CHPC Healthcare Privacy Regulations Questions and Answers — Questions and Answers
Question 1: A hospital discovers that a billing employee impermissibly accessed the electronic health records of 550 patients out of curiosity. According to the HITECH Act's breach notification rule, which of the following actions is the hospital required to take?
- Notify the affected individuals, the Secretary of HHS, and prominent media outlets in the state. (Correct answer)
- Notify only the affected individuals and the hospital's internal compliance officer.
- Report the breach in the annual report to the Secretary of HHS and notify the affected individuals.
- Notify the Secretary of HHS and local law enforcement within 60 days of discovery.
Correct answer: Notify the affected individuals, the Secretary of HHS, and prominent media outlets in the state.
The HITECH Act requires covered entities to notify affected individuals, the Secretary of Health and Human Services (HHS), and, in cases involving more than 500 residents of a single state or jurisdiction, prominent media outlets. The notification must occur without unreasonable delay and no later than 60 days from the breach's discovery. Since this breach affected 550 patients, all three notification requirements are triggered.
Question 2: Which of the following is a core patient right guaranteed under the HIPAA Privacy Rule?
- The right to demand deletion of their entire medical record.
- The right to access and obtain a copy of their protected health information (PHI). (Correct answer)
- The right to veto any disclosure of their PHI for treatment, payment, or healthcare operations.
- The right to audit the healthcare provider's internal security logs.
Correct answer: The right to access and obtain a copy of their protected health information (PHI).
The HIPAA Privacy Rule provides individuals with the right to access, inspect, and obtain a copy of their PHI from a covered entity in a designated record set. While they can request amendments, they cannot demand complete deletion of records that providers are legally required to maintain. Their right to restrict disclosures for TPO (Treatment, Payment, Operations) is limited, and they do not have a right to audit internal security logs.
Question 3: A pharmaceutical company offers to pay a hospital for a list of patients diagnosed with a specific condition to send them marketing materials about a new drug. Under HIPAA marketing rules, what must the hospital do before disclosing this PHI?
- De-identify the patient data before providing it.
- Enter into a Business Associate Agreement with the pharmaceutical company.
- Obtain a valid, written authorization from each individual patient. (Correct answer)
- Notify the patients of the marketing communication via their Notice of Privacy Practices.
Correct answer: Obtain a valid, written authorization from each individual patient.
The HIPAA Privacy Rule defines this type of communication as marketing, especially since the hospital receives remuneration. For nearly all marketing purposes that involve the use or disclosure of PHI and involve payment to the covered entity, a specific, written authorization from the patient is required. A Business Associate Agreement or a notice in the NPP is insufficient for this purpose.
Question 4: A Privacy Officer is developing a policy based on the 'Minimum Necessary' standard. Which of the following scenarios best demonstrates the correct application of this HIPAA principle?
- Allowing the entire nursing staff to have full access to all patient electronic health records to ensure efficient care.
- Providing a health insurance company with a patient's complete medical history to process a claim for a single office visit.
- Releasing a patient's name and general condition to a reporter without the patient's authorization.
- Granting a hospital's billing clerk access only to the demographic and insurance information needed to process claims. (Correct answer)
Correct answer: Granting a hospital's billing clerk access only to the demographic and insurance information needed to process claims.
The 'Minimum Necessary' standard, a key principle of the HIPAA Privacy Rule, requires covered entities to take reasonable steps to limit the use or disclosure of, and requests for, PHI to the minimum necessary to accomplish the intended purpose. Granting a billing clerk access only to the specific data elements required for their job function is a perfect example of this role-based access control. The other options represent overly broad disclosures of PHI.
Question 5: A business associate discovers a breach of unsecured PHI that it maintains on behalf of a covered entity. What is the business associate's primary notification responsibility under the HITECH Act?
- Notify the affected individuals directly within 60 days.
- Notify the covered entity without unreasonable delay and in no case later than 60 days of discovery. (Correct answer)
- Report the breach to the HHS Secretary on behalf of the covered entity.
- Wait for the covered entity to discover the breach independently through an audit.
Correct answer: Notify the covered entity without unreasonable delay and in no case later than 60 days of discovery.
Under the HITECH Act and the HIPAA Final Omnibus Rule, a business associate must notify the covered entity of a breach of unsecured PHI. This notification allows the covered entity to fulfill its own breach notification duties to individuals, HHS, and potentially the media. The contract (Business Associate Agreement) between the two parties will often specify a shorter timeframe for this internal notification, but the outer limit aligns with the 60-day rule.
Question 6: Which of the following is NOT one of the three types of safeguards required by the HIPAA Security Rule?
- Administrative Safeguards
- Physical Safeguards
- Procedural Safeguards (Correct answer)
- Technical Safeguards
Correct answer: Procedural Safeguards
The HIPAA Security Rule specifies three categories of safeguards that covered entities and their business associates must implement to protect electronic protected health information (ePHI). These are Administrative, Physical, and Technical Safeguards. 'Procedural Safeguards' is not a defined category under the Security Rule, although procedures are a component of the required administrative safeguards.
A hospital discovers that a billing employee impermissibly accessed the electronic health records of 550 patients out of curiosity.
According to the HITECH Act's breach notification rule, which of the following actions is the hospital required to take?