CMAS Healthcare Laws & Ethics 3 — Questions and Answers
Question 1: A covered entity must provide patients with a Notice of Privacy Practices (NPP):
- only upon written request
- at first service delivery and upon request thereafter (Correct answer)
- annually by certified mail
- only when sharing PHI with third parties
Correct answer: at first service delivery and upon request thereafter
HIPAA requires covered entities to provide the NPP at the first point of service contact and make it available upon request at any time.
Question 2: Which act allows qualified individuals to inspect and copy their own medical records held by HIPAA-covered entities?
- Freedom of Information Act
- HIPAA Privacy Rule (Correct answer)
- Health Information Technology for Economic and Clinical Health Act
- Gramm-Leach-Bliley Act
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule grants individuals the right to access and obtain copies of their own PHI held by covered entities.
Question 3: The False Claims Act imposes liability on individuals or companies that:
- fail to obtain informed consent
- submit fraudulent claims to the federal government (Correct answer)
- breach patient confidentiality
- violate licensing requirements
Correct answer: submit fraudulent claims to the federal government
The False Claims Act holds parties liable who knowingly submit or cause submission of false or fraudulent claims for payment to the federal government.
Question 4: In medical ethics, 'non-maleficence' specifically means:
- doing good for the patient
- respecting patient decisions
- avoiding harm to the patient (Correct answer)
- distributing resources fairly
Correct answer: avoiding harm to the patient
Non-maleficence is the principle of 'do no harm,' obligating healthcare workers to avoid actions that injure or harm patients.
Question 5: A HIPAA Business Associate Agreement (BAA) is required when a covered entity shares PHI with a vendor that:
- provides office cleaning services only
- performs functions involving PHI on behalf of the covered entity (Correct answer)
- sells medical supplies without accessing patient data
- sends generic marketing mail to all patients
Correct answer: performs functions involving PHI on behalf of the covered entity
A BAA is required whenever a business associate performs services for a covered entity that involve the use or disclosure of PHI.
Question 6: Which of the following is NOT a permissible use or disclosure of PHI without patient authorization under HIPAA?
- Treatment purposes between providers
- Marketing a third-party's product to the patient (Correct answer)
- Required public health reporting
- Healthcare operations such as quality review
Correct answer: Marketing a third-party's product to the patient
Marketing a third-party product generally requires patient authorization; treatment, operations, and mandated public health activities are permitted without it.
Question 7: The doctrine of respondeat superior in healthcare means:
- patients have the right to refuse treatment
- employers can be held liable for employees' negligent acts within scope of employment (Correct answer)
- physicians must obtain consent before procedures
- hospitals must maintain adequate staff levels
Correct answer: employers can be held liable for employees' negligent acts within scope of employment
Respondeat superior ('let the master answer') holds employers vicariously liable for negligent acts committed by employees within their scope of employment.
A covered entity must provide patients with a Notice of Privacy Practices (NPP):