HIPAA Basics
PHI
Privacy Rule
Security Rule
Scenarios and Consequences
100

HIPAA stands for...

Health Insurance Portability and Accountability Act.

100

Define PHI

Protected Health Information

100

What does the Privacy Rule require for marketing (brochures, website, social media, etc.)?

Written authorization.

100

What does the Security Rule protect?

Electronic PHI.

100

You find a client file or document left on a table, what do you do?

Secure it immediately and report to your supervisor.

200

What year was HIPAA was enacted into law?

1996

200

Give two examples of PHI

Name, address, medical record number, social security number, birthdate, etc.

200

What is the "Minimum Necessary" standard?

Share only what is needed.

200

Name one safeguard for electronic PHI

Use strong passwords

200

What is the maximum fine for a HIPAA violation?

$50,000

300

Who must comply with HIPAA?

All staff handling client health information.

300

True or False: a diagnosis is PHI

True

300

Where should you avoid discussing client health?

Any public area.

300

What should you do when stepping away from the computer?

Lock or log off the computer.

300

True or False: Criminal charges are possible for violations?

True

400

Does HIPAA apply to verbal information?

HIPAA applies to written and verbal communication

400

Is a phone number considered PHI?

Yes

400

What should you do if a family member asks for information without consent?

Politely decline, explain the HIPAA rules and refer to your supervisor.

400

Can you email PHI?

Only if you use encryption.

400

Who should you report breaches to?

Your supervisor.
500

The main purpose of HIPAA is to...

Protect the privacy and security of individuals' health information

500

What is a rule of thumb for identifying PHI?

If you can identify the person and it relates to health or payment, it's PHI.

500

Can you post client photos on social media with their verbal permission?

No! Written authorization is required.

500

A staff member accesses a client's record out of curiosity. What is this called?

Snooping and it is a HIPAA violation.

500

What is a good rule of thumb for HIPAA compliance?

When in doubt, don't share, ask your supervisor, report breaches immediately.

M
e
n
u