SlideShare a Scribd company logo
Chapter 2: The HIPAA Privacy Rule1
True or False2
 1. Release of PHI for treatment, payment, or health care operations purposes is permitted under HIPAA law.3
2. The basic HIPAA privacy standard states that covered entities must have the authorization of patients to release their PHI for other than treatment purposes.4
3. Incidental use and disclosure of PHI is not prohibited under HIPAA.5
4. Under the HIPAA privacy standards, covered entities must have privacy policies and procedures in place.6
5. Protected health information includes any data that identify individuals.7
6. Health care providers who have a physical service site, like an office, must make their Notice of Privacy Practices (NPP) available at that site.8
7. If a patient does not sign an Acknowledgment of Receipt of NPP, the provider cannot treat the individual.9
8. Minors are not allowed to sign Acknowledgments of Receipt of NPP’s.10
9. With reasonable confidence that a patient has identified another person as being involved with his or her care, a covered entity can release the patient’s PHI to that person.11
10. Providers cannot send patients’ protected health information to health plans without a signed authorization.12
Multiple Guess13
11. What is included in protected health information under HIPAA?The patient’s addressThe patient’s allergiesThe patient’s medical record numberAll of the above14
12. What is protected under HIPAA privacy standards?Patient data that are printed and mailedPatient information sent by e-mailPatient information communicated over the phoneAll of the above15
13. Patients always have the right toa. Withdraw their authorization to release informationb. Alter the information of their medical recordsc. Block release of information about their communicable diseases to the state health departmentd. None of the above16
14. The Notice of Privacy Practice (NPP) is given toa. Patientsb. Business Associatesc. Other covered entitiesd. None of the above17
MATCHING18
15. Accounting of DisclosuresA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.19
16. AuthorizationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.20
17. De-Identified Health InformationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.21
18. Incidental use and disclosureA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.22
19. Minimum Necessary StandardA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.23
20. Protected Health Information (PHI)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.24
21. Release of Information (ROI)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.25
22. Treatment, Payment, and Healthcare Operations (TPO)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.26
23. AmendmentA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.27
24. DocumentationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose.                                                J. Individually identifiable health information that is transmitted or maintained electronically.28
HIPAA Compliant Act—Yes or NO?29
25.A laboratory communicates a patient’s medical test results to a physician by the phone.  The physician is treating the patient whose results that are being reported.30
26.A physician mails a copy of a patient’s medical record to a specialist who intends to treat the patient.31
27.A hospital faxes a patient’s health care instructions to a nursing home to which the patient is to be transferred.32
28.A doctor discusses a patient’s condition over the phone with an emergency room physician who is providing the patient with emergency care.33
29.A doctor orally discusses a patient’s treatment regimen with a nurse who will be involved in the patient’s care.34
30.A physician consults with another physician about a patient’s care by e-mail.35
31. A hospital faxes an organ donor’s medical information to another hospital that is treating the organ recipient. 36
32.A medical insurance specialist answers questions over the phone from a health plan about the dates of service on a submitted claim.37
33.A nineteen year-old has registered for a physician visit using an insurance card listing him as a qualified dependent on a parents’ health plan.  Later, the parents call the practice to find out why their child saw the physician.  The age of majority in the state is eighteen.  Is releasing any information beyond verifying the patient’s visit a HIPAA-compliant action?38
HURRAY!(The End.)39

More Related Content

DOCX
Rights of the unborn child
PPT
PPTX
POLST Skills Development - Sharmon Figenshaw and Bruce Smith
PDF
Healthcare Information Privacy & Confidentiality: How To Work Very Well With ...
PPT
HIPAA 2010
PPTX
2018-HIPAA-Renewal-Training.pptx
PPTX
2018-HIPAA-Renewal-Training for executives
PPTX
Confidentiality and hipaa
Rights of the unborn child
POLST Skills Development - Sharmon Figenshaw and Bruce Smith
Healthcare Information Privacy & Confidentiality: How To Work Very Well With ...
HIPAA 2010
2018-HIPAA-Renewal-Training.pptx
2018-HIPAA-Renewal-Training for executives
Confidentiality and hipaa

Similar to Chapter 2 class exam exercise (20)

PDF
Hipaa training new_staff_december 2018 - compatibility mode
PPT
Introduction HIPAA-For Health Care Professionals
PPTX
HIPAA, PHI, & 42 CFR Part 2
PPTX
HIPAA Access Medical Records by Sainsbury-Wong
PPTX
Privacy & confedentiality
PPT
HIPAA Audio Presentation
PPTX
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
PPTX
HIPAA & PHI Training
PPTX
Hipaa presentation
PPTX
HIPPA-Health Insurance Portability and Accountability Act
PPTX
Week 1 discussion 2
DOCX
Medical Administrative Assistance
PPT
Hipaa.ppt6
PPT
Hipaa.ppt3
PPT
Hipaa.ppt5
PPT
Hipaa.ppt4
PPT
Hipaa.ppt2
PPT
Hipaa.ppt1
PPTX
Hi103 week 4 chpt 10
Hipaa training new_staff_december 2018 - compatibility mode
Introduction HIPAA-For Health Care Professionals
HIPAA, PHI, & 42 CFR Part 2
HIPAA Access Medical Records by Sainsbury-Wong
Privacy & confedentiality
HIPAA Audio Presentation
HIPPA COMPLIANCE (SANJEEV.S.BHARWAN)
HIPAA & PHI Training
Hipaa presentation
HIPPA-Health Insurance Portability and Accountability Act
Week 1 discussion 2
Medical Administrative Assistance
Hipaa.ppt6
Hipaa.ppt3
Hipaa.ppt5
Hipaa.ppt4
Hipaa.ppt2
Hipaa.ppt1
Hi103 week 4 chpt 10
Ad

More from York County School of Technology (6)

PPTX
Addiction powerpoint q ^l0 a format
PPTX
Substance abuse during pregnancy
DOCX
Tort powerpoint from slideshare
PPTX
Chapter 1 the goal of hipaa administrative simplification
PPTX
PPTX
Hipaa final enforcement rule
Addiction powerpoint q ^l0 a format
Substance abuse during pregnancy
Tort powerpoint from slideshare
Chapter 1 the goal of hipaa administrative simplification
Hipaa final enforcement rule
Ad

Recently uploaded (20)

PPTX
Introduction to Building Materials
PDF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PDF
Indian roads congress 037 - 2012 Flexible pavement
PDF
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
PDF
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf
PPTX
A powerpoint presentation on the Revised K-10 Science Shaping Paper
PDF
My India Quiz Book_20210205121199924.pdf
PPTX
Virtual and Augmented Reality in Current Scenario
PPTX
Computer Architecture Input Output Memory.pptx
PDF
Computing-Curriculum for Schools in Ghana
PDF
Hazard Identification & Risk Assessment .pdf
PDF
advance database management system book.pdf
PDF
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
PDF
Paper A Mock Exam 9_ Attempt review.pdf.
PDF
What if we spent less time fighting change, and more time building what’s rig...
PPTX
Unit 4 Computer Architecture Multicore Processor.pptx
PPTX
20th Century Theater, Methods, History.pptx
PDF
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
DOC
Soft-furnishing-By-Architect-A.F.M.Mohiuddin-Akhand.doc
PDF
IGGE1 Understanding the Self1234567891011
Introduction to Building Materials
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
Indian roads congress 037 - 2012 Flexible pavement
ChatGPT for Dummies - Pam Baker Ccesa007.pdf
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf
A powerpoint presentation on the Revised K-10 Science Shaping Paper
My India Quiz Book_20210205121199924.pdf
Virtual and Augmented Reality in Current Scenario
Computer Architecture Input Output Memory.pptx
Computing-Curriculum for Schools in Ghana
Hazard Identification & Risk Assessment .pdf
advance database management system book.pdf
Τίμαιος είναι φιλοσοφικός διάλογος του Πλάτωνα
Paper A Mock Exam 9_ Attempt review.pdf.
What if we spent less time fighting change, and more time building what’s rig...
Unit 4 Computer Architecture Multicore Processor.pptx
20th Century Theater, Methods, History.pptx
FOISHS ANNUAL IMPLEMENTATION PLAN 2025.pdf
Soft-furnishing-By-Architect-A.F.M.Mohiuddin-Akhand.doc
IGGE1 Understanding the Self1234567891011

Chapter 2 class exam exercise

  • 1. Chapter 2: The HIPAA Privacy Rule1
  • 3. 1. Release of PHI for treatment, payment, or health care operations purposes is permitted under HIPAA law.3
  • 4. 2. The basic HIPAA privacy standard states that covered entities must have the authorization of patients to release their PHI for other than treatment purposes.4
  • 5. 3. Incidental use and disclosure of PHI is not prohibited under HIPAA.5
  • 6. 4. Under the HIPAA privacy standards, covered entities must have privacy policies and procedures in place.6
  • 7. 5. Protected health information includes any data that identify individuals.7
  • 8. 6. Health care providers who have a physical service site, like an office, must make their Notice of Privacy Practices (NPP) available at that site.8
  • 9. 7. If a patient does not sign an Acknowledgment of Receipt of NPP, the provider cannot treat the individual.9
  • 10. 8. Minors are not allowed to sign Acknowledgments of Receipt of NPP’s.10
  • 11. 9. With reasonable confidence that a patient has identified another person as being involved with his or her care, a covered entity can release the patient’s PHI to that person.11
  • 12. 10. Providers cannot send patients’ protected health information to health plans without a signed authorization.12
  • 14. 11. What is included in protected health information under HIPAA?The patient’s addressThe patient’s allergiesThe patient’s medical record numberAll of the above14
  • 15. 12. What is protected under HIPAA privacy standards?Patient data that are printed and mailedPatient information sent by e-mailPatient information communicated over the phoneAll of the above15
  • 16. 13. Patients always have the right toa. Withdraw their authorization to release informationb. Alter the information of their medical recordsc. Block release of information about their communicable diseases to the state health departmentd. None of the above16
  • 17. 14. The Notice of Privacy Practice (NPP) is given toa. Patientsb. Business Associatesc. Other covered entitiesd. None of the above17
  • 19. 15. Accounting of DisclosuresA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.19
  • 20. 16. AuthorizationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.20
  • 21. 17. De-Identified Health InformationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.21
  • 22. 18. Incidental use and disclosureA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.22
  • 23. 19. Minimum Necessary StandardA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.23
  • 24. 20. Protected Health Information (PHI)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.24
  • 25. 21. Release of Information (ROI)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.25
  • 26. 22. Treatment, Payment, and Healthcare Operations (TPO)A. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.26
  • 27. 23. AmendmentA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.27
  • 28. 24. DocumentationA. A patient’s written approval to release PHIB. Health information from which all identifying data have been removed.C. Accidental use or disclosure that occurs during a correct use or disclosure.D. Sharing a patient’s protected health information with another entity.E. Under HIPAA, the three purposes for which PHI may be released without authorization.F. A list of ROI of their PHI that patients can ask to review.G. A chronological record of a patient’s health care.H. A patient’s requested alteration of an item in the medical record.I. Under HIPAA, the principle of releasing only PHI that is pertinent for the purpose. J. Individually identifiable health information that is transmitted or maintained electronically.28
  • 30. 25.A laboratory communicates a patient’s medical test results to a physician by the phone. The physician is treating the patient whose results that are being reported.30
  • 31. 26.A physician mails a copy of a patient’s medical record to a specialist who intends to treat the patient.31
  • 32. 27.A hospital faxes a patient’s health care instructions to a nursing home to which the patient is to be transferred.32
  • 33. 28.A doctor discusses a patient’s condition over the phone with an emergency room physician who is providing the patient with emergency care.33
  • 34. 29.A doctor orally discusses a patient’s treatment regimen with a nurse who will be involved in the patient’s care.34
  • 35. 30.A physician consults with another physician about a patient’s care by e-mail.35
  • 36. 31. A hospital faxes an organ donor’s medical information to another hospital that is treating the organ recipient. 36
  • 37. 32.A medical insurance specialist answers questions over the phone from a health plan about the dates of service on a submitted claim.37
  • 38. 33.A nineteen year-old has registered for a physician visit using an insurance card listing him as a qualified dependent on a parents’ health plan. Later, the parents call the practice to find out why their child saw the physician. The age of majority in the state is eighteen. Is releasing any information beyond verifying the patient’s visit a HIPAA-compliant action?38