What is PHI?
a. Patient Health Information
b. Protected Health Information
c. Personal Health Information
b. Protected Health Information
What does HITECH mean for BA’s?
a. Stiffer fines/penalties
b. Mandatory breach notification
c. Requiring information security programs
d. A and B
e. All of the above
e. All of the above
Stiffer fines/penalties
Mandatory breach notification
Requiring information security programs
Your new Customer Service Representative began work today and she needs access to your records management
software to retrieve client records. She hasn’t received her user id and password yet but needs access to the
system.
What should you do?
a. Contact IT and ask if the new staff member can quickly get a login and password.
b. Login yourself and let her use your account for a few days. If she gets logged out you can always log her
back in.
c. Let her borrow your login and password this time; then change it later.
a. Contact IT and ask if the new staff member can quickly get a login and password
Safeguards that your organization must establish include:
a. Administrative, Physical, Technical
b. Technical, Security, Personnel
c. Electronic, Physical, Training
a. Administrative, Physical, Technical
How many shred containers did SSBRM - South Carolina rotate in 2018?
a. 5,200 containers
b. 5,700 containers
c. 6,300 containers
b. 5,700 containers
Before you access any PHI you should ask:
a. Do I need this information to perform my job?
b. Does this access comply with our BA agreement?
c. What is the least amount of information needed to perform my job?
d. All of the above
d. All of the above
Do I need this information to perform my job?
Does this access comply with our BA agreement?
What is the least amount of information needed to perform my job?
HITECH states that BA’s must now comply with the HIPAA Security Rule?
a. True
b. False
a. True
You work as an Indexing Clerk for a document imaging company and perform data entry for a variety of client
records. This week you are working on data entry for a local physician and come across the medical chart of a close friend. Your friend had mentioned that she had not been feeling well lately but hasn’t really given you any details. You realize that the profile for this job only requires you to enter the first name and medical records number which are easily identifiable at the top of all charts.
You are obviously concerned about her, what should you do?
a. Read through her chart to see what is going on with her, she is your friend and she won’t mind.
b. Call your friend and mention that you came across her chart at work and that you are concerned about
her.
c. Only review the minimum necessary information to perform your job and enter the details required
without reading the medical chart.
c. Only review the minimum necessary information to perform your job and enter the details required
without reading the medical chart.
Which option is NOT a way to protect security?
a. Logging off your computer when not in use.
b. Choosing a password that is easily guessed.
c. Securing confidential materials when not in use.
b. Choosing a password that is easily guessed.
How many work orders did SSBRM - South Carolina process in 2018?
a. 2,150
b. 3,750
c. 4,125
d. 5,200
c. 4,125
Which of the following is NOT considered PHI?
a. Type of car they drive
b. Medical record number
c. Name
a. Type of car they drive
The HITECH Act includes increased penalties for violations of HIPAA’s Privacy and Security regulations?
a. True
b. False
a. True
As a provider of document destruction services, you are making a routine shred console pickup at a local
surgery center. As you begin to retrieve the items from the secure console, one of the surgical center
staff approaches you to retrieve a patient file that was placed in it by mistake.
Your response should be:
a. Allow them to retrieve the file. Although you are not familiar with this staff member, they are
in company uniform so they must work there.
HIPAA & HITECH for Business Associates
b. Ask the staff member for their name and department and seek authorization from an authorized company representative.
c. Politely decline, stating that it is against your company’s policy to allow clients to retrieve
documents from the console without permission.
b. Ask the staff member for their name and department and seek authorization from an authorized
company representative.
*Recently, a breach occurred when PHI was released by a business associate providing document
shredding services when an imposter, posing as a representative of the business associate’s client
indicated that they had mistakenly dropped a file in the secure shred console.
When working with printed PHI, working on multiple jobs at once could be risky?
a. True
b. False
a. True
Work on one job at a time to avoid co-mingling of records containing PHI.
What Stevens & Stevens work year anniversary is Robert celebrating later this year?
a. 5 Years
b. 9 Years
c. 10 Years
d. 12 Years
b. 9 Years (6/1/2010)
Accidentally sending a fax containing PHI to a wrong number is a security incident and you should notify management.
a. True
b. False
a. True
*Even though the fax was unintentionally sent to the wrong number, it is still a security incident. Always verify authorized personnel, fax number and receipt of fax.
Under HITECH, the BA does NOT have to respond to breaches?
a. True
b. False
b. False
As a business associate, you provide records management services for a local Department of Social
Services agency. They have requested that you produce an inventory report on a CD and mail it to their
office. The inventory report contains container listings to include names, social security numbers and
dates of birth.
a. Document the request and produce and mail the CD as requested.
b. Suggest that for security purposes, the report be emailed with encryption to an authorized
representative to avoid unauthorized access or disclosure.
c. Produce the report as requested but add encryption or password protection for security. Send
the disc by a carrier such as FedEx or UPS and require a delivery signature from the designated
authorized representative.
d. B and C
d. B and C
b. Suggest that for security purposes, the report be emailed with encryption to an authorized
representative to avoid unauthorized access or disclosure.
c. Produce the report as requested but add encryption or password protection for security. Send
the disc by a carrier such as FedEx or UPS and require a delivery signature from the designated
authorized representative.
Empty prescription bottles discarded in a customer's shred container should be separated from the paper and put in trash.
a. True
b. False
b. False
What was the former name of this company prior to Stevens & Stevens BRM?
What is: SDE (Storing Documents Electronically)
Which of the following are risky ways to manage PHI?
a. Working off‐site
b. Printed materials
c. E‐mail
d. Faxes
e. All of the above
e. All of the above
Working off‐site
Printed materials
E‐mail
Faxes
The HITECH Act requires that BA’s respond to breaches to include notifying:
a. Covered Entity (CE)
b. CE and patient(s)
c. CE, patients, government agencies, and the media
d. None of the above
c. CE, patients, government agencies, and the media
As a provider of records management services, your company offers scan‐on‐demand services. On
Monday when you arrive at work you notice an urgent request received via the web request system.
This urgent request has been received from a growing home health agency that has five locations. In
the past few months, an additional agency has been added to the account.
In processing the urgent request, you locate the file from the new agencies inventory however; you do
not locate the requestors name on the authorized personnel list. The requestor is asking that the last
dictated emergency room visit be retrieved from the file and scanned to them. What should you do?
a. Process the request to ensure you meet the urgent time requirement and add the person to the
authorized personnel list.
b. Inform management of the situation and contact the requestor to let them know you cannot
process the request until proper authorization is obtained.
c. Contact the designated authorized personnel at the agency and inform them of the request. Let
them know that for security purposes you cannot process the request though it is urgent. Ask
that they update their authorized personnel list so that you can process their request
c. Contact the designated authorized personnel at the agency and inform them of the request. Let
them know that for security purposes you cannot process the request though it is urgent. Ask
that they update their authorized personnel list so that you can process their request.
What does HIPAA stand for?
a. Health Insurance Personal and Accountability Act
b. Health Insurance Portability and Accountability Act
c. Health Insurance Privacy and Accountability Act
d. Health Insurance Privacy and Awareness Act
b. Health Insurance Portability and Accountability Act
How many years of business is SSBRM celebrating this year?
a. 15 Years
b. 20 Years
c. 25 Years
d. 30 Years
c. 25 Years
CONGRATULATIONS!!!