HIPAA

25 July 2022
4.7 (114 reviews)
236 test answers

Unlock all answers in this set

Unlock answers (232)
question
State or local laws can never override HIPAA.
answer
False
question
Protected health information (PHI) requires an association between an individual and a diagnosis.
answer
True
question
Some covered entities are exempted under HIPAA from submitting claims electronically using the standard transaction format.
answer
True
question
The acronym EDI stands for
answer
Electronic data interchange.
question
Which group of providers would be considered covered entities?
answer
a. Rehabilitation center, same-day surgical center, mental health clinic b. Clinical laboratory, durable medical equipment store, rural-based physician c. Home help personnel assisting homebound patients, ambulance service, clinic pharmacy d. All of the above
question
Which law takes precedence when there is a difference in laws?
answer
State law when it is more restrictive
question
A health care clearinghouse functions as
answer
An intermediary to submit claims on behalf of a provider
question
The HIPAA Officer is responsible to train which group of workers in a facility? a. Nursing staff, radiology department staff, laboratory staff, and medical staff b. Housekeeping staff and maintenance staff c. Office workers (medical records and business office/patient accounts staff) d. a and c e. a, b, and c
answer
e. a, b, and c
question
What are the main areas of health care that HIPAA addresses? Select the best answer.
answer
d. Identifiers, electronic transactions, security of e-PHI, and privacy of PHI
question
Medical Savings Account (now Health Savings Account) is a means to shelter funds from taxes to pay for....
answer
medical expenses.
question
Written policies are a responsibility of the HIPAA Officer.
answer
True
question
What type of health information does the Security Rule address?
answer
Electronic PHI held by a covered entity
question
Only clinical staff need to understand HIPAA.
answer
False
question
The HIPAA Privacy Officer is responsible for....
answer
tracking who has access to PHI.
question
Choose the correct acronym for Public Law 104-91.
answer
HIPAA
question
Home help personnel, taxicab companies, and carpenters may fit the definition of a covered entity.
answer
True
question
COBRA (Consolidated Omnibus Budget Reconciliation Act of 1985) helps workers who have coverage with a....
answer
group health plan.
question
How many titles are included in the Public Law 104-91?
answer
7
question
What government agency approves final rules released in the Federal Register?
answer
Department of Health and Human Services
question
Which is not a responsibility of the HIPAA Officer?
answer
Ensuring all wastepaper is shredded
question
An employer who has fewer than 50 employees and is self-insured is a covered entity.
answer
False
question
The HIPAA Security Officer is responsible for
answer
safeguarding all electronic patient health information.
question
Privacy Rule covers disclosure of protected health information (PHI) in any form or media.
answer
True
question
The Department of Health and Human Services (DHHS) is responsible to notify all health care providers of changes in the HIPAA rulings.
answer
False
question
Which group is not one of the three covered entities?
answer
Patients
question
Under HIPAA, providers may choose to submit claims either on paper or electronically.
answer
HIPAA officer
question
Health care professionals have generally found that HIPAA has simplified claims submissions.
answer
True
question
With the passage of HIPAA, large health care providers would be treated with faster service since their volume of claims is larger than small rural providers.
answer
False
question
What year did Public Law 104-91 pass both houses of Congress?
answer
1996
question
List the four key words that summarize the areas of health care that HIPAA has addressed.
answer
Privacy,Transactions, Security, Identifiers
question
Which group is the focus of Title I of HIPAA ruling?
answer
Health plans
question
PHI (protected health information) is
answer
c. health information related to a physical or mental condition.
question
Which is the most efficient means to store PHI?
answer
Electronic storage
question
There is a 24-month grace period after the effective date for the HIPAA rules before a covered entity must comply with the ruling.
answer
True
question
What is a major point of the Title I portion of HIPAA?
answer
Guarantee of renewability
question
Under HIPAA, all covered entities will be treated equally regarding payment for health care services.
answer
True
question
What does HIPAA define as a "covered entity"? a. Health care clearinghouse b. Health plan c. Patient d. Provider e. a, b, and d f. c and d
answer
e. a, b, and d
question
What is the intent of the clarification Congress passed in 1996?
