CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 6 — Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, what principle must covered entities follow when using or disclosing PHI?
- Share all available PHI whenever treatment is involved
- Disclose only the amount of PHI reasonably needed to accomplish the intended purpose (Correct answer)
- Obtain patient consent before sharing any information internally
- Encrypt all PHI before any disclosure regardless of purpose
Correct answer: Disclose only the amount of PHI reasonably needed to accomplish the intended purpose
The Minimum Necessary Standard requires covered entities to make reasonable efforts to limit PHI use and disclosure to what is needed for the specific purpose, reducing unnecessary exposure of patient information.
Question 2: Which of the following is NOT one of the 18 identifiers that make health information considered Protected Health Information (PHI)?
- Patient's date of birth
- Patient's blood type alone (Correct answer)
- Patient's telephone number
- Patient's medical record number
Correct answer: Patient's blood type alone
Blood type by itself is a clinical value not on HIPAA's list of 18 identifiers. Dates, phone numbers, and medical record numbers are all listed identifiers that, combined with health data, create PHI.
Question 3: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within how many days of discovery?
- 30 days
- 45 days
- 60 days (Correct answer)
- 60 calendar days
Correct answer: 60 days
HIPAA requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.
Question 4: What is a Business Associate Agreement (BAA) under HIPAA?
- A contract between a patient and their insurance provider
- An agreement between a covered entity and a vendor who handles PHI on its behalf (Correct answer)
- A government form required when submitting Medicare claims
- An internal policy document outlining employee privacy responsibilities
Correct answer: An agreement between a covered entity and a vendor who handles PHI on its behalf
A BAA is a required written contract between a covered entity and a business associate — any third party that creates, receives, or transmits PHI on behalf of that entity — ensuring the associate safeguards the information.
Question 5: Under the HIPAA Security Rule, which category of safeguards covers physical measures such as workstation security and facility access controls?
- Administrative safeguards
- Technical safeguards
- Physical safeguards (Correct answer)
- Operational safeguards
Correct answer: Physical safeguards
Physical safeguards are the tangible, real-world measures required to protect electronic PHI, including controls over facility access, workstation use, and device and media handling.
Question 6: A patient requests an amendment to their medical record under HIPAA. Which of the following is a valid reason for a covered entity to deny that request?
- The provider disagrees with the patient's opinion about their diagnosis
- The record was not created by the covered entity receiving the request (Correct answer)
- The patient did not submit the request in writing
- The information in the record is more than five years old
Correct answer: The record was not created by the covered entity receiving the request
HIPAA permits denial of an amendment request when the covered entity did not create the record in question — the patient should direct the request to the originating provider. Age of the record and provider disagreement are not valid grounds for denial.
Under HIPAA's Minimum Necessary Standard, what principle must covered entities follow when using or disclosing PHI?