HITECH Flashcards

(11 cards)

1
Q

HITECH updates HIPAA how?

A

BAs now directly covered by HIPAA instead of via BAAs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is considered a breach under HITECH?

A
  • unauthorized MADE (modification/access/deletion/exfiltration) of unsecurred ePHI
  • privacy/security compromised
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is NOT considered a breach under HITECH?

A
  • unauthorized MADE but high confidence ePHI not affected
    (ePHI is not access or is encrypted)
  • burden of proof on CE/BA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

HITECH Rulemaking

A

HHS OCR
HHS ONC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HITECH Enforcement

A
  • HHS OCR enforces obligations of CEs/BAs
  • FTC enforces Breach notification duties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

HITECH HBNR duty to individuals

A
  • must notify individuals within 60 days
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

HITECH HBNR duty to HHS

A
  • over 500 = must notify HHS immediately
  • under 500 = must notify HHS annually
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

HITECH HBNR duty to media

A
  • 500+ in same jurisdiction = CE must notify media
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Penalties

A
  • up tot 2 million fine
  • criminal liability for misue of ePHI
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What did HITECH push for?

A
  • EHR to be adopted
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

EHR Requirements

A
  • provide patients with EHR upon request
  • account for all non-oral disclosures within the last 3 years
  • not sell EHR w/o patient consent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly