The Basics
PHI
True or False
FACTS
Scenarios
100

Is HIPAA applicable to BCBH employees?

Yes.

100

What does PHI Stand for? 

Protected Health Information 

100

You can talk about your clients with your family. 

FALSE 

100

A U.S. law that sets the standard for protecting sensitive patient health information (PHI) 

HIPPA (Health insurance portability and accountability Act) 

100

Patty and Victor left work after a long day. As they passed the cleaners coming in, Patty said, "Man, Matthew Kolej bit me today and I'm really getting tired of working with him.  I wish they would take me off his case.  Victor replied, "Yeah, but he's not as bad as Vajra Reuben, he kicked my kneecaps repeatedly.".  The cleaner stared at them as they passed with a look of horror on their face.  Was HIPAA violated? 

Yes.  Using full names of client's in a non-HIPAA compliant environment is a violation. 

200

What does the Acronym HIPAA stand for?

Health Insurance Portability & Accountability Act of 1996

200

Examples of common patient identifiers included in PHI?

Name, date of birth, address, phone #, SSN, email address, diagnosis,  

200

You can take a picture with your client and post it on social media. 

FALSE

200

The federal office that investigates violations of HIPPA? 

Office of Civil Rights (OCR) 

200

Tika was talking to Jeanine on her phone.  She was in her office and mentioned several client's names, along with their treatment goals.  Is this a violation of HIPAA?  

No. 

300

A requirement that all covered entities under HIPPA must be in compliance with the privacy, security and electronic data provision. 

Privacy Rule 

300

An example of a physical safeguard required under the Security Rule of our clients 

*The HIPAA Security Rule is a national federal standard that requires the protection of individuals' electronic protected health information (ePHI) against unauthorized access, use, or disclosure

locking documents that say clients names, restricting physical access to tablets, log out of central reach after each session, do not share you CR password

300

HIPAA protections only applies to our current clients. 

FALSE 

300

Fine Range of a violation of HIPPA 

Up to $50,000 per penalty, per violation 

300

Matthew saved his email and central reach password to his personal laptop.  His wife was using his laptop and Central Reach was left up from a previous work session.  Curious as to what Matthew does at work, she logs into Central Reach and ends up viewing several client's names and session books.  Was HIPAA violated? 

Yes.  It is important to refrain from saving your Central Reach email as password to your personal devices. Matthew's wife was able to view a significant amount of PHI.

400

This Must be granted in order to use or disclose patient health information 

Signed Permission for Release of information 

400

PHI should be limited to a "need to know" basis.

True

400

You can disclose patient information to child protective services when they request records. 

True: Healthcare providers can legally disclose a child's protected health information to child protection authorities or law enforcement without parental consent when reporting suspected abuse or neglect.

400

What does HIPPA Protect?

Medical Records, diagnosis, treatment information, insurance details, any health information that can identify a patient (PHI) 

400

Peter runs a session with a client.  The client proceeded to his several other clients immediately.  Upon pickup, Peter tells the client's caregiver that they hit the three other clients, but that the situation improved after that and the session went well. Is this a HIPAA violation?

No. 

500

Who is required to complete HIPPA compliance training? 

Each person who handles protected Health Information (PHI) 

500

You bring your tablet home from work in order to use with your morning client who is in-home. You log out of Central Reach and turn off the tablet.  Is there anything wrong with this scenario?  If so, what is wrong?

This is totally fine.  Central Reach has a lock and so does your tablet, meeting the two-lock rule.  
500

It is ok to save your email and password to your work tablet?

False.  This will violate the two lock rule and also, in the event it is a clinic tablet, your personal information may be at risk.  

500

3 main rules of HIPPA  

1. Privacy Rule 

2. Security Rule

3. Breach notification Rule 

500

Vajra is shopping at Walmart and picking up Sam's Diet Cola. While there, he runs into the Speech Therapist of one of his clients with whom there is a signed release of information for.  He greets the SLP and begins to express how well the client is doing on their tacting and requesting goals, using the client's first name.  At one point, Vajra mentions how glad he is the client's mother got him into so many early intervention services, expounding that many parents don't know what to do when their child is diagnosed with autism. Is this a HIPAA violation? 

Yes.  Vajra mentioned the client's first name along with PHI (the client's diagnosis and information about the client's treatment).  

M
e
n
u