Clinical Informatics Certification Privacy & Security Regulations 3 — Questions and Answers
Question 1: Which of the following is NOT one of the 18 HIPAA Safe Harbor de-identification identifiers that must be removed?
- Geographic data smaller than a state
- Patient's blood type (Correct answer)
- Dates directly related to the individual
- Device identifiers and serial numbers
Correct answer: Patient's blood type
Blood type is a clinical data element but is not one of the 18 categories of identifiers enumerated in the HIPAA Safe Harbor de-identification standard.
Question 2: The Expert Determination method of HIPAA de-identification requires a statistician to certify that re-identification risk is:
- Zero percent
- Less than one percent
- Very small (Correct answer)
- Below the industry average
Correct answer: Very small
Under Expert Determination, a qualified statistician must certify that the risk of identifying an individual is 'very small,' though no specific numerical threshold is mandated.
Question 3: A clinical informaticist is building a query tool for a research database. Which principle best describes limiting each researcher's access to only the data fields needed for their specific study?
- Defense in depth
- Minimum necessary standard (Correct answer)
- Role-based access control
- Data masking
Correct answer: Minimum necessary standard
The minimum necessary standard requires that disclosures and requests for PHI be limited to the least amount needed to accomplish the intended purpose.
Question 4: Under GDPR, which legal basis most commonly applies when a European hospital processes patient health data for treatment purposes?
- Legitimate interests
- Explicit consent
- Vital interests
- Public interest in public health (Correct answer)
Correct answer: Public interest in public health
GDPR Article 9(2)(i) permits processing of special category health data when necessary for public interest in public health, which commonly applies to healthcare treatment.
Question 5: A state law provides patients with stronger privacy protections than HIPAA's federal minimums. Which standard applies?
- Federal HIPAA standards always preempt state law
- The state law applies because it is more protective (Correct answer)
- The provider may choose which standard to follow
- State law only applies to state-funded facilities
Correct answer: The state law applies because it is more protective
HIPAA sets a federal floor, and state laws that are more stringent (more protective of patient privacy) are not preempted and must be followed.
Question 6: Which security concept describes ensuring that PHI has not been altered or destroyed in an unauthorized manner?
- Confidentiality
- Availability
- Integrity (Correct answer)
- Non-repudiation
Correct answer: Integrity
Integrity in the context of the HIPAA Security Rule means ensuring that ePHI is not improperly modified or destroyed.
Question 7: A covered entity discovers a ransomware attack has encrypted ePHI. Under HIPAA, this is presumed to be a reportable breach unless:
- The attacker did not exfiltrate data
- The encryption was applied before the attack
- A low probability assessment shows PHI was not compromised (Correct answer)
- The incident was reported to law enforcement within 24 hours
Correct answer: A low probability assessment shows PHI was not compromised
A covered entity can overcome the breach presumption by conducting a four-factor risk assessment demonstrating a low probability that PHI was actually compromised.
Which of the following is NOT one of the 18 HIPAA Safe Harbor de-identification identifiers that must be removed?