Hipaa Compliance Questions And Answers
15 community-sourced questions and answers. Free — no login.
HIPAA
Health Insurance Portability and Accountability Act
Healthcare provider
any person or organization who furnishes, bills, or is paid for healthcare in the normal course of business
PHI (Protected Health Information)
individually identifiable health information (demographics like name or SSN, or medial records) -- do not disclose information someone could use to reverse engineer individual
Minimum Necessary Principle
make reasonable efforts to limit the use or disclosure of PHI to a minimum amount necessary to accomplish intended goal
When should you be aware of patient privacy?
1. ensuring computer security 2. communication on the phone 3. sending/receiving faxes and emails 4. printing information 5. Using PHI at desk 6. Dispose of information (only shred)
Who to report to when HIPAA breach
1. speak to supervisor 2. speak with EPPA's privacy official (Chad Strathman) 3. you know you've made a mistake - self report
Enforcement
1. office for civil right enforces privacy rule 2. civl money penalties - $100 to $50,000 per violation 3. criminal penalties - up to $250,000 and 10 years in jail
Compliance Plan
a way of self-policing and reporting any impropriety within a business entity
Fraud
the intentional deception or misrepresentation that an individual knows to be false or does not believe to be true and makes knowing that deception could result in some unauthorized benefit
Waste
Acting with gross negligence or reckless disregard for the truth in a manner that results in any unnecessary cost or any unnecessary consumption of a healthcare resource
Abuse
those incidents that are inconsistent with accepted medial or business practices, improper or excessive
Fraud and Abuse Examples
billing for services that were never performed or provided upcoding - billing for a higher-level treatment than was actually provided unbundling - billing separately for services that are already included in primary procedure billing for services that are not medically necessary false ID - use of medical benefits by an unauthorized individual
Employee Responsiblity
1. report fraud and abuse 2. provide documentation 3. attend education sessions
Harassment and Inappropriate Conduct
verbal, visual, or physical conduct that relates to another person's sex, race, color, nationality, creed, religion, or other status protected by law examples can arise in personal contact, comments, visual displays, exposure to email, social media, other media
Sexual Harassment
may include suggestive sexual comments, jokes or innuendo, persistent, unwanted flirtation or invitations for dates or social activities. Unwanted remarks or questions about a person's body clothing or sexual activities,
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials