CHP Treatment Protocols & Procedures 2 — Questions and Answers
Question 1: Under HIPAA, which entity is primarily responsible for ensuring that treatment protocols involving PHI are documented and safeguarded?
- The treating physician only
- The covered entity (e.g., hospital or clinic) (Correct answer)
- The patient's insurance company
- The HHS Office for Civil Rights
Correct answer: The covered entity (e.g., hospital or clinic)
The covered entity—such as a hospital or clinic—bears primary responsibility under HIPAA for safeguarding PHI used in treatment protocols.
Question 2: A nurse shares a patient's medication protocol with a specialist who is treating the same patient. Under HIPAA, this disclosure is:
- Prohibited without a signed authorization
- Permitted as TPO (Treatment, Payment, Operations) (Correct answer)
- Permitted only if de-identified first
- Requires a Business Associate Agreement
Correct answer: Permitted as TPO (Treatment, Payment, Operations)
HIPAA explicitly permits disclosures for treatment purposes among providers involved in a patient's care without patient authorization.
Question 3: Which of the following best describes a 'minimum necessary' violation in a treatment context?
- A physician reviews only the records needed to treat a current condition
- A billing clerk accesses complete medical histories to verify one charge (Correct answer)
- A nurse reads a patient's allergy list before administering medication
- A specialist receives a referral summary from a primary care provider
Correct answer: A billing clerk accesses complete medical histories to verify one charge
Accessing more PHI than is required for the task at hand—such as full medical histories for a single billing inquiry—violates the minimum necessary standard.
Question 4: A hospital's care coordination team shares a patient's treatment plan with a home health agency that will continue care post-discharge. This requires:
- Patient authorization each time
- A Business Associate Agreement with the home health agency (Correct answer)
- Only verbal consent from the patient
- No additional steps since it is a treatment disclosure
Correct answer: A Business Associate Agreement with the home health agency
When sharing PHI with a home health agency that provides services on behalf of the hospital, a Business Associate Agreement (BAA) is required.
Question 5: Under the HIPAA Privacy Rule, a patient requests restrictions on sharing their diabetes treatment protocol with their health plan. The covered entity must honor this restriction if:
- The patient provides written consent
- The disclosure is to the plan and the patient pays out-of-pocket in full for the service (Correct answer)
- The plan is not a covered entity
- The restriction applies only to mental health information
Correct answer: The disclosure is to the plan and the patient pays out-of-pocket in full for the service
The HITECH Act requires covered entities to honor restriction requests when the patient pays out-of-pocket in full and the disclosure would only go to a health plan.
Question 6: When a patient is unconscious and emergency treatment is required, HIPAA permits providers to:
- Disclose PHI only if a family member is present
- Use professional judgment to disclose PHI necessary for emergency treatment (Correct answer)
- Withhold all PHI until written authorization is obtained
- Disclose PHI only to law enforcement
Correct answer: Use professional judgment to disclose PHI necessary for emergency treatment
HIPAA allows providers to use professional judgment to disclose necessary PHI for emergency treatment when the patient cannot give consent.
Question 7: A hospital implements a new protocol requiring providers to document PHI access in the EHR for each treatment encounter. This practice supports which HIPAA requirement?
- Notice of Privacy Practices distribution
- Accounting of disclosures
- Audit controls under the Security Rule (Correct answer)
- Minimum necessary standard enforcement
Correct answer: Audit controls under the Security Rule
Logging PHI access within the EHR supports the HIPAA Security Rule's audit controls requirement, ensuring access is tracked and reviewable.
Under HIPAA, which entity is primarily responsible for ensuring that treatment protocols involving PHI are documented and safeguarded?