Black Friday Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

HCISPP Sample Questions Answers

Questions 4

Data collected without identifiers, never coded, that was never tied to an individual, thereby fully protecting health information is considered what form of data?

Options:

A.

Data aggregation

B.

Anonymous

C.

Non-disclosed

D.

Anonymized

Buy Now
Questions 5

He discovered X-Rays.

Options:

A.

Lister

B.

Flemming

C.

Koch

D.

Roentgen

Buy Now
Questions 6

HIPAA guidelines say employers that sponsor employee group health plans must maintain privacy of which __________________ in secured locations, if kept in the office?

Options:

A.

Information related to lawsuits again employers

B.

Enrollment and claim information

C.

Workman's Compensation claims

D.

Deidentified information

Buy Now
Questions 7

A therapist's client requests an accounting of disclosures of their medical record. What should that therapist do?

Options:

A.

Pull the file with the accounting of disclosures for the client

B.

Explain that disclosures are allowed as long as the client's information is deidentified or the client consents

C.

Refer the client to the agency's Privacy Officer

D.

Review the client's releases of information with the client

Buy Now
Questions 8

When controlling the type of supply, increasing the amount of generalists could contain costs because.

Options:

A.

Generalists earn lower incomes than specialists

B.

Generalists practice resource-intensive medicine and generate lower overall health care expenditures

C.

Generalists use less hospital and laboratory services

D.

All of the above

Buy Now
Questions 9

In its historical context, which of the following has played a major role in revolutionizing health care delivery?

Options:

A.

Beliefs and values

B.

Science and technology

C.

Medical education

D.

Economic growth

Buy Now
Questions 10

____________ is a accrediting community bases health care organization (home health, Hospice). It has received deeming authority from CMS for home health, hospice and home medical equipment agencies.

Options:

A.

The Joint Commission

B.

American Osteopathic Association

C.

Community Health Accreditation Program ( CHAP)

Buy Now
Questions 11

Among women, which racial/ethnic group has the highest percentage distribution of AIDS?

Options:

A.

White, non-Hispanic

B.

Black, non-Hispanic

C.

Hispanic

D.

American Indian

Buy Now
Questions 12

Substance abuse regulations do not allow disclosure with a subpoena unless a court has issued an order following a show cause hearing.

Options:

A.

True

B.

False

Buy Now
Questions 13

What is a credential for Cancer Registrar?

Options:

A.

AAPC

B.

ACMCS

C.

AHIMA

D.

NCRA

Buy Now
Questions 14

Privacy and security includes which of the following best practices?

Options:

A.

Talking about consumers in public areas or where you can be overheard

B.

Sharing your computer password with a new staff that does not have their own

C.

Including PHI in an unecypted email via a public system

D.

Keeping computer screens out of sight of others

E.

None of the above

Buy Now
Questions 15

For most privately insured Americans, health insurance is:

Options:

A.

employer based

B.

financed by the government

C.

privately purchased

D.

none of the above

Buy Now
Questions 16

Business Associate Agreements are required by the regulation whenever a business associate relationship exists. This is true even when the business associates are both covered entities.

Options:

A.

There are no specific elements which must be included in a Business Associate Agreement. However some recommended but not compulsory elements are listed in 164.504(e) (2)

B.

There are specific elements which must be included in a Business Associate Agreement. These elements are listed Privacy Legislation

C.

There are no specific elements which must be included in a Business Associate Agreement.

D.

There are specific elements which must be included in a Business Associate Agreement. These elements are listed in 164.504(e) (2)

Buy Now
Questions 17

Supplier-induced demand is created by:

Options:

A.

Patients

B.

Providers

C.

Health insurance companies

D.

The government

Buy Now
Questions 18

During the risk assessment phase of the project the CISO discovered that a college within the University is collecting Protected Health Information (PHI) data via an application that was developed in-house. The college collecting this data is fully aware of the regulations for Health Insurance Portability and Accountability Act (HIPAA) and is fully compliant.

