HIPAA Lesson 6 Flashcards
(46 cards)
List the seven fundamental privacy rights that patients have under the Privacy Rule.
- The right to a notice of privacy practices (NPP)
- The right to request access to their own health information
- The right to request amendments to their own designated record sets
- The right to request restrictions to the use and disclosure of information about them
- The right to request an accounting of disclosures (in other words, a list of who has seen and used that person’s health information)
- The right to request the use of alternate communication (email rather than phone calls, for instance)
- The right to authorizations for use and disclosure
The Privacy Rule doesn’t require which CEs to develop a notice:
- Healthcare clearinghouses, if the only protected health information they create or receive is as a business associate of another CE
- A correctional institution that is a CE (for example, one that has a covered healthcare provider component)
- A group health plan that provides benefits only through contracts with health insurance issuers or HMOs (The group health plan must not create or receive protected health information other than summary health information. It also must not handle enrollment or disenrollment information.)
What’s in the Notice of Privacy Practices?
- How the CE may use and disclose protected health information about an individual.
- The individual’s rights concerning that information.
- The CE’s legal duties with respect to the information.
- A contact for further information about the CE’s privacy policies.
What language in the NoPP is required to be capitalized and in bold print as a prominent header?
THIS NOTICE DESCRIBES HOW YOUR PATIENT INFORMATION WILL BE USED AND DISCLOSED. PLEASE REVIEW IT CAREFULLY.
When are Health plans required to provide the NoPP to new enrollees.
At the time of enrollment
Providers who treat patients directly must provide the notice to an individual no later than:
The date of first service delivery.
In an emergency, providers must give the notice _____.
As soon as is reasonably possible.
Health plans also must provide a revised notice to covered individuals within _____ days of the revision. And at least once every _____ years, they must notify covered individuals that the notice is available and tell them how to get it.
- 60
2. Three
CEs must also make a good-faith effort to obtain a _______ that the individual received the notice.
written acknowledgment
If a patient refuses to sign NoPP acknowledgment, the organization must record that it _______receive acknowledgement.
didn’t
When sending an electronic version of the notice automatically, the provider must make a good-faith effort to get a _______ indicating that the individual received the notice.
return receipt
Certain CEs must provide a notice of privacy practices to all patients at the ______.
first encounter.
The NoPP must list all the _______ that will have access to that patient’s PHI, following the legal requirements that the Privacy Rule sets out.
organizations
A CE must respond to an individuals request for medical records within ____ days unless the information is off-site. In that case, the CE has ____ days to respond.
- 30
2. 60
The CE can have a ___-day extension if it notifies the person making the request within 30 days. And in the notification, the CE must include the ______ for the delay and the ______ the patient will get the information. The law permits the CE only ______ extension.
- 30
- 30
- reason
- date
- one
If the CE cannot provide the requested information in the requested format, the CE and individual can agree on a _______ format.
Different
Individuals do not have the right to access records that a CE compiled in anticipation of ________.
Court Action
CLIA
Clinical Laboratory Improvements Amendment
CLIA’s goal is to ensure high-quality ________ testing.
Laboratory
Name two automatic denials.
- The requested information is part of other research, and the individual previously agreed to denial of access.
- An inmate makes a request, and special conditions apply.
Which denial is subject to the right to review?
If a CE or healthcare professional determines that access to the records would endanger someone’s life.
If a CE denies a request, the denial must be in ______, and contain the following: ______, ______. _____, & _____.
- Writing
- A description of the organization’s compliant procedures.
- Name of the contact person
- Title of the contact person
- Telephone number of the contact person
Name the three considerations that go along with a request to correct/amend a medical record.
- Timing
- Notifying the Organizations
- Documenting Amendments
The CE must respond within _____ days to a medial record correction request, and can have one _____ day extension to respond, provided it ______ the individual making the request. The notice must include the _____ for the delay and the _____ the CE will respond.
- 60
- 30
- notifies
- reason
- date