click below
click below
Normal Size Small Size show me how
Med 149 rev. chapt.8
| Question | Answer |
|---|---|
| One of the best ways to ensure against loss or corruption of medical data is to: | Back up all data regularly. |
| The authority to administer the Security Rule of HIPAA rests with the _________ | OCR |
| A risk analysis for the Security Rule is | a requirement for the health care organization. |
| Which of the following constitutes a data breach? | A medical office computer is sold without erasing the hard drive., A hacker accesses a hospital’s list of patients with HIV,A business-use laptop is stolen from a health insurance company executive while she is traveling.All of these |
| A breach of more than _________ records requires notification to the media. | 500 |
| Medicare fraud is not easy to estimate. Which of the following does not contribute to the challenge of determining Medicare fraud? | State mandates determine the length of time records are retained, however they are not destroyed yearly. |
| The Criminal Healthcare Fraud Statue provides for: | making it a criminal offense to defraud any health care benefit program. |
| A physician pays a long-term care administrator to refer all new Medicare and Medicaid patients to his medical practice. He is most likely to be accused of violating which federal law? | Federal Anti-Kickback Law |
| An entity may have violated the Stark Law if “yes” is answered to which of the following questions? | Has a physician or a member of the physician’s family referred a Medicare or Medicaid patient to an entity, Is the referral for a “designated health service”?, Is there a financial relationship between the referring physician or family member and the enti |
| Which of the following statements is true? | The Federal Anti-Kickback Law and the Stark Law are not the same. |
| Which of the following might a health care practitioner face if convicted of the False Claims Act, the Federal Anti-Kickback Law, the Stark Law, or the Criminal Health Care Fraud Statute? | A fine, A prison sentence, Loss of medical license, All of these |
| Contains all patient medical records for one practice in electronic form. | Electronic medical record (EMR) |
| A more comprehensive record than the EMR, focusing on the total health of the patient and traveling with the patient. | Electronic health record (EHR) |
| Establishes a national set of security standards for protecting certain health information that is held or transferred in electronic form. | HIPAA Standard 3 Security Rule |
| A section of the American Recovery and Reinvestment Act (ARRA) that strengthened certain HIPAA privacy and security provisions. | Health Information Technology for Economic and Clinical Health Act (HITECH) |
| A 2009 act that made substantive change to HIPAA’s privacy and security regulations. A 2009 act that made substantive change to HIPAA’s privacy and security regulations. | American Recovery and Reinvestment Act (ARRA) |
| Any unauthorized acquisition, access, use, or disclosure of personal health in-formation that compromises the security or privacy of such information. | Breach |
| American Recovery and Reinvestment Act (ARRA), is commonly called this. | Stimulus Bill |
| Information that contains one or more patient identifiers. | protected health information (PHI) |
| To remove from health care transactions all information that identifies patients. | de-identify |
| Health care providers who conduct administrative and financial transactions in electronic form. This includes all employees, volunteers, trainees, and all others who are under the control of the entity. | covered entities |
| A reason under HIPAA for disclosing patient information. | permission |
| Individuals and/or organizations that provide certain functions, activities, or services on behalf of covered entities that involve access to, or the use of, disclosure of protected health information. | business associates |
| A list provided by all covered entities that demonstrates adherence to HIPAA's privacy practices rules. | Notice of Privacy Practices |
| Protected health information from which certain patient identifiers have been removed. | limited data set |
| A transaction refers to the transmission of information between two parties to carry out financial or administrative activities. A code set is any set of codes used to encode data elements, such as tables of terms, medical concepts, medical diagnostic cod | Transactions and Code Sets |
| Policies and procedures health care providers and their business associates put in place to ensure confidentiality of electronic, written, and oral protected health information. | Privacy Rule |
| Security refers to those policies and procedures health care providers and their business associates use to protect electronically transmitted and stored PHI from unauthorized access. | Security Rule |
| Provide unique identifiers (addresses) for electronic transmissions. | National Identifier Standards |
| When you violate privacy information regarding a patient, the following could happen: | You could lose your job. |
| Providers and their business associates are required to put in place policies and procedures that ensure privacy of the health record under which HIPAA standard? | Standard 2 |
| Which of the following statements about HIPAA is true? | HIPAA covers privacy and other health care rights for patients. |
| The physician in this case is also paying a nursing home administrator to refer patients to his practice. What law is he violating?Which U.S. constitutional amendment pertains to health care privacy? | Federal Anti-Kickback Law |
| What legal principle might protect and possibly reward Marie if she reports the fraud? | Qui Tam |
| A risk analysis under the Security Rule is completed by | The health care organization |
| If more than _________ records are compromised as a result of a hacker, the incident must be reported to the media. | 500 |
| When a _________ of patients’ records is discovered, the health care organization must notify affected individuals and the Health and Human Services (HHS) agency and possibly the media. | Breach |
| What is a Covered Entity? | Insurance company, Rehabilitation facility, Hospital, All of these |
| Which of the following organizations has the authority to administer the Security Rule of HIPAA? | Health and Human Services Office of Civil Rights |