CCM Ethical & Legal Issues in Care Management 2 — Questions and Answers
Question 1: Under HIPAA, which category of information is protected from unauthorized disclosure?
- Only electronically stored health information
- Only written medical records
- Protected Health Information (PHI) in any form (Correct answer)
- Only information shared between providers
Correct answer: Protected Health Information (PHI) in any form
HIPAA protects PHI in all forms — electronic, written, and oral — from unauthorized disclosure.
Question 2: A care manager may legally share a patient's health information without explicit written authorization when it is for:
- A family member who requests it verbally
- Another provider for marketing research
- Treatment, payment, or healthcare operations (TPO) (Correct answer)
- The patient's employer upon request
Correct answer: Treatment, payment, or healthcare operations (TPO)
HIPAA permits disclosure of PHI without specific patient authorization for treatment, payment, and healthcare operations purposes.
Question 3: A patient's right to access and receive copies of their own medical records is primarily protected under:
- The Americans with Disabilities Act
- HIPAA's Privacy Rule (Correct answer)
- The Affordable Care Act
- ERISA
Correct answer: HIPAA's Privacy Rule
HIPAA's Privacy Rule grants patients the right to inspect, access, and obtain copies of their own protected health information.
Question 4: In which situation is a care manager legally REQUIRED to breach patient confidentiality?
- When a supervisor requests patient details for a meeting
- When the patient's adult children are worried about their health
- When there is a credible threat of harm to an identifiable third party (Correct answer)
- When a payer requires additional clinical documentation
Correct answer: When there is a credible threat of harm to an identifiable third party
The duty to warn requires care managers to breach confidentiality when a patient poses a credible, specific threat of harm to an identifiable third party.
Question 5: For informed consent to be legally and ethically valid, the patient must:
- Simply sign a consent form prepared by the provider
- Understand the proposed plan, its risks, benefits, and alternatives (Correct answer)
- Agree to all recommendations made by the care team
- Provide consent only once at the start of care
Correct answer: Understand the proposed plan, its risks, benefits, and alternatives
Valid informed consent requires that patients receive, comprehend, and voluntarily agree to information about the proposed plan including its risks, benefits, and alternatives.
Question 6: When a patient has been determined to lack decision-making capacity, healthcare decisions should be made by:
- A court for every individual decision required
- A legally designated surrogate acting in the patient's best interest (Correct answer)
- The care manager as the patient's primary advocate
- The treatment team by consensus without a surrogate
Correct answer: A legally designated surrogate acting in the patient's best interest
When a patient lacks capacity, a legally designated surrogate or proxy makes decisions based on the patient's previously expressed wishes or best interests.
Question 7: Which legal document allows a competent patient to specify their healthcare wishes in the event they become incapacitated?
- A living will or advance directive (Correct answer)
- A general durable power of attorney
- A HIPAA authorization form
- A do-not-hospitalize order signed by the physician
Correct answer: A living will or advance directive
An advance directive or living will is a legal document completed while the patient has capacity that specifies their healthcare preferences for future incapacity.
Under HIPAA, which category of information is protected from unauthorized disclosure?