HIPAA BASICS
PRIVACY RULES
PHI
VIOLATIONS
PENALTIES
100

This is what HIPAA stands for: 

What is the Health Insurance Portability and Accountbility Act?

100

Q: The HIPAA Privacy Rule protects this type of health information.  

 A: What is individually identifiable health information?

100

PHI stands for this.

What is Protected Health In formation ?

100

Accessing patient records without a valid reason is the type of HIPAA violation

What is unauthorized access?

100

HIPAA violations can result in both this type of penalty and criminal charges. 

What are civil penalties?

200

HIPAA  was enacted in this year

What is 1996?

200

 Covered entities must provide this document to patients, outlining how their health information may be used.

What is a notice of privacy practices?

200

 This common identifier is considered PHI under HIPAA

What is a patient's name, address, or phone number?

200

Leaving a patient file visible on a desk in a public area violates this HIPAA principle

What is minimum necessary standard.

200

The maximum penalty for a single HIPAA violation

What is 1.5 million per year? 

300

This government department is responsible for enforcing HIPAA

What is the department of Health and Human services (HHS)

300

Under the Privacy Rule, patients have this right regarding their health information.

What is the right to access and receive a copy of their health records?

300

Health information must be associated with this to be considered PHI

What are identifiers that could be used to identify an individual?

300

Sharing patient information on social media without consent is a violation of this

What is HIPAA privacy rule.

300

Penalties are divided into this many tiers based on the nature of the violations ?

What is 4 tiers.
400

These three types of organizations are considered "covered entities" under HIPAA

What is healthcare providers, health plans and healthcare clearing houses.

400

This rule sets national standards for the security of electronic protected health information.

What is the HIPAA Security Rule?

400

This type of health information is not protected by HIPAA.

What is deidentified health information

400

This common office practice can lead to HIPAA violations if not done securely.

What is disposing of documents containing PHI?

400

This factor is considered when determining the penalty for a HIPAA violation

What is the organization's level of culpability (no knowledge, reasonable cause, willful neglect)?

500

This 2009 act significantly strengthened HIPAA enforcement. 

What is the Health Information Technology for Economics and Clinical Health act?

500

This is the minimum time that covered entities must retain HIPAA-related documentation.

What is 6 years?

500

Under HIPAA, genetic information is considered this type of information.

What is Protected Health Information (PHI)?

500

A breach affecting 500 or more individuals must be reported to HHS and the media within this timeframe.

What is 60 days?

500

n addition to monetary fines, covered entities that violate HIPAA may be required to do this

What is implement a corrective action plan?

M
e
n
u