Privacy, Confidentiality, and Security
Anonymity: - correct answer The patient's right to have private health data collected in
a way that can never be linked or traced back to him or her.
Audit Trail: - correct answer A record that traces a user's electronic footsteps by
recording activity and transactions, including unsuccessful attempts to view
unauthorized screens, within the EHR system.
Authentication: - correct answer The process of determining whether the person
attempting to access a given network or EHR system has authorization. User
authentication can include password entry or use of biometric data (such as a digital
fingerprint or voice signature) or a smart card (a data-laden microchip).
Authorization: - correct answer A document giving a covered entity permission to use
protected health information for specified purposes other than treatment, payment, or
healthcare operations or to disclose protected health information to a third party
specified by the patient.
Business Associates: - correct answer A person or entity that performs certain
functions or activities that involve the use or disclosure of protected health information
on behalf of a covered entity.
Confidentiality: - correct answer The obligation of professionals to keep a patient's
information in confidence. Anyone entrusted with health information has a duty to keep
that information private. Confidentiality is protected by law to varying degrees.
Consent: - correct answer Permission given to a covered entity for uses and
disclosures of protected health information for treatment, payment, and healthcare
operations.
Consumer Reporting Agency: - correct answer An agency regulated by the Federal
Trade Commission (FTC) under the Fair Credit Reporting Act (FCRA) that sells or
cooperatively exchanges consumer credit information and history.
Covered Entities: - correct answer Healthcare providers, health plans, and healthcare
clearinghouses that transmit health information electronically.
Disclosure: - correct answer Giving access to, releasing, or transferring information to
a person or entity.
Ethics: - correct answer Rules and standards of conduct that govern professional
behavior and arise from our shared understanding of morality.
, Laws: - correct answer Formal enforceable rules and policies based on community
standards of conduct.
Minimum Necessary Standard: - correct answer A key provision of the HIPAA Privacy
Rule requiring that covered entities limit unnecessary or inappropriate access to and
disclosure of protected health information. Disclosures should include only the minimum
necessary amount of information to accomplish a given purpose.
Off-Label Indication: - correct answer A use for a prescription drug other than that for
which the US Food and Drug Administration (FDA) has approved it.
Password: - correct answer A sequence of characters and sometimes spaces used to
prevent unauthorized access to or disclosure of patient information contained in secure
electronic files.
Privacy: - correct answer The patient's freedom to determine when, how much, and
under what circumstances his or her medical information may be disclosed. The
patient's right and expectation that individually identifiable health information will be kept
private and not disclosed without the patient's permission.
Protected Health Information (PHI): - correct answer Individually identifiable health
information (for example, demographic information, billing information, medical record
numbers, account numbers, physical or mental condition, etc.) that is stored,
maintained, or transmitted electronically.
Safeguards: - correct answer Measures taken to prevent interference with computer
network operations and to avert security breaches involving the unauthorized use,
disclosure, modification, erasure, or destruction of PHI; these measures are specified by
the HIPAA Security Rule, which applies only to data in electronic form.
Screen Saver: - correct answer A program that displays animation or image on the
screen if input (such as a pressing a key) is not received for a given time period.
Secondary Use - correct answer A use of health information that is not directly related
to patient care. Such uses include statistical analysis, research, quality and safety
assurance processes, public health monitoring, payment, provider certification or
accreditation, and marketing and other business activities.
Although privacy, confidentiality, and security have always been important in the world
of healthcare, - correct answer it was the Health Insurance Portability and
Accountability Act (HIPAA) that made it mandatory to have measures in place to protect
all three. HIPAA was brought about to address the issues of protecting healthcare
information in the electronic age.
The electronic age has made our lives easier, safer, and more rewarding in many ways,
yet it poses problems that were inconceivable just a few years ago. - correct answer