Critique This Statement According To Hipaa Workforce Members Include Students
19 community-sourced questions and answers. Free — no login.
Which of the following should be included in a covered entity's notice of privacy practices?
Description with one example of disclosures made for treatment purposes -HIPAA mandates what must be included in the notice of privacy practices. This includes one example of disclosures for treatment purposes.
Which of the following is true of the Health Insurance Portability and Accountability Act (HIPAA)?
Provides a federal floor for healthcare privacy-HIPAA is a federal floor for privacy.
Which of the following is true of the notice of privacy practices?
It must be posted in a prominent place-HIPAA gives specific requirements for the notice of privacy practices that includes the requirement for the notice to be posted in a prominent place.
How many days does a covered entity have to respond to an individual's request for access to his or her PHI when the PHI is stored off-site?
60 days-The covered entity has 60 days to respond to a patient's request for access to their health record.
An individual has a number of rights and prohibitions including
Under HIPAA, an individual may revoke an authorization at any time if it is in writing; however, revocation does not apply to disclosures that have already been made.
Which of the following statements about a facility directory of patients is true?
Disclosures from the directory need not be included in an accounting of disclosures.-The facility directory is an exception to the accounting of disclosures requirement.
The breach notification requirement applies to
Breach notification requirement applies only to unsecured PHI.
A subpoena should be accompanied by which of the following?
Patient authorization-In most cases, the subpoena should be accompanied by patient authorization.
Who of the following would be considered a member of a hospital's workforce?
The workforce consists of employees, but also employees of outsourced vendors who routinely work on-site.
The American Recovery and Reinvestment Act expanded the definition of business associates to include which of the following?
According to the American Recovery and Reinvestment Act, patient safety organizations are considered to be a covered entity.
Under usual circumstances, a covered entity must act on a patient's request to review or copy his or her health information within what time frame?
30 days-The covered entity has 30 days in which to allow the patient to review or copy PHI.
Which of the following statements about a business associate agreement is true?
There are specific requirements for the business associate agreement including the requirement to provide records to HHS.
In which of the following instances must patient authorization be obtained prior to disclosure?
To submit PHI to the patient's attorney, a signed authorization is required.
When would PHI lose its status?
After an individual has been deceased more than 50 years
Which of the following describes consents?
They are not required to permit use and disclosure of PHI for treatment, payment, and operations.-Under HIPAA, use and disclosure of PHI for treatment, payment, and operations does not require a consent.
Critique this statement: According to HIPAA, workforce members include students.
According to HIPAA, the workforce includes employees, volunteers, and students.
Which of the following statements is true?
HIPAA mandates that the content of a valid authorization must include an expiration date or event.
In which of the following situations can PHI be disclosed without authorization, as long as there was an opportunity for the individual to agree or object?
Facility directory disclosures is the correct answer because it requires the opportunity for an individual to agree or object.
Which of the following is true about a facility's patient directory?
The covered entity must notify the patient of the information to be shared via the facility's patient directory.
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials