Facility Policies Flashcards

0
Q

About ___ of HIPAA regulations address policies and procedures.

A

Half

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

___ are rules. ___ are steps needed to implement those rules.

A

Policies, Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A policy is best described as how?

A

A written rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Training should be repeated and documented every ___, at a minimum

A

Year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Although it remains a significant risk, HHS has not yet imposed significant fines for failure to develops written policies and procedures.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PCI DSS protects___ data

A

Credit Card

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Best way to describe procedures

A

A detailed list of steps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Technological limitations make it difficult to document attendance at lunch, learns and webinars.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which law or regulation is more specific about passwords?

A

PCI DSS, Payment Card Industry Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

To comply with multiple regulations, you must first do what?

A

Identify regulations that apply to your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Awareness programs can be difficult to document because of what?

A

Some prompts and reminders are intangible and cannot be saved directly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Every publicly traded company must comply with what?

A

SOX, Sarbanes- Oxley Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In California, a data breach must be reported within ___ days.

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

It is good practice to include the specific HIPAA regulation when documenting procedures.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Sarbanes-Oxley Act

A

Made board members and executives criminally responsible for publicly traded company’s failure to adhere to financial disclosure standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The Gramm-Leach-Bliley Act requires financial institutions to protect identifiable financial data including,___,income and credit histories, and Social Security Numbers.

A

Bank and credit card account numbers

16
Q

PCI DSS applies to companies that accept, acquire, transmit, process, or store ___ information

A

Payment card