#1
Which regulation establishes the standards for the privacy of individually identifiable health information?
HIPAA
ExplanationHIPAA sets standards for protecting health information.
#2
What does PHI stand for in the context of healthcare privacy?
Protected Health Information
ExplanationPHI refers to individually identifiable health information.
#3
Which of the following is an example of a security measure to protect healthcare information?
Regularly updating antivirus software
ExplanationRegularly updating antivirus software is a security measure.
#4
Which of the following is NOT considered a covered entity under HIPAA?
Pharmaceutical company
ExplanationPharmaceutical companies are not covered entities under HIPAA.
#5
Which of the following entities is NOT considered a business associate under HIPAA?
Pharmaceutical manufacturers
ExplanationPharmaceutical manufacturers are not HIPAA business associates.
#6
Who is primarily responsible for ensuring compliance with healthcare confidentiality regulations within a healthcare organization?
Healthcare providers and staff
ExplanationHealthcare providers and staff ensure compliance with confidentiality regulations.
#7
Under HIPAA, what is considered a covered entity?
Healthcare providers, health plans, and healthcare clearinghouses
ExplanationCovered entities under HIPAA include providers, plans, and clearinghouses.
#8
Which of the following is NOT considered a breach of healthcare confidentiality?
Intentional sharing of patient information for treatment purposes
ExplanationSharing patient info for treatment purposes isn't a breach.
#9
What is the role of the Office for Civil Rights (OCR) in enforcing healthcare privacy regulations?
Investigating complaints and enforcing HIPAA rules
ExplanationOCR investigates complaints and enforces HIPAA.
#10
What action should be taken in the event of a healthcare data breach?
Notify affected individuals, the Secretary of Health and Human Services, and, in some cases, the media
ExplanationNotify affected parties, HHS Secretary, and sometimes media in data breaches.
#11
What is the purpose of the Health Information Technology for Economic and Clinical Health (HITECH) Act?
To promote the adoption and meaningful use of health information technology
ExplanationHITECH Act promotes the adoption of health information technology.
#12
What is the purpose of a Business Associate Agreement (BAA) in healthcare?
To outline responsibilities and obligations regarding protected health information
ExplanationBAA outlines responsibilities regarding protected health info.
#13
What is the purpose of a Notice of Privacy Practices (NPP) in healthcare?
To inform patients about their rights regarding their protected health information
ExplanationNPP informs patients about their rights regarding health info.
#14
Which federal agency is responsible for enforcing the privacy and security provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act?
Office for Civil Rights (OCR)
ExplanationOCR enforces privacy and security provisions of HITECH Act.
#15
What is the purpose of a Data Use Agreement (DUA) in healthcare?
To outline the terms for the exchange of protected health information
ExplanationDUA outlines terms for exchanging protected health info.