious oral statements about someone
Examples of PHI
Ethical
Firewalls
28. Civil law
concerns noncriminal disputes between private parties
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
29. A reason for each use and disclosure of patient information.
Examples of PHI
addresses portability of insurance coverage when employees change or lose their jobs
Designated record set
Permission
30. Key entities
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
A written set of questions requiring written answers from a plaintiff or defendant under oath
Covered entities
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
31. Any set of codes use to encode health care data elements.
Electronic transmission
need to know
law concerned with public wrongs against society
Code sets
32. Fax machines
should only be used when no other - more secure mode of transmission is available
Standard
illegal touching of another person
Notice of Privacy Practices
33. making known - or using information relating to the private life or affairs of a person without their approval or permission
false charges and malicious oral statements about someone
Transaction
should never be released w/o a patient's signed consent or court order
Invasion of Privacy Publishing
34. Implied contract
Patient Identifiable Information
Covered transactions
Permission
a contract that comes about from the actions of the parties rather than words
35. In HIPAA language health plans - Health care clearinghouses - and all health care providers that transmit HIPAA standard transactions electronically are called covered entities. Hospitals - nursing homes - hospices - pharmacies - physician practices
law concerned with public wrongs against society
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
Designated record set
Covered entities
36. Professional Negligence
only those who meed to know should have access to patient information
improper performance of an otherwise lawful act. civil
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
malpractice
37. interrogatory
only those who meed to know should have access to patient information
A written set of questions requiring written answers from a plaintiff or defendant under oath
improper performance of an otherwise lawful act. civil
Transaction
38. Any wrongdoing for which an action for damages may be brought
The body of laws made by states is their own statutory laws
Tort
same legal standards apply to all patient records whether on paper or computer
Electronic transmission
39. Releasing patient information
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
purpose - pride - patience - persistence - perspective
Notice of Privacy Practices (NPP)
generally only patient can auth release of own medical record - there are a few exceptions
40. Medical records can be released w/o consent to...
Limited data set
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
should only be used when no other - more secure mode of transmission is available
substance abuse treatment
41. Privacy Officer
have a unique password and it should be changed frequently
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Insurance portability - administrative simplification - privacy and security
42. The person recieving treatment
have a unique password and it should be changed frequently
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
must be reported to authorities by law
Patient
43. Doctor release of patient
generally only patient can auth release of own medical record - there are a few exceptions
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
Ethical
malpractice
44. General exceptions for releasing patient information
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
addresses portability of insurance coverage when employees change or lose their jobs
45. Protecting healthcare coverage for employees who change jobs - allowing them to continue existing plans with a new employer.
Limited data set
improper performance of an otherwise lawful act. civil
Portability
a contract that comes about from the actions of the parties rather than words
46. If a states privacy laws are stricter than HIPAA privacy standards - the state laws take precedence.
De-Identified Information
Health Information
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
State preemption
47. What information do patients NOT have access to?
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
Electronic Protected Health Information
Privacy
What types of disclosures do not require patient permission?
48. Subpoenas
U.S. goverment
What types of disclosures do not require patient permission?
illegal touching of another person
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
49. Guidelines and standards made by government agencies and licensing boards that have the authority to enforce compliance
treatment - payment - & healthcare operations
Health Information
Regulations
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
50. Protected health information from which certain patient identifiers have been removed
only those who meed to know should have access to patient information
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
Limited data set
Insurance portability - administrative simplification - privacy and security