In which of the following circumstances must an individual be given the opportunity to agree or object
to the use and disclosure of their PHI? - answerBoth A and C
-Before their information is included in a facility directory
-Before PHI directly relevant to a person's involvement with the individual's care or payment of
healthcare is shared with that person
Which of the following statements about the HIPAA Security Rule are true? - answerAll of the above
-Established a national set of standards for the protection of PHI that is created, received, maintained, or
transmitted in electronic media by a HIPAA covered entity (CE) or business associate (BA)
-Protects electronic PHI (ePHI)
-Addresses three types of safeguards - administrative, technical, and physical- that must be in place to
secure individuals' ePHI
A covered entity (CE) must have an established complaint process. - answerTrue
The e-Government Act provides the use of electronic government services by the public and improves
the use of information technology in the government. - answerTrue
When must a breach be reported to the U.S. Computer Emergency Readiness Team? - answerWithin 1
hour of discovery
Which of the following statements about the Privacy Act are true? - answerAll of the above