CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 3 — Questions and Answers
Question 1: Under HIPAA's 'minimum necessary' standard, what must a healthcare access associate consider when requesting or using patient information?
- Access all available PHI to ensure the most comprehensive care possible
- Use only the minimum amount of PHI reasonably needed to accomplish the intended purpose (Correct answer)
- Share PHI freely among all care team members to improve coordination
- Request the maximum amount of PHI available to avoid making follow-up requests
Correct answer: Use only the minimum amount of PHI reasonably needed to accomplish the intended purpose
The minimum necessary standard requires that covered entities limit access and disclosure of PHI to only what is needed for the specific task at hand. Staff should not routinely access or share more patient information than necessary for their role.
Question 2: What is the primary purpose of a Business Associate Agreement (BAA) under HIPAA?
- To allow patients to authorize family members to receive their PHI
- To legally obligate a third-party vendor handling PHI to protect it according to HIPAA standards (Correct answer)
- To document an internal hospital policy for staff data access
- To establish a pricing agreement between two competing healthcare facilities
Correct answer: To legally obligate a third-party vendor handling PHI to protect it according to HIPAA standards
A BAA is a required contract between a covered entity and a business associate (any vendor or third party that handles PHI on behalf of the covered entity). It ensures the business associate will appropriately safeguard the PHI they access or process.
Question 3: Under the HIPAA Breach Notification Rule, within how many days must a covered entity notify affected individuals following discovery of a breach of unsecured PHI?
- 24 hours
- 30 days
- 60 days (Correct answer)
- 180 days
Correct answer: 60 days
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI. If the breach affects more than 500 residents of a state, prominent media outlets must also be notified.
Question 4: Which of the following is NOT one of the 18 identifiers that make health information 'individually identifiable' under HIPAA?
- Social Security Number
- Email address
- Blood type (Correct answer)
- Dates other than year (e.g., date of birth)
Correct answer: Blood type
Blood type is not among the 18 HIPAA identifiers. The 18 identifiers include names, geographic data, specific dates, SSNs, phone/fax numbers, email addresses, medical record numbers, biometric identifiers, and others — but not clinical values like blood type or diagnosis codes on their own.
Question 5: A patient's right to an 'accounting of disclosures' under the HIPAA Privacy Rule entitles them to:
- A complete list of every healthcare provider who has ever treated them
- A summary of all insurance payments made on their behalf
- A log of disclosures of their PHI made without their authorization over the past six years (Correct answer)
- A copy of every clinical note written about them by their physicians
Correct answer: A log of disclosures of their PHI made without their authorization over the past six years
The right to an accounting of disclosures allows patients to request a record of when and to whom their PHI was disclosed without their authorization (e.g., for public health reporting or law enforcement). It does not cover disclosures made for treatment, payment, or healthcare operations.
Question 6: Which category of safeguards under the HIPAA Security Rule covers physical measures such as facility access controls, workstation security policies, and device and media controls?
- Technical safeguards
- Administrative safeguards
- Organizational safeguards
- Physical safeguards (Correct answer)
Correct answer: Physical safeguards
Physical safeguards address the tangible, real-world protections for systems containing electronic PHI — things like locked server rooms, badge access to workstations, and policies for disposing of hardware. Technical safeguards cover software/encryption controls, while administrative safeguards cover policies and workforce training.
Under HIPAA's 'minimum necessary' standard, what must a healthcare access associate consider when requesting or using patient information?