Privacy Rule
Security Rule
Breach Notifications
Violations
100

What is the HIPAA Privacy Rule?

It ensures that healthcare providers are correctly implementing the requirements of the HIPPA Act: the protection of patents' medical records and other personal information in all forms of media.

https://hipaatrek.com/10-common-questions-hipaa-privacy-rule/

100

What is the HIPAA Security Rule?

It requires that covered entities have security measures and requirements in place to protect patient information.


https://healthitsecurity.com/features/what-is-the-hipaa-security-rule

100

What is the HIPAA Breach Notification Rule?

The part of HIPAA that requires covered entities to report any breaches of patients' protected health information.


https://www.hipaajournal.com/hipaa-breach-notification-requirements/

200

Who has to comply with the Privacy Rule?

Health Insurers, Health Care Providers, business associates, and clearinghouses


https://hipaatrek.com/10-common-questions-hipaa-privacy-rule/

200

What are the three safeguards required by the Security Rule?

200

Who must a covered entity notify if a breach occurs?

The individuals impacted, the Secretary of HHS and the OCR, and the media.


https://www.hipaajournal.com/hipaa-breach-notification-requirements/

200

How are violations discovered and reported?

300

What information of a patient is protected under the rule?

All personal identification information (name, address, DOB, phone number, …) and personal health records and numbers.


https://hipaatrek.com/10-common-questions-hipaa-privacy-rule/

300

What does the Security Rule require covered entities to consider?

300

What is the leading cause in the U.S. for a breach?

400

What is a PHI and who has access to it?

Protected health information. Patient's own information upon request, the patient's healthcare provider, and any individual representative as stated by the patient.


https://www.hhs.gov/hipaa/for-professionals/faq/2069/under-hipaa-when-can-a-family-member/index.html#:~:text=The%20HIPAA%20Privacy%20Rule%20provides,personal%20representative%20of%20the%20individual.

400

What is a business associate and are they required to adhere to HIPAA?

A business associate is an entity that performs tasks that will involve the use of protected health information. They are required under law to adhere to HIPAA all the same as the covered entities.


https://www.schellman.com/blog/healthcare-compliance/business-associates-hipaa-responsibilities#:~:text=The%20business%20associate%20will%20implement,under%20the%20HIPAA%20Privacy%20Rule.

400

What is required for a covered entity to have in place in case of a breach?

Written policies and procedures as an action plan in case of a breach.


https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html

500

What are steps to take to adhere to the Privacy Rule?

Conducting a risk analysis to locate any system or workflow vulnerabilities.


https://hipaatrek.com/10-common-questions-hipaa-privacy-rule/

500

What are the risk analysis requirements?

Outline the potential risks of your physical and technological systems of workflow.


https://www.cms.gov/regulations-and-guidance/legislation/ehrincentiveprograms/downloads/2016_securityriskanalysis.pdf

500

What should a covered entity's breach notification policy entail?

A breach notification to the secretary outlining how the breach occurred and what is going to be done to patch the leak.


https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html

M
e
n
u