Hip Hip Hooray
Strictly Confidential
Q and A
What we need to know
More Q & A
100

PHI

Any oral, written, or electronic individually identifiable health information collected or stored by a facility.  Identifiable information includes demographic information and any information that relates to the past, present, or future physical or mental condition of an individual. 

100

Document obtained before releasing Protected Health Information for purposes other than treatment, payment, and operations.

What is a release of information (ROI)?

100

I can respond to patient's requests via Facebook messenger.

What is no?

Facebook is not HIPAA-compliant; we should not respond to any patient on this platform. 

100

This is the most common violation during the HIPAA walk-through at BCHC.

What is leaving your computer unlocked while unattended?

If you leave your computer unlocked, you must be able to see your monitor.

100

Your supervisor has access to review your entire personnel file.

What is no?

 There would be no need for your supervisor to have access to your health information to do their job.

200

ePHI

What is electronic protected health information (ePHI) is protected health information (PHI) that is produced, saved, transferred or received in an electronic form. 

200

Dental, Medical, Behavioral Health patient treatment areas.

What is considered confidential areas?

200

We can leave a message for a patient about an upcoming appointment.

What is yes?

If no specific health information is included in the message.

200

Papers with PHI should be placed face down on unattended desks.

What is yes?

200

All patients must take a copy of our "Notice of our Privacy Practices."

What is no?

We must offer it to everyone one time. If they refuse it, simply document the attempt to give it to them.

300

sPHI

What is PHI that could cause harm or embarrassment to an individual financially, reputationally, or emotionally. 

300
HIPAA
What is The Health Insurance Portability and Accountability Act.
300

I can install Bullhook Community Health Center's email and/or teams on my personal electronic device.

What is no.

Only Management and/or C-Suite members.  

300

The same requirements apply to mental health records and to medical records.

What is yes?

300

We can fax PHI.

What is yes?

Standard precautions should be taken to ensure the reasonable security of the transmitted data.

400

Compliance officers are Adam, Vic, and Leah.

What is no?

Our compliance officers are Rozan Kerr, Deidre Reiter, Kyndra Hall, Marie Gillett, Stacey Moore, Jennifer Gobin, Darin Miller, Jared Esteves. 

400

These provider records are considered part of 42 CFR Part 2 and cannot be released with a regular ROI.

What is a Licensed Addiction Counselor?

400

I can discuss a patient's situation with them on the phone when other patients are at the desk or in the lobby.

What is yes? 

You may, but caution should be used to minimize exposure to others, this is an example of incidental disclosure that is unavoidable in day-to-day practice.

400

Rozan Kerr

Who is the HIPAA Security Compliance Officer?

400

There are 16 HIPAA patient identifiers. 

What is no? 

  1. Patient names  
  2. Geographical elements (such as a street address, city, county, or zip code)
  3. Dates related to the health or identity of individuals (including birthdates, date of admission, date of discharge, date of death, or exact age of a patient older than 89)
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social security numbers
  8. Medical record numbers
  9. Health insurance beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers
  13. Device attributes or serial numbers
  14. Digital identifiers, such as website URLs 
  15. IP addresses
  16. Biometric elements, including finger, retinal, and voiceprints
  17. Full face photographic images 
  18. Other identifying numbers or codes 
500

This country singer's medical records were sold to the National Enquirer and Star tabloids by a hospital employee for $2,610.

Who is Tammy Wynette

500

"Minimum necessary HIPAA rule"

What is information that cannot be shared if you do not need the information to do your job.

500

An adult who is not a child's parent or legal guardian can consent for the child's appointment at Bullhook Community Health Center.

What is no?

500

Kyndra Hall

What is the HIPAA Privacy Compliance Officer?

500

We can discuss a client's PHI with other providers involved in their care or other provider to whom we are referring them.

What is yes?

This is part of treatment and does not require authorization.