answer
d. To mandate that medical billing have a nationwide standard to transmit electronically using electronic data interchange
question
Since 1996 when HIPAA was written, why are more laws passed relating to HIPAA regulations?
answer
a. New technologies are developed that were not included in the original HIPAA
question
According to HIPAA, written consent is required for treatment of a patient.
answer
False
question
Medical identity theft is a growing concern today for health care providers.
answer
True
question
If a patient does not sign the receipt of a Notice of Privacy Practices (NOPP), the physician can refuse to treat the patient under HIPAA law.
answer
False
question
Which governmental agency wrote the details of the Privacy Rule?
answer
Department of Health and Human Services
question
The HIPAA definition for marketing is when
answer
A patient is encouraged to purchase a product that may not be related to his treatment.
question
The minimum necessary policy encouraged by HIPAA allows disclosure of
answer
Enough PHI to accomplish the purposes for which it will be used.
question
Regarding the listed disclosures of their PHI, individuals may see
answer
All disclosures, authorized or not.
question
If an individual feels that a covered entity has violated the HIPAA Privacy Rule, a complaint is to be filed with the
answer
Office for Civil Rights
question
HIPAA training is
answer
Mandated by law to be reviewed periodically with all employees and staff.
question
Insurance companies who provide automobile and life insurance come under the HIPAA ruling as covered entities.
answer
False
question
If a medical office does not use electronic means to send its insurance claims, it is considered a covered entity.
answer
False
question
The HIPAA Privacy Rule gives patients assurance that their personal health information will be treated the same no matter which state or organization receives their medical information.
answer
True
question
During an investigation by the Office for Civil Rights, the inspector will depend upon the HIPAA Officer to know the details of the written policies of the organization.
answer
True
question
The Regional Offices of the Centers for Medicare and Medicaid Services (CMS) is the only way to contact the government about HIPAA questions and complaints.
answer
False
question
The response, "She was taken to ICU because her diabetes became acute" is an example of HIPAA-compliant disclosure of information.
answer
False
question
Financial records fall outside the scope of HIPAA.
answer
False
question
Nursing notes are not considered PHI since they are not physician's notes and therefore are not protected by HIPAA.
answer
False
question
It is possible for a first name and zip code to be considered individually identifiable health information (IIHI).
answer
False
question
A covered entity does not have to disclose PHI to the Office for Civil Rights if they come to investigate a complaint. That is not allowed by HIPAA law.
answer
False
question
In HIPAA usage, TPO stands for treatment, payment, and optional care.
answer
False
question
A signed receipt of the facility's Notice of Privacy Practices (NOPP) is mandated by the Privacy Rule in order for a patient to receive services from a health care provider.
answer
False
question
Who in the health care organization is responsible to know where the written policies are located regarding HIPAA compliance?
answer
All staff members, paid or not paid
question
What specific government agency receives complaints about the HIPAA Privacy ruling?
answer
Office for Civil Rights
question
The Privacy Rule a. applies only to protected health information (PHI). b. establishes policies for covered entities. c. details when authorization to release PHI is needed. d. none of the above. e. both answers A and C.
answer
both answers A and C.
question
Protected health information is an association between a(n)
answer
diagnosis and an individual.
question
Consent as defined by HIPAA is for..... a. permission to reveal PHI for payment of services provided to a patient. b. permission to reveal PHI for comprehensive treatment of a patient. c. permission to reveal PHI for normal business operations of the provider's facility. d. all of the above. e. both A and B
answer
d. all of the above.
question
Use and disclosure of PHI is permitted without authorization with the EXCEPTION of which of the following?
answer
When releasing process or psychotherapy notes
question
An emancipated minor is
answer
a person younger than 18 who is totally self-supporting and possesses decision-making rights.
question
Research organizations are permitted to receive
answer
a limited data set that has been de-identified for research purposes.
question
Psychotherapy notes or process notes include
answer
the therapist's impressions of the patient.
question
A hospital or other inpatient facility may include patients in their published directory
answer
only when the patient or family has not chosen to "opt-out" of the published directory.
question
Typical Business Associate individuals are
answer
biometric device repairmen, legal counsel to a clinic, and outside coding service.
question
Requesting to amend a medical record was a feature included in HIPAA because of
answer
possible difference in opinion between patient and physician regarding the diagnosis and treatment.
question
During an investigation by the Office for Civil Rights, each provider is expected to have the following EXCEPT
answer
a workforce trained in state law.
question
The Office for Civil Rights receives complaints regarding the Privacy Rule. About what percentage of these complaints have been ruled either no violation or the entity is working toward compliance?
answer
About 75%
question
For individuals requesting to amend their medical record
answer
the provider has the option to reject the amendment.
question
Written policies and procedures relating to the HIPAA Privacy Rule
answer
must be available to all employees.
question
According to AHIMA report, the most common problem that health care providers face in relation to PHI is....
answer
lack of a standardized process to release PHI.
question
The minimum penalty per incidence for violations that the Office for Civil Rights finds for noncompliance to the Privacy Rule is...
answer
$100.
question
When there is an alleged violation to HIPAA Privacy Rule....
answer
there is no option to sue a health care provider for HIPAA violations.
question
Another name for the Title II portion of HIPAA law is....
answer
Administrative Simplification
question
When policies for a facility are in both ------and ------form, the Office for Civil Rights will assume the policies are the most trustworthy.
answer
written/electronic
question
Many pieces of information can connect a patient with his diagnosis. Which pair does not show a connection between patient and diagnosis?
answer
Phone number and provider name
question
Authorization is not needed to disclose protected health information (PHI) in which of the following circumstances?
answer
Patient treatment, payment purposes, and other normal operations of the facility
question
Any Business Associate who finds a breach of protected health information (PHI) must report it to....
answer
The covered entity responsible for the original health information.
question
A HIPAA investigator seeks to find willingness in each organization to comply with what is------- for their particular situation.
answer
reasonable
question
A refusal by a patient to sign a receipt of the NOPP allows the physician to refuse treatment to that patient.
answer
False
question
All covered entities must keep e-PHI secure to ensure data integrity, yet keep it available for access by those who treat patients.
answer
True
question
Compliance with the Security Rule is the sole responsibility of the Security Officer.
answer
False
question
Risk management, as written under Administrative Safeguards, is a continuous process to re-evaluate electronic hardware and software for possible weaknesses in security.
answer
True
question
A workstation login and password should be set to allow access to information needed for the particular location of the workstation, rather than the job description of the user.
answer
False
question
Protecting e-PHI against anticipated threats or hazards
answer
Ensures data is secure, and will survive with complete integrity of e-PHI.
question
Integrity of e-PHI requires confirmation that the data
answer
Is accurate and has not been altered, lost, or destroyed in an unauthorized manner.
question
The HIPAA Security Officer is to see that each job description is evaluated to...
answer
Disclose the "minimum necessary" PHI to perform the particular job function.
question
What are the three areas of safeguards the Security Rule addresses?
answer
Administrative, physical, and technical safeguards
question
If there has been a breach in the security of medical information systems, what are the steps a covered entity must take?
answer
A written report is created and all parties involved must be notified in writing of the event.
question
Security and privacy of protected health information really cover the same issues.
answer
False
question
The Security Rule requires that all paper files of medical records be copied and kept securely locked up.
answer
False
question
Compliance to the Security Rule is solely the responsibility of the Security Officer.
answer
False
question
Requirements that are identified as "addressable" under the Security Rule may be omitted by the Security Officer.
answer
False
question
The Centers for Medicare and Medicaid Services (CMS) have information on their Web site to help a HIPAA Security Officer know the required and addressable areas of securing e-PHI.
answer
True
question
Risk management for the HIPAA Security Officer is a "one-time" task.
answer
False
question
Only a serious security incident is to be documented and measures taken to limit further disclosure.
answer
False
question
If a business visitor is also a Business Associate, that individual does not need to be escorted in the building to ensure protection of PHI.
