SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. HIPAA states...
Designated record set
Malfeasance
only those who meed to know should have access to patient information
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
2. The person recieving treatment
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
should only be used when no other - more secure mode of transmission is available
Patient
3. Titile II of HIPAA
should only be used when no other - more secure mode of transmission is available
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
generally only patient can auth release of own medical record - there are a few exceptions
Examples of PHI
4. Any wrongdoing for which an action for damages may be brought
Verification
Tort
Minimum necessary
Security
5. DII
De-Identified Information
Ethical
testimony under oath
Security
6. If a states privacy laws are stricter than HIPAA privacy standards - the state laws take precedence.
U.S. goverment
State preemption
state laws setting time limit for bringing a lawsuit
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
7. Some state laws specifically protect __________. A patient would need to sign a specific request.
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
Regulations
State preemption
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
8. HI
Health Information
law concerned with public wrongs against society
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Minimum necessary
9. What information do patients NOT have access to?
false charges and malicious oral statements about someone
addresses portability of insurance coverage when employees change or lose their jobs
should never be released w/o a patient's signed consent or court order
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
10. Treatment means that a health care provider can provide care; payment means that a provider can disclose PHI to be reimbursed; health care operations refers to HIPAA approved activities and transactions.
De-Identified Information
Verification
must be reported to authorities by law
Treatment - payment and health care operations (TPO)
11. Deposition
testimony under oath
Firewalls
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
12. Policies and procedures use to protect electronic information from unauthorized access
Security
Electronic Protected Health Information
concerns noncriminal disputes between private parties
should never be released w/o a patient's signed consent or court order
13. Doctor release of patient
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
should only be used when no other - more secure mode of transmission is available
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
only those who meed to know should have access to patient information
14. Libel
false and malicious writing about another
Electronic data interchange
Code sets
security rule
15. Gunshot wound - child abuse - infectious diseases - required by law - law enforcement purposes.
Limited data set
What types of disclosures do not require patient permission?
false charges and malicious oral statements about someone
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
16. Name - address - date of birth - phone/fax numbers - social security number - medical record number - and photographs - nursing and physician notes - billing and other treatment records used during a patient's visit in a hospital or office.
addresses portability of insurance coverage when employees change or lose their jobs
The body of laws made by states is their own statutory laws
Designated record set
Examples of PHI
17. Computes and HIPAA
a minor - rather than the parent - must sign the release of patient information
U.S. goverment
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
same legal standards apply to all patient records whether on paper or computer
18. Professional Negligence
a contract that comes about from the actions of the parties rather than words
malpractice
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
Examples of PHI
19. Includes records maintained by or for a covered entity.
Ethical
Designated record set
De-Identified Information
Regulations
20. Any set of codes use to encode health care data elements.
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
Limited data set
Code sets
need to know
21. HIPAA compliance mandates that computer systems must be...
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Treatment - payment and health care operations (TPO)
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
located in a secured and private space
22. making known - or using information relating to the private life or affairs of a person without their approval or permission
Minimum necessary
Invasion of Privacy Publishing
Notice of Privacy Practices
a contract that comes about from the actions of the parties rather than words
23. Transmission of information between two parties fro financial or administrative activities.
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Malfeasance
Transaction
concerns noncriminal disputes between private parties
24. Implied consent
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
Tort
Insurance portability - administrative simplification - privacy and security
25. See & Copy their health records - update health records - obtain a list of the institution's disclosures - other than for payment & healthcare operations - request a restriction on a certain uses or disclosures - choose how to receive their health in
purpose - pride - patience - persistence - perspective
Electronic data interchange
Patient rights under HIPAA
Patient
26. Common law
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
Notice of Privacy Practices
Code sets
27. Conforming to proper professional behavior
Ethical
Covered entities
Treatment - payment and health care operations (TPO)
substance abuse treatment
28. Electronic exchanges of information between two covered-entity business partners using HIPAA mandated transaction standards.
law that permits a person w/ a legal age and sound mind to give their body to donation
regular - in a secure location
Covered transactions
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
29. Federal law protects patient records dealing with...
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Covered transactions
substance abuse treatment
false charges and malicious oral statements about someone
30. Coded information that can't be read until is decoded.
Electronic transmission
Notice of Privacy Practices
Encryption
Tort
31. IIHI
Standard
state law that protects healthcare professionals from liability when they provide emergency assistance/services within their scope of training
Patient Identifiable Information
Individually Identifiable Health Information
32. In order for a fax document to be HIPAA compliant...
33. The use of uniform electronic network protocols to transfer business information between organizations.
although medical records are confidential - there are times when they can be released w/o a patient consent.
a contract that comes about from the actions of the parties rather than words
Electronic data interchange
addresses portability of insurance coverage when employees change or lose their jobs
34. Reportable diseases...
must be reported to authorities by law
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
addresses portability of insurance coverage when employees change or lose their jobs
Insurance portability - administrative simplification - privacy and security
35. Fax machines
should only be used when no other - more secure mode of transmission is available
Security
have a unique password and it should be changed frequently
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
36. EPHI
Electronic Protected Health Information
substance abuse treatment
Notice of Privacy Practices
although medical records are confidential - there are times when they can be released w/o a patient consent.
37. The ability to control access and protect information from accidental or intentional disclosure to unauthorized persons and from altercation - destruction - or loss
Electronic Protected Health Information
security rule
a contract that comes about from the actions of the parties rather than words
Invasion of Privacy Publishing
38. 5P's of ethical power
malpractice
purpose - pride - patience - persistence - perspective
Verification
law concerned with public wrongs against society
39. Under some circumstances ...
a minor - rather than the parent - must sign the release of patient information
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
allows patients to give directions to health care providers about treatment choices in circumstances in which the patient may no longer be able to provide that direction. There are two types: Living Will and Durable Power of Attorney
40. A reason for each use and disclosure of patient information.
Patient
located in a secured and private space
Permission
law concerned with public wrongs against society
41. Criminal law
law concerned with public wrongs against society
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Electronic transmission
Permission
42. A written document detailing a health care provider's privacy practices.
treatment - payment - & healthcare operations
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Notice of Privacy Practices (NPP)
43. General exceptions for releasing patient information
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Patient
What types of disclosures do not require patient permission?
44. Protecting healthcare coverage for employees who change jobs - allowing them to continue existing plans with a new employer.
concerns noncriminal disputes between private parties
Portability
Notice of Privacy Practices
state laws setting time limit for bringing a lawsuit
45. Subpoenas
Every office should have one! - responsible for making surethat thise office is HIPAA compliant - privacy officer should be.. an effective communicator with ability to answer questions about sespected HIPPA violations and complaints
addresses portability of insurance coverage when employees change or lose their jobs
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
located in a secured and private space
46. PII
Regulations
Patient Identifiable Information
The body of laws made by states is their own statutory laws
Ethical
47. In HIPAA language health plans - Health care clearinghouses - and all health care providers that transmit HIPAA standard transactions electronically are called covered entities. Hospitals - nursing homes - hospices - pharmacies - physician practices
although medical records are confidential - there are times when they can be released w/o a patient consent.
Covered entities
Security
concerns noncriminal disputes between private parties
48. Fax Machines and HIPAA
Designated record set
false and malicious writing about another
should only be used when no other - more secure mode of transmission is available
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
49. All persons who will have access are required to...
false charges and malicious oral statements about someone
have a unique password and it should be changed frequently
regular - in a secure location
located in a secured and private space
50. TPO
regular - in a secure location
Examples of PHI
should never be released w/o a patient's signed consent or court order
treatment - payment - & healthcare operations