CEHRS - Certified Electronic Health Records Specialist HIPAA and Patient Confidentiality Questions and Answers 1 — Questions and Answers
Question 1: A CEHRS is working at the registration desk when a patient's friend approaches and asks for an update on the patient's condition. The friend is not listed on any of the patient's authorization forms. Which of the following is the MOST appropriate response?
- "I can confirm they are here, but you will need to speak directly with the patient for any health updates."
- "I'm sorry, but due to privacy laws, I cannot confirm or deny whether that person is a patient here." (Correct answer)
- "Let me check the chart quickly to see if I can give you a general update."
- "The patient is doing fine, but for more details, you should wait for the doctor."
Correct answer: "I'm sorry, but due to privacy laws, I cannot confirm or deny whether that person is a patient here."
According to HIPAA, a covered entity cannot disclose any Protected Health Information (PHI) to individuals not authorized by the patient. Even confirming that someone is a patient is a disclosure of PHI. Therefore, the safest and most compliant response is to neither confirm nor deny the person's patient status.
Question 2: The HIPAA Security Rule requires covered entities to implement specific safeguards to protect electronic protected health information (ePHI). Which of the following is an example of an administrative safeguard?
- Installing encrypted software on all workstations.
- Positioning computer monitors to prevent viewing by the public.
- Implementing policies for sanctioning employees who violate HIPAA. (Correct answer)
- Using key card access for rooms containing servers with ePHI.
Correct answer: Implementing policies for sanctioning employees who violate HIPAA.
Administrative safeguards are defined as 'administrative actions, and policies and procedures, to manage the selection, development, implementation, and maintenance of security measures to protect ePHI...' A sanction policy is a required administrative action. Encrypted software is a technical safeguard, monitor positioning is a physical safeguard, and key card access is a physical safeguard.
Question 3: A CEHRS receives a request from the billing department for a patient's entire medical record to verify a single service date. Which HIPAA principle should guide the CEHRS's response?
- Patient's Right of Access
- Minimum Necessary Standard (Correct answer)
- Breach Notification Rule
- Notice of Privacy Practices
Correct answer: Minimum Necessary Standard
The Minimum Necessary Standard requires covered entities to make reasonable efforts to limit the use or disclosure of PHI to the minimum necessary to accomplish the intended purpose. Releasing the entire record when only a service date is needed would violate this principle. The CEHRS should provide only the specific information required.
Question 4: During a busy clinic session, a CEHRS accidentally hands a patient a visit summary belonging to another patient. The patient returns the document immediately. What is the CEHRS's first and most critical action?
- Shred the document immediately to destroy the evidence.
- Apologize to the patient and ask them not to tell anyone.
- Report the incident to the designated Privacy Officer. (Correct answer)
- Wait to see if the patient whose information was disclosed files a complaint.
Correct answer: Report the incident to the designated Privacy Officer.
Any accidental disclosure of PHI, even if seemingly minor, must be reported internally to the designated Privacy or Security Officer. The Privacy Officer is responsible for investigating the incident, performing a risk assessment to determine if it constitutes a reportable breach, and documenting the event according to facility policy and HIPAA regulations.
Question 5: Which of the following is a primary purpose of the Notice of Privacy Practices (NPP) given to patients?
- To obtain a patient's consent for all future treatments and procedures.
- To serve as a legal waiver protecting the facility from all lawsuits.
- To inform patients of their privacy rights and how their PHI may be used. (Correct answer)
- To collect emergency contact and insurance information from the patient.
Correct answer: To inform patients of their privacy rights and how their PHI may be used.
The HIPAA Privacy Rule requires covered entities to provide patients with a Notice of Privacy Practices (NPP). This document's purpose is to detail how their Protected Health Information (PHI) may be used and disclosed for treatment, payment, and operations, and to inform them of their legal rights regarding their PHI, such as the right to access their records.
Question 6: A patient submits a written request for a copy of their electronic health record to be sent to their personal email. According to the HIPAA Privacy Rule's Right of Access, what is the covered entity's obligation?
- To refuse the request, as email is not a secure method of transmission.
- To mail a paper copy to the patient's home address instead.
- To provide the record in the requested electronic format, after informing the patient of the risks. (Correct answer)
- To require the patient to come to the office and view the record on-screen only.
Correct answer: To provide the record in the requested electronic format, after informing the patient of the risks.
The HIPAA Privacy Rule's right of access requires a covered entity to provide individuals with access to their PHI in the form and format they request, if it is readily producible. If a patient requests their EHR be sent to an unsecure email, the provider must do so after warning the patient of the associated security risks.
A CEHRS is working at the registration desk when a patient's friend approaches and asks for an update on the patient's condition.
The friend is not listed on any of the patient's authorization forms.
Which of the following is the MOST appropriate response?