answer
False
question
"At home" workers such as transcriptionists are not required to follow the workstation security rules for passwords, viewing of monitors by others, or locking of computer screens.
answer
False
question
One good requirement to ensure secure access control is to install automatic logoff at each workstation.
answer
True
question
To protect e-PHI that is sent through the Internet, a covered entity must use encryption technology to minimize the risks. E-PHI that is "at rest" must also be encrypted to maintain security.
answer
False
question
Only monetary fines may be levied for violation under the HIPAA Security Rule.
answer
False
question
The Office of HIPAA Standards seeks voluntary compliance to the Security Rule.
answer
True
question
The Office of HIPAA Standards may not initiate an investigation without receiving a formal complaint.
answer
False
question
Closed circuit cameras are mandated by HIPAA Security Rule.
answer
False
question
Security of e-PHI has to do with keeping the data secure from a breach in the information system's security protocols.
answer
True
question
Access privilege to protected health information is
answer
what allows an individual to enter a computer system for an authorized purpose.
question
Keeping e-PHI secure includes which of the following?
answer
Safeguards are in place to protect e-PHI against unauthorized access or loss.
question
Which are the five areas the DHHS has mandated each covered entity to address so that e-PHI is maintained securely?
answer
Organization requirements; policies, procedures, and documentation; technical safeguards; administrative safeguards; and physical safeguards
question
HIPAA Security Rule applies to data contained in...
answer
any computer storage media.
question
The required areas of the Security Rule
answer
must be achieved and documented.
question
The Administrative Safeguards mandated by HIPAA include which of the following?
answer
Workforce security training
question
Risk analysis in the Security Rule considers
answer
a balance between what is cost-effective and the potential risks of disclosure.
question
Responsibilities of the HIPAA Security Officer include
answer
developing and implementing policies and procedures for the facility.
question
Information access is a required administrative safeguard under HIPAA Security Rule. It is defined as
answer
limiting access to the minimum necessary for the particular job assigned to the particular login.
question
Record of HIPAA training is to be maintained by a health care provider for
answer
6 years.
question
What step is part of reporting of security incidents?
answer
Change passwords to protect from further invasion.
question
The ability to continue after a disaster of some kind is a requirement of Security Rule. What item is considered part of the contingency plan or business continuity plan?
answer
Emergency mode operation plan
question
Business Associate contracts must include
answer
implementation of safeguards to ensure data integrity.
question
Reasonable physical safeguards for patient care areas include....
answer
having monitors turned away from viewing by visitors.
question
The Security Officer is to keep record of.....
answer
all computer hardware and software used within the facility when it comes in and when it goes out of the facility.
question
Which of the following items is a technical safeguard of the Security Rule?
answer
Entity authentication
question
Audit trails of computer systems include
answer
who logged in, what was done, when it was done, and what equipment was accessed.
question
Integrity of e-PHI requires confirmation that the data
answer
is accurate and has not been altered, lost, or destroyed in an unauthorized manner.
question
The act of changing readable text into a vast series of "garbled" characters using complex mathematical algorithms is called...
answer
encryption
question
The Security Officer is responsible to review all...
answer
Business Associate contracts for compliancy issues.
question
Telemedicine videoconference tapes are
answer
covered by HIPAA Security Rule if they are not erased after the physician's report is signed.
question
Use of e-mail for transmitting PHI is...
answer
permitted only if a security algorithm is in place.
question
Complaints about security breaches may be reported to...
answer
Office of E-Health Standards and Services.
question
Investigation of complaints of violations to the Security Rule are under the direction of the...
answer
Office of HIPAA Standards.
question
The policy of disclosing the "minimum necessary" e-PHI addresses....
answer
authorizing personnel to view PHI.
question
HIPAA training must be provided to....
answer
all workforce employees and nonemployees.
question
Whenever a device has become obsolete, the Security Office must....
answer
record when and how it is disposed of and that all data was deleted from the device.
question
The HIPAA Security Officer has many responsibilities. Which of the following is not a job of the Security Officer?
answer
Ensure that authorizations to disclose protected health information (PHI) are compliant with HIPAA rules
question
All health care staff members are responsible to..... a. Protect access to the electronic devices assigned to them. b. See that patients are given the Notice of Privacy Practices for their specific facility. c. Be aware of HIPAA policies and where to find them for reference. d. Report any incident or possible breach of protected health information (PHI). e. All of the above.
answer
e. All of the above.
question
The Security Rule addresses four areas in order to provide sufficient physical safeguards. Which of the following is NOT one of them?
answer
Electronic signatures
question
To ensure minimum opportunity to access data, passwords......
answer
should be changed every ninety days or sooner.
question
The documentation for policies and procedures of the Security Rule must be kept for....
answer
6 years.
question
A health care provider who is compliant with the Privacy and Security Rules of HIPAA has greatly improved protection against medical identity theft.
answer
True
question
All four type of entities written in the original law have been issued unique identifiers.
answer
False
question
The main reason for unique identifiers is so....
answer
Each entity on a standard transaction will be uniquely identified.
question
Which federal government office is responsible to investigate HIPAA privacy complaints?
answer
Office for Civil Rights
question
Protected health information (PHI) includes....
answer
Both medical and financial records of patients.
question
What are the three types of covered entities that must comply with HIPAA?
answer
Health plans, health care providers, and health care clearinghouses
question
Under HIPAA, members of the press can....
answer
Receive the same information as any other person would when asking for a patient by name.
question
The new National Provider Identifier (NPI) has "intelligence" that allows you to find out the provider's specialty.
answer
False
question
Faxing PHI is still permitted under HIPAA law.
answer
True
question
Administrative Simplification focuses on reducing the time it takes to submit health claims. The unique identifiers are part of this simplification.
answer
True
question
The unique identifier for employers is the Social Security Number (SSN) of the business owner.
answer
False
question
The National Provider Identifier (NPI) issued by Centers for Medicare and Medicaid Services (CMS) replaces only those numbers issued by private health plans.
answer
False
question
One reason not to use the SSN for patient identifiers is that there is no check digit for verification of the number.
answer
True
question
Covered entities who violate HIPAA law are only punished with civil, monetary penalties.
answer
False
question
If a covered entity has disclosed some protected health information (PHI) in violation of HIPAA, a patient can sue the covered entity for damages.
answer
False
question
HIPAA seeks to protect individual PHI and discloses that information only when it is in the best interest of the patient.
answer
True
question
When registering a patient for outpatient or inpatient services, the office does not need to enter complete information prior to the encounter. It can be found out later.
answer
False
question
Prescriptions may only be picked up by the patient to protect the privacy of the individual's health information.
answer
False
question
Notice of Privacy Practices (NOPP) must be given to patients every time they visit the facility.
answer
False
question
When a patient refuses to sign a receipt of the NOPP, the facility will ask the patient to leave since they cannot treat the patient without a signature.
answer
False
question
HIPAA allows disclosure of PHI in many new ways.
answer
False
question
When a patient is transferred to another facility, access to the medical records by the receiving facility is no longer permitted under HIPAA.
answer
False
question
All four parties on a health claim now have unique identifiers.
answer
False
question
The law Congress passed in 1996 mandated identifiers for which four categories of entities?
answer
Health care providers, health plans, patients, employers
question
HIPAA requires that using unique identifiers
answer
improve efficiency, effectiveness, and safety of the health care system.
question
Including employers in the standard transaction
answer
is necessary for Workers' Compensation claims and when verifying enrollment in a plan.
question
The adopted standard identifier for employers is the
answer
EIN.
question
Use of the EIN on a standard transaction is required
answer
when the sponsor of health plan is a self-insured employer.
question
Enforcement of the unique identifiers is under the direction of
answer
Office of E-Health Standards and Services.
question
Health plan identifiers defined for HIPAA are....
answer
the HPID (health plan identifier).
question
Two of the reasons for patient identifiers are
answer
enhanced quality of care and coordination of medications to avoid adverse reactions.
