HIPAA Basics
Privacy Rule
Security Rule
Enforcement Rule
Others
100

This is what HIPAA stands for.

What is the Health Insurance Portability and Accountability Act?

100

This acronym refers to individually identifiable health information.

What is Protected Health Information (PHI)?

100

The tree types of safeguards under the Security Rule

What are administrative, physical, and technical safeguards?

100

The maximum annual penalty for civil penalties

What is $2 million?

100

Patients can request this if they find errors in their medical records.

What is the Right to Amendment?

200

The year HIPAA was signed into law.

What is 1996?


200

Patients can request these to see their own medical records.

What is Right to Access?

200

This safeguard includes staff training and risk assessments.

What are administrative safeguards?

200

Tier where fines are the lowest on civil penalties

What is Tier 1?
200

These penalties apply to individuals who knowingly misuse PHI.

What are criminal penalties?

300

HIPAA's two main goals.

What are protecting patient privacy and ensuring data security?

300

The principle that limits PHI sharing to only what's necessary.

What is the Minimum Necessary Standard?

300

Encrypting data is an example of this type of safeguard.

What is a technical safeguard?

300

Criminal penalties for HIPAA violations can include this.

What is jail time?

300

The Minimum Necessary rule applies to these types of PHI disclosures.

What is treatment, payment, and operations?

400

This entity is responsible for enforcing HIPAA

What is the Office for Civil Rights (OCR)?

400

A type of form that is required before sharing PHI for non-treatment purposes?

What is Authorization?
400

Physical safeguards require these to protect facilities.

What are locked doors?

400

The agency that conducts HIPAA auidts

What is the Office for Civil Rights?

400

This 2009 law strengthened HIPAA's breach notification requirements.

What is the HITECH Act?

500
Two main sections of HIPAA

What are the Privacy and Security Rule?

500

The time frame providers have to respond to a patient's record request.

15-days

500
An assessment that is required for organizations to identify vulnerabilities and threats

What is a risk assessment?

500

A hospital loses an unencrypted laptop with PHI. This is the penalty tier.

What is Tier 4?

500
Privacy Rule updated on 2024 on making stricter guidelines for what health information.

What is Reproductive Health Information?

M
e
n
u