Generally HIPPA
HIPPA Scenarios
What does that mean?
True or False
HIPPA Rules
100

Why do we want to protect patients information?

To protect residents from identity fraud, among other cybersecurity concerns

100

A hospital’s public website lists a patient’s first name next to their diagnosis for educational purposes. Is this Protected Health Information (PHI) under HIPAA?

YES

 it is individually identifiable health information held by a covered entity, even if published online

100

State what the HIPPA acronym stands for?

Health Insurance Portability and Accountability Act

100

True or False 

Healthcare workers can go to jail for selling resident information.

TRUE! Penalties can be up to $250,000 or 10 years in jail 

100

What is the Privacy Rule?

Limits uses/disclosure of PHI without authorization

200

What is considered PHI? 

Name, Address, Dates, phone number, fax address, email address, social security number, medical records, many more! 

200

A medical courier is given a patient’s chart to deliver to another clinic. Can the courier use the PHI for personal needs?

NO 

a business associate may not use PHI for personal purposes; they must have a Business Associate Agreement (BAA) and follow HIPAA rules

200

What does HIPPA seek to address in Senior Living? 

Growing concerns surrounding the privacy and security of healthcare data.

200

True OR False

The HIPPA Privacy Rule applies only to written information

FALSE

PHI can be in any form

200

What is the Security Rule?

Standards for protecting electronic PHI

300

True or False 

The Privacy Officer enforces HIPAA privacy rules. 

True

300

A clinic stores ePHI on a shared office computer without encryption. Which Security Rule safeguards are violatied?

A. Administrative

B. Safeguards

C. Technical

D. All of the above

D. ALL OF THE ABOVE


300

When was HIPPA enacted into law? 

1996

300

True or False 

Patient's information should be thrown away in an unlocked bin unless it has been shredded or otherwise destroyed.

False

300

What is the Breach Notification Rule?

Requires covered entities and business associates to notify affected individuals, HHS, and sometimes the media within 60 days after discovering a breach of unsecured protected health information

400

True or False?

Doctors are permitted to see all information about every patient.

FALSE

Doctors are only permitted to see PHI of their own patients. 

400

A researcher wants to use de‑identified data from a clinic for a study. Does HIPAA require consent for this use?  

NO

if the data is truly de‑identified under HIPAA standards, it is not PHI and does not require consent

400

What does PHI stand for?

Protected Health Information 

400

True or False

A patient can access their PHI whenever they want

True 

In any case a resident themselves requests access to their PHI they can do so. 

400

What is the Enforcement Rule?

The HIPAA Enforcement Rule is a federal regulation that outlines how the U.S. Department of Health and Human Services (HHS) investigates HIPAA violations and imposes civil and criminal penalties on covered entities and business associates.

500

What is the most common HIPPA breach in senior living organizations? 

Leaving a computer unlocked. 

500

A patient is in a life‑threatening situation, and the provider needs to share information with another hospital. Can the provider disclose PHI without patient authorization?

YES

HIPAA allows disclosure for treatment in emergencies without prior authorization

500

For how long are HIPPA protections in place on residents PHI after they are deceased? 

50 years. 

500

True or False

A patient care staff member who leaves a patient chart open to go get a quick coffee is violating HIPPA

True

Leaving PHI visible in plain sight is a privacy violation

500

What is the Omnibus Rule?

The Omnibus Rule, issued by the U.S. Department of Health and Human Services (HHS) in January 2013, implemented major provisions of the HITECH Act and the Genetic Information Nondiscrimination Act (GINA). It consolidated four HIPAA rules—Privacy, Security, Breach Notification, and Enforcement—into one updated framework.

M
e
n
u