ACRONYMS
POLICIES
IT'S NOT MY FAULT
ACCESS & DISCLOSURE
SAFEGUARDS
100

PHI

What is Protected Health Information? 

100

This policy requires a work environment where individuals can report potential compliance and regulatory concerns without fear of negative consequences.

What is the Non-Retaliation Policy? 

100

Applied to an email containing PHI being sent outside of the organization. 

What is encryption? 

100

This is what a concerned team member might do when their co-worker calls out sick.

What is inappropriate accessing of co-worker record/snooping?

100

This type of physical safeguard would protect the paper PHI stored in an office file cabinet.

What is locking the file cabinet?

200

HIPAA

What is Health Information Portability and Accountability Act?

200

Team members will complete at the time of hire or onboarding and annually thereafter while active with the organization. 

What is the Annual Compliance and Ethics Training Policy? 

200

A suspicious email sent to our organization, users or more to collect sensitive information. 

What is phishing? 

200

This is the recommended application for parents, guardians, or caregivers to access a patient’s medical record.

What is MyChart proxy access? 

200

This is an example of a technical safeguard that should not be shared with your teammates.

What is a password?


300

OCR

What is the Office for Civil Rights?

300

Violations or suspected violations may be submitted on a confidential basis by the complainant and may be submitted anonymously. 

What is the Reporting Compliance Violations Policy or Hotline Policy? 

300

A set of guidelines that outlines ethical behavior for employees.

What is the Code of Conduct? 

300

These are the 3 conditions when it is permissible to disclose PHI without a patient’s consent.

What is TPO (Treatment, Payment or Healthcare Operations)?

300

This is one type of safeguard that might be used to limit the view of PHI displayed on a computer monitor while in use.

What is a privacy screen?