CMRT Privacy & Security 4 — Questions and Answers
Question 1: Which HIPAA provision gives patients the right to request restrictions on how their PHI is used for treatment, payment, or operations?
- Right of Access
- Right to Request Restrictions (Correct answer)
- Right to Accounting of Disclosures
- Right to Amend
Correct answer: Right to Request Restrictions
The HIPAA Privacy Rule grants patients the right to request that a covered entity restrict uses or disclosures of PHI, though the entity is generally not required to agree.
Question 2: When a covered entity discloses PHI for public health reporting purposes, this is considered:
- A violation requiring patient authorization
- A permitted disclosure under HIPAA without patient consent (Correct answer)
- An incidental disclosure requiring breach notification
- A disclosure requiring a court order
Correct answer: A permitted disclosure under HIPAA without patient consent
HIPAA permits disclosures for public health activities such as reporting communicable diseases to public health authorities without patient authorization.
Question 3: Which of the following is a 'technical safeguard' required by the HIPAA Security Rule?
- Shredding paper records containing PHI
- Locking server room doors
- Implementing encryption for PHI transmitted over open networks (Correct answer)
- Training workforce members on privacy policies
Correct answer: Implementing encryption for PHI transmitted over open networks
Technical safeguards include encryption, access controls, audit controls, and integrity controls that protect electronic PHI through technology.
Question 4: A patient has paid out-of-pocket in full for a service and requests that the covered entity not disclose that encounter to their health plan. The covered entity must:
- Consult the health plan before agreeing
- Honor the restriction request (Correct answer)
- Deny the request as impractical
- Disclose only the diagnosis, not the treatment
Correct answer: Honor the restriction request
Under HITECH, when a patient pays out-of-pocket in full and requests restriction from their health plan, the covered entity is required to honor that restriction.
Question 5: What distinguishes a 'covered entity' from a 'business associate' under HIPAA?
- Covered entities never handle electronic records
- Covered entities are healthcare providers, health plans, or clearinghouses that transmit PHI; business associates perform functions for them (Correct answer)
- Business associates are regulated only by state law, not HIPAA
- There is no distinction; both terms are interchangeable under HIPAA
Correct answer: Covered entities are healthcare providers, health plans, or clearinghouses that transmit PHI; business associates perform functions for them
Covered entities are defined entities (providers, plans, clearinghouses) directly subject to HIPAA, while business associates are third parties that perform services involving PHI on their behalf.
Question 6: An organization conducting a risk analysis under HIPAA is assessing:
- Which employees need salary increases
- The potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- The financial cost of implementing an EHR system
- The clinical quality metrics of patient care
Correct answer: The potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
HIPAA requires a thorough risk analysis to identify threats and vulnerabilities to ePHI as the foundation of a security management process.
Question 7: Which method ensures that PHI is unreadable to unauthorized parties if a laptop is lost or stolen?
- Password protection alone
- Full-disk encryption (Correct answer)
- Installing antivirus software
- Enabling automatic screen lock after 10 minutes
Correct answer: Full-disk encryption
Full-disk encryption renders data on a lost or stolen device unreadable without the decryption key, which is why HIPAA guidelines recognize it as a key safeguard.
Which HIPAA provision gives patients the right to request restrictions on how their PHI is used for treatment, payment, or operations?