What is the best approach for the CISO?

During the risk assessment phase of the project the CISO discovered that a college within the University is collecting Protected Health Information (PHI) data via an application that was developed in-house. The college collecting this data is fully aware of the regulations for Health Insurance Portability and Accountability Act (HIPAA) and is fully compliant.

What is the best approach for the CISO?

Options:

A.

Document the system as high risk

B.

Perform a vulnerability assessment

C.

Perform a quantitative threat assessment

D.

Notate the information and move on

Buy Now
Questions 19

Are there penalties under HIPPA?

Options:

A.

No penalties

B.

HIPPA calls for severe civil and criminal penalties for noncompliance, including: -- fines up to $25k for multiple violations of the same standard in a calendar year -- fines up to $250k and/or imprisonment up to 10 years for knowing misuse of individually identifiable health information.

C.

HIPPA calls for severe civil and criminal penalties for noncompliance, includes: -- fines up to 50k for multiple violations of the same standard in a calendar year -- fines up to $500k and/or imprisonment up to 10 years for knowing misuse of individually identifiable health information

D.

HIPPA calls for severe civil and criminal penalties for noncompliance, including: -- fines up to $100 for multiple violations of the same standard in a calendar year -- fines up to $750k and/or imprisonment up to 20 years for knowing misuse of individually identifiable health information

Buy Now
Questions 20

Which is NOT an element of Security Awareness Training?

Options:

A.

Determination that all staff will receive security training

B.

Policy related to documentation of all security training

C.

Procedural issues of who will terminate user access

D.

Training on vulnerabilities of the electronic Protected Health Information policies

Buy Now
Questions 21

Who was the first company to give their employees health insurance? What was the health insurance?

Options:

A.

Ford Motor Company/Blue Cross

B.

General Motors/Blue Cross

C.

General Motors/Metropolitan life

Buy Now
Questions 22

The Federal Regulations on Confidentiality of Alcohol and Drug Abuse Patient Records is one example of.

Options:

A.

Confidentiality

B.

Release of information

C.

Preemption

Buy Now
Questions 23

Which of the following is true of experience rating?

Options:

A.

High risk patients pay relatively low premiums.

B.

It provides affordable coverage to the chronically ill.

C.

Young, healthier groups have cheaper premiums.

D.

The elderly have among the lowest premiums.

Buy Now
Questions 24

Under Title II of The Health Insurance Portability and Accountability Act, the administrative simplification provision:

Options:

A.

Forbids individual health plans from denying coverage or imposing preexisting condition exclusions

B.

Creates opportunities for fraud and abuse within the health care system

C.

Requires the establishment of national standards for electronic health care transactions

D.

Protects health insurance coverage for workers and their families

Buy Now
Questions 25

Assigning numeric and alphanumeric codes to diagnoses, procedures and services.

Options:

A.

Coding and Abstracting

B.

Incomplete Record Processing

C.

Redcord Circulatoin

Buy Now
Questions 26

Lack of insurance can result in:

Options:

A.

Decreased utilization of lower cost preventive services

B.

Increased need for more expensive, emergency health care

C.

The spread of infectious diseases

D.

All of the above

Buy Now
Questions 27

The traditional dispersed model of independent private physicians working as solo practitioners or in small groups is in competition with.

Options:

A.

Neighborhood health centers

B.

Multispecialty group practices

C.

Large "corporate" group practice organizations and networks

D.

None of the above

Buy Now
Questions 28

The continuous quality improvement model (CQI) seeks to.

Options:

A.

improve access to care

B.

develop formalized standards of care

C.

separate financial and clinical decisions

D.

focus on individual caregivers

Buy Now
Questions 29

Compared to other industrialized countries, the United States' health care system is.

Options:

A.

The most costly

B.

The least universal

C.

Both a and b

D.

Neither a or b

Buy Now
Questions 30

True or False? In a single-payer system, the primary payer usually is an insurance company.

