Business Associates
If are not a healthcare provider but you do business with one, you may be a Business Associate.




  

Test your HIPAA Knowledge!


PHI stands for:

A. Personal Health Information
B. Protected Health Information
C. Private Health Information
D. None of the above

You would like to include a patient's case in a medical study. What are you required to do first?

A. Have the patient sign a release
B. Tell the patient you're doing so
C. You're not required to do anything; include whatever data you want
D. Remove all Identifiable Health Information from the records before including them
E. A and D

What does the P in HIPAA stand for?

A. Portability of medical insurance for employees changing jobs
B. The Privacy of PHI information
C. The Protection of PHI and office medical records
D. The Personal medical information of PHI

The federal penalties for HIPAA include:

A. Up to $50,000 and/or one year in prison for disclosing PHI
B. Up to $100,000 and/or 5 years in prison for obtaining PHI under false pretenses
C. Up to $250,000 and/or ten years in prison for using PHI for personal gain
D. All of the above are correct
E. None of the above are correct

What does IHI stand for?

A. Interesting Hospital Issues
B. Important Health Inspections
C. Identifiable Health Information
D. Important Health Information
E. Identifiable Hospital Information

Health Care information is:

A. Oral or recorded information no matter where it is kept
B. Received or created by an employer
C. Past, present or future health information of an individual
D. A, B, and C
E. None of the above

The Business Associate Agreement is required when someone your office does business with has access to client medical information. That agreement:

A. Has no specific language that is required although there are some recommendations
B. Does not require any specific language or points
C. Requires the use of specific elements
D. Protects the Business Associate from the improper use of Protected Health Information.

After an employee leaves the business, amicably or not, what should you do?

A. Nothing- we trust them
B. Get their keys, keycards, etc.
C. Change the passwords on any common computer accounts
D. Change lock combinations on the doors
E. B, C, and D

The security portion of the HIPAA law involves:

A. The security of the practice
B. Protecting the paper files and computer data files of the practice
C. Protection of patient information for unauthorized disclosure
D. Protection of patient information from unauthorized access
E. B and D

The receptionist's spouse has come to the office to pick them up for lunch, and is waiting in the back office, where there are medical records sitting out waiting to be filed from the morning's patients. What is wrong with this picture?

A. The receptionist has enough time to go out for lunch!?
B. Unauthorized personnel do not belong in areas where they could potentially access PHI
C. Nothing
D. Someone let an unauthorized person into what should be a locked area.
E. B and D



© 2002,2003 HIPAA PS