Under Hipaa An Individual Has The Right To Request
41 community-sourced questions and answers. Free — no login.
Under HIPAA, the CE is obligated to provide a __________ for issues related to the protection of Health information.
contact person
Under HIPAA, the individual has the right to request to _______ his her health record.
amend
Under HIPAA, the CE is obligated to _________ policies and procedures regarding access to medical records.
implement
Under HIPAA, the individual has the right to ________ a copy of his or her health record.
inspect
Under HIPAA, the CE is obligated to ________ by the terms of the privacy notice.
abide
Under HIPAA, and individual has the right to request communication by a way of _________ means.
alternative
Under HIPAA, the CE is obligated to take ________ steps to safeguard patient information.
reasonable
Under HIPAA, the CE is obligated to _______ patients with a Notice of Privacy Practices. NPP
provide
Under HIPAA, an individual has the right to ________ a paper copy of the Notice of Privacy Practices. NPP
obtain
Under HIPAA, the individual has the right to ________ specific uses and disclosures of PHI.
restrict
_________ authorizes the CE to disclose PHI to carry out TPO.
Consent
_________ is required before any PHI can be used for any purpose other than TPO.
Authorization
__________ is the "reasonable standard" to "use" or "disclose" PHI.
"Minimum Necessary"
Civil penalties of $____ to $_______.
$100 to $25,000
Criminal penalties of as much as _________ in fines and ____ year in prison for CEs that knowingly obtain or disclose identifiable health information
$50,000 and 1 year
Criminal penalties of as much as _________ in fines and ____ years in prison if an offense is committed under false pretenses
$100,000 and 5 years
Criminal penalties of as much as _________ in fines and ____ years in prison if an offense is committed with the intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm
$250,000 and 10 years
HITECH penalties for each violation of HIPAA can now exceed civil penalties for violating the __________ statue.
anti-kickback
HITECH mandates much more enforcement by HHS, including compliance audits, and allows enforcement by _____________.
State Attorney General, SAG
Under the Breech notification rules ce are required to submit _______ logs of protected health information (PHI) breached to the ___________.
annual, Secretary of HHS
HITECH - Congress provided that unless a violation is caused by willful neglect, penalties for the violation can be avoided by taking _________ within ___ days.
corrective action, 30
HIPAA AND ______ provides training for new employees and _________ to existing employees to ensure compliance.
HITECH, annually
Federal official who presides over a trial type of hearing and makes decisions to resolve a dispute
Administrative Law Judge
A change or action implemented to eliminate the cause of a detected nonconformity
Corrective Action
Legal agreement between two parties that lays out the method and timetable for solving conflict between them
Resolution agreement
Time elapsed since the date of occurrence in which it is permissible to report a violation of the Privacy Rule
180 days
A CE's self -imposed actions to prevent or resolve violations of the Privacy Rule
Voluntary Compliance
Monies collected from the CE's in the form of fines assessed for Privacy Rule violations.
Civil Monetary Penalty
The entity required to investigate compliance with the Privacy Rule.
Office of Civil Rights
The OCR's audit or examination of a CE's policies and procedures carried out to determine whether the CE is adhering to the Privacy Rule
Compliance Review
An action of revenge prohibited by the Privacy Rule against any individual filing a complaint.
Retaliate
No, the CE has an obligation to mitigate harmful effects of the violation
If a workforce member wrongfully discloses PHI, is the CE obligated to notify the subject?
Yes
As part of a Corrective Action Plan, may the OCR order a CE to engage a third party to oversee and assess compliance efforts over a specified period?
No
A CE has policies and procedures outlining how to provide safeguards to protect PHI, is this adequate?
CE's 3 requirements:
A CE must have 1)policies and procedures to protect PHI, 2)training for workforce members, 3)periodically assess organizations compliance with those procedures
The time a CE has to respond to requests to PHI IF the PHI is maintained OFF SITE.
60 days
The time a CE has to respond to request to PHI IF the PHI is maintained ON SITE.
30 days
HITECH
Health Information Technology for Economic and Clinical Health ACT
HITECH act 2 most important changes to:
Business Associates and Breach Notification
HIPAA title one
Insurance Portability- keeping coverage.
HIPAA title two
Administrative Simplification issues, protection of privacy
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials