CCT HIPAA Privacy and Security 4 — Questions and Answers
Question 1: Which of the following transactions is covered under HIPAA's Electronic Transaction Standards?
- Email between two physicians
- Electronic claims submission (837 transaction set) (Correct answer)
- Social media postings about patient outcomes
- Online appointment scheduling without PHI
Correct answer: Electronic claims submission (837 transaction set)
HIPAA's Transaction Standards mandate the use of standard electronic formats (like the 837 claim) for healthcare financial and administrative transactions.
Question 2: What is the primary purpose of a HIPAA Risk Analysis?
- To train employees on privacy policies
- To identify potential threats and vulnerabilities to ePHI confidentiality, integrity, and availability (Correct answer)
- To calculate the cost of HIPAA compliance
- To audit business associates annually
Correct answer: To identify potential threats and vulnerabilities to ePHI confidentiality, integrity, and availability
A HIPAA Risk Analysis identifies threats, vulnerabilities, and the likelihood and impact of potential risks to ePHI as the foundation of the security management process.
Question 3: Under HIPAA, 'treatment' as a basis for PHI use/disclosure refers to:
- Only the primary treating physician
- Provision, coordination, or management of healthcare and related services by providers (Correct answer)
- Psychological counseling only
- Preventive care services only
Correct answer: Provision, coordination, or management of healthcare and related services by providers
HIPAA broadly defines 'treatment' to include provision, coordination, and management of healthcare by one or more providers, including referrals.
Question 4: An individual's right to an accounting of disclosures under HIPAA applies to disclosures made for which purpose?
- Treatment, payment, and operations
- Public interest disclosures made without authorization (Correct answer)
- All disclosures regardless of purpose
- Disclosures within the same covered entity only
Correct answer: Public interest disclosures made without authorization
The right to an accounting of disclosures covers most disclosures made without authorization, but generally excludes those for TPO (treatment, payment, operations).
Question 5: Which office within HHS is primarily responsible for enforcing HIPAA Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) (Correct answer)
- Office of the Inspector General (OIG)
- Food and Drug Administration (FDA)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Question 6: Under HIPAA, psychotherapy notes receive special protection because:
- They are subject to state law only
- They are separated from the medical record and require explicit authorization for most disclosures (Correct answer)
- They are not considered PHI
- They may only be disclosed to other mental health providers
Correct answer: They are separated from the medical record and require explicit authorization for most disclosures
Psychotherapy notes are singled out under HIPAA for heightened protection and generally require individual authorization for disclosure, even for TPO purposes.
Question 7: A small physician practice with fewer than 10 full-time employees that transmits claims electronically is considered a:
- Hybrid entity
- Small business associate
- Covered entity (Correct answer)
- Exempt provider
Correct answer: Covered entity
Any healthcare provider that transmits health information in electronic form in connection with a HIPAA-covered transaction is a covered entity, regardless of size.
Which of the following transactions is covered under HIPAA's Electronic Transaction Standards?