CET Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under HIPAA's minimum necessary standard, a sonographer sharing echocardiography results should disclose:
- All available clinical history for context
- Only the information required for the specific purpose (Correct answer)
- The complete imaging report and raw DICOM files
- PHI only after obtaining written patient authorization each time
Correct answer: Only the information required for the specific purpose
The minimum necessary standard limits disclosure to only the information needed to accomplish the intended purpose.
Question 2: A patient requests a copy of their echocardiogram report. Under HIPAA, the covered entity must provide access within:
- 24 hours of the request
- 30 days, with a possible 30-day extension (Correct answer)
- 7 business days
- 60 days with no extension permitted
Correct answer: 30 days, with a possible 30-day extension
HIPAA requires covered entities to provide access to PHI within 30 days, extendable by another 30 days with written notice.
Question 3: Which situation represents a permitted disclosure of PHI without patient authorization under HIPAA?
- Sharing results with a patient's employer for benefits verification
- Releasing images to a marketing company for case studies
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Disclosing echo findings to the patient's attorney without a subpoena
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosures required by law, including mandatory reporting of certain injuries to law enforcement.
Question 4: When transmitting echocardiography images electronically, HIPAA Security Rule requires:
- Encryption only for data stored on portable devices
- Encryption and access controls for all ePHI in transit and at rest (Correct answer)
- Password protection without encryption for internal network transfers
- Only audit logs with no encryption requirement for intra-facility transfers
Correct answer: Encryption and access controls for all ePHI in transit and at rest
The HIPAA Security Rule requires administrative, physical, and technical safeguards—including encryption and access controls—for all electronic PHI.
Question 5: A HIPAA breach involving unsecured PHI of 600 patients requires notification to:
- Patients only, within 60 days
- Patients and HHS; media notification is also required for breaches over 500 in a state (Correct answer)
- HHS only; patient notification is optional for breaches under 1,000
- State health department exclusively
Correct answer: Patients and HHS; media notification is also required for breaches over 500 in a state
Breaches affecting 500+ individuals in a state or jurisdiction require notification to patients, HHS, and prominent media outlets in that state.
Question 6: Which action would violate the HIPAA Privacy Rule in an echo lab setting?
- Discussing a patient's results with the ordering cardiologist
- Posting a de-identified case image in an educational seminar
- Leaving a printed echo report visible at an unattended workstation (Correct answer)
- Using a password-protected portal to share results with a referring physician
Correct answer: Leaving a printed echo report visible at an unattended workstation
Leaving PHI visible and unattended violates the Privacy Rule's requirement to protect against incidental disclosures.
Question 7: A patient revokes their authorization for a research study using their echo images. The covered entity must:
- Continue the study since authorization was already given
- Honor the revocation for future use but may retain already-collected data (Correct answer)
- Destroy all previously collected images immediately
- Require the patient to submit the revocation in writing to the IRB directly
Correct answer: Honor the revocation for future use but may retain already-collected data
Revocation stops future use of PHI but does not retroactively invalidate actions already taken under the original authorization.
Under HIPAA's minimum necessary standard, a sonographer sharing echocardiography results should disclose: