HIPAA Breaches And Penalties Flashcards

0
Q

HITECH Act of 2009 was enacted as part of the American Recovery and ___ reinvestment Act (ARRA), the stimulus package.

A

Reinvestment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

What does HITECH stand for?

A

Health Information Technology of Economic and Clinical Health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Obamacare also to referred to as?

A

Patient Protection and Affordable Care Act (PPACA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data is considered breached if…

A
  • it is sold to a personal injury attorney
  • it is hacked and published on a website
  • it is stored on an unencrypted hard drive that is lost or stolen
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

HITECH exempts a breach from being reported if the lost data was ___

A

Encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The HITECH Act requires breaches to be reported within ___ days

A

60

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

You must notify the Office of Civil Rights within 60 days of a breach of more than ___ patient records

A

500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: State laws may require stricter reporting and privacy standards than federal law. Business associates must comply with both state and federal laws, meeting the ____ standard.

A

True, stricter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The OCR investigates approximately ___ potential HIPAA violations a year.

A

9,000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Reports of HIPAA violations typically come from breach reports, patient complaints, and ___ complaints.

A

Whistleblower

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Civil penalties for data breaches may not exceed

A

$1,500,000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The HIPAA Omnibus Final Rule of 2013 somewhat relaxed the data breach reporting requirements of HIPAA.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A business associate that becomes aware of the breach must report it to who?

A

The covered entity with which they are contracted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The HITECH Act was part of the ___

A

American Recovery and Reinvestment Act of 2009

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Actions for civil violations of HIPAA may be brought by___

A

The DHHS Office of Civil Rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly