AHIMA Compliance and Legal 3 — Questions and Answers
Question 1: A valid authorization for release of PHI under HIPAA must contain which required element?
- The Social Security number of the patient
- An expiration date or expiration event (Correct answer)
- The signature of the treating physician
- The facility's Joint Commission accreditation number
Correct answer: An expiration date or expiration event
A HIPAA-compliant authorization must include an expiration date or expiration event (e.g., one year from the date of signature or upon completion of a research study).
Question 2: Under HIPAA's Minimum Necessary Standard, a covered entity must:
- Disclose only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Redact all demographic information before any disclosure
- Obtain separate authorizations for each data field disclosed
- Disclose complete records whenever requested by any provider
Correct answer: Disclose only the minimum amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires that covered entities make reasonable efforts to limit PHI disclosed to the smallest amount necessary to accomplish the intended purpose.
Question 3: The Stark Law (Physician Self-Referral Law) is primarily a:
- Criminal statute requiring intent
- Civil statute with strict liability (Correct answer)
- State licensure regulation
- Voluntary compliance guideline
Correct answer: Civil statute with strict liability
The Stark Law is a civil strict-liability statute, meaning a violation can occur without any intent to violate the law, making compliance programs especially critical.
Question 4: A patient requests amendment of their medical record, claiming a diagnosis is incorrect. The covered entity may deny the request if:
- The record was created more than one year ago
- The information was created by another provider and is accurate and complete (Correct answer)
- The patient did not submit the request in writing
- The diagnosis was entered by a licensed physician
Correct answer: The information was created by another provider and is accurate and complete
A covered entity may deny an amendment request if the PHI was not created by the entity and it believes the originating provider is better positioned to assess accuracy.
Question 5: Which act requires healthcare facilities to treat or stabilize patients presenting to emergency departments regardless of their ability to pay?
- Hill-Burton Act
- Anti-Kickback Statute
- EMTALA (Correct answer)
- Medicare Conditions of Participation
Correct answer: EMTALA
EMTALA (Emergency Medical Treatment and Labor Act) mandates that hospitals participating in Medicare provide a medical screening exam and stabilizing treatment regardless of insurance or ability to pay.
Question 6: In healthcare compliance, a 'corporate integrity agreement' (CIA) is typically entered into between a provider and:
- The Joint Commission
- The Office of Inspector General (OIG) (Correct answer)
- CMS
- State Medicaid agency
Correct answer: The Office of Inspector General (OIG)
Corporate Integrity Agreements are negotiated between the OIG and providers as an alternative to exclusion from federal healthcare programs following fraud or abuse settlements.
Question 7: A covered entity must provide patients with a Notice of Privacy Practices (NPP):
- Only at initial treatment, never again
- At first service delivery and upon request thereafter (Correct answer)
- Only when there has been a breach
- Annually to all patients on file
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP no later than the first date of service and must make it available upon request at any subsequent time.
A valid authorization for release of PHI under HIPAA must contain which required element?