Clinical Informatics Privacy & Ethics Flashcards
7 cards from real Clinical Informatics Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Clinical Informatics Privacy & Ethics flashcards as text
A patient gives permission for their data to be used in one specific research study but not others. This is an example of:
Answer: Tiered consent
Tiered consent allows patients to grant specific permissions for data use at different levels (e.g., this study only, this institution only), giving them granular control over their information.
Under the HIPAA Breach Notification Rule, what is the deadline for notifying affected individuals after discovery of a breach involving more than 500 patients?
Answer: Within 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Which of the following is NOT one of the 18 identifiers that must be removed to achieve Safe Harbor de-identification under HIPAA?
Answer: Diagnosis codes (ICD-10)
ICD-10 diagnosis codes are not on the list of 18 Safe Harbor identifiers; they are clinical data elements that can remain in a de-identified dataset under Safe Harbor.
A clinical decision support (CDS) tool recommends against prescribing a medication to patients of a specific ethnic group based on flawed training data. This BEST illustrates which ethical issue?
Answer: Algorithmic bias leading to health disparities
Algorithmic bias occurs when flawed or unrepresentative training data causes a CDS tool to produce recommendations that are inaccurate or discriminatory for certain patient groups.
The 21st Century Cures Act's Information Blocking Rule primarily prohibits covered actors from:
Answer: Interfering with the access, exchange, or use of electronic health information
The Information Blocking Rule prohibits health IT developers, health information networks, and healthcare providers from unreasonably restricting the flow of electronic health information (EHI).
Which of the following BEST describes the concept of 'contextual integrity' in health information privacy?
Answer: Information flows appropriately when they match the norms of the context in which data was originally shared
Contextual integrity (Nissenbaum) holds that privacy is violated when information flows in ways that don't match the norms of the original context, such as sharing clinical information for marketing.
A hospital uses a cloud-based EHR hosted by a vendor. To comply with HIPAA, which of the following is REQUIRED before PHI is stored in the cloud?
Answer: A signed Business Associate Agreement must be in place with the cloud vendor
Cloud vendors who store or process PHI on behalf of a covered entity are business associates, and a signed BAA is required before any PHI can be shared with them.