click below
click below
Normal Size Small Size show me how
HITT 1301
Chapter 9
| Question | Multiple Choice |
|---|---|
| Which of the following is true of the notice of privacy practice? | It must be posted in a prominent place |
| In all cases, a covered entity may deny an individual's request to restrict the use or disclosure of his or her PHI. | False |
| Under HIPAA Privacy Rule, which of the following is a covered entity category? | Healthcare clearinghouse |
| In which of the following situations must a covered entity provide an appeal process for denials to request from individuals to see their own health information? | When a licensed healthcare professional has determined the access to PHI would likely endanger the life or safety of the individual |
| Critique this statement: According to HIPAA, workforce members include students. | This is a true statement |
| The designated record set includes which of the following? | Billing records |
| Which of the following statements is true in responding to requests from individuals who wish to access their PHI? | A cost-based fee may be charged for making a copy of the PHI. |
| A subpoena should be accompanied by which of the following? | Patient authorization |
| Mary's PHI was breached by her physician office when it was disclosed in error to another patient. Which of the following breach notification statements is correct regarding the physician office's required action? | It must report the breach to HHS within 60 days after the end of the calendar year in which the breach occurred |
| What types of health records are subject to the HIPAA Privacy Rule? | Health records in any format |
| Which of the following provides a complete description to patients about how PHI is used in a healthcare facility? | Notice of privacy practices |
| In which of the following instances must patient authorization be obtained prior to disclosure? | To the patient's attorney |
| Which of the following statements is true? | State law preempts HIPAA |
| In which of the following circumstances does the patient have an opportunity to agree or object? | Whether the patient should be in the facility directory |
| Which of the following statements is true of the notice of privacy practices? | It must be provided to every individual at the first time of contact or service with the covered entity. |
| Stricter state statutes that provide greater confidentiality of healthcare information take precedence over the provisions of the HIPAA Privacy Rule. | True |
| When would PHI loses its status? | After an individual has been deceased more than 50 years |
| How many days does a covered entity have to respond to an individual's request for access to his or her PHI when the PHI is stored off-site? | 60 days |
| Which of the following statements is true? | An authorization must contain an expiration date or event |
| Under the HIPAA Privacy Rule, when an individual asks to see his or her own health information, a covered entity _______________. | Can deny access to psychotherapy notes |
| Which of the following is true of the Health Insurance Portability and Accountability Act (HIPAA)? | Provides a federal floor for healthcare privacy |
| In court, hearsay is generally ____________. | Non-admissible |
| The HIPAA Privacy Rule requires that covered entities limit use, access, and disclosure of PHI to the least amount necessary to accomplish the intended purpose. What concept is this? | a. Minimum necessary |
| Which of the following actions by a physician requires the patient's authorization? | Giving the name of an expectant mother to a baby formula manufacturer |
| What does the acronym PHI stand for? | Protected health information |
| Which of the following statements about the directory of patients maintained by a covered entity is true? | a. Individuals must be given an opportunity to deny permission to place information about them in the directory. |
| Which of the following rights did HIPAA give patients? | Right to request an amendment of the health record |
| A notice of privacy practices should include a statement explaining that individuals may complain to the Secretary of the Department of Health and Human Services if they believe that their privacy rights have been violated. | True |
| How many days does a covered entity have to respond to an individual's request for access to PHI under HIPAA rules? | 30 days |
| ARRA and HITECH granted which of the following the ability to bring civil actions in federal district court on behalf of residents believed to have been affected by a HIPAA violation? | State attorneys general |
| HIPAA administrative requirements include which of the following? | Designating a privacy officer |
| Which of the following is a covered entity under the HIPAA Privacy Rule? | Newspaper that publishes births at an area hospital |
| A valid authorization requires which of the following? | An expiration date or event |
| Who of the following would be considered a member of a hospital's workforce? | A clerk working in the hospital's registration office |
| The designated record set includes which of the following? | Billing records |