Client Confidentiality and HIPAA Flashcards
7 cards from real CBHT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Client Confidentiality and HIPAA flashcards as text
A BHT is working with a client whose case is being discussed in a multidisciplinary team meeting. Which staff member should NOT receive full access to the client's PHI?
Answer: The facility's receptionist who is not involved in the client's treatment
The minimum necessary standard limits access to PHI to staff who have a treatment-related need; a receptionist not involved in care does not qualify.
Under HIPAA, a 'covered entity' in behavioral health includes:
Answer: A licensed outpatient mental health clinic that transmits health information electronically
Covered entities include health care providers that transmit health information electronically in connection with covered transactions, such as billing.
A client's attorney sends a subpoena for the client's mental health records. The BHT's supervisor should:
Answer: Consult the facility's legal counsel before releasing any records, as a subpoena alone may not override confidentiality
A subpoena is not always sufficient to override HIPAA protections; a court order or client authorization may be required, and legal counsel should advise on the appropriate response.
Which of the following best describes a 'business associate' under HIPAA?
Answer: A third-party entity that performs services for a covered entity and handles PHI in doing so
A business associate is an outside person or organization that performs functions on behalf of a covered entity that involve the use or disclosure of PHI.
A BHT accidentally views another staff member's personal health record while logged into the electronic health record system. The appropriate action is to:
Answer: Immediately exit the record, refrain from sharing any information seen, and report the accidental access to a supervisor
Accidental access to PHI should be immediately terminated, information should not be shared, and the incident should be reported according to facility policy.
Texting a client's name and diagnosis to another clinician using a personal, non-encrypted cell phone most directly violates which HIPAA rule?
Answer: The Security Rule, which requires administrative, physical, and technical safeguards for electronic PHI
Sending PHI via unencrypted personal devices violates the HIPAA Security Rule's requirement for appropriate technical safeguards protecting electronic PHI.
A client revokes a previously signed authorization for release of records. The BHT should:
Answer: Honor the revocation in writing and stop further disclosures, unless disclosures have already been made in reliance on the authorization
Clients have the right to revoke a HIPAA authorization at any time in writing, and the facility must honor the revocation except for disclosures already made.