SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
HIPAA
Start Test
Study First
Subjects
:
certifications
,
hipaa
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. HIPAA states...
must be reported to authorities by law
Patient
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
only those who meed to know should have access to patient information
2. HI
comes on after a few idle seconds and the use of a privacy screen should be mandatory
Health Information
The body of laws made by states is their own statutory laws
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
3. Guidelines and standards made by government agencies and licensing boards that have the authority to enforce compliance
Regulations
illegal touching of another person
Standard
must be reported to authorities by law
4. PII
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
Patient Identifiable Information
Patient
5. Statutory
Individually Identifiable Health Information
false charges and malicious oral statements about someone
The body of laws made by states is their own statutory laws
Patient
6. Fax machines
Code sets
substance abuse treatment
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
should only be used when no other - more secure mode of transmission is available
7. Doctor release of patient
testimony under oath
Notice of Privacy Practices
A written set of questions requiring written answers from a plaintiff or defendant under oath
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
8. The computer screen should have a screensaver that...
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
security rule
comes on after a few idle seconds and the use of a privacy screen should be mandatory
State preemption
9. If a states privacy laws are stricter than HIPAA privacy standards - the state laws take precedence.
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
State preemption
De-Identified Information
Privacy
10. Criminal law
Individually Identifiable Health Information
only those who meed to know should have access to patient information
purpose - pride - patience - persistence - perspective
law concerned with public wrongs against society
11. The ability to control access and protect information from accidental or intentional disclosure to unauthorized persons and from altercation - destruction - or loss
Regulations
security rule
Notice of Privacy Practices
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
12. Fax Machines and HIPAA
Covered transactions
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
improper performance of an otherwise lawful act. civil
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
13. Protected Health Information (PHI)
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
Standard
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
Electronic Protected Health Information
14. Any set of codes use to encode health care data elements.
Electronic data interchange
Code sets
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
Tort
15. Business Associate Agreements applies to...
Electronic data interchange
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Tort
De-Identified Information
16. Some state laws specifically protect __________. A patient would need to sign a specific request.
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
human immunodeficiency virus/acquired immune deficiency syndrome (HIV/AIDS)
illegal touching of another person
17. Protected health information from which certain patient identifiers have been removed
Health Insurance Portability and Accountability Act of 1996 (passed by congress because of portability problems - also to protect PHI)
treatment - payment - & healthcare operations
state laws setting time limit for bringing a lawsuit
Limited data set
18. The person recieving treatment
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Patient
concerned with mostly with h/c providers. It addresses fraud and abuse - administrative simplification and medical liability
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
19. Includes records maintained by or for a covered entity.
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
only those who meed to know should have access to patient information
parent of a minor - legal guardian - Agent (patient selected on behalf in h/c power of attorney)
Designated record set
20. Deposition
h/c workers --qualified people of organizations(perf. data processinf or transcript) -certain gov. auth. (pub health activities) -appropriate auth(protect vic. of abuse) -law enforcement officials or judicial orders
same legal standards apply to all patient records whether on paper or computer
testimony under oath
false and malicious writing about another
21. Hardware or software designed to prevent unauthorized access to electronic information.
need to know
addresses portability of insurance coverage when employees change or lose their jobs
Firewalls
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
22. Clearinghouse
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
in order to maintain patient confidentiality - fax machines must be kept in areas not accessible to patients.
testimony under oath
Standard
23. Title I of HIPAA
law that permits a person w/ a legal age and sound mind to give their body to donation
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
a service company that recieves electronic or paper claims from the provider - checks and prepares them for processing - and transmits them in HIPAA-complaint format to the correct carriers
addresses portability of insurance coverage when employees change or lose their jobs
24. NPP
security rule
The body of laws made by states is their own statutory laws
A written set of questions requiring written answers from a plaintiff or defendant under oath
Notice of Privacy Practices
25. Ethics
Invasion of Privacy Publishing
the philosophical study of moral values and rules - conducts
generally only patient can auth release of own medical record - there are a few exceptions
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
26. Uniform anotomical gift act
must be reported to authorities by law
law that permits a person w/ a legal age and sound mind to give their body to donation
Security
Notice of Privacy Practices
27. Gunshot wound - child abuse - infectious diseases - required by law - law enforcement purposes.
What types of disclosures do not require patient permission?
have a unique password and it should be changed frequently
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
concerns noncriminal disputes between private parties
28. Common law
judge made law from decisions of a court - interpretation of constitution and statuatory law - often known as precedents
Ethical
Prohibits discrimination preventing indiviualds with physical or mental disabilities or chronic illness - from accessing public services & accomodations. Employers requires 'reasonable accommodation' be provided so they can perform duties.
