click below
click below
Normal Size Small Size show me how
MED 112
Chapter 2 terms
| Question | Answer |
|---|---|
| medical record | A file that contains the documentation of a patient’s medical history, record of care, progress notes, correspondence, and related billing/financial information |
| malpractice | Failure to use an acceptable level of professional skill when giving medical services that results in injury or harm to a patient |
| documentation | The systematic, logical, and consistent recording of a patient’s health status |
| medical standards of care | State-specified performance measures for the delivery of healthcare by medical professionals |
| encounter | An office visit between a patient and a medical professional |
| informed consent | The process by which a patient authorizes medical treatment after discussion about the nature, indications, benefits, and risks of a treatment a physician recommends |
| 21st Century Cures Act | A federal law that requires providers to make certain specific categories of clinical notes digitally accessible to patients |
| information blocking | Delaying or limiting patients’ access to their electronic health records |
| medical documentation and revenue cycle | A series of steps that explain how using EHRs is integrated with practice management programs as the 10-step billing process is formed |
| Centers for Medicare and Medicaid Services (CMS) | Federal agency within the Department of Health and Human Services (HHS) that runs Medicare, Medicaid, clinical laboratories (under the CLIA program), and other government health programs |
| Health Insurance Portability and Accountability Act (HIPAA) of 1996 | Federal act that set forth guidelines for standardizing the electronic data interchange of administrative and financial transactions, exposing fraud and abuse in government programs, and protecting the security and privacy of health information |
| Health Information Technology for Economic and Clinical Health (HITECH) Act | Law promoting the adoption and use of health information technology |
| meaningful use | The utilization of certified EHR technology to improve quality, efficiency, and patient safety in the healthcare system |
| Affordable Care Act (ACA) | Health system reform legislation that offers improved insurance coverage and other benefits |
| electronic data interchange (EDI) | The system-to-system exchange of data in a standardized format |
| interoperability | Ability of different computer systems and devices to share data |
| transaction | Under HIPAA, structured set of electronic data transmitted between two parties to carry out financial or administrative activities related to healthcare |
| covered entity (CE) | Under HIPAA, a health plan, clearinghouse, or provider who transmits any health information in electronic form in connection with a HIPAA transaction |
| clearinghouse | A company (billing service, repricing company, or network) that converts nonstandard transactions into standard transactions and transmits the data to health plans |
| business associate (BA) | A person or organization that performs a function or activity for a covered entity but is not part of its workforce |
| HIPAA Privacy Rule | Law that regulates the use and disclosure of patients’ protected health information (PHI) |
| protected health information (PHI) | Individually identifiable health information that is transmitted or maintained by electronic media |
| treatment, payment, and healthcare operation (TPO) | Under HIPAA, patients’ protected health information may be shared without authorization for the purposes of treatment, payment, and operations |
| minimum necessary standard | Principle that individually identifiable health information should be disclosed only to the extent needed to support the purpose of the disclosure |
| designated record set (DRS) | A covered entity’s records that contain protected health information (PHI); for providers, the designated record set is the medical/financial patient record |
| Notice of Privacy Practices (NPP) | A HIPAA-mandated description of a covered entity’s principles and procedures related to the protection of patients’ health information |
| authorization | (1) Document signed by a patient to permit release of particular medical information under the stated specific conditions. (2) A health plan’s system of approving payment of benefits for services that satisfy the plan’s requirements for coverage |
| de-identified health information | Medical data from which individual identifiers have been removed; also known as a redacted or blinded record |
| HIPAA Security Rule | Law that requires covered entities to establish administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of health information |
| encryption | A method of scrambling transmitted data so they cannot be deciphered without the use of a confidential process or key |
| password | Confidential authentication information composed of a string of characters |
| cybersecurity | The process of protecting information confidentiality, integrity, and availability by preventing, detecting, and responding to attacks on digital data |
| deepfake | Type of synthetic data intended to imitate real people or entities for criminal purposes |
| Artificial Intelligence (AI) | Machine-based system that can make predictions, recommendations, or decisions |
| breach | An impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI and also that could pose significant risk of financial, reputational, or other harm to the affected person |
| breach notification | The document notifying an individual of a breach |
| HIPAA Electronic Health Care Transactions and Code Sets (TCS) | The HIPAA rule governing the electronic exchange of health information |
| operating rules | Rules that improve interoperability between the data systems of different entities, such as health plans and providers, and so increase their usefulness |
| code set | Alphabetic and/or numeric representations for data. Medical code sets are systems of medical terms that are required for HIPAA transactions |
| HIPAA National Identifier | HIPAA-mandated identification systems for employers, healthcare providers, health plans, and patients; the NPI, National Provider System, and employer system are in place; health plan and patient systems are yet to be created |
| National Provider Identifier (NPI) | Under HIPAA, unique ten-digit identifier assigned to each provider by the National Provider System |
| Omnibus Rule | Set of regulations enhancing patients’ privacy protections and rights to information and the government’s ability to enforce HIPAA |
| Office for Civil Rights (OCR) | Government agency that enforces the HIPAA Privacy Act |
| Office of the Inspector General (OIG) | Government agency that investigates and prosecutes fraud against government healthcare programs such as Medicare |
| False Claims Act | A federal law that prohibits intentional misrepresentation related to healthcare claims |
| relator | Person who makes an accusation of fraud or abuse in a qui tam case |
| audit | Methodical review; in medical insurance, a formal examination of a physician’s accounting or patient medical records |
| fraud | Intentional deceptive act to obtain a benefit |
| abuse | Action that improperly uses another person’s resources |
| compliance plan | A medical practice’s written plan for the following: the appointment of a compliance officer and committee |