PHAR 516 Pharmacy Law

Independent learning · P3 Pharmacy Law

HIPAA for the Pharmacist

Learn to protect information without putting unnecessary barriers in the way of patient care.

100–120 minutesEight lessons + Pharmacy Practice CasesUngraded · Exam-relevant
Your task

Read each explanation, work through the examples, and answer the practice cases before checking the reasoning. There is no required score, login, or completion gate. You can revisit any lesson and retry every question. The learning targets will be tested on a course exam; material marked “Background” is context only.

Before you begin

This refreshes the HIPAA foundation from Pharmacy Informatics. You need a current browser and basic ability to select answers, follow links, and print or save a page. No specialist software is needed.

How to learn

Follow the numbered lessons first, then try the Pharmacy Practice Cases without consulting the text. Feedback explains every option. Finish with the printable review and identify questions for class.

Learning objectives (41)

Original numbers are retained for traceability. Background topics are marked in the lessons and are not exam targets.

  1. Define HIPAA and describe its original intent and expanded scope.
  2. Distinguish the Privacy, Security, and Breach Notification Rules and their roles in pharmacy practice.
  3. Identify the three safeguard categories under the Security Rule: administrative, physical, and technical.
  4. Describe examples of each safeguard type in a pharmacy setting.
  5. Evaluate whether a pharmacy’s security measures are “reasonable and appropriate” under HIPAA.
  6. Define Protected Health Information (PHI) and list examples relevant to pharmacy practice.
  7. Identify types of identifiers that make health information individually identifiable.
  8. Explain and apply Safe Harbor de-identification to pharmacy information.
  9. Distinguish between covered entities and business associates under HIPAA.
  10. Identify examples of business associates in pharmacy operations.
  11. List and describe the rights patients have under HIPAA (access, amend, accounting, restrict, confidential communication).
  12. Apply procedures for responding to patient requests regarding their PHI.
  13. Determine when a personal representative may access PHI and when an agent may not.
  14. Identify treatment, payment, and health care operations (TPO) as important permitted uses and disclosures without authorization.
  15. Apply the TPO framework to pharmacy scenarios.
  16. Determine when written authorization is required for PHI disclosure.
  17. Explain the Minimum Necessary Standard and its exceptions.
  18. Evaluate whether a PHI disclosure meets the Minimum Necessary Standard.
  19. Define incidental disclosures and assess whether they are HIPAA violations.
  20. Describe the distribution and posting requirements for the NPP.
  21. Explain the acknowledgment of receipt process and documentation requirements.
  22. Apply HIPAA rules to situations involving refusal to sign the acknowledgment.
  23. Define a designated record set and its relevance to patient access.
  24. Describe the format and fee requirements for providing PHI to patients.
  25. Apply professional judgment in disclosing PHI to agents.
  26. List the required elements of an accounting of disclosures.
  27. Identify disclosures excluded from the accounting requirement.
  28. Define a breach under HIPAA and list the exceptions.
  29. Apply breach-notification recipients, thresholds, and deadlines for individuals, HHS, and media.
  30. Explain the concept and use of substitute notice.
  31. Describe HIPAA’s expectations for PHI disposal.
  32. Identify common violations and enforcement actions related to disposal.
  33. List recommended disposal methods for different PHI formats.
  34. Apply disposal best practices to pharmacy operations.
  35. Identify enforcement authorities under HIPAA and their roles.
  36. Describe the tiered civil penalty structure and apply it to pharmacy violations.
  37. List criminal offenses under HIPAA and their associated penalties.
  38. Apply criminal penalty categories to intentional misconduct scenarios.
  39. Explain the legal implications of HIPAA violations in state courts.
  40. Apply patient access and amendment response deadlines and permitted extensions.
  41. Apply accounting request deadlines, extensions, lookback periods, and fee rules.

Objective 16 covers treatment, payment, and health care operations; these are not the only permitted disclosure pathways. Objectives 43–44 make patient-request deadlines explicit.

Your route through the module

  1. 1What HIPAA covers
    About 10 minutes
  2. 2Recognizing and protecting information
    About 13 minutes
  3. 3Deciding whether information may be shared
    About 15 minutes
  4. 4Patients, representatives, and others
    About 18 minutes
  5. 5Notices and acknowledgment
    About 9 minutes
  6. 6Accounting for disclosures
    About 8 minutes
  7. 7Incidents, notification, and disposal
    About 17 minutes
  8. 8Enforcement and consequences
    About 10 minutes

The lesson estimates total about 100 minutes; allow another 10–20 for Pharmacy Practice Cases and review. Reading pace and retries will vary.

A green checkmark appears after you reach a lesson’s end and submit every practice question; answers need not all be correct. Checkmarks stay on this browser and are not sent to the instructor. Resetting progress does not remove already submitted anonymous answers.

Help and class follow-up

Write down confusing cases or rules and bring questions to class on Monday, November 2. We will review the content that proved most problematic. For technical or accessibility barriers, use the Samford technology and accommodation resources linked in your Canvas course. If a page fails, try another current browser or the downloadable HTML. Essential instruction is available as text; no audio or video is required.

Anonymous question reporting

The module sends your first submitted choice for each practice question to anonymous class totals. The instructor can see which questions and distractors caused difficulty. Anonymous reporting does not send names, email addresses, student IDs, grades, completion records, or an identifier linking your answers across questions.

More about anonymous reporting

A separate random receipt for each question prevents repeat network submissions. This browser remembers first answers so retries do not alter totals. Clearing storage or using a new device may cause another first answer to count; these are instructional signals, not unique-student measures. Hosting infrastructure may process ordinary connection information, such as IP addresses, to deliver the site; the application does not add it to answer records.

Begin lesson 1 Download HTML

Clears lesson checkmarks on this browser; anonymous totals remain unchanged.