HIPAA and Patient Confidentiality Flashcards
6 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 HIPAA and Patient Confidentiality flashcards as text
A patient's spouse calls the medical office requesting the results of their partner's recent blood test. The patient has not signed a release of information form authorizing this disclosure. What is the most appropriate response from the CMAA?
Answer: Inform the spouse that due to privacy regulations, the information cannot be released without the patient's written consent.
HIPAA's Privacy Rule requires that a covered entity obtain the patient's written authorization before using or disclosing Protected Health Information (PHI) for purposes other than treatment, payment, or healthcare operations. Disclosing results to a spouse, without explicit consent, would be a violation of the patient's privacy.
Under the Health Insurance Portability and Accountability Act (HIPAA), which of the following is the best example of Protected Health Information (PHI)?
Answer: A patient's name listed on an appointment sign-in sheet.
Protected Health Information (PHI) is any individually identifiable health information held or transmitted by a covered entity. A patient's name on a sign-in sheet links an individual to the receipt of healthcare services, making it PHI. The other options are not identifiable to a specific individual.
A CMAA is tasked with disposing of old paper documents containing patient demographic and billing information. Which of the following methods is compliant with HIPAA regulations?
Answer: Using a cross-cut shredder to destroy the documents until they are unreadable and cannot be reconstructed.
HIPAA requires that PHI be rendered unreadable, indecipherable, and unable to be reconstructed upon disposal. Cross-cut shredding is an appropriate method for destroying paper records to meet this standard. Simply marking out names, tearing, or using a standard recycling bin does not provide adequate protection against reconstruction.
A CMAA at the front desk is speaking with a patient on the phone about their medical condition. The conversation is loud enough to be overheard by other patients in the waiting room. This is a potential violation of which HIPAA principle?
Answer: The requirement for reasonable safeguards.
HIPAA requires covered entities to have 'reasonable safeguards' in place to protect PHI from incidental disclosure. This includes administrative, technical, and physical safeguards, such as speaking quietly when discussing PHI where others might overhear. While the minimum necessary standard is related, the direct failure to protect the conversation itself points to a lack of reasonable safeguards.
What is the primary purpose of the HIPAA Privacy Rule?
Answer: To give patients rights over their health information and to set limits on its use and disclosure without their authorization.
The main goal of the HIPAA Privacy Rule is to ensure that individuals' health information is properly protected while allowing the flow of information needed for high-quality care. It establishes national standards and gives patients specific rights to control how their health information is used and disclosed.
Which of the following scenarios constitutes a HIPAA breach that would require notification to the affected individuals?
Answer: An unencrypted laptop containing the PHI of 600 patients is stolen from a billing manager's car.
A breach is an impermissible use or disclosure of unsecured PHI that compromises its security or privacy. The theft of an unencrypted device containing the PHI of more than 500 individuals is a significant breach that requires notification to the affected individuals, the media, and the Secretary of Health and Human Services. The other options are either permissible disclosures for treatment or internal policy violations that do not necessarily meet the formal definition of a reportable breach.