CHAA Legal and Regulatory Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- A hospital's annual revenue report
- A patient's name combined with their diagnosis and date of service (Correct answer)
- General health statistics about a community
- A physician's medical school transcripts
Correct answer: A patient's name combined with their diagnosis and date of service
PHI is individually identifiable health information that relates to a person's health condition, treatment, or payment for care.
Under HIPAA, Protected Health Information includes any individually identifiable health information that relates to the past, present, or future physical or mental health of an individual, the provision of healthcare, or payment for healthcare. PHI includes 18 specific identifiers when linked to health information. Patient access staff handle PHI extensively during registration, insurance verification, and financial counseling.
Question 2: What is the minimum necessary standard under HIPAA, and how does it apply to patient access?
- It requires providing the minimum amount of care necessary
- It requires limiting PHI access and disclosure to the minimum amount needed to accomplish the intended purpose (Correct answer)
- It sets the minimum number of staff required in the access department
- It establishes minimum wait time standards for patients
Correct answer: It requires limiting PHI access and disclosure to the minimum amount needed to accomplish the intended purpose
The minimum necessary standard requires that workforce members access only the PHI needed for their specific job functions.
HIPAA's minimum necessary standard (45 CFR 164.502(b)) requires covered entities to make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose. For patient access, this means staff should access only the information needed for registration, verification, and scheduling. Role-based access controls enforce this by limiting system views based on job function.
Question 3: A patient requests a copy of their complete medical record. Under HIPAA, what is the organization's obligation?
- Deny the request as medical records are hospital property
- Provide the records within 30 days (with a possible 30-day extension) in the format requested by the patient if readily producible (Correct answer)
- Charge the patient the full cost of copying without any limits
- Require the patient to obtain a court order
Correct answer: Provide the records within 30 days (with a possible 30-day extension) in the format requested by the patient if readily producible
HIPAA gives patients the right to access their health information, and organizations must fulfill requests within 30 days, with reasonable cost-based fees.
Under HIPAA's Right of Access (45 CFR 164.524), patients have the right to inspect and obtain a copy of their PHI in designated record sets. Organizations must act on requests within 30 days (extendable by 30 days with written notice), provide records in the format requested if readily producible, and charge only a reasonable cost-based fee.
Question 4: What is the purpose of the Medicare Secondary Payer (MSP) questionnaire administered during registration?
- To determine if the patient qualifies for Medicare Part D
- To identify whether another insurer should be the primary payer before Medicare (Correct answer)
- To verify the patient's Medicare eligibility
- To enroll the patient in a Medicare Advantage plan
Correct answer: To identify whether another insurer should be the primary payer before Medicare
The MSP questionnaire identifies situations where Medicare should be the secondary payer, such as when the patient has employer group health coverage.
The Medicare Secondary Payer provisions require that Medicare not pay for services when another insurer is primarily responsible. Patient access staff administer MSP screening questions at each encounter to identify these situations. Common MSP scenarios include working aged, disability with large group health plan, end-stage renal disease within the coordination period, auto or liability insurance, and workers' compensation.
Question 5: Which regulation requires healthcare facilities to inform patients of their right to create advance directives?
- HIPAA
- The Patient Self-Determination Act (PSDA) (Correct answer)
- The Stark Law
- OSHA
Correct answer: The Patient Self-Determination Act (PSDA)
The Patient Self-Determination Act requires healthcare facilities to inform patients about their right to make advance directives and to document whether they have them.
The Patient Self-Determination Act of 1990 requires Medicare and Medicaid participating facilities to inform adult patients at admission about their right to accept or refuse treatment, their right to create advance directives, the facility's policy regarding advance directives, and to document whether the patient has advance directives. Patient access staff typically fulfill this requirement during the registration process.
Question 6: What constitutes a HIPAA breach, and what is the organization's notification obligation?
- Any use of a computer system constitutes a breach
- An impermissible use or disclosure of PHI that compromises the security or privacy of the information, requiring notification to affected individuals within 60 days (Correct answer)
- A breach only occurs if information is published in a newspaper
- Breaches only need to be reported to the IT department
Correct answer: An impermissible use or disclosure of PHI that compromises the security or privacy of the information, requiring notification to affected individuals within 60 days
A HIPAA breach is an impermissible acquisition, access, use, or disclosure of PHI, requiring notification to affected individuals, HHS, and potentially the media.
Under the HIPAA Breach Notification Rule (45 CFR 164.400-414), a breach is an impermissible use or disclosure of PHI that compromises its security or privacy. When confirmed, the organization must notify affected individuals within 60 days, notify HHS, and notify prominent media if 500+ individuals in a state are affected. Patient access staff must report potential breaches immediately per policy.
Under HIPAA, which of the following is considered Protected Health Information (PHI)?