CEHRS Information Management and Privacy 2 — Questions and Answers
Question 1: Under HIPAA, a covered entity must respond to a patient's request to access their PHI within how many days?
- 15 days
- 30 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
HIPAA requires covered entities to act on a patient's access request within 30 days, with a possible 30-day extension (60 days total).
Question 2: Which type of EHR audit log entry would BEST identify unauthorized access to a patient record?
- A log showing the patient's diagnosis changes
- A log showing which user accessed the record and at what time (Correct answer)
- A log showing the number of pages printed
- A log showing the system backup timestamp
Correct answer: A log showing which user accessed the record and at what time
Audit logs that capture user identity, record accessed, and timestamp are the primary tool for detecting and investigating unauthorized access.
Question 3: A patient calls asking for their lab results to be faxed directly to their employer. What should the EHR specialist do?
- Fax the results immediately since the patient requested it
- Obtain a valid written authorization from the patient before releasing (Correct answer)
- Refuse the request entirely as employer disclosures are prohibited
- Consult the attending physician before taking any action
Correct answer: Obtain a valid written authorization from the patient before releasing
Releasing PHI to an employer requires a valid patient authorization because employers are not covered entities and this disclosure exceeds standard TPO purposes.
Question 4: Which HIPAA Privacy Rule provision allows a patient to request that a specific disclosure of their PHI not be made to their health plan?
- Right to amend
- Right to an accounting of disclosures
- Right to request restrictions (Correct answer)
- Right to confidential communications
Correct answer: Right to request restrictions
The right to request restrictions permits patients to ask covered entities to limit certain uses or disclosures, including to health plans when the patient pays out-of-pocket in full.
Question 5: An EHR system automatically generates a summary of a patient's visit and sends it to a referring physician. This is an example of PHI disclosure for which purpose?
- Marketing
- Treatment (Correct answer)
- Payment
- Health care operations
Correct answer: Treatment
Sharing clinical information with a referring physician to coordinate care is a treatment-related disclosure, which does not require patient authorization.
Question 6: Which of the following best describes a 'minimum necessary' determination when releasing PHI?
- Release only the information reasonably needed to accomplish the intended purpose (Correct answer)
- Release the complete medical record to avoid missing relevant details
- Release only information that is less than one page in length
- Release information only after legal counsel reviews each request
Correct answer: Release only the information reasonably needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to limit PHI to the least amount needed to fulfill the specific purpose of the disclosure.
Question 7: A patient wants to know who has accessed their EHR over the past two years. Which HIPAA right allows this request?
- Right to access
- Right to amend
- Right to an accounting of disclosures (Correct answer)
- Right to confidential communications
Correct answer: Right to an accounting of disclosures
The right to an accounting of disclosures entitles patients to a list of certain disclosures made outside of TPO purposes for up to six years.
Under HIPAA, a covered entity must respond to a patient's request to access their PHI within how many days?