CHL Law and Ethics 5 — Questions and Answers
Question 1: A healthcare organization's board is establishing an effective compliance program. According to OIG guidance, which element is foundational to all other compliance activities?
- Conducting annual billing audits
- Written policies and procedures and a code of conduct (Correct answer)
- Hiring a full-time compliance attorney
- Obtaining accreditation from The Joint Commission
Correct answer: Written policies and procedures and a code of conduct
The OIG identifies written standards of conduct and policies as the first and most foundational of the seven elements of an effective compliance program.
Question 2: Which legal doctrine holds hospitals liable for the negligent acts of their employees, even if the hospital itself was not negligent?
- Corporate negligence
- Ostensible agency
- Respondeat superior (Correct answer)
- Res ipsa loquitur
Correct answer: Respondeat superior
Respondeat superior ('let the master answer') holds employers vicariously liable for torts committed by employees acting within the scope of their employment.
Question 3: The concept of 'justice' in healthcare ethics is most closely associated with:
- Providing only beneficial treatments
- Fair distribution of healthcare resources and equal treatment (Correct answer)
- Telling patients the truth about their diagnoses
- Honoring patient treatment refusals
Correct answer: Fair distribution of healthcare resources and equal treatment
Justice in bioethics refers to fairness, equity, and impartiality — including equitable distribution of healthcare resources and non-discriminatory treatment of patients.
Question 4: A healthcare leader is informed that a Business Associate has experienced a data breach affecting 600 patients' PHI. Under HIPAA Breach Notification Rule, the covered entity must notify affected individuals within:
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
- 6 months of discovery
Correct answer: 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days following discovery of a breach.
Question 5: A state law requires healthcare facilities to report certain communicable diseases to public health authorities. Sharing this information without patient authorization is ethically justified primarily by:
- The principle of autonomy
- The public health exception and the duty to protect the community (Correct answer)
- The facility's financial interest in avoiding outbreaks
- Federal preemption of state privacy laws
Correct answer: The public health exception and the duty to protect the community
Mandatory disease reporting is justified by the principle of justice and the societal interest in protecting public health, which can override individual privacy in defined circumstances.
Question 6: Which standard of proof is required to prevail in a civil medical malpractice lawsuit?
- Beyond a reasonable doubt
- Clear and convincing evidence
- Preponderance of the evidence (more likely than not) (Correct answer)
- Probable cause
Correct answer: Preponderance of the evidence (more likely than not)
Civil cases, including medical malpractice, require proof by a preponderance of the evidence — meaning the plaintiff's claims are more likely true than not (greater than 50%).
Question 7: A healthcare leader must balance organizational financial pressures with the duty to provide medically necessary care. This tension most directly reflects which ethical conflict?
- Autonomy versus paternalism
- Justice versus beneficence (Correct answer)
- Veracity versus fidelity
- Nonmaleficence versus autonomy
Correct answer: Justice versus beneficence
The conflict between fair resource allocation (justice) and the obligation to act in each patient's best interest (beneficence) is a central tension in healthcare leadership ethics.
A healthcare organization's board is establishing an effective compliance program.
According to OIG guidance, which element is foundational to all other compliance activities?