Written Policies And Procedures Relating To The Hipaa Privacy Rule
32 community-sourced questions and answers. Free — no login.
A covered entity does not have to disclose PHI to the Office for Civil Rights if they come to investigate a complaint. That is not allowed by HIPAA law.
False
A signed receipt of the facility's Notice of Privacy Practices (NOPP) is mandated by the Privacy Rule in order for a patient to receive services from a health care provider.
False
Another name for the Title II portion of HIPAA law is
Administrative Simplification
Typical Business Associate individuals are:
Biometric device repairmen, legal counsel to a clinic, and outside coding service.
The Office for Civil Rights receives complaints regarding the Privacy Rule. About what percentage of these complaints have been ruled either no violation or the entity is working toward compliance?
About 75%
Who in the health care organization is responsible to know where the written policies are located regarding HIPAA compliance?
All staff members, paid or not paid
For individuals requesting to amend their medical record
the provider has the option to reject the amendment.
An emancipated minor is
a person younger than 18 who is totally self-supporting and possesses decision-making rights.
Use and disclosure of PHI is permitted without authorization with the EXCEPTION of which of the following?
When releasing process or psychotherapy notes.
During an investigation by the Office for Civil Rights, each provider is expected to have the following EXCEPT
Put the wrong answer (written policy and procedures)
If a medical office does not use electronic means to send its insurance claims, it is considered a covered entity.
False
The Regional Offices of the Centers for Medicare and Medicaid Services (CMS) is the only way to contact the government about HIPAA questions and complaints.
False
Written policies and procedures relating to the HIPAA Privacy Rule
Must be available to all employees.
During an investigation by the Office for Civil Rights, the inspector will depend upon the HIPAA Officer to know the details of the written policies of the organization.
True
Consent as defined by HIPAA is for
all of the above.
In HIPAA usage, TPO stands for treatment, payment, and optional care.
False
A hospital or other inpatient facility may include patients in their published directory
only when the patient or family has not chosen to "opt-out" of the published directory.
The minimum penalty per incidence for violations that the Office for Civil Rights finds for noncompliance to the Privacy Rule is
$100.
The response, "She was taken to ICU because her diabetes became acute" is an example of HIPAA-compliant disclosure of information.
False
It is possible for a first name and zip code to be considered individually identifiable health information (IIHI).
False
Psychotherapy notes or process notes include
the therapist's impressions of the patient.
The Privacy Rule
both answers A and C.
Financial records fall outside the scope of HIPPA
false
Research organizations are permitted to receive
a limited data set that has been de-identified for research purposes.
Protected health information is an association between a
diagnosis and an individual
What specific government agency receives complaints about the HIPAA Privacy ruling?
Office for Civil Rights
Nursing notes are not considered PHI since they are not physician's notes and therefore are not protected by HIPAA.
false
Requesting to amend a medical record was a feature included in HIPAA because of
WRONG ANSWER Answered both b and c
When there is an alleged violation to HIPAA Privacy Rule
there is no option to sue a health care provider for HIPAA violations.
According to AHIMA report, the most common problem that health care providers face in relation to PHI is
lack of a standardized process to release PHI
Insurance companies who provide automobile and life insurance come under the HIPAA ruling as covered entities.
False
The HIPAA Privacy Rule gives patients assurance that their personal health information will be treated the same no matter which state or organization receives their medical information.
True
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials