CHP Regulatory Compliance & Standards 3 — Questions and Answers
Question 1: A hospital shares PHI with a medical transcription company. Under HIPAA, what document must be in place before sharing?
- Data Use Agreement (DUA)
- Business Associate Agreement (BAA) (Correct answer)
- Memorandum of Understanding (MOU)
- Notice of Privacy Practices (NPP)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is required before a covered entity shares PHI with a business associate performing services on its behalf.
Question 2: Which of the following constitutes a 'limited data set' under HIPAA?
- PHI with all 18 identifiers removed
- PHI with direct identifiers removed but dates and geographic data retained (Correct answer)
- PHI encrypted with AES-256
- Fully de-identified data under Safe Harbor method
Correct answer: PHI with direct identifiers removed but dates and geographic data retained
A limited data set removes direct identifiers (like names and SSNs) but may retain dates, ages, and geographic subdivisions larger than a street address.
Question 3: Under the HIPAA Privacy Rule, which of the following is a permitted disclosure without patient authorization?
- Disclosing PHI to a patient's employer for workforce management
- Sharing PHI with a marketing firm for targeted health advertisements
- Disclosing PHI for treatment, payment, or healthcare operations (TPO) (Correct answer)
- Providing PHI to a life insurance company for underwriting purposes
Correct answer: Disclosing PHI for treatment, payment, or healthcare operations (TPO)
HIPAA explicitly permits PHI disclosure for treatment, payment, and healthcare operations (TPO) without requiring patient authorization.
Question 4: A patient requests an amendment to their medical record, which the provider denies. What must the provider include with the denial?
- A mandatory 30-day waiting period before resubmission
- A written denial with the basis for denial and information on how the individual may submit a statement of disagreement (Correct answer)
- A referral to the state medical board
- An automatic forwarding to the Office for Civil Rights
Correct answer: A written denial with the basis for denial and information on how the individual may submit a statement of disagreement
When denying an amendment request, the covered entity must provide a written denial explaining the basis and inform the patient of their right to submit a statement of disagreement.
Question 5: The Omnibus Rule of 2013 modified HIPAA by changing which aspect of breach notification?
- It eliminated the harm threshold, making any unauthorized PHI access presumed a breach (Correct answer)
- It extended the notification window from 60 to 90 days
- It removed the requirement to notify affected individuals
- It limited breach notification solely to electronic PHI breaches
Correct answer: It eliminated the harm threshold, making any unauthorized PHI access presumed a breach
The Omnibus Rule replaced the 'harm threshold' with a presumption that any impermissible PHI use or disclosure is a breach unless the entity can demonstrate low probability of compromise.
Question 6: Which HIPAA provision grants individuals the right to request restrictions on disclosures of their PHI to health plans for services they paid for out-of-pocket in full?
- Right to Access
- Right to Restrict Disclosure (Correct answer)
- Right to Accounting of Disclosures
- Right to Data Portability
Correct answer: Right to Restrict Disclosure
Under the Omnibus Rule, covered entities must honor a patient's request to restrict disclosure to a health plan for items or services paid entirely out-of-pocket.
Question 7: For workforce HIPAA training, what does the Security Rule require regarding documentation?
- Training records must be submitted to OCR annually
- Policies and procedures must be retained for a minimum of 6 years (Correct answer)
- Training must be completed within 30 days of hire with no documentation needed
- Only workforce members with PHI access require documented training
Correct answer: Policies and procedures must be retained for a minimum of 6 years
The HIPAA Security Rule requires covered entities to retain security policies, procedures, and training records for at least 6 years from creation or last effective date.
A hospital shares PHI with a medical transcription company.
Under HIPAA, what document must be in place before sharing?