AHIMA HIPAA Privacy and Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is the minimum necessary standard designed to protect?
- All patient records from any disclosure
- PHI disclosed to only the minimum amount needed to accomplish the purpose (Correct answer)
- Only electronic health records from breaches
- Protected information from being used for treatment purposes
Correct answer: PHI disclosed to only the minimum amount needed to accomplish the purpose
The minimum necessary standard requires covered entities to limit PHI disclosures to only what is reasonably necessary to accomplish the intended purpose.
Question 2: A Business Associate Agreement (BAA) is required when a vendor:
- Sells office supplies to a covered entity
- Creates, receives, maintains, or transmits PHI on behalf of a covered entity (Correct answer)
- Provides janitorial services and never accesses records
- Only handles de-identified data
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is legally required whenever a vendor performs functions or activities on behalf of a covered entity that involve PHI.
Question 3: Which HIPAA rule specifically governs the administrative, physical, and technical safeguards for ePHI?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule establishes national standards for protecting electronic protected health information through administrative, physical, and technical safeguards.
Question 4: Which of the following represents a permissible disclosure of PHI without patient authorization under HIPAA?
- Sharing PHI with an employer for performance review
- Disclosing PHI to a marketing company for targeted ads
- Reporting communicable disease information to a public health authority (Correct answer)
- Selling PHI to a pharmaceutical company for research
Correct answer: Reporting communicable disease information to a public health authority
HIPAA permits disclosure of PHI to public health authorities for disease surveillance and reporting without patient authorization.
Question 5: When a patient requests an amendment to their health record and the covered entity denies it, the entity must:
- Delete the original record entry
- Allow the patient to submit a statement of disagreement (Correct answer)
- Notify the patient's insurance company of the denial
- Immediately report the denial to HHS
Correct answer: Allow the patient to submit a statement of disagreement
If a covered entity denies an amendment request, the patient has the right to submit a statement of disagreement that must be appended to their record.
Question 6: Which of the following is NOT considered Protected Health Information (PHI) under HIPAA?
- A patient's date of birth linked to a diagnosis
- A patient's name combined with their prescription information
- De-identified statistical health data (Correct answer)
- An MRI scan with the patient's name
Correct answer: De-identified statistical health data
De-identified health information that has had all 18 identifying elements removed does not meet the definition of PHI and is not protected under HIPAA.
Question 7: Under the HIPAA Privacy Rule, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon written request
- At first service delivery and upon request thereafter (Correct answer)
- Annually regardless of patient contact
- Only when PHI is disclosed to a third party
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP to patients at the first point of service delivery and make it available upon request at any time.
Under HIPAA, which of the following is the minimum necessary standard designed to protect?