ExamGecko
Home Home / ISC / HCISPP

ISC HCISPP Practice Test - Questions Answers, Page 20

Question list
Search
Search

List of questions

Search

Related questions











HIPAA guidelines say employers that sponsor employee group health plans must maintain privacy of which __________________ in secured locations, if kept in the office?

A.
Information related to lawsuits again employers
A.
Information related to lawsuits again employers
Answers
B.
Enrollment and claim information
B.
Enrollment and claim information
Answers
C.
Workman's Compensation claims
C.
Workman's Compensation claims
Answers
D.
Deidentified information
D.
Deidentified information
Answers
Suggested answer: B

Explanation:

Enrollment and claim information must be kept locked and secured if maintained in office spaces.

Explanation:

Under HIPAA, Regional Health Information Organizations and Personal Health Record Vendors are considered to be:

A.
Health care clearinghouses
A.
Health care clearinghouses
Answers
B.
Business associates
B.
Business associates
Answers
C.
Covered entities
C.
Covered entities
Answers
D.
Personal health care vendors
D.
Personal health care vendors
Answers
Suggested answer: B

Explanation:

Under HIPAA, Regional Health Information Organizations and Personal Health Record Vendors are considered to be business associates.

Explanation:

What administrative safeguard puts into place measures to assure that only authorized persons have access to electronic personal health information?

A.
Log-in monitoring
A.
Log-in monitoring
Answers
B.
Information management
B.
Information management
Answers
C.
Workforce security
C.
Workforce security
Answers
D.
Termination procedures
D.
Termination procedures
Answers
Suggested answer: C

Explanation:

Workforce security puts into place measures to assure that only authorized persons have access to electronic personal health information.

Explanation:

Data collected without identifiers, never coded, that was never tied to an individual, thereby fully protecting health information is considered what form of data?

A.
Data aggregation
A.
Data aggregation
Answers
B.
Anonymous
B.
Anonymous
Answers
C.
Non-disclosed
C.
Non-disclosed
Answers
D.
Anonymized
D.
Anonymized
Answers
Suggested answer: B

Explanation:

Anonymous information is data collected without identifiers that were never tied to an individual.

Explanation:

Administrative Safeguards on Security Awareness related to electronic Protected Health Information (PHI) and Log-in Monitoring includes all, EXCEPT:

A.
Review the system's login reports at regular intervals
A.
Review the system's login reports at regular intervals
Answers
B.
Prohibit the sharing of passwords among any employees, paid or unpaid
B.
Prohibit the sharing of passwords among any employees, paid or unpaid
Answers
C.
Limit the number of attempts a computer user can make at a log-in attempt
C.
Limit the number of attempts a computer user can make at a log-in attempt
Answers
D.
Use of software that locks the user out of the system after a certain number of unsuccessful log-in attempts are made
D.
Use of software that locks the user out of the system after a certain number of unsuccessful log-in attempts are made
Answers
Suggested answer: B

Explanation:

The least appropriate answer is to prohibit the sharing of passwords among any employees, paid or unpaid.

Explanation:

Sammy applied for and received her National Provider Identifier online. What may she now do?

A.
Have guaranteed payment by a health plan
A.
Have guaranteed payment by a health plan
Answers
B.
Receive credentialing or licensing as a therapist provider
B.
Receive credentialing or licensing as a therapist provider
Answers
C.
Be guaranteed enrollment as a provider in a health plan
C.
Be guaranteed enrollment as a provider in a health plan
Answers
D.
Be identified as a unique health care provider during HIPAA transactions
D.
Be identified as a unique health care provider during HIPAA transactions
Answers
Suggested answer: D

Explanation:

Sammy may now be identified as a unique health care provider during HIPAA transactions.

Explanation:

Marcus, age 33, is fully competent to handle his own affairs. He is starting services with a covered entity, as defined by HIPAA, and has received a copy of the organization's privacy practices. How many signatures are going to be required on the receipt or acknowledgement form indicating Marcus received the required information?

A.
One
A.
One
Answers
B.
Three
B.
Three
Answers
C.
Four
C.
Four
Answers
D.
Two
D.
Two
Answers
Suggested answer: D

Explanation:

Two signatures are required on the receipt form. One signature from the client, Marcus, and one from a witness or staff member.

Explanation:

What is the title given to the group authorized by the HIPAA Privacy Rule to approve a waiver of authorization for the disclosure and/or use of personally identifiable health information?

A.
Cohort Group
A.
Cohort Group
Answers
B.
Institutional Review Board
B.
Institutional Review Board
Answers
C.
Privacy Board
C.
Privacy Board
Answers
D.
Board of Directors
D.
Board of Directors
Answers
Suggested answer: C

Explanation:

The Privacy Board is the group authorized by the HIPAA Privacy Rule to approve a waiver of authorization for the disclosure and/or use of personally identifiable health information.

Explanation:

Breach notification exceptions are provided to all, EXCEPT:

A.
Business associates who access information by good faith, unintentional means and do not further disclose information
A.
Business associates who access information by good faith, unintentional means and do not further disclose information
Answers
B.
Unintentional, good faith access by employees of covered entities if the information was not further disclosed
B.
Unintentional, good faith access by employees of covered entities if the information was not further disclosed
Answers
C.
If the information impacted less than 500 people within a single demographic area
C.
If the information impacted less than 500 people within a single demographic area
Answers
D.
Inadvertent disclosure made individual to individual within a covered entity who is authorized to access protected health information
D.
Inadvertent disclosure made individual to individual within a covered entity who is authorized to access protected health information
Answers
Suggested answer: C

Explanation:

Information impacting less than 500 individuals, regardless of their demographic area, is regarded as a breach unless one of the other three qualifiers is met.

Explanation:

Handled the first bioterrorism attack in the mail. Also replaced Health Care Financing Administration.

A.
Joint Commission
A.
Joint Commission
Answers
B.
CMS
B.
CMS
Answers
C.
HIPPA
C.
HIPPA
Answers
Suggested answer: B
Total 305 questions
Go to page: of 31