Client Confidentiality and HIPAA Flashcards
7 cards from real CBHT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Client Confidentiality and HIPAA flashcards as text
A client in a residential program asks to review their own behavioral health records. Under HIPAA, the facility must generally provide access within how many days of the request?
Answer: 30 days, with a possible 30-day extension
HIPAA requires covered entities to act on a client's access request within 30 days, with one 30-day extension if the client is notified in writing.
Which scenario best illustrates a HIPAA 'minimum necessary' violation?
Answer: A BHT copies an entire psychiatric history to share with a billing clerk who only needs the diagnosis code
The minimum necessary standard requires disclosing only the information needed for the specific purpose; sharing a full history when only a code is needed violates this standard.
42 CFR Part 2 provides additional confidentiality protections beyond HIPAA for clients with records related to:
Answer: Substance use disorder treatment
42 CFR Part 2 imposes stricter confidentiality rules on records related to substance use disorder treatment programs that receive federal assistance.
A BHT's family member asks about a neighbor who is a client at the BHT's facility. The BHT should:
Answer: Decline to confirm or provide any information and explain they cannot discuss clients
BHTs must not disclose any client information to unauthorized individuals, including family members, regardless of the relationship.
When a client provides written authorization for the release of their records, which element is NOT required on the authorization form?
Answer: The client's insurance policy number
A valid HIPAA authorization requires a description of the information, the recipient, an expiration date/event, and the client's signature — but does not require an insurance policy number.
A BHT working in a group home notices that client charts are left open on a shared computer in a common hallway. This is a concern because:
Answer: It may allow unauthorized individuals to view PHI, violating the HIPAA Security Rule's physical safeguard requirements
Electronic PHI must be protected by physical safeguards including workstation controls that prevent unauthorized viewing.
A client expresses suicidal ideation with a specific plan. Disclosing this information to emergency services without the client's consent is:
Answer: Permissible under HIPAA when necessary to prevent a serious and imminent threat to the client's safety
HIPAA permits disclosure to prevent serious and imminent threats to the health or safety of the individual or others, including to emergency responders.