CIPP/US Healthcare & Financial Privacy 1 — Questions and Answers
Question 1: Under HIPAA, 'Protected Health Information' (PHI) is defined as individually identifiable health information that is:
- Only information stored in electronic format
- Held or transmitted by a covered entity or its business associate in any form or medium (Correct answer)
- Only information shared with insurance companies
- Only information contained in a patient's medical chart
Correct answer: Held or transmitted by a covered entity or its business associate in any form or medium
PHI encompasses any individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate, regardless of format.
Question 2: Which of the following entities are classified as 'covered entities' under the HIPAA Privacy Rule?
- All businesses that store any health-related data
- Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically (Correct answer)
- Only hospitals and large health systems
- Any company that offers employee health benefits
Correct answer: Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically
HIPAA covered entities are specifically health plans, healthcare clearinghouses, and healthcare providers that conduct covered transactions electronically.
Question 3: The HIPAA Privacy Rule's 'minimum necessary' standard requires covered entities to:
- Collect as much patient data as possible for comprehensive care
- Limit PHI uses and disclosures to the minimum necessary to accomplish the intended purpose (Correct answer)
- Obtain written patient consent before every internal use of PHI
- Delete patient records within one year of the last treatment
Correct answer: Limit PHI uses and disclosures to the minimum necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI access and disclosure to only what is needed for the specific purpose.
Question 4: Under HIPAA, a 'business associate' is best described as:
- An employee of a covered entity who handles PHI
- A person or entity that performs functions on behalf of a covered entity that involve the use or disclosure of PHI (Correct answer)
- A government health oversight agency
- A patient's authorized personal representative
Correct answer: A person or entity that performs functions on behalf of a covered entity that involve the use or disclosure of PHI
A business associate is a person or organization that performs services for a covered entity that involve creating, receiving, maintaining, or transmitting PHI.
Question 5: The HIPAA Security Rule's requirements apply specifically to which type of protected health information?
- All PHI in any format
- Electronic protected health information (ePHI) only (Correct answer)
- Paper records and verbal communications only
- PHI shared with third parties only
Correct answer: Electronic protected health information (ePHI) only
The HIPAA Security Rule applies specifically to ePHI — PHI that is created, received, maintained, or transmitted in electronic form.
Question 6: Under the HIPAA Privacy Rule, patients have the right to do all of the following EXCEPT:
- Request access to their PHI
- Request an amendment to their PHI
- Receive an accounting of disclosures of their PHI
- Prohibit all sharing of their PHI for treatment purposes (Correct answer)
Correct answer: Prohibit all sharing of their PHI for treatment purposes
HIPAA does not give patients an absolute right to block all PHI disclosures for treatment; covered entities may share PHI for treatment, payment, and healthcare operations without patient authorization.
Under HIPAA, 'Protected Health Information' (PHI) is defined as individually identifiable health information that is: