AHIC Privacy and Security 3 — Questions and Answers
Question 1: Which HIPAA rule specifically requires covered entities to implement administrative, physical, and technical safeguards for ePHI?
- HIPAA Privacy Rule
- HIPAA Security Rule (Correct answer)
- HIPAA Enforcement Rule
- HIPAA Breach Notification Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates safeguards specifically for electronically protected health information (ePHI).
Question 2: In a health information exchange (HIE), the 'opt-in' consent model means:
- Patients are automatically included unless they actively withdraw consent
- Patients must affirmatively agree before their data is shared through the HIE (Correct answer)
- Providers must opt in to participate in the exchange
- Only government-authorized data elements may be shared
Correct answer: Patients must affirmatively agree before their data is shared through the HIE
An opt-in model requires explicit patient consent before their health information is shared, giving patients more control over their data.
Question 3: A nurse accesses the medical records of a celebrity patient out of curiosity, with no clinical justification. This is an example of:
- Incidental disclosure
- Insider threat and privacy violation (Correct answer)
- Permitted use under the treatment exception
- A de minimis security incident
Correct answer: Insider threat and privacy violation
Accessing PHI without a legitimate need constitutes an insider threat and a HIPAA privacy violation, regardless of the employee's good intentions.
Question 4: Which encryption standard is commonly recommended for protecting ePHI in transit in U.S. healthcare?
- DES (Data Encryption Standard)
- MD5 hashing
- TLS (Transport Layer Security) (Correct answer)
- Base64 encoding
Correct answer: TLS (Transport Layer Security)
TLS is the standard protocol for encrypting data in transit, protecting ePHI from interception during transmission.
Question 5: A patient requests an amendment to their medical record because they believe it contains an error. Under HIPAA, the covered entity may deny the request if:
- The record was created more than two years ago
- The information was not created by the covered entity (Correct answer)
- The patient cannot provide a written rationale
- The amendment would increase the size of the record
Correct answer: The information was not created by the covered entity
A covered entity may deny an amendment request if the information was not created by that entity, as it may lack the context to assess accuracy.
Question 6: What is the primary purpose of a HIPAA Security Risk Assessment?
- To train staff on phishing awareness
- To identify and evaluate potential vulnerabilities to ePHI confidentiality, integrity, and availability (Correct answer)
- To audit billing codes for compliance
- To verify that all staff have completed privacy training
Correct answer: To identify and evaluate potential vulnerabilities to ePHI confidentiality, integrity, and availability
A security risk assessment systematically identifies threats and vulnerabilities to ePHI to guide the implementation of appropriate safeguards.
Question 7: Under the HIPAA Privacy Rule, which of the following does NOT require patient authorization for disclosure?
- Disclosure to a marketing company for product promotion
- Disclosure for payment of healthcare services (Correct answer)
- Disclosure to a life insurance company at the patient's request
- Disclosure for research with IRB waiver of authorization
Correct answer: Disclosure for payment of healthcare services
HIPAA permits covered entities to use and disclose PHI for treatment, payment, and healthcare operations without patient authorization.
Which HIPAA rule specifically requires covered entities to implement administrative, physical, and technical safeguards for ePHI?