Which law governs patient privacy rights in the United States?
Health Insurance Portability and Accountability Act (HIPAA)
Americans with Disabilities Act (ADA)
Food and Drug Administration Modernization Act (FDAMA)
Patient Protection and Affordable Care Act (ACA)
#2
What does HIPAA stand for?
Healthcare Information Privacy and Protection Act
Healthcare Insurance Privacy and Accountability Act
Health Insurance Portability and Accountability Act
Health Information Privacy and Protection Act
#3
Which entity enforces penalties for HIPAA violations?
Centers for Disease Control and Prevention (CDC)
Food and Drug Administration (FDA)
Office for Civil Rights (OCR)
National Institutes of Health (NIH)
#4
What is the purpose of the Privacy Rule under HIPAA?
To regulate the confidentiality of medical records and personal health information
To mandate universal access to all patient health information
To encourage the sale of patient health information to third-party companies
To require patients to share their health information on social media platforms
#5
Which of the following is NOT a requirement of the Notice of Privacy Practices (NPP) under HIPAA?
Informing patients of their rights regarding their protected health information (PHI)
Detailing how patient information will be used and disclosed
Providing patients with a list of all healthcare providers in the country
Explaining how patients can file complaints about privacy violations
#6
Which of the following is NOT considered protected health information (PHI) under HIPAA?
Name
Email address
Medical record number
Social Security number
#7
What is the purpose of a Notice of Privacy Practices (NPP)?
To inform patients about their rights regarding their protected health information
To schedule appointments for patients
To administer medications to patients
To bill insurance companies for medical services
#8
What rights do patients have regarding their protected health information (PHI) under HIPAA?
Right to request access to their PHI
Right to sell their PHI to third parties
Right to demand deletion of their PHI
Right to disclose PHI to anyone without restrictions
#9
Who is responsible for ensuring compliance with HIPAA regulations within a healthcare organization?
Patients
Healthcare providers
Health insurance companies
HIPAA privacy officers
#10
Which of the following entities is NOT considered a covered entity under HIPAA?
Hospitals
Healthcare clearinghouses
Health insurance companies
Social media platforms
#11
Under HIPAA, healthcare providers must obtain patient consent for which of the following actions?
Sharing protected health information (PHI) for treatment purposes
Disclosing PHI for billing and administrative purposes
Releasing PHI to law enforcement without a warrant
Using PHI for internal research studies
#12
Which of the following statements about HIPAA's minimum necessary standard is TRUE?
It requires covered entities to disclose all available patient information to third parties.
It mandates that healthcare providers access and use the maximum amount of patient information possible.
It limits the use and disclosure of PHI to the minimum necessary to accomplish the intended purpose.
It only applies to large healthcare organizations with more than 500 employees.
#13
What actions can patients take if they believe their privacy rights under HIPAA have been violated?
File a lawsuit against the healthcare provider
Report the violation to the U.S. Department of Health and Human Services (HHS)
Seek compensation for damages caused by the violation
All of the above
#14
Which of the following is an example of a HIPAA violation?
Sharing a patient's medical information with their consent
Encrypting electronic health records (EHRs) to protect patient privacy
Posting a patient's medical condition on social media without authorization
Providing access to patient records only to authorized personnel
#15
What is the primary purpose of the Breach Notification Rule under HIPAA?
To require covered entities to notify affected individuals and the U.S. Department of Health and Human Services (HHS) of breaches of unsecured protected health information (PHI)
To encourage healthcare providers to withhold information about data breaches
To penalize individuals for reporting breaches of patient information
To mandate the sale of breached patient information to interested parties