SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Freedom from unauthorized intrusion
security rule
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
Privacy
Invasion of Privacy Publishing
2. Coded information that can't be read until is decoded.
Encryption
Security
Individually Identifiable Health Information
Verification
3. Slander
false charges and malicious oral statements about someone
Regulations
Permission
purpose - pride - patience - persistence - perspective
4. Doctor release of patient
Firewalls
What types of disclosures do not require patient permission?
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
De-Identified Information
5. Unlawful act done without permission.
Malfeasance
Code sets
testimony under oath
Patient Identifiable Information
6. Business Associate Agreements applies to...
generally only patient can auth release of own medical record - there are a few exceptions
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
testimony under oath
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
7. Data must be backed up at ___________ and those back-up files should be stored ________.
regular - in a secure location
purpose - pride - patience - persistence - perspective
security rule
Notice of Privacy Practices (NPP)
8. Electronic exchanges of information between two covered-entity business partners using HIPAA mandated transaction standards.
state laws setting time limit for bringing a lawsuit
same legal standards apply to all patient records whether on paper or computer
Covered transactions
Insurance portability - administrative simplification - privacy and security
9. Patient records are _____________ so not all staff will have access.
purpose - pride - patience - persistence - perspective
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
need to know
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
10. Federal law protects patient records dealing with...
law concerned with public wrongs against society
Transaction
substance abuse treatment
regular - in a secure location
11. Key entities
false charges and malicious oral statements about someone
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
Verification
12. Fax machines
Portability
should only be used when no other - more secure mode of transmission is available
testimony under oath
Health Information
13. HIPAA compliance mandates that computer systems must be...
located in a secured and private space
illegal touching of another person
Electronic Protected Health Information
Malfeasance
14. Releasing patient information
should only be used when no other - more secure mode of transmission is available
generally only patient can auth release of own medical record - there are a few exceptions
purpose - pride - patience - persistence - perspective
Encryption
15. Who regulates HIPAA?
Standard
U.S. goverment
need to know
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
16. In order for a fax document to be HIPAA compliant...
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
17. Any set of codes use to encode health care data elements.
Rule
Electronic transmission
Code sets
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
18. Policies and procedures use to protect electronic information from unauthorized access
The body of laws made by states is their own statutory laws
Security
security rule
generally only patient can auth release of own medical record - there are a few exceptions
19. PII
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
Patient Identifiable Information
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
purpose - pride - patience - persistence - perspective
20. Privacy Officer
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
Examples of PHI
only those who meed to know should have access to patient information
21. The ability to control access and protect information from accidental or intentional disclosure to unauthorized persons and from altercation - destruction - or loss
security rule
Notice of Privacy Practices (NPP)
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
22. The limited amount of patient information to be disclosed - depending on circumstances.
Examples of PHI
Ethical
Code sets
Minimum necessary
23. Protected health information from which certain patient identifiers have been removed
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
addresses portability of insurance coverage when employees change or lose their jobs
Limited data set
Covered entities
24. A reason for each use and disclosure of patient information.
Permission
purpose - pride - patience - persistence - perspective
same legal standards apply to all patient records whether on paper or computer
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
25. NPP
located in a secured and private space
Transaction
Notice of Privacy Practices
purpose - pride - patience - persistence - perspective
26. Title I of HIPAA
addresses portability of insurance coverage when employees change or lose their jobs
must be reported to authorities by law
have a unique password and it should be changed frequently
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
27. De-Identified Information
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
generally only patient can auth release of own medical record - there are a few exceptions
should never be released w/o a patient's signed consent or court order
28. making known - or using information relating to the private life or affairs of a person without their approval or permission
Invasion of Privacy Publishing
De-Identified Information
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
regular - in a secure location
29. Hardware or software designed to prevent unauthorized access to electronic information.
purpose - pride - patience - persistence - perspective
Firewalls
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Electronic data interchange
30. Negligence
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Permission
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
A written set of questions requiring written answers from a plaintiff or defendant under oath
31. The computer screen should have a screensaver that...
should never be released w/o a patient's signed consent or court order
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
Encryption
comes on after a few idle seconds and the use of a privacy screen should be mandatory
32. Under some circumstances ...
substance abuse treatment
a contract that comes about from the actions of the parties rather than words
a minor - rather than the parent - must sign the release of patient information
Treatment - payment and health care operations (TPO)
33. Medical records can be released w/o consent to...
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
Notice of Privacy Practices
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
34. Implied contract
Ethical
Patient rights under HIPAA
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
a contract that comes about from the actions of the parties rather than words
35. Deposition
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
Health Information
testimony under oath
should never be released w/o a patient's signed consent or court order
36. Battery
treatment - payment - & healthcare operations
illegal touching of another person
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
addresses portability of insurance coverage when employees change or lose their jobs
37. Bioethics
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
Rule
illegal touching of another person
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
38. A general HIPAA requirement
Standard
also called biomedical ethics - the moral dilemmas and issues of advanced medicine and medical research
Security
Insurance portability - administrative simplification - privacy and security
39. A written document detailing a health care provider's privacy practices.
Notice of Privacy Practices (NPP)
Individually Identifiable Health Information
regular - in a secure location
located in a secured and private space
40. The use of uniform electronic network protocols to transfer business information between organizations.
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
Electronic data interchange
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
have a unique password and it should be changed frequently
41. If a states privacy laws are stricter than HIPAA privacy standards - the state laws take precedence.
addresses portability of insurance coverage when employees change or lose their jobs
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
State preemption
Code sets
42. Clearinghouse
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
Verification
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
located in a secured and private space
43. Any wrongdoing for which an action for damages may be brought
Tort
A written set of questions requiring written answers from a plaintiff or defendant under oath
Permission
Health Information
44. Advanced directives
substance abuse treatment
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
concerns noncriminal disputes between private parties
45. EPHI
should only be used when no other - more secure mode of transmission is available
U.S. goverment
Minimum necessary
Electronic Protected Health Information
46. See & Copy their health records - update health records - obtain a list of the institution's disclosures - other than for payment & healthcare operations - request a restriction on a certain uses or disclosures - choose how to receive their health in
treatment - payment - & healthcare operations
state laws setting time limit for bringing a lawsuit
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
Patient rights under HIPAA
47. Name - address - date of birth - phone/fax numbers - social security number - medical record number - and photographs - nursing and physician notes - billing and other treatment records used during a patient's visit in a hospital or office.
Examples of PHI
Regulations
Notice of Privacy Practices (NPP)
Invasion of Privacy Publishing
48. Document that includes the standards
generally only patient can auth release of own medical record - there are a few exceptions
Electronic transmission
Rule
security rule
49. Fax Machines and HIPAA
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
Firewalls
false and malicious writing about another
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
50. Good samaritan law
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Ethical
Privacy
although medical records are confidential - there are times when they can be released w/o a patient consent.