HIPAA… It’s Kind of a Big Deal
PHI or Nah?
Verify Before You Vibe
Who Are You & Why Are You Calling?
Keep It Compliant
100

This federal law protects individually identifiable health information.

What is HIPAA?

100

Health conditions, diagnoses, and treatments fall under this category when tied to a member.

What is PHI?


100

This is the number of identifiers required for inbound calls.

What is 3 identifiers?

100

You must always complete this step with the member before speaking with a representative.

What is HIPAA verification?

100

This communication tool is not secure and should never be used to share PHI.

What is Slack?

200

This type of information includes anything that identifies a member and relates to their health, care, or payment.

What is Protected Health Information (PHI)?

200

Drug names, dosages, and refill status are examples of this type of protected information.

What is medication-related PHI?

200

This is the number of identifiers required for outbound calls.

What is 2 identifiers?

200

This must be obtained and documented before speaking with a representative about PHI.

What is verbal authorization?

200

You should never include this type of information in voicemail messages.

What is PHI?

300

This is required before discussing or releasing any member’s private health information.

What is identity verification?

300

Phone number, DOB, and Member ID become PHI when combined with this type of information.

What is health or plan information?

300

These include items like DOB, address, Member ID, and phone number used to confirm identity.

What are HIPAA identifiers?

300

If a representative is not authorized, you must do this before sharing PHI.

What is verify directly with the member?

300

If verification cannot be completed, you must take this action instead of proceeding.

What is not disclose PHI and offer a callback?

400

Devoted is classified as this type of organization, making it legally responsible for protecting PHI.

What is a covered entity?

400

This type of information is NOT considered PHI because it cannot identify a specific member.

What is public or general plan information?

400

If a member is uncomfortable verifying, you should offer this safe alternative.

What is calling the official Devoted phone line?

400

When a vendor calls alone without the member, you should take this action.

What is do not disclose PHI and request the member join the call?

400

This should always be documented: identifiers used, outcome, and any authorizations.

What is HIPAA verification documentation?

500

This rule requires you to only access, use, or share the least amount of PHI necessary to complete a task.

What is the minimum necessary standard?

500

Even general discussions about care become PHI when they are linked to this.

What is a specific member?

500

This additional security measure can be used but never replaces standard verification requirements.

What is a passcode or phrase?

500

PHI can only be shared with a broker if they meet this requirement.

What is being the Agent of Record?

500

If something feels suspicious during a call, you should do this before continuing.

What is pause, gather additional verification, and escalate if needed?

M
e
n
u