CMAA HIPAA and Patient Confidentiality 4 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity'?
- A medical billing company hired by a clinic
- A health insurance plan that pays for medical services (Correct answer)
- A software vendor selling EHR systems
- A medical equipment manufacturer
Correct answer: A health insurance plan that pays for medical services
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
Question 2: A patient requests an amendment to their medical record because they believe information is incorrect. Under HIPAA, the covered entity must respond within:
- 30 days, with one possible 30-day extension
- 60 days, with one possible 30-day extension (Correct answer)
- 90 days, with no extension allowed
- 14 days, with no extension allowed
Correct answer: 60 days, with one possible 30-day extension
HIPAA requires covered entities to act on a request for amendment within 60 days, with one 30-day extension if needed and notice is provided.
Question 3: Which of the following best describes a 'limited data set' under HIPAA?
- PHI with all 18 identifiers removed
- PHI with most direct identifiers removed but may include dates and geographic data (Correct answer)
- De-identified data that can be shared freely
- Data shared only with covered entities
Correct answer: PHI with most direct identifiers removed but may include dates and geographic data
A limited data set has most direct identifiers removed but may still include dates (e.g., admission, discharge) and geographic subdivisions, and requires a data use agreement.
Question 4: A medical administrative assistant receives a subpoena for a patient's records. What is the correct first step?
- Immediately send the records to the requesting court
- Notify the patient and consult the facility's legal counsel or privacy officer (Correct answer)
- Refuse to release any records without the patient present
- Fax the records to the requesting attorney
Correct answer: Notify the patient and consult the facility's legal counsel or privacy officer
Before releasing records pursuant to a subpoena, the facility should notify the patient and seek legal guidance to ensure HIPAA compliance.
Question 5: Under the HIPAA Privacy Rule, which of the following uses of PHI does NOT require patient authorization?
- Using PHI for marketing a new prescription drug
- Disclosing PHI to the patient's employer for pre-employment screening
- Sharing PHI with a public health authority to report a communicable disease (Correct answer)
- Selling PHI to a pharmaceutical research company
Correct answer: Sharing PHI with a public health authority to report a communicable disease
Public health activities, such as reporting communicable diseases to authorized public health authorities, are permitted disclosures under HIPAA without patient authorization.
Question 6: What is the purpose of a Notice of Privacy Practices (NPP)?
- To obtain patient consent for all uses of their health information
- To inform patients of how their PHI may be used and their rights regarding that information (Correct answer)
- To authorize disclosure of PHI to business associates
- To document that a patient waived their HIPAA rights
Correct answer: To inform patients of how their PHI may be used and their rights regarding that information
The NPP informs patients about how the covered entity may use and disclose their PHI and describes the patient's rights under HIPAA.
Question 7: Which HIPAA rule specifically addresses the security of electronic protected health information (ePHI)?
- The Privacy Rule
- The Breach Notification Rule
- The Security Rule (Correct answer)
- The Enforcement Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect individuals' electronic personal health information that is created, received, used, or maintained by a covered entity.
Under HIPAA, which of the following is considered a 'covered entity'?