Games · Test prep
Stuff Every Healthcare Worker Should Know
HIPAA training prep: the Privacy, Security and Breach Notification Rules, and what to do on the job.
Start Stuff Every Healthcare Worker Should Know ⚡ Today's sprint
Print the first 50 cards (free)Get the whole test as a printable PDF: $3 (pre-order)
Free to start, no sign-up. 111 cards so far. One Knowledge Score and day streak across all your courses.
Try 3 cards
- Does HIPAA protect patient information that is spoken out loud, or only paper and computer records?
Show the answer
Spoken, paper and electronic information. Protected health information (PHI) is identifiable health information in any form or medium. A comment at the nurses' station is protected just like a chart or a database.
- A hospital's HR office keeps Dana's pre-hire physical in Dana's personnel file, as the employer. Is that file PHI?
Show the answer
No, employment records held as employer are excluded. HIPAA's definition of PHI leaves out employment records a covered entity holds in its role as employer. Dana's records as a patient would still be PHI, and other workplace laws may still protect the HR file.
- For how long after a person dies must a covered entity keep protecting that person's health information?
Show the answer
50 years. The Privacy Rule keeps protecting a deceased person's PHI for 50 years after death. After that, the information no longer counts as PHI.
All 111 practice questions
Each one has the answer, why it's right, and the official sources. Or play them as a game and track what you've learned.
Show all 111 questions
- Does HIPAA protect patient information that is spoken out loud, or only paper and computer records?
- A hospital's HR office keeps Dana's pre-hire physical in Dana's personnel file, as the employer. Is that file PHI?
- For how long after a person dies must a covered entity keep protecting that person's health information?
- How many identifiers must be removed under HIPAA's Safe Harbor method to de-identify health data?
- Besides Safe Harbor, what is HIPAA's other way to de-identify health data?
- Under Safe Harbor, how much of a patient's ZIP code may stay in de-identified data?
- Under Safe Harbor, which part of a patient's admission date may stay in de-identified data?
- In Safe Harbor de-identified data, how must a 93-year-old patient's age appear?
- Which of these is one of HIPAA's 18 Safe Harbor identifiers?
- Under Safe Harbor, whose identifiers must be removed besides the patient's own?
- Which three kinds of organizations are HIPAA covered entities?
- A clinic hires an outside company to handle its insurance billing using patient records. What is that company under HIPAA?
- Is an unpaid hospital volunteer part of the workforce under HIPAA?
- A clinic sends records to a specialist who will treat the patient. Is the specialist the clinic's business associate?
- A business associate hires a subcontractor that will handle PHI. Who must get the subcontractor's written assurances?
- When a business associate contract ends, what must happen to the PHI the business associate still holds, if feasible?
- What must a clinic have before letting a cloud company store its patient records?
- A billing clerk needs a patient's insurance ID. How much of the patient's chart should the clerk look at?
- Does the minimum necessary rule limit what a nurse shares with a doctor who is treating the same patient?
- Does a hospital need a patient's signed authorization to use PHI for treatment, payment or health care operations?
- A hospital sends a claim to a patient's insurer to get paid. Which HIPAA category is that?
- A hospital uses real charts to review how well its nurses perform. Which HIPAA category is that?
- What does a covered entity generally need before disclosing a patient's psychotherapy notes?
- Which of these is NOT part of a patient's psychotherapy notes under HIPAA?
- A drug company pays a clinic to mail its patients ads for a new product. What does the clinic need?
- Is a pharmacy's refill reminder about a drug a patient is currently prescribed considered marketing under HIPAA?
- Can a covered entity sell patients' PHI to a data company without the patients' authorization?
- How can a patient take back a HIPAA authorization they signed?
- Can a clinic refuse to treat a patient who won't sign an authorization for marketing?
- A patient is awake and alert with a friend in the room. Before discussing care in front of the friend, staff should:
- Can a pharmacy let a patient's neighbor pick up the patient's filled prescription?
- Which hospital directory detail may go only to clergy, not to visitors who ask for a patient by name?
- How long does a covered entity generally have to act on a patient's request for copies of their records?
- A patient asks for an electronic copy of records the clinic keeps electronically. What must the clinic do?
- What may a provider charge a patient for a copy of their own records?
- How long does a covered entity have to act on a patient's request to amend their record?
- If a covered entity denies a patient's request to amend their record, what may the patient do?
- A patient asks for an accounting of disclosures of their PHI. How far back can it cover?
- How often must a covered entity give a patient an accounting of disclosures for free?
- A patient pays in full out of pocket and asks that the visit not be shared with their health plan. Must the provider agree?
- A patient asks the clinic to call a cell phone instead of the home phone. Can the clinic demand a reason?
- When must a provider with a direct treatment relationship give a patient its Notice of Privacy Practices?
- Who usually acts as a minor child's personal representative under HIPAA?
- Who can act as a deceased patient's personal representative under HIPAA?
- May a provider refuse to treat someone as a patient's personal representative if it suspects that person of abuse?
- HIPAA requires a covered entity to disclose PHI in only two situations. Which pair?
- What is electronic protected health information, or ePHI?
- Who must comply with the HIPAA Security Rule?
- What are administrative safeguards in the HIPAA Security Rule?
- What are physical safeguards under the Security Rule?
- What are technical safeguards in HIPAA?
- What does the Security Rule require before choosing safeguards?
- After a risk analysis, what must an organization do?
- Who is responsible for security policies under the Security Rule?
- Which workers must receive HIPAA security training?
- What should happen if a workforce member violates security policies?
- Under the HIPAA Security Rule, what are "security reminders"?
- Under the Security Rule, how are password procedures classified?
- Which HIPAA security awareness topic covers phishing emails?
- What does the Security Rule's log-in monitoring item call for?
- What must a healthcare group do about security incidents?
- What is a contingency plan in the Security Rule?
- What kind of data backup plan is required under HIPAA?
- Which plan helps restore lost ePHI after a disaster?
- What does an emergency mode operation plan address?
- How often should contingency plans be tested?
- What is a facility security plan under the Security Rule?
- What does a workstation use policy specify?
- What physical safeguard protects workstations that access ePHI?
- How must electronic media with ePHI be disposed of?
- Before reusing a hard drive that held ePHI, what must happen?
- Which addressable safeguard tracks hardware and media movement?
- How can a system track who accessed ePHI?
- What access must be available during an emergency?
- What does automatic logoff do for ePHI workstations?
- Is encryption always required for stored ePHI?
- What do HIPAA audit controls require?
- Which addressable control helps prove ePHI was not altered?
- What must happen before someone accesses ePHI?
- Which addressable safeguard helps detect changes to ePHI sent over a network?
- Is encryption required for ePHI sent over a network?
- Which HIPAA rule covers safe disposal of paper records with PHI?
- How long must HIPAA security documentation be kept?
- How does the Security Rule treat phones that store ePHI?
- What does addressable mean in the HIPAA Security Rule?
- What documentation does the HIPAA Security Rule require?
- What is a HIPAA breach?
- Is every impermissible PHI disclosure a breach?
- How many factors are used in a HIPAA breach risk assessment?
- What is the first factor in a HIPAA breach risk assessment?
- Within how many days must individuals be notified of a breach?
- A breach affects more than 500 residents of one state. Who must be told besides the patients?
- How are breaches affecting fewer than 500 people reported?
- What provides safe harbor from HIPAA breach rules?
- How many tiers exist for HIPAA civil penalties?
- What is the maximum prison time for criminal HIPAA violations?
- Where do you file a HIPAA privacy complaint?
- Nurse Kim looks up her neighbor's chart out of curiosity. Is that allowed?
- Two nurses need to discuss a patient in a hospital elevator. What should they do?
- Is posting patient photos or stories on social media allowed?
- Are sign in sheets allowed in a doctors waiting room?
- What should you do before faxing PHI?
- What should you do if you suspect a breach?
- Can your employer punish you for filing a HIPAA complaint?
- When is a breach considered discovered?
- Who must notify patients if a business associate has a breach?
- What must a breach notification letter include?
- When is substitute notice used for breach notification?
- Under the Privacy Rule, which job must every covered entity give to a named person?
- What is the highest civil penalty tier for HIPAA violations?
- Leah gets an email asking her to log in to a strange link to keep her account. What should she do?