dha family
DHA HIPAA and Privacy Act training answers: PHI use and disclosure, the HIPAA Privacy/Security/Breach rules, and Privacy Act requirements for MHS personnel.
Studying for this with your unit? Send it to them.
01Which of the following statements about the HIPAA Security Rule are true?
All of the above β the Security Rule (1) covers only protected health information that is stored or transmitted electronically (ePHI), not oral or paper-only PHI; (2) requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit, to protect against reasonably anticipated threats and against impermissible uses or disclosures, and to ensure workforce compliance; and (3) requires reasonable and appropriate administrative, physical, and technical safeguards, applied flexibly according to the entity's size, complexity, capabilities, technical infrastructure, costs, and risk.
VERIFIED AGAINST THE SOURCE
β(1) Covered entities and business associates may use any security measures that allow the covered entity or business associate to reasonably and appropriately implement the standards and implementation specifications as specified in this subpart. (2) In deciding which security measures to use, a covered entity or business associate must take into account the following factors: (i) The size, complexity, and capabilities of the covered entity or business associate. (ii) The covered entity's or the business associate's technical infrastructure, hardware, and software security capabilities. (iii) The costs of security measures. (iv) The probability and criticality of potential risks to electronic protected health information.β
β 45 CFR 164.306, Security standards: General rules (2023 CFR, Title 45, Vol. 2), paragraph (b), Flexibility of approach β02A covered entity (CE) must have an established complaint process.
True. A covered entity β including a DoD covered entity such as a military treatment facility β must provide a process for individuals to make complaints about its privacy policies and procedures or its compliance with them, and must document all complaints received and their disposition.
VERIFIED AGAINST THE SOURCE
β(1) Standard: Complaints to the DoD Covered Entity. A DoD covered entity, including an MTF, must provide a process for individuals to make complaints concerning the DoD covered entityβs policies and procedures required by this issuance or its compliance with such policies and procedures or the requirements of this issuance.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 7.2.a.(1) β03The e-Government Act promotes the use of electronic government services by the public and improves the use of information technology in the government.
True. The E-Government Act of 2002 (Public Law 107-347) was enacted to enhance the management and promotion of electronic Government services and processes and to establish a framework of measures requiring the use of Internet-based information technology to improve citizen access to Government information and services. Its Section 208 is what requires agencies to conduct Privacy Impact Assessments.
VERIFIED AGAINST THE SOURCE
β(2) To promote use of the Internet and other information technologies to provide increased opportunities for citizen participation in Government.β
β E-Government Act of 2002, Public Law 107-347, 116 Stat. 2899, Section 2(b)(2), Purposes β04When must a breach be reported to the U.S. Computer Emergency Readiness Team?
Within 1 hour. DoDM 6025.18 requires all confirmed cyber-related breaches involving PII and PHI to be reported to the United States Computer Emergency Readiness Team (US-CERT) within 1 hour of being confirmed. Separately, every discovered breach of PHI must be reported to the DHA Privacy Office within 24 hours of discovery.
VERIFIED AGAINST THE SOURCE
β(1) For all discovered breaches of PHI, the DoD covered entity or business associate must report discovery of the breach to the DHA Privacy Office within 24 hours of discovery of such breach, in addition to breach response and reporting requirements in applicable Office of Management and Budget guidance, DoD Privacy Program issuances, and as prescribed by the Directorate of Oversight and Compliance, including the Defense Privacy, Civil Liberties, and Transparency Division.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 6.2.b.(1) β05Which of the following statements about the Privacy Act are true?
All of the above β the Privacy Act of 1974 (1) bars an agency from disclosing a record contained in a system of records without the prior written consent of the individual the record is about, unless a listed exception applies; (2) gives individuals the right to gain access to their records and to request amendment of them; and (3) requires an agency to publish a system of records notice in the Federal Register upon establishment or revision of a system of records.
VERIFIED AGAINST THE SOURCE
β(4) subject to the provisions of paragraph (11) of this subsection, publish in the Federal Register upon establishment or revision a notice of the existence and character of the system of records, which notice shall include- (A) the name and location of the system; (B) the categories of individuals on whom records are maintained in the system; (C) the categories of records maintained in the system; (D) each routine use of the records contained in the system, including the categories of users and the purpose of such use;β
β Privacy Act of 1974, 5 U.S.C. 552a, subsection (e)(4) β06What of the following are categories for punishing violations of federal health care laws?
All of the above β violations are punished through (1) civil money penalties; (2) criminal penalties (fines and imprisonment) for wrongful disclosure of individually identifiable health information; and (3) administrative sanctions that the covered entity itself must apply to workforce members who fail to comply β for Service members this may include action under the UCMJ.
