HIPAA Flashcards

(6 cards)

1
Q

Why was HIPAA enacted, and who enforces it today?

A

Enacted in 1996 to ensure insurance portability, HIPAA now protects health data privacy and security under enforcement by the Office for Civil Rights (OCR) within HHS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which entities must follow HIPAA rules?

A

Covered Entities—providers, insurance companies, clearinghouses—and their Business Associates, such as billing, legal, or data analysis vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does the HIPAA Privacy Rule protect?

A

It protects Protected Health Information (PHI)—any data that can identify a patient, including names, addresses, dates, ID numbers, biometrics, and photos.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the Security Rule require?

A

Covered entities and business associates must safeguard electronic PHI through administrative, physical, and technical measures

Confidentiality, Integrity, Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When must a breach be reported under HIPAA?

A

If PHI is improperly used or disclosed, it’s presumed a breach unless a risk assessment shows low likelihood of compromise—requiring notice to patients, HHS, and sometimes media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are providers’ responsibilities and risks under HIPAA?

A

Providers must protect patient data or face major fines. Because medical records are valuable to hackers, many organizations carry cyber liability insurance for breaches and ransomware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly