HIPAA Basics
Privacy Rules
PHI
Violations
Penalties
100

This is what HIPAA stands for. 

What is the Health Insurance Portability and Accountability Act?

100

The HIPAA Privacy Rule protects this type of health information. 

What is individually identifiable health information?

100

PHI stands for this.

What is Protected Health Information?

100

Accessing patient records without a valid reason is this type of HIPAA violation.

What is unauthorized access?

100

HIPAA violations can result in both this type of penalty and criminal charges. 

What are civil penalties?

200

HIPAA was enacted in this year. 

What is 1996?

200

Covered entities must provide this document to patients, outlining how their health information may be used.

What is Notice of Privacy Practices?

200

This common identifier is considered PHI under HIPAA. 

What is a patient's name, address, or phone number?

200

Leaving patient files visible on a desk in a public area violates this HIPAA principle.

What is the minimum necessary standard?

200

The maximum penalty for a single HIPAA violation.

What is $1.5 million per year?

300

This government department is responsible for enforcing HIPAA.

What is the Department of Health and Human Services?

300

Under the HIPAA Privacy Rule, patients have the right regarding their health information. 

What is the right to access and receive a copy of their health information. 

300

Health information must be associated with this to be considered PHI.

What are identifiers that could be used to identify an individual?

300

Sharing patient information on social media without consent is a violation of this.

What is the HIPAA Privacy Rule?

300

Penalties are divided into this many tiers based on the nature of the violation.

What is 4 tiers?

400

These 3 types of organizations are considered "covered entities" under HIPAA.

What are healthcare providers, health plans, and healthcare organizations. 

400

This rule sets national standards for the security of electronic protected health information. 

What is the HIPAA Security Rule. 

400

This type of health information is not protected by HIPAA. 

What is de-identified health information? 

400

This common office practice can lead to HIPAA violations if not done securely.

What is disposing of documents containing PHI?

400

This factor is considered when determining the penalty for a HIPAA violation. 

What is the organization's level of culpability?

500

This 2009 act significantly strengthened HIPAA enforcement.

What is the HITECH (Health Information Technology for Economic and Clinical Health) Act?

500

This is the minimum time that covered entities must retain HIPAA-related documentation.

What is 6 years?

500

Under HIPAA, genetic information is considered this type of information.

What is PHI?

500

A breach affecting 500 or more individuals must be reported to HHS and the media within this timeframe. 

What is 60 days?

500

In addition to monetary fines, covered entities that violate HIPAA may be required to do this.

What is implement a corrective action plan?