answers correctly solved 2025/2026
Authorization - correct answer ✔Written permission from a patient to use use/disclose PHI for non -
TPO purposes
Business associate (BA) - correct answer ✔A person or entity performing services for a CE that involves
PHI
Business associate agreement (BAA) - correct answer ✔Contract ensuring BAs protected PHI
Conditions of participation - correct answer ✔CMS standards providers must meet to receive
Medicare/Medicaid reimbursement
Covered Entities (CE) - correct answer ✔Healthcare providers, health plans, healthcare cleaning houses
that transmit PHI electronically
Designated Record Set (DRS) - correct answer ✔Includes medical and bill records used to make
decisions about an individual
Disclosure - correct answer ✔PHI shared outside the entity
HIPAA - correct answer ✔Federal law protected sensitive patient health information
NPP notice of privacy practices - correct answer ✔Written notice describing how PHI is used/disclosed-
must be given at first service
, HITECH - correct answer ✔Strengthened HIPAA by increasing penalties and requiring breach
notifications
Incidental use and disclosure - correct answer ✔Minor, unavoidable disclosures that occur while using
PHI appropriately (example: overhead conversations)
Preemption - correct answer ✔HIPAA overrides state laws unless the state law is more stringent
Protected health information (PHI) - correct answer ✔Identifiable health info transmitted or
maintained in any form
Re-disclosure - correct answer ✔Re-release a previously shared PHI; must comply with HIPAA
Release of information (ROI) - correct answer ✔Process of providing PHI to authorize requesters
Request - correct answer ✔Individuals right to ask for access, amendment, or restrictions on PHI
Treatment, payment, operations (TPO) - correct answer ✔Uses/disclosures of PHI without patient
authorization
Use - correct answer ✔PHI shared within the over entity
Workforce - correct answer ✔Employees, volunteers, trainees under the control of the CE
Distinguish between privacy and confidentiality - correct answer ✔Privacy: patient right to control
access to their PHI
Confidentiality: duty of the healthcare provider to protect patient information