VERIFIED AGAINST THE SOURCE
β(a) A DoD covered entity must have and apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures of the DoD covered entity or the requirements of this issuance. The sanctions must reasonably relate to the severity and nature of the failure or misconduct. 1. For Service members, this may include action under the UCMJ, administrative, or other appropriate sanctions.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 7.2.c.(1)(a), Standard: Sanctions β07Which of the following are common causes of breaches?
All of the above β breaches most often happen when PII or PHI is mishandled. The DHA Privacy and Civil Liberties Office lists misdirected faxes, failing to properly secure documents when mailing or transporting them, lost or stolen removable media devices (laptops, thumb drives, compact discs), transmission of unsecured e-mails and unencrypted files, unauthorized access to computer systems, inappropriate disposal of documents, and inadvertent posting on the internet.
VERIFIED AGAINST THE SOURCE
βBreaches often occur when PII or PHI is mishandled. Examples of these types of breaches may include, but are not limited to: β’ Misdirected fax documents that reach anyone other than the intended recipient β’ Failing to properly secure documents when mailing or transporting β’ Lost or stolen removable media devices (e.g., laptops, thumb drives, compact discs) β’ Transmission of unsecured e-mails and unencrypted files β’ Unauthorized access to computer systems β’ Inappropriate disposal of documents β’ Inadvertent posting on the internetβ
β DHA Privacy and Civil Liberties Office, "Guidelines for Reporting Breaches" (revised August 2018) β08Which of the following are fundamental objectives of information security?
All of the above β confidentiality, integrity, and availability. Federal law defines information security as protecting information and information systems in order to provide integrity, confidentiality, and availability, and the HIPAA Security Rule states the same three objectives for ePHI.
VERIFIED AGAINST THE SOURCE
βAvailability means the property that data or information is accessible and useable upon demand by an authorized person. Confidentiality means the property that data or information is not made available or disclosed to unauthorized persons or processes. Integrity means the property that data or information have not been altered or destroyed in an unauthorized manner.β
β 45 CFR 164.304, Definitions (Security Rule) (2023 CFR, Title 45, Vol. 2) β09If an individual believes that a DoD covered entity (CE) is not complying with HIPAA, he or she may file a complaint with the:
All of the above β an individual may file a HIPAA complaint directly with the involved DoD covered entity (which must route it to its HIPAA privacy officer), with the DHA Privacy Office, or with HHS, whose Office for Civil Rights provides the complaint form.
VERIFIED AGAINST THE SOURCE
β(2) Implementation Specification: Processing of Complaints. Individuals may file a HIPAA complaint directly with the involved DoD covered entity, the DHA Privacy Office, or HHS. When an individual files a HIPAA complaint directly with a DoD covered entity, that entity must direct the complaint to its HIPAA privacy officer for action. DHA will ensure instructions on how to file a HIPAA complaint are made available to individuals.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 7.2.a.(2), Implementation Specification: Processing of Complaints β10Technical safeguards are:
Information technology and the associated policies and procedures that are used to protect and control access to ePHI.
VERIFIED AGAINST THE SOURCE
βTechnical safeguards means the technology and the policy and procedures for its use that protect electronic protected health information and control access to it.β
β 45 CFR 164.304, Definitions (Security Rule) (2023 CFR, Title 45, Vol. 2) β11A Privacy Impact Assessment (PIA) is an analysis of how information is handled:
All of the above β a PIA is an analysis of how information is handled (1) to ensure the handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; (2) to determine the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronic information system; and (3) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.
VERIFIED AGAINST THE SOURCE
βPrivacy Impact Assessment (PIA) - is an analysis of how information is handled: (i) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy, (ii) to determine the risks and effects of collecting, maintaining and disseminating information in identifiable form in an electronic information system, and (iii) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks.β
β OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002, Attachment A, Section II (Definitions) β12A breach as defined by the DoD is broader than a HIPAA breach (or breach defined by HHS).
True. The DoD breach definition covers any loss of control, compromise, unauthorized disclosure or acquisition, or similar occurrence involving personally identifiable information β including merely potential access, and including an authorized user who accesses PII for an unauthorized purpose. The HHS/HIPAA definition is narrower: it is limited to protected health information, requires an impermissible acquisition, access, use or disclosure that actually compromises the security or privacy of the PHI, and can be rebutted by a risk assessment showing a low probability of compromise.
VERIFIED AGAINST THE SOURCE
βHHS breach. A breach as defined in Section 164.402 of the HIPAA Breach Rule. The text of that HHS definition states: Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Glossary, "HHS breach" β13Which of the following are breach prevention best practices?
All of the above β the safeguards the HIPAA rules put on every workforce member: (1) access and share only the minimum amount of PHI necessary to accomplish the purpose; (2) protect unattended equipment β terminate an electronic session after a set period of inactivity and restrict workstation access to authorized users; and (3) reasonably safeguard PHI at all times, including limiting incidental disclosures and properly disposing of PHI and of the media it is stored on.
VERIFIED AGAINST THE SOURCE
βImplement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored.β
β 45 CFR 164.310, Physical safeguards (2023 CFR, Title 45, Vol. 2), paragraph (d)(2)(i), Disposal (Required) β14An incidental use or disclosure is not a violation of the HIPAA Privacy Rule if the covered entity (CE) has:
All of the above β an incidental use or disclosure is permitted only where it is incident to a use or disclosure that is otherwise permitted or required, and the covered entity has applied the minimum necessary standard (45 CFR 164.502(b) and 164.514(d)) and the reasonable safeguards required by 45 CFR 164.530(c).
VERIFIED AGAINST THE SOURCE
βWhen using or disclosing protected health information or when requesting protected health information from another covered entity or business associate, a covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.β
β 45 CFR 164.502, Uses and disclosures of protected health information: General rules (2023 CFR, Title 45, Vol. 2), paragraph (b)(1) β15Under the Privacy Act, individuals have the right to request amendments of their records contained in a system of records.
True. Each agency that maintains a system of records must permit the individual to request amendment of a record about them, acknowledge the request in writing within 10 working days, and either make the correction or explain its refusal and the procedure for review of that refusal.
VERIFIED AGAINST THE SOURCE
β(2) permit the individual to request amendment of a record pertaining to him and- (A) not later than 10 days (excluding Saturdays, Sundays, and legal public holidays) after the date of receipt of such request, acknowledge in writing such receipt; and (B) promptly, either- (i) make any correction of any portion thereof which the individual believes is not accurate, relevant, timely, or complete;β
β Privacy Act of 1974, 5 U.S.C. 552a, subsection (d)(2), Access to Records β16Which HHS Office is charged with protecting an individual patient's health information privacy and security through the enforcement of HIPAA?
The Office for Civil Rights (OCR). Its Health Information Privacy Division oversees OCR's enforcement of the HIPAA Privacy, Security and Breach Notification Rules, and OCR enforces those rules by investigating complaints alleging noncompliance.
VERIFIED AGAINST THE SOURCE
βOCR enforces the HIPAA Rules by investigating complaints submitted to OCR that allege noncompliance with the HIPAA Rules.β
β HHS Office for Civil Rights, Request for Information on the HITECH Act, 87 FR 19833 (Apr. 6, 2022), Background on OCR's Enforcement of the HIPAA Rules β17Physical safeguards are:
Physical measures, including policies and procedures that are used to protect electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.
VERIFIED AGAINST THE SOURCE
βPhysical safeguards are physical measures, policies, and procedures to protect a covered entity's or business associate's electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.β
β 45 CFR 164.304, Definitions (Security Rule) (2023 CFR, Title 45, Vol. 2) β18Which of the following would be considered PHI?
An individual's first and last name together with the medical diagnosis in a physician's progress report. Health information becomes individually identifiable β and therefore PHI β when it relates to a person's health condition or care and also identifies the individual or could reasonably be used to identify them.
VERIFIED AGAINST THE SOURCE
βProtected health information means individually identifiable health information: (1) Except as provided in paragraph (2) of this definition, that is: (i) Transmitted by electronic media; (ii) Maintained in electronic media; or (iii) Transmitted or maintained in any other form or medium.β
β 45 CFR 160.103, Definitions (2023 CFR, Title 45, Vol. 2) β19The minimum necessary standard:
All of the above β when using or disclosing PHI, or requesting PHI from another covered entity or business associate, a covered entity or business associate must make reasonable efforts to limit the PHI to the minimum necessary to accomplish the intended purpose; and the standard does not apply to disclosures to or requests by a health care provider for treatment, to uses or disclosures made to the individual, to uses or disclosures made under an authorization, to disclosures to the Secretary, or to uses or disclosures required by law.
