CHP Treatment Protocols & Procedures 3 — Questions and Answers
Question 1: A covered entity uses a telemedicine platform for treatment. Under HIPAA, the telemedicine vendor must be treated as:
- A covered entity subject to the full Privacy Rule
- A Business Associate requiring a signed BAA (Correct answer)
- An exempt party since it provides only technology
- A workforce member with standard access controls
Correct answer: A Business Associate requiring a signed BAA
A telemedicine vendor that accesses, transmits, or stores PHI on behalf of a covered entity qualifies as a Business Associate and must sign a BAA.
Question 2: Which of the following actions by a provider BEST demonstrates compliance with HIPAA's treatment disclosure rules?
- Sending a full patient record to a specialist without reviewing relevance
- Forwarding only the pertinent treatment summary needed by a consulting physician (Correct answer)
- Emailing all lab results to a patient's employer upon request
- Posting discharge instructions on a public hospital portal
Correct answer: Forwarding only the pertinent treatment summary needed by a consulting physician
Sending only the pertinent treatment summary to a consulting physician aligns with both the treatment disclosure permission and the minimum necessary standard.
Question 3: A mental health provider wishes to share a patient's psychiatric treatment notes with the patient's primary care physician. Under HIPAA, psychotherapy notes:
- Are treated the same as general medical records for treatment purposes
- Require a separate, specific authorization even for treatment by another provider (Correct answer)
- Can be shared freely among treating providers without restriction
- Are excluded from HIPAA protections entirely
Correct answer: Require a separate, specific authorization even for treatment by another provider
Psychotherapy notes receive heightened protection under HIPAA and generally require a separate specific authorization even for treatment disclosures to other providers.
Question 4: A clinic's treatment protocol requires staff to verify patient identity before administering medication. From a HIPAA perspective, this practice:
- Violates patient privacy by requiring ID disclosure
- Supports PHI accuracy and patient safety, consistent with HIPAA (Correct answer)
- Is only required for mental health medications
- Must be documented in the Notice of Privacy Practices
Correct answer: Supports PHI accuracy and patient safety, consistent with HIPAA
Identity verification before treatment protects PHI accuracy and patient safety, which is consistent with HIPAA's intent to safeguard health information quality.
Question 5: Under HIPAA, which of the following describes when a healthcare provider may share PHI for treatment WITHOUT patient authorization?
- Only when the patient is a minor
- When sharing with another provider involved in the patient's care (Correct answer)
- Only when law enforcement requests it
- Only when the patient has signed a consent form
Correct answer: When sharing with another provider involved in the patient's care
HIPAA's Privacy Rule allows providers to share PHI for treatment purposes with other providers involved in the patient's care without obtaining patient authorization.
Question 6: A hospital creates care protocols that involve sending PHI to a research university analyzing treatment outcomes. This arrangement typically requires:
- A Business Associate Agreement and possibly IRB approval or a data use agreement (Correct answer)
- Only a Notice of Privacy Practices update
- No additional safeguards if de-identified data is used
- Patient authorization only if the patient is still receiving treatment
Correct answer: A Business Associate Agreement and possibly IRB approval or a data use agreement
Sharing PHI with a research institution typically requires a BAA and may also require IRB approval or a data use agreement depending on the nature of the research.
Question 7: A provider's treatment protocol inadvertently includes PHI of a patient who was not the intended recipient of a fax. Under HIPAA, this is considered:
- A permissible incidental disclosure requiring no action
- An impermissible disclosure that may require breach analysis (Correct answer)
- A minor administrative error exempt from HIPAA reporting
- Acceptable if the fax cover sheet included a confidentiality notice
Correct answer: An impermissible disclosure that may require breach analysis
A misdirected fax containing PHI is an impermissible disclosure that must be assessed under the breach notification rule.
A covered entity uses a telemedicine platform for treatment.
Under HIPAA, the telemedicine vendor must be treated as: