Patient Assessment & Clinical Evaluation Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Patient Assessment & Clinical Evaluation flashcards as text
A physician shares a patient's functional assessment results with the patient's physical therapist to coordinate a rehabilitation plan. This is an example of:
Answer: Permitted treatment disclosure under TPO
Sharing clinical assessment information between treating providers to coordinate care is a Treatment disclosure permitted without authorization under HIPAA.
A nurse accidentally mentions a patient's diagnosis to an unauthorized visitor in the hallway. Under HIPAA, this event is most accurately classified as:
Answer: An incidental disclosure, which is permissible if safeguards were in place
Incidental disclosures that occur despite reasonable safeguards being in place are not HIPAA violations, though covered entities should still work to minimize them.
A hospital is evaluating whether to de-identify clinical assessment data for research. Under the Expert Determination method, de-identification requires:
Answer: A qualified statistical expert certifying very small re-identification risk
The Expert Determination method requires a qualified expert to apply statistical methods and certify that re-identification risk is very small.
A law enforcement officer requests a patient's clinical evaluation records to investigate a crime. Without a court order or subpoena, the covered entity may disclose:
Answer: Limited information such as name, address, and blood type under specific circumstances
HIPAA permits limited PHI disclosure to law enforcement for identifying suspects or victims, but restricts the specific data elements that may be shared without legal process.
A patient's neuropsychological evaluation report is requested by their life insurance company. The covered entity should:
Answer: Require a valid HIPAA authorization from the patient before disclosing
Disclosing PHI to a life insurance company (not a health plan covering the patient's treatment) requires a valid individual authorization.
An EHR system automatically generates a risk assessment alert during a clinical evaluation. Under HIPAA, the access log for this alert is considered:
Answer: PHI if it contains individually identifiable health information
Any data element linked to an identifiable individual that relates to health status or care—whether system-generated or manually entered—is PHI if maintained by a covered entity.
Under the HIPAA Privacy Rule's Right of Access, a covered entity must provide a patient with their clinical assessment records within:
Answer: 30 calendar days, extendable by 30 more days with written notice
Covered entities must act on access requests within 30 days and may extend by one additional 30-day period with written explanation to the patient.