Regulations
29. Coded information that can't be read until is decoded.
Encryption
false charges and malicious oral statements about someone
Electronic Protected Health Information
must be reported to authorities by law
30. Protecting healthcare coverage for employees who change jobs - allowing them to continue existing plans with a new employer.
Portability
Transaction
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
31. Computes and HIPAA
Treatment - payment and health care operations (TPO)
located in a secured and private space
Privacy
same legal standards apply to all patient records whether on paper or computer
32. OIG - Office of the Inspector General
Invasion of Privacy Publishing
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
The body of laws made by states is their own statutory laws
Notice of Privacy Practices (NPP)
33. Implied contract
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
a minor - rather than the parent - must sign the release of patient information
illegal touching of another person
a contract that comes about from the actions of the parties rather than words
34. A written document detailing a health care provider's privacy practices.
Notice of Privacy Practices (NPP)
Portability
Invasion of Privacy Publishing
State preemption
35. A general HIPAA requirement
Code sets
should never be released w/o a patient's signed consent or court order
Standard
Invasion of Privacy Publishing
36. TPO
A court order requiring someone to appear in court on a certain date time and reason. A medical record could be subpoenaed.
Encryption
U.S. goverment
treatment - payment - & healthcare operations
37. Battery
regular - in a secure location
illegal touching of another person
Tort
individuals in their mid- to late teens who legally live outside of parents' or guardians' control
38. Implied consent
false charges and malicious oral statements about someone
Type of consent in which a patient who is unable to give consent is given treatment under the legal assumption that he or she would want treatment.
illegal touching of another person
it must have an accompanying disclaimer stating the fax information cannot be shared with any other party w/o patient's written consent
39. Key entities
Regulations
need to know
U.S. Department of Health and Human Services (HHS; established national standards for HIPAA) - Centers for Medicare and Medicaid Services (CMS; enforce insurance portability and transaction/code set requirements) - Office for Civil Rights (OCR; enfor
The body of laws made by states is their own statutory laws
40. The limited amount of patient information to be disclosed - depending on circumstances.
Minimum necessary
Portability
Designated record set
malpractice
41. Disclosure without Consent
Covered entities
safeguards health & wealthfare of Medicare/Medicaid beneficiaries & protect program integrity
should never be released w/o a patient's signed consent or court order
although medical records are confidential - there are times when they can be released w/o a patient consent.
42. Emancipated minors
43. EPHI
failure to act with the standard of care that a reasonable person would exercise under the same circumstances
Invasion of Privacy Publishing
although medical records are confidential - there are times when they can be released w/o a patient consent.
Electronic Protected Health Information
44. Transmission of information between two parties fro financial or administrative activities.
Individually Identifiable Health Information
U.S. goverment
Regulations
Transaction
45. Verify the identification of anyone requesting patient information.
Verification
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
Medical data from which individual identifiers have been removed; also known as a redacted or blinded record.
Limited data set
46. 4d's of negligence
Firewalls
patient discharges doctor with letter - doctor formally withdraws from patient with a certified letter or patient no longer needs treatment
state laws setting time limit for bringing a lawsuit
Duty; duty of care - Derelict; breach of the duty of care - Direct cause; legally recognizable injury occurs as a result of breach of care - Damage; wrongful activity must have been the cause
47. What are the 3 purposes of HIPAA?
Insurance portability - administrative simplification - privacy and security
a minor - rather than the parent - must sign the release of patient information
Examples of PHI
only those who meed to know should have access to patient information
48. Any wrongdoing for which an action for damages may be brought
Tort
must be reported to authorities by law
Any information that would identify a patient (name - add - tele - DOB - SSN - email - med. rec. number - etc)
may be disclosed to public health agencies - patient identifiers are removed so it's covered by HIPAA
49. See & Copy their health records - update health records - obtain a list of the institution's disclosures - other than for payment & healthcare operations - request a restriction on a certain uses or disclosures - choose how to receive their health in
Patient rights under HIPAA
individuals such as cleaning staff and consultants who work in the office. These individuals do not need access to patient info but may come in contact while completing their duties
Designated record set
U.S. goverment
50. What information do patients NOT have access to?
treatment - payment - & healthcare operations
Psychotherapy notes - information for legal proceedings - information exempted from disclosure under CLIA
Health Information
must be reported to authorities by law