SPHR Human Resources

Category - Rewards

Which of the following is not required of covered entities by the HIPAA privacy rule?
  1. Designation of a privacy officer
  2. Creation of a code of ethics that applies to all employees who have access to health-related information
  3. Establishment of a complaint handling and resolution process for issues related to the HIPAA privacy rule
  4. Agreements signed by business associates stating that they will respect the confidentiality of patient information
Answer - B - The HIPAA privacy rule requires creation of a code of ethics that applies to the company’s key officers.

Key Takeaway: At a minimum, this code must apply to the company’s principal executive officer, principal financial officer, principal accounting officer or controller, or persons performing similar functions. It does not, however, have to apply more broadly within the organization. All covered entities are required by the HIPAA privacy rule to designate a privacy officer, establish a compliant handling and resolution process, and sign agreements stating business associates will respect confidentiality of patient information.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz