PHI & Privacy
HIPAA Basics
Violations & Penalties
Workplace Scenarios
Documentation & Responsibility
100

This type of health info can be written, spoken, or electronic and can be used to identify a patient.

What is Protected Health Information (PHI)?

100

Name 3 examples of PHI

DOB/Address/SSN/Medical Record Number, Phone Number etc. 

100

Viewing patient info without a work-related reason is called this.

What is snooping?

100

True or False: You can look up your neighbor’s record if you're curious.

What is false?

100

This is your primary responsibility regarding PHI.

What is to keep it confidential?

200

There are this many patient identifiers in PHI.

What is 18?

200

HIPAA is enforced by this level of government.

What is the federal government? 

200

Talking about patients in public areas is this type of violation.

What is a HIPAA breach or unauthorized disclosure?

200

You're overheard discussing a patient in the elevator. What policy did you violate?

What is HIPAA confidentiality/privacy?

200

Only access PHI on this basis.

What is “need to know”?

300

This protects the right of individuals to keep their health info private.

What is Privacy? 

300

HIPAA stands for this.

What is the Health Insurance Portability and Accountability Act?

300

One of the most common HIPAA violations involves posting about patients here.

What is social media?

300

Teresa Lopez-Gonzalez is being audited for access in the EHR. Which patient name raises a red flag?

 a. Gloria Smith
b. Jorge Gomez
c. Tammy Cluff
d. Ashley Lopez

d. Ashley Lopez 

300

To release HIV or substance use records, you must first get this.

What is patient authorization?

400

When you leave your computer unattended, you must do this.

What is lock it or log out? 
400

This U.S. department enforces HIPAA violations.

What is the Department of Health and Human Services (HHS)?

400

HIPAA fines can reach up to this amount per incident.

What is $50,000–$250,000?

400

You leave your screen unlocked in a public area. What have you failed to do?

What is secure your workstation?

400

This ensures you're accountable for your documentation.

What is using your own login or signing off correctly?

500

PHI remains protected even after this event happens in a patient's life

Death

500

This type of individual can access a patient's PHi if legally authorized, such as power of attorney or court order. 

What is Personal representative.

500

This action should be taken if you witness a breach of patient privacy.

What is report it to the Privacy Officer?

500

This is the term for employees sharing PHI through unsecure texting apps.

What is a HIPAA violation via insecure communication?

500

Name the 7 Rights of Correct Patient Documentation.

What are: Right patient, time/date, info, reason, response, provider/author, and chart/system?

600

These records must not be left open where others can view them.

What are medical records or charts? 

600

These are the three key reasons PHI may be used without authorization.

What are treatment, payment, and healthcare operations? 

600

True or False: 

A spouse is automatically considered the head of the household and can receive their spouse's Protected Health Information (PHI).

What is False, not without a signed authorization.

600

If a Patient/member refuses to verity their identity but demands PHI, the correct action is this. 

Politely refuse disclosure and explain verification is required under HIPAA 

600

Under HIPAA, providers can share PHI with family or friends only if this condition is met

What is an authorization from the patient, or it is in the best interest of the patient is unable to consent.  The provider can make that decision.  

M
e
n
u