2024 HCCA CHPC Practice Exam/ HCCA CHPC Exam New Latest Version with All Questions and 100% Correct Answers
The rights of individual patients under HIPAA rules cover their access to their information and its disclosure to others. Which of the following is not a patient right under HIPAA rules?
- To inspect and copy his or her health information
- To request changes to his or her records
- To obtain an accounting of disclosures of his or her information
- To inspect the protected health information of his or her spouse --------- Correct
Answer --------- d. To inspect the protected health information of his or her spouse
When must the patient authorize the use or disclosure of health information? a. At every visit
- Only when the information will be provided to law enforcement
- Only when used for purposes other than treatment, day-to-day operations, or to
- Only in emergency situations --------- Correct Answer --------- c. Only when used for
comply with a request to which the practice is legally obligated to respond
purposes other than treatment, day-to-day operations, or to comply with a request to which the practice is legally obligated to respond
HIPAA rules and regulations cover what kind of information?
- All personal health information in any format, for any person
- Protected health information held or transmitted by a covered entity or its business
- Diagnoses and procedure information
- All health information for persons who have insurance --------- Correct Answer ---------
- Protected health information held or transmitted by a covered entity or its business
associate, in any form or media, whether electronic, paper, or oral
associate, in any form or media, whether electronic, paper, or oral
The BOD & CEO need to understand the importance and adopt a resolution supporting the compliance program (T/F) --------- Correct Answer ---------- True
The Compliance Officer should not report to the counsel or be the counsel for an organization (T/F) --------- Correct Answer ---------- True
The Compliance Officer should be independent (T/F) --------- Correct Answer ---------- True
Compliance Committee --------- Correct Answer ---------- Advisory to the Compliance Officer and helps with oversight of the program.
- / 3
Careful attention should be given to committee member selection (T/F) --------- Correct Answer ---------- True
The Compliance Officer should be a high level individual with the authority to make decisions (T/F) --------- Correct Answer ---------- True
Under what circumstances are employees allowed to repeat to others PHI that is heard or seen on the job?
- Only when authorized for their job duties
- Once they have been terminated
- After a patient dies
- If they do not think the patient would mind --------- Correct Answer --------- a. Only
when authorized for their job duties
What should an employee do when he or she suspects another employee is in violation of the privacy or security policies?
- Gather solid evidence against the person
- Confront the individual and tell the person that he or she is violating the rules
- Nothing
- Report suspicions to the office manager, privacy/security officer, or other designated
person --------- Correct Answer --------- d. Report suspicions to the office manager, privacy/security officer, or other designated person
Which of the following phrases should employees keep in mind when deciding if they should access a patient's information?
- Since the employee works there he or she can access every patient's information
- Just a quick peek at a file will not hurt anything
- Only use what is needed to perform his or her job duties
- Thinking it is okay to look at a patient's information as long as it is not shared with
anyone else --------- Correct Answer --------- c. Only use what is needed to perform his or her job duties
A staff member needs to leave a HIPAA compliant message on a voicemail or with someone else. Which of the following is not an acceptable practice when contacting patients via phone?
- Following the minimum necessary standard when leaving a message with whoever
- Leaving detailed PHI on a voicemail without having the patient's permission c.
answers the phone
Leaving the minimum amount of information needed: name, number, and practice or
physician name
- Leaving a detailed message, if the patient has given permission to do so ---------
Correct Answer --------- b. Leaving detailed PHI on a voicemail without having the patient's permission
One of the administrative safeguard standards under the Security Rule deals with information access management. One of the basic rules of access management is: 2 / 3
- Information users should be authorized to access only the information they need to
- Information users should never be allowed to discuss protected health information
- Patients are routinely questioned about their need to access medical records
- Only clinical personnel should have access to medical records --------- Correct
do their jobs
Answer --------- a. Information users should be authorized to access only the information they need to do their jobs
Workstation security is among the physical safeguard standards. Which item below is not an appropriate practice?
- Workstations placed in a physically secure location
- Visitors should not be able to view information on computer screens
- Administrator workstations that can enable or disable security features located in
- Computer stations located in a patient waiting room --------- Correct Answer --------- d.
secure areas
Computer stations located in a patient waiting room
Before faxing PHI or confidential information, which of the following should an employee do? Select all that apply.
- Use a fax cover sheet with approved confidentiality statement
- Confirm the fax number before sending
- Send the minimum information necessary
- Use any cover sheet as long as it contains the organization's name and contact
- Confirm the fax number before sending
- Send the minimum information necessary
information --------- Correct Answer --------- a. Use a fax cover sheet with approved confidentiality statement
The HIPAA security regulations apply only to protected health information in electronic form. What about the HIPAA privacy regulations?
- These also apply only to information in electronic form
- Privacy regulations apply to information being faxed
- Privacy regulations do not apply to Medicare patients
- Privacy regulations apply to both paper and electronic formatted information ---------
Correct Answer --------- d. Privacy regulations apply to both paper and electronic formatted information
Why is giving away old computer equipment used by a health care provider's office more of a security risk than just placing the equipment in the trash?
- Recipients of old computer equipment will ultimately destroy the equipment
- PHI may remain on the equipment
- Equipment may contain blood-borne pathogen contamination
- Once given away, the equipment cannot be tracked --------- Correct Answer --------- b.
PHI may remain on the equipment
What is the definition of a breach of protected health information?
- / 3