CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 4 — Questions and Answers
Question 1: Under HIPAA's 'minimum necessary' standard, when a healthcare access associate requests patient information, they should:
- Request the complete medical record for every patient encounter
- Access only the information needed to accomplish the intended purpose (Correct answer)
- Share all available PHI with any staff member who asks
- Obtain written patient consent before viewing any records
Correct answer: Access only the information needed to accomplish the intended purpose
The minimum necessary standard requires that covered entities limit PHI access and disclosure to the least amount needed to accomplish the intended purpose, reducing unnecessary exposure of patient information.
Question 2: A patient requests a copy of their medical records. Under the HIPAA Privacy Rule, a covered entity must provide access within:
- 7 calendar days of the request
- 30 days, with one possible 30-day extension (Correct answer)
- 60 days, with no extensions allowed
- 90 days if records are stored off-site
Correct answer: 30 days, with one possible 30-day extension
HIPAA requires covered entities to provide patients access to their PHI within 30 days of the request, with a single 30-day extension allowed if the entity notifies the patient in writing of the delay and reason.
Question 3: Which of the following is an example of a Business Associate under HIPAA?
- A physician employed directly by a hospital
- A billing company that processes claims containing PHI on behalf of a covered entity (Correct answer)
- A patient who requests copies of their own health records
- A health plan member reviewing their own explanation of benefits
Correct answer: A billing company that processes claims containing PHI on behalf of a covered entity
A Business Associate is a person or entity that performs functions or services for a covered entity involving the use or disclosure of PHI. A billing company handling claims data on the covered entity's behalf meets this definition and must sign a Business Associate Agreement (BAA).
Question 4: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach of unsecured PHI within:
- 24 hours of discovery
- 60 calendar days of discovery (Correct answer)
- 30 business days of discovery
- 6 months of discovery
Correct answer: 60 calendar days of discovery
The Breach Notification Rule requires covered entities to notify affected individuals within 60 calendar days of discovering a breach of unsecured PHI. For breaches affecting 500 or more individuals, prominent media notification and HHS notification are also required within the same timeframe.
Question 5: Which of the following safeguard categories is required under the HIPAA Security Rule to protect electronic PHI (ePHI)?
- Administrative, Physical, and Technical safeguards (Correct answer)
- Clinical, Financial, and Operational safeguards
- Legal, Ethical, and Procedural safeguards
- Preventive, Detective, and Corrective safeguards
Correct answer: Administrative, Physical, and Technical safeguards
The HIPAA Security Rule organizes its protections into three categories: Administrative safeguards (policies and procedures), Physical safeguards (facility and device controls), and Technical safeguards (technology controls like encryption and access controls) — all three are required.
Question 6: A healthcare access associate may disclose a patient's PHI without obtaining prior authorization for which of the following purposes?
- Marketing a new hospital service to the patient
- Sharing records with the patient's employer upon request
- Treatment, payment, and healthcare operations (TPO) (Correct answer)
- Releasing information to a patient's attorney
Correct answer: Treatment, payment, and healthcare operations (TPO)
HIPAA permits covered entities to use and disclose PHI without patient authorization for treatment, payment, and healthcare operations (TPO). These are considered essential functions of healthcare delivery and do not require prior written consent, though the patient must be informed via the Notice of Privacy Practices.
Under HIPAA's 'minimum necessary' standard, when a healthcare access associate requests patient information, they should: