SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Protected health information from which certain patient identifiers have been removed
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Limited data set
improper performance of an otherwise lawful act. civil
illegal touching of another person
2. Civil law
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
concerns noncriminal disputes between private parties
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
need to know
3. The use of uniform electronic network protocols to transfer business information between organizations.
Electronic data interchange
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
located in a secured and private space
4. EPHI
Examples of PHI
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
substance abuse treatment
Electronic Protected Health Information
5. HIPAA
De-Identified Information
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Electronic data interchange
testimony under oath
6. Disclosure without Consent
Rule
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
although medical records are confidential - there are times when they can be released w/o a patient consent.
Insurance portability - administrative simplification - privacy and security
7. What information do patients NOT have access to?
must be reported to authorities by law
U.S. goverment
Malfeasance
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
8. All persons who will have access are required to...
only those who meed to know should have access to patient information
have a unique password and it should be changed frequently
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
purpose - pride - patience - persistence - perspective
9. Gunshot wound - child abuse - infectious diseases - required by law - law enforcement purposes.
addresses portability of insurance coverage when employees change or lose their jobs
Privacy
What types of disclosures do not require patient permission?
Permission
10. The limited amount of patient information to be disclosed - depending on circumstances.
Minimum necessary
comes on after a few idle seconds and the use of a privacy screen should be mandatory
Permission
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
11. Medical records used for health care research
12. Any wrongdoing for which an action for damages may be brought
Designated record set
false charges and malicious oral statements about someone
Tort
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
13. De-Identified Information
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
Rule
Ethical
malpractice
14. Statue of limitations
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
although medical records are confidential - there are times when they can be released w/o a patient consent.
state laws setting time limit for bringing a lawsuit
What types of disclosures do not require patient permission?
15. Verify the identification of anyone requesting patient information.
State preemption
Malfeasance
Verification
treatment - payment - & healthcare operations
16. PII
should never be released w/o a patient's signed consent or court order
located in a secured and private space
generally only patient can auth release of own medical record - there are a few exceptions
Patient Identifiable Information
17. Releasing patient information
need to know
generally only patient can auth release of own medical record - there are a few exceptions
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
18. DII
De-Identified Information
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
U.S. goverment
19. Treatment means that a health care provider can provide care; payment means that a provider can disclose PHI to be reimbursed; health care operations refers to HIPAA approved activities and transactions.
Designated record set
Insurance portability - administrative simplification - privacy and security
Treatment - payment and health care operations (TPO)
have a unique password and it should be changed frequently
20. Conforming to proper professional behavior
Ethical
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
State preemption
U.S. goverment
21. The computer screen should have a screensaver that...
false charges and malicious oral statements about someone
Limited data set
testimony under oath
comes on after a few idle seconds and the use of a privacy screen should be mandatory
22. Coded information that can't be read until is decoded.
Encryption
comes on after a few idle seconds and the use of a privacy screen should be mandatory
a contract that comes about from the actions of the parties rather than words
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
23. Deposition
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
Notice of Privacy Practices
treatment - payment - & healthcare operations
testimony under oath
24. Transmission of information between two parties fro financial or administrative activities.
Designated record set
treatment - payment - & healthcare operations
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Transaction
25. A general HIPAA requirement
must be reported to authorities by law
Ethical
Standard
Electronic transmission
26. See & Copy their health records - update health records - obtain a list of the institution's disclosures - other than for payment & healthcare operations - request a restriction on a certain uses or disclosures - choose how to receive their health in
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
Patient rights under HIPAA
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
27. Policies and procedures use to protect electronic information from unauthorized access
Security
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
need to know
De-Identified Information
28. Guidelines and standards made by government agencies and licensing boards that have the authority to enforce compliance
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
testimony under oath
Regulations
U.S. goverment
29. OIG - Office of the Inspector General
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
should only be used when no other - more secure mode of transmission is available
false and malicious writing about another
30. In order for a fax document to be HIPAA compliant...
31. Common law
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
Portability
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
32. The ability to control access and protect information from accidental or intentional disclosure to unauthorized persons and from altercation - destruction - or loss
security rule
Electronic transmission
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Patient rights under HIPAA
33. Some state laws specifically protect __________. A patient would need to sign a specific request.
substance abuse treatment
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
purpose - pride - patience - persistence - perspective
Ethical
34. Implied consent
Notice of Privacy Practices (NPP)
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
Firewalls
false charges and malicious oral statements about someone
35. Freedom from unauthorized intrusion
Notice of Privacy Practices
The body of laws made by states is their own statutory laws
false charges and malicious oral statements about someone
Privacy
36. Subpoenas
Notice of Privacy Practices
a minor - rather than the parent - must sign the release of patient information
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
37. If a states privacy laws are stricter than HIPAA privacy standards - the state laws take precedence.
State preemption
Designated record set
a minor - rather than the parent - must sign the release of patient information
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
38. Sending information over electronic networks.
Patient Identifiable Information
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Designated record set
Electronic transmission
39. Privacy Officer
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
Rule
must be reported to authorities by law
Notice of Privacy Practices
40. Battery
Notice of Privacy Practices (NPP)
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
illegal touching of another person
41. Criminal law
law concerned with public wrongs against society
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
Invasion of Privacy Publishing
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
42. Bioethics
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
Insurance portability - administrative simplification - privacy and security
located in a secured and private space
although medical records are confidential - there are times when they can be released w/o a patient consent.
43. HI
Health Information
Notice of Privacy Practices
false and malicious writing about another
Examples of PHI
44. Titile II of HIPAA
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
Patient
substance abuse treatment
Covered transactions
45. HIPAA compliance mandates that computer systems must be...
located in a secured and private space
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Notice of Privacy Practices
same legal standards apply to all patient records whether on paper or computer
46. Fax machines
Health Information
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
U.S. goverment
should only be used when no other - more secure mode of transmission is available
47. TPO
false and malicious writing about another
treatment - payment - & healthcare operations
state laws setting time limit for bringing a lawsuit
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
48. Under some circumstances ...
law that permits a person w/ a legal age and sound mind to give their body to donation
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
Invasion of Privacy Publishing
a minor - rather than the parent - must sign the release of patient information
49. Statutory
Electronic data interchange
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
The body of laws made by states is their own statutory laws
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
50. Includes records maintained by or for a covered entity.
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
The body of laws made by states is their own statutory laws
Designated record set
illegal touching of another person