m m m m m m m
estions and Verified Answers| 2023/ 2024
m m m m m
QUESTION
What mismamControllingmHealthmPlanm(CHP)?
Answer:
Healthmplanmthat mcontrolsmitsmownmbusiness,mactions,mactivities,mand mpolicies;mCon
trolsmthemsubhealthmplanm(SHP).
ThismappliesmtomstatemMedicaid mplans.mForminstance,mthemCHCmismthemstatemMedicaid,mand mthemSH
Pmwould mbemthemlocalmadministrator.
Re:mHCCA mPrivacymCompliancemHandbook
QUESTION
Describemwhat mtomdomwithmam"required"mimplementationmspecification
Answer:
Implement mthemspecificationmasmpresented
QUESTION
Describemwhat mtomdomwithmanm"addressable"mimplementationmspecification
Answer:
Implement masmpresented,mormif mnot mreasonablemand mappropriatemimplement manmequivalent malternativem
measure.
QUESTION
Designated mRecord mSet m(DRS)m-mincludes:
,Answer:
Groupmof mrecordsmmaintained mbymormformamCovered mEntitymthat mcomprisesmthemfollowing:
1. medical/billingsmrecords
2. enrollment/payment/claimsmadjudication/casemmanagement mbymhealthmplan
3. othermrecordsmused mbymormformcovered mentitymtommakemdecisionsmabout mindividuals
QUESTION
Designated mRecord mSet m(DRS)m-mrecordsmexcluded mfrommDRS:
Answer:
Administrativemdatam(audit mtrails,mappointment mschedules,mthat mdon't mimbed mPHI).
mIncident mreports.
QualitymAssurancemData
.
Statisticalmreports.
QUESTION
DVD mmedicalmrecordsmaremdestroyed mby
Answer:
Shreddingmand mcutting
QUESTION
Few mothermexamplesmformusemormdisclosuremof mPHI mothermthat mTPO:
Answer:
Publicmhealthminterest,mresearch,mseriousmthreat,morgan/tissuemdonationmdecedent minformation,mwo
rker'smcompensationminsurers.
QUESTION
Givemexamplesmof madministrativemsafeguards
Answer:
• Policiesmand mprocedures
,• Trainingmand meducation
• Designationmof mindividualsm(Ex.mSecuritymOfficer)
• ContingencymPlanning
QUESTION
Givemexamplesmof mphysicalmsafeguards
Answer:
• Facilitymsecuritymormaccessmplan
• Disposalmprocessesmand mmediamreuse
• Datambackupmand mstorage
QUESTION
Givemexamplesmof mtechnicalmsafeguards
Answer:
• Passwords
• Encryption
• AutomLogmOff
• UniquemUsermIdentification
QUESTION
HIPAA m"consent"mand m"authorization"mhavemkeymdifferences,mwhat maremthey?
Answer:
Consent mismvoluntarymformTPO,mwhilemauthorizationmismrequired mbymthemPrivacymRulemformusemand mdisc
losuremof mPHI
https://www.hhs.gov/hipaa/for-professionals/faq/264/what-is-the-difference-between-consent-
mand-authorization/index.html
QUESTION
What mismthemprimarymdifferencembetweenmHIPAA mauthorizationmand mRight mofmAccess?m(regardingmdisc
losure)
, Answer:
HIPAA mauthorizationmismamPERMITTED mdisclosure.ma
nd
Right mof mAccessmismamREQUIRED mdisclosuremhttps://www.law.cornell.edu/cfr/tex
t/45/164.524
QUESTION
What mismexcluded mfrommthemRight mof mAccess?
Answer:
1. anyminformationmthat mismnot mpart mof mthemDesignated mRecordsmSet
2. Psychotherapymnotes/recordsm(seem45mCFRm164.524(a)(1)(i)mand m164.501)
3. Recordsmgathered minmanticipationmof,mormformusemin,mamcivil,mcriminal,mormadministrativemaction
mormproceedingm(45mCFR m164.524(a)(1)(ii))
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html
QUESTION
HIPAA mCivilmPenalties
Answer:
Did mnot mknow:m$100mtom$50K mReaso
nablemcause:m$1000mtom$50K
Willfulmneglect,mcorrect minm30mdays:m$10K mtom$50K
Willfulmneglect,mnot mcorrected minm30mdays:m$50K:mMaxmpermyear:m$1.5mmillion
QUESTION
HIPAA mCriminalmPenalties
Answer:
Committed moffensemKnowinglym-
mupmtom1myearminmprisonm+m$50,000mCommitted moffensemundermFals
emPretense:m5myearsm+m$100,000
Committed moffensemwithmIntent,mHarm/PersonalmGain:m10myearsm+m$250,000