Options:

A.

True

B.

False

Buy Now
Questions 31

Flemming discovered The Cannon of Medicine.

Options:

A.

True

B.

False

Buy Now
Questions 32

HIPPA does not call for:

Options:

A.

Standardization of electronic patient health, administrative and financial data

B.

Unique health identifiers for individuals, employers, health plans, and health care providers.

C.

Common health identifiers for individuals, employers, health plans and health care providers.

D.

Security standards protecting the confidentiality and integrity of "individually identifiable health information," past, present or future.

Buy Now
Questions 33

Each healthcare provider MUST have a document that describes how information about the client is used by the agency and when the agency will disclose/release it without the client's authorization.

Options:

A.

True

B.

False

Buy Now
Questions 34

The management of a rare and complex disorder such as pituitary tumors would be considered an example of.

Options:

A.

Primary care

B.

Secondary care

C.

Tertiary care

D.

Both A and B

Buy Now
Questions 35

All of the following were a result of the Flexner Report in 1910 EXCEPT.

Options:

A.

Academic standards of medical schools became much more rigorous

B.

Many medical schools closed

C.

Homeopathic schools sanctioned homeopaths as "physicians"

D.

Only schools meeting the standards of LCME were able to award MD degrees

Buy Now
Questions 36

Under the HIPAA Privacy Rule, who is NOT considered a covered entity?

Options:

A.

Clearinghouse

B.

Client patient

C.

Health practitioner

D.

Third party

Buy Now
Questions 37

Confidentiality protections cover not just a patient's health-related information, such as his or her diagnosis, but also other identifying information such as social security number and telephone numbers.

Options:

A.

True

B.

False

Buy Now
Questions 38

Breach notification exceptions are provided to all, EXCEPT:

Options:

A.

Business associates who access information by good faith, unintentional means and do not further disclose information

B.

Unintentional, good faith access by employees of covered entities if the information was not further disclosed

C.

If the information impacted less than 500 people within a single demographic area

D.

Inadvertent disclosure made individual to individual within a covered entity who is authorized to access protected health information

Buy Now
Questions 39

The threat modeling identifies a man-in-the-middle (MITM) exposure. Which countermeasure should the information system security officer (ISSO) select to mitigate the risk of a protected Health information (PHI) data leak?

Options:

A.

Auditing

B.

Anonymization

C.

Privacy monitoring

D.

Data retention

Buy Now
Questions 40

Courtesy allows doctors to admit an occasional patient to the hospital.

Options:

A.

True

B.

False

Buy Now
Questions 41

A Governing board is also known as the___________.

Options:

A.

Medical Staff

B.

Administration

C.

Board of Trustees

Buy Now
Questions 42

A multiple payer system is more cumbersome than a single payer system for all of the following reasons except:

Options:

A.

There are numerous health plans, which is difficult for providers to handle

B.

Payments are not standardized across health plans

C.

Some healthcare services are covered for people in the north, but not in the south

D.

Government programs required extensive documentation proving services were provided before paying providers

Buy Now
Questions 43

What time period was syphilis an epidemic?

Options:

A.

Renaissance

B.

Ancient

C.

Modern

Buy Now
Questions 44

A patient is admitted into the E.R with 3rd degree burns through out their body. The physician on staff sends them to a burn center. What type of care are they in?

Options:

A.

Primary

B.

Tertiary

C.

Secondary

Buy Now
Questions 45

In addition to first contact care, the key task(s) of primary care include.

Options:

A.

Longitudinality, or following a patient over time

B.

Comprehensiveness

C.

Coordination

D.

All of the above

Buy Now
Questions 46

A risk assessment report recommends upgrading all perimeter firewalls to mitigate a particular finding. Which of the following BEST supports this recommendation?

Options:

A.

The inherent risk is greater than the residual risk.

B.

The Annualized Loss Expectancy (ALE) approaches zero.

C.

The expected loss from the risk exceeds mitigation costs.

D.

The infrastructure budget can easily cover the upgrade costs.

Buy Now
Questions 47

Handled the first bioterrorism attack in the mail. Also replaced Health Care Financing Administration.

Options:

A.

Joint Commission

B.

CMS

C.

HIPPA

Buy Now
Questions 48

Do the same requirements apply to both medical records and mental health records?

Options:

A.

No, a client is not allowed to have access to any part of a mental health record, with or without psychotherapy notes

B.

Generally, including conditioning enrollment in a plan on the client granting authorization for disclosure of psychotherapy notes

C.

Yes, and client is entitled to all of the same information in both settings

D.

Generally, psychotherapy notes are not included in the provision that allows clients to see and copy their health information

Buy Now
Questions 49

Which is not a "painless" cost control strategy?

Options:

A.

Reduction of administrative waste

B.

Use of cost-effective analysis to limit care

C.

Elimination of inappropriate care

D.

Elimination of ineffective care

Buy Now
Questions 50

Intellectual property rights are PRIMARY concerned with which of the following?

Options:

A.

Owner’s ability to realize financial gain

B.

Owner’s ability to maintain copyright

C.

Right of the owner to enjoy their creation

D.

Right of the owner to control delivery method

Buy Now
Questions 51

Private health insurance coverage has decreased over the past decades because of.

Options:

A.

The rising cost of health care.

B.

An increase in non-unionized jobs

C.

A shift from manufacturing jobs to service industry jobs

D.

All of the above

Buy Now
Questions 52

What main purpose was served by an almshouse in the preindustrial period?

Options:

A.

It was used to quarantine people who had contracted a contagious disease

B.

It provided free medical care and drugs to ambulatory patients

C.

It specialized in performing basic surgeries

D.

It performed general welfare and custodial functions

Buy Now
Questions 53

__________ is a license to operate.

Options:

A.

Licensure

B.

Regulation

Buy Now
Questions 54

Drag the following Security Engineering terms on the left to the BEST definition on the right.

Options:

Buy Now
Questions 55

True or False? In a free market, multiple patients and providers act interdependently.

Options:

A.

True

B.

False

Buy Now
Questions 56

__________________ is responsible for hospital organization, management, control and operation and for appointing medical staff.

Options:

A.

Administration

B.

Board of Trustees

C.

Medical Staff

Buy Now
Questions 57

Helps people with low incomes get the necessary medical help or need. Varies from state to state.

Options:

A.

Medicare

B.

Medicaid

C.

Chips

Buy Now
Questions 58

A continuous information security monitoring program can BEST reduce risk through which of the following?

Options:

A.

Collecting security events and correlating them to identify anomalies

B.

Facilitating system-wide visibility into the activities of critical user accounts

C.

Encompassing people, process, and technology

D.

Logging both scheduled and unscheduled system changes

Buy Now
Questions 59

HIPAA's Administrative Simplification procedures were prompted by the desire to:

Options:

A.

Reduce administrative overhead in provider-payer transactions

B.

Simplify administrative functions such as payroll and benefits

C.

Create multiple forms for various transactions

D.

Add more details to the processing of electronic transactions

Buy Now
Questions 60

Under HIPAA, Regional Health Information Organizations and Personal Health Record Vendors are considered to be:

Options:

A.

Health care clearinghouses

B.

Business associates

C.

Covered entities

D.

Personal health care vendors

Buy Now
Questions 61

The cost controlling strategy that attempts to influence physician behavior by denying payment for services deemed unnecessary is called.

Options:

A.

Supply limits

B.

Utilization management

C.

Patient cost sharing

D.

Aggregate unites of payment

Buy Now
Questions 62

You work in the billing department of your agency and while processing claims, you notice the name of someone you know. Since you are curious, you decide to investigate and you pull their medical record and read it. Is this appropriate?

Options:

A.

Yes

B.

No

Buy Now
Questions 63

The titles of CEO, CFO, CIO and COO can be found here.

Options:

A.

Board of Trustees

B.

Medical Staff

C.

Administration

Buy Now
Questions 64

Surgeons usually receive a single payment for the surgery and postoperative care. This bundling, or payment per episode, gives surgeons an economic incentive to.

Options:

A.

Limit both the number of surgeries they perform and the number of post operative visits they make.

B.

Increase both the number of surgeries and the number of post operative visits.

C.

Limit the number of surgeries and increase the number of post operative visits.

D.

Increase the number of surgeries and limit the number of post operative visits.

Buy Now
Questions 65

___________ is one of the main objectives of HIPAA.

Options:

A.

Secrecy

B.

Accountability

C.

Anonymity

D.

Complexity

Correct answer: Accountability

Buy Now
Questions 66

Which of the following factors was particularly important in promoting the growth of office-based medical practice in the postindustrial period?

Options:

A.

Urbanization

B.

Educational reform

C.

Science and technology

D.

Dependency

E.

licensing

Buy Now
Questions 67

What administrative safeguard puts into place measures to assure that only authorized persons have access to electronic personal health information?

Options:

A.

Log-in monitoring

B.

Information management

C.

Workforce security

D.

Termination procedures

Buy Now
Questions 68

Which of the following is NOT a best practice for privacy and security?

Options:

A.

Keeping fax machines in areas that are not generally accessible

B.

Keeping consumer records and other documents containing PHI out of sight

C.

Documents containing PHI do not need to be shredded

D.

Keeping medical records rooms locked/secured

Buy Now
Questions 69

Which of the following is a true statement about both the amount and quality of medical services available:

Options:

A.

an increase in medical services also increases the quality of care because it provides greater access to care

B.

minimal medical services is needed for increasing quality of care because it reduces misdiagnoses

C.

medical services can be overused or underused which can both be detrimental to the quality of care

D.

the quantity and quality of care are not related

Buy Now
Questions 70

Which of the following is an overarching goal of Healthy People 2010?

Options:

A.

Decrease health care costs

B.

Create a more coordinated health care system

C.

Establish a national health insurance program

D.

Increase quality and years of healthy life

Buy Now
Questions 71

In terms of HIPPA what an organization currently is doing in a specific area of their organization and compared current operations to other requirements mandated by state or federal law is called

Options:

A.

HIPPA status analysis

B.

gap analysis

C.

comparison analysis

D.

stop-gap analysis

Buy Now
Questions 72

Health Information Rights although your health record is the physical property of the healthcare practitioner or facility that compiled it, the information belongs to you. You do not have the right to:

Options:

A.

obtain a paper copy of the notice of information practices upon request inspect and obtain a copy of your health record as provided for in 45 CFR 164.524

B.

request a restriction on certain uses and disclosures of your information outside the terms as provided by 45 CFR 164.522

C.

amend your health record as provided in 45 CFR 164.528 obtain an accounting of disclosures of your health information as provided in 45 CFR 164.528

D.

revoke your authorization to use or disclose health information except to the extent that action has already been taken

Buy Now
Questions 73

The form of payment that is based specifically on the individual components of health care is.

Options:

A.

Fee-for-service reimbursement.

B.

Per Diem payment.

C.

Reimbursement by episode of illness.

D.

Capitation payment.

Buy Now
Questions 74

A risk assessment report recommends upgrading all perimeter firewalls to mitigate a particular finding. Which of the following BEST supports this recommendation?

Options:

A.

The inherent risk is greater than the residual risk.

B.

The Annualized Loss Expectancy (ALE) approaches zero.

C.

The expected loss from the risk exceeds mitigation costs.

D.

The infrastructure budget can easily cover the upgrade costs.

Buy Now
Questions 75

HIPAA security and privacy regulations apply to:

Options:

A.

Attending physicians, nurses, and other healthcare professionals.

B.

Health information managers, information systems staff, and other ancillary personnel only.

C.

Anyone working in the facility.

D.

Only staff that have direct patient contact.

Buy Now
Questions 76

Which of the following is a potential risk when a program runs in privileged mode?

Options:

A.

It may serve to create unnecessary code complexity

B.

It may not enforce job separation duties

C.

It may create unnecessary application hardening

D.

It may allow malicious code to be inserted

Buy Now
Questions 77

If a person has the ability to access facility of company systems or applications, they have a right to view any information contained in that system or application.

Options:

A.

True

B.

False

Buy Now
Questions 78

Are employers required to submit enrollments by the standard transactions?

Options:

A.

Though Employers are not CEs and they have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards

B.

Employers are not CEs and do not have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards.

C.

Employers are CEs and have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards.

D.

Employers are CEs and do not have to send enrollment using HIPPA standard transactions. Further, the employer health plan IS also a CE and must be able to conduct applicable transactions using the HIPPA standards.

Buy Now
Questions 79

Is concised, accurate records of actions taken and decisions made during the meeting.

Options:

A.

Minutes

B.

Agenda

C.

Committees

Buy Now
Questions 80

Marcus, age 33, is fully competent to handle his own affairs. He is starting services with a covered entity, as defined by HIPAA, and has received a copy of the organization's privacy practices. How many signatures are

going to be required on the receipt or acknowledgement form indicating Marcus received the required information?

Options:

A.

One

B.

Three

C.

Four

D.

Two

Buy Now
Questions 81

When responding to a client's request for information about the disclosure of his/her protected health information, which is NOT required?

Options:

A.

The purpose of the disclosure

B.

A description of what information was sent

C.

Disclosures for treatment, payment, or health care operations

D.

The dates of disclosure and to whom the information was sent

Buy Now
Questions 82

Avicenna was known for what?

Options:

A.

Penicillin

B.

Bacteria

C.

Cannon of Medicine

Buy Now
Questions 83

Vertical integration refers to an organization model that under one ownership.

Options:

A.

Contains all levels of care, from primary to tertiary

B.

Provides the necessary staff for this full spectrum of care

C.

Provides the necessary facility for all levels of care

D.

All of the above.

Buy Now
Questions 84

For most privately insured Americans, health insurance is:

Options:

A.

Employer-based

B.

Financed by the government

C.

Privately purchased

D.

None of the above

Buy Now
Questions 85

An international medical organization with headquarters in the United States (US) and branches in France

wants to test a drug in both countries. What is the organization allowed to do with the test subject’s data?

Options:

A.

Aggregate it into one database in the US

B.

Process it in the US, but store the information in France

C.

Share it with a third party

D.

Anonymize it and process it in the US

Buy Now
Questions 86

__________ Collects cancer Data.

Options:

A.

Health Information Manager

B.

Cancer Registrar

C.

Coder

Buy Now
Questions 87

Which of the following types of business continuity tests includes assessment of resilience to internal and external risks without endangering live operations?

Options:

A.

Walkthrough

B.

Simulation

C.

Parallel

D.

White box

Buy Now
Questions 88

He used a microscope to study organisms and also discovered bacteria.

Options:

A.

Koch

B.

Leeuwenhoek

C.

Flemming

D.

Aselli

Buy Now
Questions 89

If a state or federal law or regulation grants the client greater access to their PHI, then it will preempt HIPAA.

Options:

A.

True

B.

False

Buy Now
Questions 90

The Hippocratic Oath was in the Medieval time period.

Options:

A.

True

B.

False

Buy Now
Questions 91

Critics of the United States health care system find fault with all of the following EXCEPT:

Options:

A.

its lack of organizational coherence

B.

its tertiary care organization

C.

its over reliance on primary care

D.

its specialist orientation

Buy Now
Exam Code: HCISPP
Exam Name: HealthCare Information Security and Privacy Practitioner
Last Update: Nov 20, 2024
Questions: 305
$297.5  $850
$297.5  $850
$297.5  $850
buy now HCISPP