VERIFIED AGAINST THE SOURCE
βThis requirement does not apply to: (i) Disclosures to or requests by a health care provider for treatment; (ii) Uses or disclosures made to the individual, as permitted under paragraph (a)(1)(i) of this section or as required by paragraph (a)(2)(i) of this section; (iii) Uses or disclosures made pursuant to an authorization under Β§ 164.508; (iv) Disclosures made to the Secretary in accordance with subpart C of part 160 of this subchapter; (v) Uses or disclosures that are required by law, as described by Β§ 164.512(a); and (vi) Uses or disclosures that are required for compliance with applicable requirements of this subchapter.β
β 45 CFR 164.502, Uses and disclosures of protected health information: General rules (2023 CFR, Title 45, Vol. 2), paragraph (b)(2), Minimum necessary does not apply β20Select all that apply: In which of the following circumstances must an individual be given the opportunity to agree or object to the use and disclosure of their PHI?
Both A and C β before PHI directly relevant to a person's involvement with the individual's care or payment for that care is shared with that person, and before the individual's information is included in a facility directory.
VERIFIED AGAINST THE SOURCE
β4.3. USES AND DISCLOSURES REQUIRING AN OPPORTUNITY FOR INDIVIDUAL TO AGREE OR TO OBJECT. A DoD covered entity may use or disclose PHI when the individual is informed in advance of the use or disclosure and has the opportunity to agree to, prohibit, or restrict the disclosure, in accordance with the applicable requirements of this paragraph.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 4.3 β21Under HIPAA, a covered entity (CE) is defined as:
All of the above β (1) a health plan; (2) a health care clearinghouse; and (3) a health care provider who transmits any health information in electronic form in connection with a HIPAA-covered transaction.
VERIFIED AGAINST THE SOURCE
βCovered entity means: (1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.β
β 45 CFR 160.103, Definitions (2023 CFR, Title 45, Vol. 2) β22True or False? "Use" is defined under HIPAA as the release of information containing PHI outside of the covered entity (CE).
False. That describes a disclosure. A use is the sharing, employment, application, utilization, examination, or analysis of individually identifiable health information within the entity that maintains it; a disclosure is the release, transfer, provision of access to, or divulging of the information outside the entity holding it.
VERIFIED AGAINST THE SOURCE
βDisclosure means the release, transfer, provision of access to, or divulging in any manner of information outside the entity holding the information.β
β 45 CFR 160.103, Definitions (2023 CFR, Title 45, Vol. 2) β23The HIPAA Security Rule applies to which of the following:
PHI transmitted or maintained electronically (ePHI). The Security Rule covers only protected health information that is electronically stored or transmitted, and a covered entity or business associate must comply with its standards with respect to all electronic protected health information.
VERIFIED AGAINST THE SOURCE
βA covered entity or business associate must comply with the applicable standards as provided in this section and in Β§Β§ 164.308, 164.310, 164.312, 164.314 and 164.316 with respect to all electronic protected health information.β
β 45 CFR 164.306, Security standards: General rules (2023 CFR, Title 45, Vol. 2), paragraph (c), Standards β24Administrative safeguards are:
Administrative actions, and policies and procedures that are used to manage the selection, development, implementation and maintenance of security measures to protect electronic PHI (ePHI). These safeguards also outline how to manage the conduct of the workforce in relation to the protection of ePHI.
VERIFIED AGAINST THE SOURCE
βAdministrative safeguards are administrative actions, and policies and procedures, to manage the selection, development, implementation, and maintenance of security measures to protect electronic protected health information and to manage the conduct of the covered entity's or business associate's workforce in relation to the protection of that information.β
β 45 CFR 164.304, Definitions (Security Rule) (2023 CFR, Title 45, Vol. 2) β25Which of the following are examples of personally identifiable information (PII)?
All of the above β PII is any information that can be used to distinguish or trace an individual's identity, alone or combined with other linked or linkable information. Examples include a name (full name, maiden name, mother's maiden name, or alias); a personal identification number such as a Social Security number, passport number, driver's license number, taxpayer identification number, or financial account or credit card number; address information such as a street address or email address; and personal characteristics such as a photographic image, fingerprints, handwriting, or other biometric data.
VERIFIED AGAINST THE SOURCE
βExamples of PII include, but are not limited to: β’ Name, such as full name, maiden name, mother's maiden name, or alias β’ Personal identification number, such as social security number (SSN), passport number, driver's license number, taxpayer identification number, or financial account or credit card number β’ Address information, such as street address or email address β’ Personal characteristics, including photographic image (especially of face or other identifying characteristic), fingerprints, handwriting, or other biometric data (e.g., retina scan, voice signature, facial geometry)β
β NIST Special Publication 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII), Section 2.1 β26The HIPAA Privacy Rule applies to which of the following?
