Front | Back |
What does HIPAA stand for and who does it apply to?
|
Health Insurance Portability and Accountability, applies to Health Care industry
|
What does SOX stand for and who does it apply to?
|
Sarbanes-Oxley, applies to public companies
|
What does GLBA stand for and who does it apply to?
|
Gramm-Leach-Bliley act, applies to financial service industry
|
What are the 5 Title II rules under HIPAA that directly affect the IT department?
|
Privacy Rule
Transaction and Codes Set Rule Unique Identifer Standards Rule Security Rule Enforcement Rule |
Describe "Transactions and Codes Set Rule"
|
A common standard for the transfer of all health information between health care providers and the organizations that process payment for these services.
|
Describe "The Privacy Rule"
|
It regulates the use and disclosure of protected information held by covered entities.
|
Describe "Unique Identifier Standards rule"
|
Handles the creation and use of unique identifiers for providers, health plans, employers, and patients.
|
Describe the "security rule"
|
A complement to the privacy rule that covers how PHI is secured. Deals specifically with elecronic protected health information (EPHI)
|
The "security rule" lays ourt 3 layers of security safeguards required for compliance. What are they?
|
Administrative, physical, technical
|
Describe the "Enforcement Rule"
|
The final rule that details the basis and procedures for imposing civil monetary penalties on covered entites that violate HIPAA.
A unification of the patchwork of existing rules and regulations that governed the enforcement of different parts of HIPAA. |
What does FERPA stand for and who does it apply to?
|
Family Educational Rights and Privacy Act, applies to educational institutions
|
What are the two types of education records under FERPA?
|
Directory information
Non-Directory information |
What does CIPA stand for and who does it apply to?
|
Children's Internet Protection Act, applies to any school or library using the federal E-Rate program
|
What does NERC stand for and who does it apply to?
|
North American Reliability Council, applies to energy and itility companies.
|
What is an authorization policy?
|
High-level document that defines how an organization will assign and enforce access control rights.
|