SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. NPP
Notice of Privacy Practices
Examples of PHI
should only be used when no other - more secure mode of transmission is available
De-Identified Information
2. HIPAA states...
Individually Identifiable Health Information
U.S. goverment
law that permits a person w/ a legal age and sound mind to give their body to donation
only those who meed to know should have access to patient information
3. Data must be backed up at ___________ and those back-up files should be stored ________.
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
regular - in a secure location
Covered transactions
should never be released w/o a patient's signed consent or court order
4. Implied consent
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
Minimum necessary
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
Standard
5. Name - address - date of birth - phone/fax numbers - social security number - medical record number - and photographs - nursing and physician notes - billing and other treatment records used during a patient's visit in a hospital or office.
Limited data set
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
Examples of PHI
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
6. In order for a fax document to be HIPAA compliant...
7. A reason for each use and disclosure of patient information.
Treatment - payment and health care operations (TPO)
Permission
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
Health Information
8. interrogatory
concerns noncriminal disputes between private parties
same legal standards apply to all patient records whether on paper or computer
A written set of questions requiring written answers from a plaintiff or defendant under oath
Transaction
9. Includes records maintained by or for a covered entity.
Designated record set
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
must be reported to authorities by law
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
10. Civil law
concerns noncriminal disputes between private parties
improper performance of an otherwise lawful act. civil
The body of laws made by states is their own statutory laws
although medical records are confidential - there are times when they can be released w/o a patient consent.
11. De-Identified Information
Notice of Privacy Practices
Tort
should only be used when no other - more secure mode of transmission is available
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
12. Criminal law
Verification
law concerned with public wrongs against society
Transaction
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
13. OIG - Office of the Inspector General
have a unique password and it should be changed frequently
security rule
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
Health Information
14. Statutory
Transaction
Minimum necessary
The body of laws made by states is their own statutory laws
Notice of Privacy Practices (NPP)
15. 5P's of ethical power
purpose - pride - patience - persistence - perspective
a minor - rather than the parent - must sign the release of patient information
regular - in a secure location
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
16. Privacy Officer
The body of laws made by states is their own statutory laws
Individually Identifiable Health Information
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
17. A written document detailing a health care provider's privacy practices.
Notice of Privacy Practices (NPP)
testimony under oath
malpractice
security rule
18. HI
Health Information
Electronic transmission
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Portability
19. Disclosure without Consent
although medical records are confidential - there are times when they can be released w/o a patient consent.
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
false charges and malicious oral statements about someone
Invasion of Privacy Publishing
20. PII
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
should never be released w/o a patient's signed consent or court order
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
Patient Identifiable Information
21. Coded information that can't be read until is decoded.
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
a minor - rather than the parent - must sign the release of patient information
What types of disclosures do not require patient permission?
Encryption
22. Disabilities act
23. Policies and procedures use to protect electronic information from unauthorized access
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
Security
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
24. Statue of limitations
improper performance of an otherwise lawful act. civil
state laws setting time limit for bringing a lawsuit
Standard
U.S. goverment
25. Patient records are _____________ so not all staff will have access.
Patient
the philosophical study of moral values and rules - conducts
need to know
Covered entities
26. All persons who will have access are required to...
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
Malfeasance
have a unique password and it should be changed frequently
although medical records are confidential - there are times when they can be released w/o a patient consent.
27. Key entities
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
have a unique password and it should be changed frequently
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
same legal standards apply to all patient records whether on paper or computer
28. Common law
State preemption
Minimum necessary
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
29. The computer screen should have a screensaver that...
comes on after a few idle seconds and the use of a privacy screen should be mandatory
improper performance of an otherwise lawful act. civil
false and malicious writing about another
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
30. Uniform anotomical gift act
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
law that permits a person w/ a legal age and sound mind to give their body to donation
Invasion of Privacy Publishing
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
31. The use of uniform electronic network protocols to transfer business information between organizations.
Patient rights under HIPAA
addresses portability of insurance coverage when employees change or lose their jobs
Electronic data interchange
Limited data set
32. Titile II of HIPAA
Treatment - payment and health care operations (TPO)
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
comes on after a few idle seconds and the use of a privacy screen should be mandatory
state laws setting time limit for bringing a lawsuit
33. EPHI
Electronic Protected Health Information
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
Health Information
concerns noncriminal disputes between private parties
34. Confidentiality
35. The person recieving treatment
Patient
Rule
Standard
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
36. Computes and HIPAA
have a unique password and it should be changed frequently
testimony under oath
Notice of Privacy Practices (NPP)
same legal standards apply to all patient records whether on paper or computer
37. Fax machines
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
generally only patient can auth release of own medical record - there are a few exceptions
should only be used when no other - more secure mode of transmission is available
testimony under oath
38. Good samaritan law
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Patient Identifiable Information
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
39. Emancipated minors
40. Electronic exchanges of information between two covered-entity business partners using HIPAA mandated transaction standards.
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
Designated record set
Insurance portability - administrative simplification - privacy and security
Covered transactions
41. Bioethics
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
Standard
state laws setting time limit for bringing a lawsuit
42. HIPAA compliance mandates that computer systems must be...
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
located in a secured and private space
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
Security
43. Document that includes the standards
Rule
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
44. Title I of HIPAA
Rule
Transaction
addresses portability of insurance coverage when employees change or lose their jobs
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
45. Any wrongdoing for which an action for damages may be brought
Electronic Protected Health Information
must be reported to authorities by law
Tort
State preemption
46. Unlawful act done without permission.
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
Malfeasance
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
malpractice
47. Misfeasance
Covered entities
regular - in a secure location
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
improper performance of an otherwise lawful act. civil
48. Subpoenas
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
generally only patient can auth release of own medical record - there are a few exceptions
Verification
49. Slander
The body of laws made by states is their own statutory laws
Electronic transmission
have a unique password and it should be changed frequently
false charges and malicious oral statements about someone
50. Business Associate Agreements applies to...
Firewalls
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney