What does PHI stand for?
Protected Health Information.
Which HIPAA rule focuses on all PHI (oral, written, and electronic)?
The Privacy Rule.
What is a HIPAA breach?
Unauthorized access, use, or disclosure of PHI.
What is the basic purpose of OSHA?
To protect employees from injuries and illness in the workplace.
What are some of the requirements of a sharps container?
Leak-proof, puncture-resistant, not past the fill line, secure to the wall, has a lid, etc.
Give two examples of PHI.
Name, date of birth, address, medical record number, etc.
Which HIPAA rule focuses on electronic PHI only?
The Security Rule.
Give one example of a common HIPAA breach at CEENTA.
Giving the wrong after‑visit summary to the wrong patient from a shared printer.
Name the three categories of hazards OSHA focuses on.
Biological, Chemical and Physical Hazards.
True or False: It is acceptable to throw a used needle in the regular trash if the sharps container is full.
False. NEVER put a needle in a regular trashcan!!
What are the two main types of organizations under HIPAA: covered entities and what?
Business associates.
The primary reasons for accessing a patient's chart include for treatment, payment, and...?
Operations.
Who should you report a suspected breach to?
Your manager and Compliance (email and Healthicity).
Give one example of a bloodborne pathogen.
Hepatitis, HIV, etc.
What type of hazard is the PASS method used for?
A fire.
CEENTA is considered which type of HIPAA organization?
A covered entity.
True or False: You may access your own medical chart in Epic if you work at CEENTA.
False - you only can through your MyChart.
If you see PHI laying out, unattended, what should you do?
Bring it to your manager and report it. We also have shred bins you can put papers in.
What are the routes of exposure of a bloodborne pathogen?
Mouth, Eye, Ear, Needlestick, cut, etc.
What does PASS stand for?
Pull, Aim, Squeeze, Sweep.
What HIPAA standard requires you to use only the least amount of information needed to do your job?
The Minimum Necessary Standard.
The Security Rule requires the implementation of three security measures. What are they?
Confidentiality, Integrity, and Availability.
True or False: If you accidentally access the wrong chart, you should not report it unless someone else notices.
False — all breaches must be reported immediately.
A chemical spill occurs, and you aren't sure how to clean it up. How can you check to confirm?
The safety data sheet.
If you see that the sharps container is filled past the fill line, what should you do?
Let your clinical lead and/or manager know.