#1
Which regulation sets national standards for the protection of individually identifiable health information?
HIPAA
ExplanationHIPAA sets national standards for protecting health information.
#2
What does HIPAA stand for?
Healthcare Information Portability and Accountability Act
ExplanationHIPAA stands for Healthcare Information Portability and Accountability Act.
#3
Which of the following is NOT considered protected health information (PHI) under HIPAA?
Email address
ExplanationEmail addresses are not considered protected health information under HIPAA.
#4
What is the primary purpose of the GDPR in relation to healthcare?
To ensure data subjects have more control over their personal data
ExplanationGDPR aims to empower individuals with more control over their personal data in healthcare.
#5
What is the minimum necessary standard under HIPAA?
Healthcare providers must limit the use, disclosure, and request of protected health information to the minimum necessary to accomplish the intended purpose
ExplanationHIPAA's minimum necessary standard requires healthcare providers to limit the use, disclosure, and request of protected health information to the minimum necessary.
#6
What is the purpose of a business associate agreement (BAA) in the context of HIPAA?
To establish the permitted uses and disclosures of protected health information by the business associate
ExplanationBAAs establish permitted uses and disclosures of protected health information by business associates.
#7
What is the purpose of the Health Information Technology for Economic and Clinical Health (HITECH) Act?
To strengthen privacy and security protections for health information
ExplanationThe HITECH Act aims to bolster privacy and security protections for health information.
#8
Which of the following is NOT considered a covered entity under HIPAA?
Pharmaceutical company
ExplanationPharmaceutical companies are not considered covered entities under HIPAA.
#9
Which entity enforces HIPAA regulations?
Department of Health and Human Services (HHS)
ExplanationHIPAA regulations are enforced by the Department of Health and Human Services (HHS).
#10
Which of the following is NOT a requirement of the HIPAA Security Rule?
Encrypting all electronic protected health information (ePHI)
ExplanationEncrypting all electronic protected health information is not explicitly required by the HIPAA Security Rule.
#11
What is the purpose of the HITECH Act?
To enhance the privacy and security protections of health information
ExplanationThe HITECH Act aims to improve the privacy and security protections of health information.
#12
Under the GDPR, who is primarily responsible for ensuring compliance within an organization?
Data Protection Officer (DPO)
ExplanationData Protection Officers (DPOs) are primarily responsible for ensuring GDPR compliance within organizations.
#13
What is the purpose of the Security Rule under HIPAA?
To ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI)
ExplanationThe Security Rule under HIPAA aims to ensure the confidentiality, integrity, and availability of electronic protected health information.
#14
Which of the following rights do data subjects have under the GDPR?
Right to be forgotten
ExplanationData subjects have the right to request erasure of their personal data under the GDPR, known as the right to be forgotten.