Clinical Informatics Certification Clinical Informatics Privacy & Ethics 3 — Questions and Answers
Question 1: A patient requests an amendment to their EHR record, but the provider believes the information is accurate. Under HIPAA, what must the provider do?
- Immediately make the amendment as requested
- Deny the request and document the denial with the patient's disagreement noted in the record (Correct answer)
- Delete the disputed entry without documentation
- Transfer the patient's care to another provider
Correct answer: Deny the request and document the denial with the patient's disagreement noted in the record
Under HIPAA, a provider may deny an amendment request if the information is accurate and complete, but must provide a written denial and allow the patient to submit a statement of disagreement.
Question 2: Which type of data governance policy specifically addresses how long PHI must be retained before secure disposal?
- Data classification policy
- Data retention and destruction policy (Correct answer)
- Access control policy
- Incident response policy
Correct answer: Data retention and destruction policy
A data retention and destruction policy defines the minimum and maximum periods for retaining PHI and the approved methods for its secure disposal when no longer needed.
Question 3: In clinical informatics, the concept of 'data stewardship' PRIMARILY refers to:
- Encrypting all PHI at rest and in transit
- The responsible management and oversight of health data throughout its lifecycle (Correct answer)
- Granting system access to authorized clinical staff only
- Anonymizing patient data before research publication
Correct answer: The responsible management and oversight of health data throughout its lifecycle
Data stewardship encompasses the policies, processes, and accountabilities for managing data quality, integrity, privacy, and security across its entire lifecycle.
Question 4: A hospital shares PHI with a third-party billing company. Under HIPAA, which document is REQUIRED to govern this relationship?
- Notice of Privacy Practices
- Business Associate Agreement (BAA) (Correct answer)
- Data Use Agreement (DUA)
- Memorandum of Understanding (MOU)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement is required by HIPAA whenever a covered entity shares PHI with a vendor or contractor (business associate) who performs services on its behalf.
Question 5: Which of the following scenarios represents the GREATEST risk of re-identification from a 'de-identified' dataset?
- A dataset using the Safe Harbor method with all 18 identifiers removed
- A small rural county dataset with rare diagnosis codes linked to age and gender (Correct answer)
- A national dataset of 5 million patients with only age decade reported
- A dataset where all dates are shifted by a random offset per patient
Correct answer: A small rural county dataset with rare diagnosis codes linked to age and gender
Small geographic populations combined with rare diagnoses and demographic attributes create a high re-identification risk because very few individuals fit the combination, making patients uniquely identifiable.
Question 6: Which federal regulation governs the privacy of substance use disorder treatment records and is STRICTER than HIPAA?
- FERPA (Family Educational Rights and Privacy Act)
- 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) (Correct answer)
- The Genetic Information Nondiscrimination Act (GINA)
- The Cures Act Information Blocking Rule
Correct answer: 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records)
42 CFR Part 2 provides heightened confidentiality protections for substance use disorder (SUD) treatment records, generally requiring patient consent for most disclosures.
Question 7: An informatics team is developing a predictive model using historical EHR data. What ethical concern is MOST relevant during the model development phase?
- Whether the EHR vendor supports API integration
- Whether historical biases in clinical data will be perpetuated by the model (Correct answer)
- Whether the model can be deployed without a software update
- Whether the model output should be displayed in the EHR sidebar
Correct answer: Whether historical biases in clinical data will be perpetuated by the model
Algorithmic bias is a critical ethical concern because predictive models trained on historically biased clinical data can perpetuate or amplify health disparities.
A patient requests an amendment to their EHR record, but the provider believes the information is accurate.
Under HIPAA, what must the provider do?