CHAA Patient Identification & Identity Theft 2 — Questions and Answers
Question 1: What are the two patient identifiers recommended by The Joint Commission's National Patient Safety Goals?
- Patient's room number and bed assignment
- Patient's full name and date of birth (or medical record number) (Correct answer)
- Patient's insurance card and driver's license
- Patient's diagnosis and physician name
Correct answer: Patient's full name and date of birth (or medical record number)
The Joint Commission requires at least two patient identifiers to verify identity, and room/bed numbers cannot be used.
NPSG.01.01.01 requires at least two patient identifiers when providing care. Acceptable identifiers include full name, date of birth, medical record number, SSN last four, or telephone number. Room and bed numbers are explicitly prohibited because they change and are not unique to the patient.
Question 2: A patient's registration information does not match the name on their insurance card. What should the access representative investigate?
- Nothing; discrepancies are common and unimportant
- Whether there has been a legal name change, a data entry error, or potential identity theft or insurance fraud (Correct answer)
- Simply update the registration to match the card
- Cancel the appointment immediately
Correct answer: Whether there has been a legal name change, a data entry error, or potential identity theft or insurance fraud
Name discrepancies can indicate legitimate changes, errors, or potential fraud, all requiring investigation.
Legitimate reasons include marriage/divorce, maiden name use, data entry errors, and cultural naming conventions. Red flags include completely different names with matching DOBs, reluctance to provide ID, and inconsistent personal information. Follow the Red Flags Rule protocol if fraud is suspected.
Question 3: What is medical identity theft, and why is it particularly dangerous?
- It only affects the victim's credit score
- It involves using someone's personal information to obtain medical services, which can corrupt the victim's medical record with incorrect information leading to harmful treatment decisions (Correct answer)
- It is limited to stealing prescriptions
- It only occurs with paper records
Correct answer: It involves using someone's personal information to obtain medical services, which can corrupt the victim's medical record with incorrect information leading to harmful treatment decisions
Medical identity theft is uniquely dangerous because it can corrupt medical records with potentially life-threatening incorrect information.
Medical identity theft can cause false diagnoses in the victim's record, incorrect blood type or allergy information leading to fatal errors, mixed medical histories, exhausted insurance benefits, and extreme difficulty in record cleanup. Patient access staff are the primary defense through identity verification protocols.
Question 4: Which technology can help prevent patient misidentification during registration?
- Social media verification
- Biometric identification systems such as palm vein scanning or fingerprint recognition (Correct answer)
- Self-registration kiosks without identity verification
- Verbal name confirmation only
Correct answer: Biometric identification systems such as palm vein scanning or fingerprint recognition
Biometric identification provides high-confidence, non-transferable identity verification.
Common biometric technologies include palm vein scanning, fingerprint recognition, iris scanning, and facial recognition. These link unique biological characteristics to medical records, making identity theft virtually impossible. Studies show biometric systems reduce duplicate records by over 90%.
Question 5: A patient reports someone used their identity to receive medical services. What steps should the access representative take?
- Tell the patient it's not the hospital's problem
- Document the report, escalate to the privacy officer and compliance department, and initiate the identity theft response protocol (Correct answer)
- Ask for proof before acting
- Delete potentially fraudulent records immediately
Correct answer: Document the report, escalate to the privacy officer and compliance department, and initiate the identity theft response protocol
Reports of medical identity theft must be escalated through proper channels for investigation.
The organization must document the report, escalate to privacy and compliance, initiate the Red Flags Rule response protocol, flag affected records, investigate to identify fraudulent encounters, separate legitimate from fraudulent records, notify the patient, and assist with law enforcement reporting. Never delete records as they may be needed for investigation.
Question 6: What is the purpose of a patient identity integrity program?
- To manage employee ID badges
- To establish systematic processes for preventing, detecting, and correcting patient identification errors and maintaining MPI accuracy (Correct answer)
- To verify physician credentials
- To track visitor access
Correct answer: To establish systematic processes for preventing, detecting, and correcting patient identification errors and maintaining MPI accuracy
A patient identity integrity program provides a comprehensive framework for accurate patient identification.
The program encompasses registration standards, MPI management including duplicate prevention and resolution, monitoring of identity metrics, staff training, technology implementation, Red Flags Rule compliance, identity theft response protocols, and HIE identity matching. Key metrics include duplicate creation rate (target under 1%) and overlay detection rate.
What are the two patient identifiers recommended by The Joint Commission's National Patient Safety Goals?