Under Hipaa A Person Or Entity That Provides Services
15 community-sourced questions and answers. Free — no login.
T/F? Under HIPAA, a person or entity that provides services to a CE that do not involve the use or disclosure of PHI would be considered a BA.
False
Do Betty's actions in this scenario constitute a HIPAA Privacy rule violation?
Yes because John is not a physician and therefore not entitled to review any medical files
A friend of Phillip Livingston, a military service member who is being treated for a broken leg at Valley Forge MTF, asked what room Phillip is in so that he can visit. Which of the following is required?
The patient must be given an opportunity to agree or object to the use or disclosure
The Chief Medical Officer for Valley Forge MTF utilizing PHI is conducting a monthly physician peer review operations exercise. Which of the following is required?
Neither an authorization nor an opportunity to agree or object is required
Abigail Adams is a TRICARE beneficiary and patient at Valley Forge MTF and is applying for Sun Life Insurance. Sun Life has requested some of Abigail's medical records in order to evaluate her application. Which of the following is required?
An authorization is required
Dr. Jefferson sends a patient's medical record to the surgeons office in support of a referral for treatment he made for the patient. Which of the following is required?
Neither an authorization nor an opportunity to agree or object is required
Valley Forge MTF discloses a patient's information in response to a request from HHS in the investigation of a patient complaint. Which of the following is required?
Neither an authorization nor an opportunity to agree or object is required
Did Valley Forge MTF handle George's request appropriately?
No, because the MTF is required to respond to George in writing, providing an accounting of certain disclosures going back 6 years from the date of the request
How should John advise the staff member to proceed?
Both B and C
Was this a violation of HIPAA security safeguards?
Yes
What enforcement actions may occur based on Janet's conduct?
All the above
How should John respond?
Yes. Privacy Act Statements and a SORN should both be considered prior to initiating the research project
Major Edmund Randolph, an active member of the United States Air Force, recently discovered through a publicnotice that his PII is being maintained by the federal government in a system of records. Because Major Randolph isvery diligent about safeguarding his personal information and is aware of how this information could bevulnerable, he is interested in obtaining a copy and reviewing them for accuracy. Is Major Randolph able to obtain acopy of his records from the system of records and request changes to ensure that they are accurate?
Yes, Major Randolph is able to request to inspect and copy his records and can request an amendment to correct inaccurate information.
George is reminded of a conversation he overheard between two co-workers who were contemplating selling some old Valley Forge MTF computers instead of disposing of them through the MTF's IT department. With reason to believe Alexander is telling the truth as to the computers and PHI in his possession, what is the appropriate course of action for George?
George should immediately report the possible breach to his supervisor and assist in providing any relevant information for purposes of the investigation
Is Carla's time saving measure appropriate provided she only sends unencrypted emails on occasion?
No, because unencrypted emails containing PHI or PII may be intercepted and result in unauthorized access
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials