Data Privacy Flashcards

(55 cards)

1
Q

→ official health document of an individual shared among multiple facilities and agencies
→ demographic info, diagnosis, prescriptions, lab tests, contact info, visitation info, allergies, insurance info, family history, etc.

A

Electronic Medical Records (EMRs) or Electronic Health Records (EHRs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

→ hospital discharge data reported to a government agency
→ data that organizations collect about their operations such as status reports on their routine operations

A

Administrative Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

→ billed interactions between insured patients and healthcare systems (inpatient, outpatient, pharmacy, and enrollment)
→ collects information across a wide range of medical professionals
→ comes directly from the notes of physicians as info is recorded at the time of the appointment
→ allows researchers to analyze patients with rare conditions

A

Claims Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

→ tracks a narrow range of key data for chronic conditions
→ uses observational study methods to collect uniform data to evaluate specified outcomes for a population
→ observes the course of the disease and the variations of treatment

A

Patient/Disease Registries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

→ conducted to provide prevalence rates of certain diseases
→ includes the measures of risk factors, health behaviors, and non-health determinants or correlations (e.g. socioeconomic status)

A

Health Surveys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

→ registry and results database hosted by government agencies or the WHO
→ clinical research data made available only through national or discipline-specific organizations
→ studies new tests and treatments that evaluate their effects on human health outcomes
→ data collected are variables relevant to the research hypotheses

A

Clinical Trials Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Documents used for study implementation (acronym is CRF)

A

Case Report Forms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

→ (acc. to the dictionary)—facts and statistics collected for reference
→ (acc. to philosophy)—things known or assumed as facts which shapes the basis of reasoning
→ (acc. to computing)—quantities, characters, or symbols where operations are performed by a computer that transmits electrical signals to record on various media platforms

A

Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

→ ensures that data are not accessed by unauthorized entities

A

Data Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

HIPAA stands for?

A

Health Insurance Portability and Accountability Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

RA 10173

A

Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RA 10713 Chapter 1

A

General Provisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

RA 10173 Section 1

A

Short Title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RA 10173 Section 2

A

Declaration of Policy

  • the state shall protect the human fundamental right of privacy and communication while ensuring a free flow of information
  • the state recognizes the vital role of information and communications technology in nation-building and ensures that personal info is secured and protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

RA 10173 Section 3

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Freely given permission evidenced by written, electronic, or recorded means

A

Consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Race, ethnic origin, marital status, age, color, religion, sex, etc.

A

Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

RA 10173 Section 4

A

Scope; applies to to any natural or juridical person involved in information processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

RA 10173 Section 5

A

Journalist Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

RA 10173 Section 6

A

Extraterritorial Application; countries are obliged to deport foreign criminals running away from their country of origin if found guilty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

RA 10173 Chapter 2

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

RA 10173 Section 7

A

Function of the NPC; administer, implement, monitor, and ensure compliance of the country to international standards of data protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

RA 10173 Section 8

A

Confidentiality

24
Q

RA 10173 Section 9

A

Organizational Structure of the Commission

25
T or F: The NPC is attached to the DICT
True
26
DICT stands for?
Department of Information and Communications Technology
27
T or F: The DICT Chairman acts as the Privacy Commissioner of the NPC
True
28
The current DICT Secretary
Sec. Gringo Honasan
29
The three agencies attached to the DICT
- NTC - NPC - CICC
30
NTC stands for?
National Telecommunications Commission
31
CICC stands for?
Cybercrime Investigation and Coordinating Center
32
RA 10173 Section 10
The Secretariat
33
RA 10173 Chapter 3
Processing of Personal Information
34
RA 10173 Section 11
General Data Privacy Principles
35
RA 10173 Section 12
Criteria for Lawful Processing of Personal Information; consent must be given and the information is necessary as supported by the law
36
RA 10173 Section 13
Sensitive and Privileged Information; prohibited by law but with the following exceptions: - consent is given - supported by law (legal purposes) - to protect life and health - there is lawful and non-commercial objective of public organizations - medical treatment
37
RA 10173 Section 14
Subcontract of Personal Information (third-party processing)
38
RA 10173 Section 15
Extension of Privileged Communication (between doctor and patient)
39
RA 10173 Chapter 4
Rights of the Data Subject
40
RA 10173 Section 16
Data Subject Rights
41
RA 10173 Section 17
Transmissibility of Rights of the Data Subjects
42
RA 10173 Section 18
Right to Data Portability
43
RA 10173 Section 19
Non-Applicability
44
RA 10173 Chapter 5
Security of Personal Information
45
RA 10173 Section 20
Personal Information Security - accidental or unlawful destruction, alteration, and disclosure - accidental loss, human dangers, unlawful access, fraudulent misuse, and contamination - level of protection is dependent on the kind of information present - monitoring of 3rd party processors
46
RA 10173 Chapter 6
Accountability for Transfer of Personal Information
47
RA 10173 Section 21
Principle of Accountability; the information controller is responsible and accountable for any personal information under their control or custody—including those transferred to a 3rd party whether domestic or international
48
RA 10173 Chapter 7
Security of Sensitive Personal Information in Government
49
RA 10173 Section 22
Responsibility of the Heads of Agencies
50
RA 10173 Section 23
Requirements relating to Access by Agency Personnel to Sensitive Personal Information
51
Type of access wherein security clearance is required
Onsite and Online Access
52
Type of access approved by the head of the agency but with a limit of 1000 records only with encryptions required
Offsite Access
53
RA 10173 Section 24
Applicability to Government Contractors
54
International Data Laws: → Europe (2016) → gives control to the individual over their personal data and to simplify the regulatory environment
General Data Protection Regulation (GDPR)
55
International Data Laws: → USA (1996) → stipulates how healthcare information should be protected from fraud and theft → addresses limitations on healthcare insurance coverage
Health Insurance Portability and Accountability Act (HIPAA)