question
Congress passed HIPAA to focus on four main areas of our health care system. They are to
answer
keep electronic information secure, keep all information private, allow continuation of health coverage, and standardize the claims process.
question
Administrative Simplification means that all
answer
health claims will be submitted on the same form.
question
Which government department did Congress direct to write the HIPAA rules?
answer
Department of Health and Human Services
question
Questions other people have asked about HIPAA can be found by searching FAQ at...
answer
Department of Health and Human Services Web site.
question
The source documents for original federal documents such as the Federal Register can be found at
answer
Government Printing Office Web site.
question
Fraud and abuse investigation of HIPAA Privacy Rule is under the direction of
answer
Officer for Civil Rights.
question
Which federal government office is responsible to investigate non-privacy complaints about HIPAA law?
answer
Office of E-Health Services and Standards.
question
Funding to pay for oversight and compliance to HIPAA is provided by...
answer
monies received from government to pay for HIPAA services.
question
American Health Information Management Association (AHIMA) has found that the problems of complying with HIPAA Privacy Rule are mainly those that
answer
account for the release of PHI.
question
Medical identity theft is...
answer
obtaining personal medical information for use in submitting false claims or seeking medical care or goods.
question
In keeping with the "minimum necessary" policy, an office may leave....
answer
the date, time, and doctor's name on voicemail.
question
Privacy of PHI includes
answer
both medical and financial records of patients.
question
Standardization of claims allows covered entities to... a. communicate efficiently and quickly, which saves time and money. b. save the cost of new computer systems. c. simplify the billing process since all claims fit the same format. d. all of the above. e. both A and C.
answer
e. both A and C.
question
Filing a complaint with the government about a violation of HIPAA is possible...
answer
if you access the Web site to complete an official form.
question
What are the three covered entities that must comply with HIPAA?
answer
health plan, health care provider, health care clearinghouse
question
HIPAA serves as a national standard of protection.
answer
True
question
Coded identifiers for all parties included in a claims transaction are needed to
answer
Simplify electronic transmission of claims information
question
The Employer Identification Number (EIN) contains...
answer
two digits, a hyphen, then nine other digits without intelligence.
question
When patients "opt-out" of the facility directory, it means...
answer
their name will not be disclosed on a published list of patients being treated at the facility.
question
When visiting a hospital, clergy members are
answer
receive a list of patients who have identified themselves as members of the same particular denomination.
question
The HITECH (Health information Technology for Economic and Clinical Health) mandates all health care providers adopt high standards of technology without any compensation for the cost to individual providers
answer
False
question
One process mandated to health care providers is writing prescriptions via e-prescribing.
answer
True
question
One additional benefit of completely electronic medical records is that more accurate data can be obtained from a greater population, so efficient research can be done to improve our country's health status.
answer
True
question
With the ruling in the Omnibus Rule of 2013, any genetic information is now covered by HIPAA Privacy and Security Rule.
answer
True
question
The purpose of health information exchanges (HIE) is so
answer
Other health care providers can access the medical record of a patient for better coordination of care.
question
Health care providers set up patient portals to
answer
Allow patients secure, encrypted access to their own medical record held by the provider.
question
The long range goal of HIPAA and further refinements of the original law is... a. So all patients can maintain their own personal health record (PHR). b. To develop interoperability so all medical information is electronic. c. To develop health information exchanges (HIE) for providers to view the medical records of other providers for better coordination of care. d. To have the electronic medical record (EMR) used in a meaningful way. e. All of the above
answer
e. All of the above
question
One benefit of personal health records (PHR) is that...
answer
Each patient can add or adjust the information included in the record.
question
How can you easily find the latest information about HIPAA?
answer
From Department of Health and Human Services website
question
The Personal Health Record (PHR) is the legal medical record.
answer
False
question
HIPAA in 1996 enacted security measures that do not need updating and are valid today as written.
answer
False
question
After a patient downloads personal health information, all the Security and Privacy measures of HIPAA are gone.
answer
True
question
Any changes or additions made by patients in their Personal Health record are automatically updated in the Electronic Medical Record (EMR).
answer
False
question
When there is a difference in state law and HIPAA, HIPAA will always supersede the local or state law.
answer
False
question
What information is not to be stored in a Personal Health Record (PHR)?
answer
Tax return information
question
What is the difference between Personal Health Record (PHR) and Electronic Medical Record (EMR)?
answer
PHR can be modified by the patient; EMR is the legal medical record
question
The Meaningful Use mandate is part of
answer
American Recovery and Reinvestment Act (ARRA) of 2009.
question
The Health Information Technology for Economic and Clinical Health (HITECH) is part of...
answer
American Recovery and Reinvestment Act (ARRA) of 2009.
question
Who is responsible to update and maintain Personal Health Records?
answer
Patient
question
Which safeguard is not required for patients to access their Patient Portal...
answer
Provider key
question
What is the name of the format that allows other providers to access another physician's record of a patient?
answer
Health Information Exchange (HIE)
question
Which federal act mandated that physicians use the Health Information Exchange (HIE)?
answer
Affordable Care Act (ACA) of 2010
question
The Medicare Electronic Health Record Incentive Program is part of Affordable Care Act (ACA) and is under the direction of
answer
Centers for Medicare and Medicaid Services (CMS).
question
Physicians were given incentives to use "e-prescribing" under which federal mandate?
answer
b. Health Information Technology for Economic and Clinical Health (HITECH)
question
Meaningful Use program included incentives for physicians to begin using all but which of the following?
answer
Voice mail messages
question
Strengthened restrictions on security redefineed the subcontractors of business associates who might have even incidental exposure to Personal Health Information (PHI) as...
answer
Business associates.
question
The implementation of unique Health Plan Identifiers (HPID) was mandated in which ruling?
answer
Affordable Care Act (ACA) of 2009
question
The Centers for Medicare and Medicaid Services (CMS) set up the ICD-9-CM Coordination and maintenance Committee to
answer
Maintain a crosswalk between ICD-9-CM and ICD-10-CM.
question
Health Information Exchanges (HIE) are designed to allow authorized physicians to exchange health information. Which federal law(s) influenced the implementation and provided incentives for HIE? a. American Recovery and Reinvestment Act (ARRA) of 2009 b. Affordable Care Act (ACA) of 2009 c. Omnibus Rule of 2013 d. All of these
answer
All of these
question
Enforcement of Health Insurance Portability and Accountability Act (HIPAA) is under the direction of....
answer
Office for Civil Rights (OCR)
question
Where is the best place to find the latest changes to HIPAA law?
answer
Department of Health and Human Services (DHHS) Website
question
If any staff member is found to have violated HIPAA rules, what is a possible result?
answer
The incident retained in personnel file and immediate termination
question
Which organization directs the Medicare Electronic Health Record Incentive Program?
answer
CMS
question
Electronic messaging is one important means for patients to confer with their physicians. What platform is used for this?
answer
patient portal
question
A result of this federal mandate brought increased transparency and better efficiency, and empowered patients to utilize the electronic health record of their physician to view their own medical records. This mandate is called
answer
meaningful use
question
Genetic Information is now protected as all other Personal Health Information (PHI) with the passing of which federal law?
answer
Omnibus Rule of 2013
question
Which federal office has the responsibility to enforce updated HIPAA mandates?
answer
OCR
question
Reliable accuracy of a personal health record is limited
answer
Since the electronic medical record (EMR) is the legal medical record kept by each provider who generated the record.
question
To comply with HIPAA, it is vital to... a. Maintain integrity and security of protected health information (PHI). b. Ensure that protected health information (PHI) is kept private. c. Use proper codes to secure payment of medical claims.
answer
All of the above
question
Genetic information is
answer
Unique information about you and the characteristics found in your DNA.
question
Patients are given access to their physician's EMR to view their own records through a (an)...
answer
Patient portal.
question
The purpose of Health Information Exchange (HIE) is to facilitate secure encrypted transport of health information between...
answer
Authorized providers treating the same patient.