All of the above β the Privacy Rule protects protected health information in every form: transmitted by electronic media, maintained in electronic media, and transmitted or maintained in any other form or medium, which includes paper records and oral communication.
VERIFIED AGAINST THE SOURCE
βProtected Health Information: Individually identifiable health information created or received by a CE that relates to the past, present or future physical or mental health of an individual and is transmitted or maintained in electronic, paper, or any other form. It excludes health information in employment records held by a CE in its role as an employer. PHI does not include health information of persons deceased more than 50 yearsβ
β DHA Privacy and Civil Liberties Office, "Overview of the HIPAA Security Rule" HIPAA Security Information Paper, Definitions β27A Systems of Records Notice (SORN) serves as a notice to the public about a system of records and must:
All of the above β a SORN must be published in the Federal Register upon establishment or revision of the system of records, and must state the name and location of the system, the categories of individuals on whom records are maintained, the categories of records maintained, and each routine use of the records including the categories of users and the purpose of the use.
VERIFIED AGAINST THE SOURCE
β(4) subject to the provisions of paragraph (11) of this subsection, publish in the Federal Register upon establishment or revision a notice of the existence and character of the system of records, which notice shall include- (A) the name and location of the system; (B) the categories of individuals on whom records are maintained in the system; (C) the categories of records maintained in the system; (D) each routine use of the records contained in the system, including the categories of users and the purpose of such use;β
β Privacy Act of 1974, 5 U.S.C. 552a, subsection (e)(4) β28HIPAA provides individuals with the right to request an accounting of disclosures of their PHI.
True. An individual has a right to receive an accounting of disclosures of their PHI made by a covered entity in the six years before the request, subject to listed exceptions such as disclosures for treatment, payment and health care operations, disclosures to the individual, and disclosures made under an authorization.
VERIFIED AGAINST THE SOURCE
β(1) An individual has a right to receive an accounting of disclosures of protected health information made by a covered entity in the six years prior to the date on which the accounting is requestedβ
β 45 CFR 164.528(a), Right to an accounting of disclosures of protected health information (2023 CFR, Title 45, Vol. 2), paragraph (a)(1) β29Select all that apply: The HIPAA Privacy Rule permits use or disclosure of a patient's PHI in accordance with an individual's authorization that:
Includes the core elements and required statements set out in the HIPAA Privacy Rule and DoD's implementing issuance; and is a written document signed and dated by the patient. (An authorization is not valid if it is incomplete, expired, revoked, or known to contain false material information.)
VERIFIED AGAINST THE SOURCE
β(f) Signature of the individual and the date the individual signed. If a personal representative of the individual signs the authorization, a description of such representative's authority to act for the individual must also be provided.β
β DoD Manual 6025.18, Implementation of the HIPAA Privacy Rule in DoD Health Care Programs (March 13, 2019), Paragraph 4.2.c.(1)(f) β30Which of the following is NOT electronic PHI (ePHI)?
Health information stored on paper in a file cabinet. ePHI is limited to PHI that is transmitted by, or maintained in, electronic media; PHI held only on paper is protected by the Privacy Rule but is not ePHI.
VERIFIED AGAINST THE SOURCE
βProtected health information means individually identifiable health information: (1) Except as provided in paragraph (2) of this definition, that is: (i) Transmitted by electronic media; (ii) Maintained in electronic media; or (iii) Transmitted or maintained in any other form or medium.β
β 45 CFR 160.103, Definitions (2023 CFR, Title 45, Vol. 2) β31Which of the following are true statements about limited data sets?
All of the above β a limited data set is PHI stripped of 16 listed direct identifiers of the individual and of relatives, employers and household members (names, address detail finer than town/city, State and ZIP, telephone and fax numbers, e-mail addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle and device identifiers, URLs, IP addresses, biometric identifiers, and full face photographic images); it may be used or disclosed only for research, public health, or health care operations; and only if the covered entity enters into a data use agreement with the recipient.
VERIFIED AGAINST THE SOURCE
βA covered entity may use or disclose a limited data set that meets the requirements of paragraphs (e)(2) and (e)(3) of this section, if the covered entity enters into a data use agreement with the limited data set recipient, in accordance with paragraph (e)(4) of this section.β
β 45 CFR 164.514(e), Limited data set (2023 CFR, Title 45, Vol. 2), paragraph (e)(1) βKnow questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 31 questions into a free study set β flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too β not just military training.
Most-searched questions from this course
Individual answer pages with the keyed answer verified across every CBT version we index.
Veteran? vetaid.ai β free VA benefits help.