CEHRS HIPAA and Patient Confidentiality 3 — Questions and Answers
Question 1: An EHR specialist accidentally emails a patient's lab results to the wrong patient. Under HIPAA's Breach Notification Rule, this is most likely classified as:
- A security incident requiring no notification
- A breach requiring notification unless a low probability of compromise is demonstrated (Correct answer)
- An incidental disclosure exempt from notification
- A minor violation requiring only internal documentation
Correct answer: A breach requiring notification unless a low probability of compromise is demonstrated
Unauthorized disclosures are presumed to be breaches unless the covered entity can demonstrate a low probability that PHI was compromised through a four-factor risk assessment.
Question 2: How long must covered entities retain HIPAA-related documentation, such as policies and procedures?
- 3 years from creation or last effective date
- 6 years from creation or last effective date (Correct answer)
- 7 years from creation or last effective date
- 10 years from creation or last effective date
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain documentation for 6 years from the date of its creation or the date it was last in effect, whichever is later.
Question 3: Which type of PHI de-identification method requires a statistician to certify that the risk of re-identification is very small?
- Safe Harbor method
- Expert Determination method (Correct answer)
- Limited Data Set method
- Minimum Necessary method
Correct answer: Expert Determination method
The Expert Determination method requires a qualified statistical expert to certify that the risk of identifying an individual is very small.
Question 4: A covered entity may share PHI with law enforcement WITHOUT patient authorization in which situation?
- When an attorney requests records for a civil lawsuit
- To report a crime that occurred on the premises (Correct answer)
- When an employer requests information about an employee's injury
- To share with a life insurance company for policy underwriting
Correct answer: To report a crime that occurred on the premises
HIPAA permits disclosure to law enforcement to report a crime that occurred on the premises or to alert law enforcement to a crime committed against the covered entity's personnel.
Question 5: Under HIPAA, which of the following disclosures requires an OPPORTUNITY for the patient to agree or object?
- Disclosure to the patient's treating physician
- Disclosure to a health oversight agency
- Disclosure of PHI in a facility directory to callers who ask by name (Correct answer)
- Disclosure for public health reporting of communicable diseases
Correct answer: Disclosure of PHI in a facility directory to callers who ask by name
Facilities must give patients the opportunity to object to or restrict inclusion of their information in the facility directory before the information is disclosed.
Question 6: Which government agency is primarily responsible for enforcing HIPAA's Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Department of Justice (DOJ)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Federal Trade Commission (FTC)
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary enforcer of HIPAA's Privacy and Security Rules and investigates complaints.
Question 7: A patient's adult child calls asking for information about the patient's diagnosis. The patient has not provided authorization. The EHR specialist should:
- Provide the information since it is an immediate family member
- Provide general condition information only if clinically appropriate
- Verify the caller's identity and then share the full medical record
- Decline to confirm or deny whether the person is a patient (Correct answer)
Correct answer: Decline to confirm or deny whether the person is a patient
Without patient authorization or a healthcare power of attorney, the EHR specialist should not confirm or deny the individual's status as a patient or share any PHI.
An EHR specialist accidentally emails a patient's lab results to the wrong patient.
Under HIPAA's Breach Notification Rule, this is most likely classified as: