PHI Basics
Verification Rules
Communication Do's and Dont's
Workplace Security
Tricky Situations
100

This law protects patient health information

HIPAA
100

Before disclosing PHI, you must confirm at least this many identifiers. 

 UPMC: 4

Legally:2

100

Calling a patient to remind them of an appointment is allowed, but you must avoid including this detail.

Specialist or Diagnosis

100
You must always do this before leaving your workstation

Lock/Log out

100

True or False: Supervisors may listen to calls containing PHI for quality assurance

True

200

Name 2 examples of PHI

DOB/Address/SSN/Medical ID number, Phone Number

200

True or False: A patient's SSN by itself is enough to verify identity

False

200

PHI can only be emailed this way

Encrypted or through a secure portal
200

Leaving PHI on your desk in plain sight is a violation of this

Physical Safeguards (HIPAA)

200

A member requests their call recordings. Do they have the right to them? 

Yes, if they contain PHI

300

PHI includes this type of audio content if it contains patient identifiers

Call recordings

300

A spouse is the Head of household but not on the HIPAA form. Can they receive PHI? 

NO

300

Posting about a member on social media without identifiers is still a violation if this is implied. 

Diagnosis or condition

300

Using speakerphone in a shared office risks this

unauthorized disclosure of PHI

300

A coworker asks you to pull up their neighbor's record out of curiosity. You should respond:

No, that is a HIPAA violation

400
PHI remains protected even after this event happens in a patient's life
Death
400

This type of individual can access a patient's PHI if legally authorized, such as power of attorney or court order. 

Personal representative 

400

under HIPAA, providers can share PHI with family or friends only if this condition is met

Patient has given permission, or it is patient's best interest if they are unable to consent 
400

This HIPAA safeguard includes passwords, encryption and secure logins

Technical safeguards 

400

If a member refuses to verify their identity but demands PHI, the correct action is this. 

Politely refuse disclosure and explain verification is required under HIPAA

M
e
n
u