Instructions: Print this exam worksheet. Return to the course page using the link below. Read the course material. Enter your answers on this worksheet. Return to the course page and click the link 'Take Test.' Transfer your answers.

https://www.quantumunitsed.com/go/1844

Quantum Units Education®

HIPAA Privacy Law Update

Entities Covered by the HIPAA Privacy Rule-What Health Plans Are Covered

1. Entities that are not considered health plans include each of the following EXCEPT:

A. Excepted Benefit Plans

B. Employer plans that are administered by an outside agency and have 25 or fewer participants

C. Certain government funded programs

D. Employer plans with fewer than 50 participants and which are self-administered


Protected Health Information-What is Covered

2. Protected health information (PHI) includes individually identifiable health information that is transmitted or maintained in any form or medium by a covered entity or its business associate.

A. True

B. False


Uses and Disclosures of PHI-General Rule

3. In general, a covered entity may not use or disclose health information, except as permitted or required by Privacy Rule.

A. True

B. False


Treatment, Payment and Health Care Operations

4. Health Care Operations are administrative, financial, legal and ____________ activities necessary to run a business and to support core functions of treatment and payment.

A. Organizational

B. Policy-making

C. Regulatory

D. Quality improvement


Opportunity for Individual to Agree or Object

5. Individuals are allowed to prohibit the use or disclosure of name, location, general condition, and religious affiliation in facility directories, but the request must be made in writing.

A. True

B. False


Research-Relationship to Other Research Rules

6. For research purposes, The HIPAA Privacy Rule will always override the Common Rule or FDA's human subject protection regulations.

A. True

B. False


Minimum Necessary

7. Covered entities must make reasonable efforts to limit the uses, disclosures, and requests for PHI to the minimum amount necessary to accomplish the intended purpose.

A. True

B. False


Administrative Requirements

8. HIPAA regulations require employers to:

A. Provide privacy training to all of its workforce, as necessary and appropriate to their functions

B. Develop and apply a system of sanctions for employees who violate the entity’s policies or the requirements of the Privacy Rule

C. Designate a privacy official who is responsible for policies and procedures

D. All of the above


Compliance and Enforcement of the Privacy Rule

9. Which of the following is NOT one of the responsibilities of the Office of Civil Rights with respect to the Privacy Rule?

A. Promote voluntary compliance

B. Investigate and resolve complaints

C. Provide training to covered entities upon request

D. Determine exceptions


10. Privacy rule compliance complaints should be filed within 90 days of when the complainant knew or should have known that the act or omission occurred.

A. True

B. False


Copyright © 2024 Quantum Units Education

Visit us at QuantumUnitsEd.com!