CHPS Trivia 4 — Questions and Answers
Question 1: Which right allows patients to request that a covered entity not share their health information with their health plan for services the patient pays for out-of-pocket?
- Right to access
- Right to restrict disclosures (Correct answer)
- Right to accounting of disclosures
- Right to amend
Correct answer: Right to restrict disclosures
Under HITECH, patients who pay out-of-pocket in full for a service can request that the covered entity not disclose related PHI to their health plan, and the entity must comply.
Question 2: What is 'de-identification' of PHI under HIPAA, and what are the two accepted methods?
- Removing the patient's name; methods are redaction and pseudonymization
- Removing 18 specific identifiers (Safe Harbor) or statistical expert determination (Correct answer)
- Encrypting data; methods are symmetric and asymmetric encryption
- Aggregating records; methods are averaging and suppression
Correct answer: Removing 18 specific identifiers (Safe Harbor) or statistical expert determination
HIPAA recognizes two de-identification methods: Safe Harbor (removing all 18 specified identifiers) and Expert Determination (statistical certification that re-identification risk is very small).
Question 3: A hacker encrypts a hospital's ePHI and demands ransom. Under HIPAA's Breach Notification Rule, this event is presumed to be what?
- A security incident only, not a breach
- A breach unless the entity can demonstrate low probability of PHI compromise (Correct answer)
- Automatically exempt if the ransom is paid
- Not covered because it involves external actors
Correct answer: A breach unless the entity can demonstrate low probability of PHI compromise
A ransomware attack on ePHI is presumed to be a reportable breach unless the covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 4: What is the maximum number of days a covered entity has to respond to a patient's request to access their own PHI?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
Covered entities must act on access requests within 30 days, with one 30-day extension permitted if the entity notifies the patient of the delay and reason.
Question 5: Which ISO standard is specifically designed for information security management systems and is used as a benchmark in healthcare security programs?
- ISO 9001
- ISO 27001 (Correct answer)
- ISO 31000
- ISO 13485
Correct answer: ISO 27001
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) and is widely adopted in healthcare.
Question 6: Under HIPAA, which of the following is NOT one of the 18 identifiers that must be removed to achieve Safe Harbor de-identification?
- Full-face photographs
- ZIP codes (first 3 digits retained if population > 20,000)
- Patient's blood type (Correct answer)
- Vehicle identifiers and serial numbers
Correct answer: Patient's blood type
Blood type is not among the 18 HIPAA Safe Harbor identifiers because it is not individually identifying; the 18 identifiers focus on names, dates, geographic data, contact information, and unique ID numbers.
Question 7: What is the term for a risk management strategy where a covered entity accepts the potential cost of a risk rather than implementing controls to mitigate it?
- Risk transference
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance is the deliberate decision to accept a risk's potential impact without additional controls, typically documented when the cost of controls exceeds the expected loss.
Which right allows patients to request that a covered entity not share their health information with their health plan for services the patient pays for out-of-pocket?