🇺🇸 Registered Health Information Administrator / Technician (RHIA / RHIT) · flashcards
Registered Health Information Administrator / Technician (RHIA / RHIT) Health Law, Privacy, Security, and Compliance Flashcards
50 question-and-answer cards covering Health Law, Privacy, Security, and Compliance as it is examined in Registered Health Information Administrator / Technician (RHIA / RHIT). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Health Law, Privacy, Security, and Compliance deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
List the patient rights granted under the HIPAA Privacy Rule.
Right to notice of privacy practices, right to access/inspect and obtain a copy of PHI, right to request amendment, right to an accounting of disclosures, right to request restrictions, right to request confidential communications, and right to file a complaint.
What is the timeframe for a covered entity to provide an individual access to their PHI?
Within 30 days of the request, with one allowable 30-day extension if the individual is notified in writing of the reason and expected date.
Can a covered entity deny a patient's request to amend their record, and what must it then do?
Yes—e.g., if the information is accurate/complete or not part of the designated record set. It must provide a written denial and allow the patient to submit a statement of disagreement to be included in the record.
What is the Notice of Privacy Practices (NPP)?
A document covered entities must give patients describing how their PHI may be used and disclosed and outlining the patient's privacy rights; providers must make a good-faith effort to obtain written acknowledgment of receipt.
What are the three categories of safeguards required by the HIPAA Security Rule?
Administrative safeguards, physical safeguards, and technical safeguards (to protect the confidentiality, integrity, and availability of ePHI).
Give two examples of administrative safeguards under the HIPAA Security Rule.
Security management process and risk analysis, workforce security and training, assigned security responsibility, contingency planning, and information access management.
Give two examples of physical safeguards under the HIPAA Security Rule.
Facility access controls, workstation use and security policies, and device and media controls (disposal, reuse, backup).
Give two examples of technical safeguards under the HIPAA Security Rule.
Access control (unique user IDs), audit controls, integrity controls, person/entity authentication, and transmission security (encryption).
What is the difference between 'required' and 'addressable' implementation specifications in the HIPAA Security Rule?
Required specifications must be implemented; addressable specifications must be assessed and implemented if reasonable/appropriate—or an equivalent alternative documented if not, but they cannot simply be ignored.
Define confidentiality, integrity, and availability (the CIA triad) for ePHI.
Confidentiality: ePHI is not disclosed to unauthorized persons; Integrity: ePHI is not improperly altered or destroyed; Availability: ePHI is accessible and usable by authorized persons when needed.
What is role-based access control (RBAC)?
An access control method that grants users permission to information based on their job role/function, supporting the minimum necessary standard.
What is risk analysis under the HIPAA Security Rule?
A required, accurate, and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.
In risk management, how is risk commonly expressed in terms of threat, vulnerability, and impact?
Risk = the likelihood that a threat will exploit a vulnerability, combined with the resulting impact/magnitude of harm to ePHI.
What is the difference between a threat and a vulnerability?
A threat is any potential cause of an unwanted incident (e.g., hacker, fire, malware); a vulnerability is a weakness or flaw that a threat can exploit (e.g., unpatched software, no encryption).
Name four common strategies for responding to identified risk in risk management.
Risk mitigation/reduction (apply controls), risk acceptance, risk avoidance, and risk transfer (e.g., insurance).
How does the HITECH Act define a breach of unsecured PHI?
The unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy, unless a low probability of compromise is demonstrated by a risk assessment.
What four factors must be assessed to determine the probability that PHI has been compromised in a breach risk assessment?
(1) Nature and extent of the PHI involved, (2) the unauthorized person who used/received it, (3) whether the PHI was actually acquired or viewed, and (4) the extent to which the risk has been mitigated.
Under the Breach Notification Rule, when must affected individuals be notified of a breach?
Without unreasonable delay and no later than 60 days after discovery of the breach.
When must a breach be reported to HHS and the media, based on number of individuals affected?
Breaches affecting 500 or more residents of a state/jurisdiction require notice to HHS and prominent media outlets without unreasonable delay (within 60 days); breaches under 500 are logged and reported to HHS annually.
What are the seven core elements of an effective compliance program per the OIG/Federal Sentencing Guidelines?
(1) Written policies/standards of conduct, (2) a compliance officer/committee, (3) effective training and education, (4) effective lines of communication (e.g., hotline), (5) internal monitoring and auditing, (6) enforcement through well-publicized disciplinary guidelines, and (7) prompt response and corrective action to detected offenses.
What is the difference between fraud and abuse in health care?
Fraud is an intentional deception or misrepresentation to gain an unauthorized benefit (knowingly false claims); abuse involves practices inconsistent with sound fiscal or medical practices that result in unnecessary cost, without the requisite intent of fraud.
What does the federal False Claims Act (FCA) prohibit?
Knowingly submitting, or causing to be submitted, false or fraudulent claims for payment to the federal government (e.g., Medicare/Medicaid); it includes qui tam (whistleblower) provisions and treble damages plus per-claim penalties.
What is the difference between the Anti-Kickback Statute and the Stark Law (physician self-referral)?
The Anti-Kickback Statute is an intent-based criminal law prohibiting remuneration to induce referrals for federally funded items/services; the Stark Law is a strict-liability civil law prohibiting physician referrals for designated health services to entities with which they have a financial relationship.
What is the AHIMA Code of Ethics intended to do for health information professionals?
It establishes the ethical principles and professional values (e.g., protecting confidentiality, ensuring information integrity, refusing to participate in unethical practices) that guide HIM professionals' conduct and decision-making.
What this deck covers
The Health Law, Privacy, Security, and Compliance deck follows the Registered Health Information Administrator / Technician (RHIA / RHIT) Health Law, Privacy, Security, and Compliance syllabus — 4 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 12.5 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 194 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Health Law, Privacy, Security, and Compliance flashcards FAQ
How many Health Law, Privacy, Security, and Compliance flashcards are in this Registered Health Information Administrator / Technician (RHIA / RHIT) deck?
50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Registered Health Information Administrator / Technician (RHIA / RHIT) flashcards free?
Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.
What do the Health Law, Privacy, Security, and Compliance cards cover?
They follow the Registered Health Information Administrator / Technician (RHIA / RHIT) Health Law, Privacy, Security, and Compliance syllabus — 4 chapters and 12 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.