HIPAA Basics
Confidentiality Policy
Duty to Report
Documentation
Technology Assessment
100

HIPAA protects this type of information.

What is Protected Health Information (PHI)?

100

Confidential information should only be shared on a __________ basis.

What is need-to-know?

100

If a client threatens harm to themselves or others, confidentiality may be broken because of this duty.

What is duty to report / duty to warn?

100

Documentation should be factual, objective, and free from this.

What is opinion or judgmental language?

100

Using your personal phone to photograph a client file.

What is a confidentiality violation?

200

PHI includes name plus this type of information.

What is medical, mental health, treatment, or diagnosis information?

200

True or False: If another staff member asks for information, you must automatically share it.

What is False?

200

Child abuse disclosures must be reported to this type of authority.

What is law enforcement or child protective services?

200

Instead of writing “She was crazy and out of control,” documentation should include this.

What is specific observed behavior?

200

Posting on social media: “Rough shift at work tonight 😩 these residents are wild.” 

What is indirect identification / contextual identification risk?  

300

True or False: HIPAA only applies to doctors and hospitals.

What is False?

300

The purpose of confidentiality policy is to protect these three things.

What are clients, staff, and the organization?

300

True or False: If you are unsure whether something is reportable, you should ignore it until you’re certain.

What is False?

300

Client files should always be stored in this manner

What is secure, locked, or password-protected systems?

300

You step away from your computer in a shared office. What must you do to protect confidentiality?

What is log out or lock the screen?

400

Under HIPAA, information may be disclosed without consent in cases of this type of emergency.

What is threat to safety / medical emergency / mandatory reporting situation?

400

A staff member overhears confidential information being discussed improperly. According to most policies, they should do this.

What is report it to a supervisor or follow reporting procedures?

400

Mandatory reporting laws override confidentiality in cases involving this. (Name two.)

What are abuse, neglect, threats of harm, or court orders?

400

True or False: Records must be organized and accessible to authorized staff and auditors at any time.

What is True?

400

You text a coworker about a resident’s behavior using your personal phone. This is risky because it may violate what two protections?

What are secure communication policy and data protection standards?

500

Name three identifiers that make health information protected under HIPAA

What are name, date of birth, address, Social Security number, medical record number, or other identifying data?

500

Violations of confidentiality may result in these four types of consequences.

What are discipline, termination, civil liability, and possible criminal penalties?

500

Failure to report when required may result in this type of personal consequence for staff.

What is legal liability, fines, loss of license, or criminal charges?

500

Why is over-documenting personal details unrelated to services a confidentiality risk?

What is it increases exposure of sensitive information and violates minimum necessary standards?

500

Name two risks of discussing client information in public areas like parking lots, restaurants, or hallways.

What are being overheard and unauthorized disclosure of confidential information?

M
e
n
u