Clinical Informatics Privacy & Ethics Flashcards
7 cards from real Clinical Informatics Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Clinical Informatics Privacy & Ethics flashcards as text
Which principle of the Fair Information Practice Principles (FIPPs) requires that organizations tell individuals what data is being collected and how it will be used?
Answer: Transparency/Notice
The Transparency/Notice principle of FIPPs requires organizations to inform individuals about their data collection practices before or at the time of collection.
A clinician discovers a fellow provider accessing patient records with no clinical justification. Under HIPAA, the clinician's MOST appropriate first action is to:
Answer: Report the observed privacy violation to the organization's Privacy Officer
Suspected HIPAA violations should be reported to the organization's Privacy Officer, who is responsible for investigating and managing privacy complaints and incidents.
Patients who opt out of the hospital directory under HIPAA are requesting that the facility:
Answer: Not disclose their presence, location, or condition to callers or visitors
The HIPAA facility directory allows patients to opt out of having their presence and general condition disclosed to those who inquire, including family members and clergy.
In the context of health data ethics, 'data minimization' means:
Answer: Collecting only the minimum amount of personal data necessary to achieve a specific purpose
Data minimization is the principle of limiting data collection to only what is directly relevant and necessary for the specified purpose, reducing privacy risk.
A patient with limited English proficiency (LEP) needs to consent to a clinical informatics research study. Which action BEST upholds ethical standards?
Answer: Provide a professionally translated consent form and a qualified interpreter
Ethical and legal standards require providing translated consent materials and qualified interpreters to ensure LEP patients can give truly informed consent.
Which of the following HIPAA Security Rule safeguards requires covered entities to implement policies for authorizing and supervising workforce members who work with PHI?
Answer: Administrative safeguards
Administrative safeguards under the HIPAA Security Rule include workforce training, access management policies, and security management processes for personnel who handle ePHI.
When an EHR vendor discovers a vulnerability that could expose PHI, the ethical obligation of 'responsible disclosure' means the vendor should:
Answer: Notify the covered entity clients and provide a patch before public disclosure
Responsible disclosure requires notifying affected parties and providing remediation before public disclosure, balancing transparency with the need to protect users from exploitation.