CMT - Certified Medical Technician Regulatory Standards and Ethics 1 — Questions and Answers
Question 1: Under HIPAA, a covered entity may disclose a patient's protected health information (PHI) without written authorization for which of the following purposes?
- Marketing campaigns by a pharmaceutical company partner
- Public health activities authorized by law, such as disease surveillance (Correct answer)
- Sharing records with the patient's employer upon the employer's request
- Providing information to a patient's adult child without patient consent
Correct answer: Public health activities authorized by law, such as disease surveillance
HIPAA permits disclosure of PHI without patient authorization for specific public interest purposes, including public health activities (e.g., reporting communicable diseases to health departments) as outlined under 45 CFR §164.512. The other options require explicit patient authorization.
Question 2: The bioethical principle of 'non-maleficence' obligates a medical technician to:
- Obtain informed consent before every procedure
- Distribute healthcare resources fairly among all patients
- Avoid performing actions that cause unnecessary harm or injury to the patient (Correct answer)
- Respect and support the patient's right to make autonomous decisions
Correct answer: Avoid performing actions that cause unnecessary harm or injury to the patient
Non-maleficence means 'do no harm.' It requires healthcare workers to weigh the risks of any intervention and refrain from actions whose potential harms outweigh their benefits. It is distinct from beneficence (acting for the patient's good), autonomy, and justice.
Question 3: Which federal agency has primary regulatory authority over in vitro diagnostic devices and reagents used in medical laboratory testing?
- Centers for Disease Control and Prevention (CDC)
- Occupational Safety and Health Administration (OSHA)
- Food and Drug Administration (FDA) (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
Correct answer: Food and Drug Administration (FDA)
The FDA regulates medical devices, including in vitro diagnostic (IVD) devices and reagents, under the Federal Food, Drug, and Cosmetic Act. The CDC provides guidance, OSHA governs workplace safety, and CMS administers CLIA certification — but device approval falls under the FDA.
Question 4: A medical technician discovers that a colleague has been documenting specimen collection times that were never actually performed. The most appropriate initial action is to:
- Confront the colleague privately and ask them to self-report
- Disregard the incident if no patient harm is immediately apparent
- Report the observation to a supervisor or through the facility's established chain of command (Correct answer)
- Contact the patient directly to disclose the documentation error
Correct answer: Report the observation to a supervisor or through the facility's established chain of command
Healthcare ethics and most facility policies require staff to report suspected fraud, falsification, or misconduct through proper internal channels (supervisor, compliance officer, or ethics hotline). Ignoring misconduct violates professional standards; direct confrontation or contacting the patient bypasses established protocol.
Question 5: State-designated mandatory reporting laws in healthcare primarily require providers to report:
- All laboratory test results that fall outside normal reference ranges
- Communicable diseases and conditions specified on the state's reportable disease list (Correct answer)
- Any patient who refuses a recommended treatment or procedure
- Cases where a patient lacks adequate health insurance coverage
Correct answer: Communicable diseases and conditions specified on the state's reportable disease list
Every U.S. state maintains a list of reportable communicable diseases (e.g., tuberculosis, hepatitis, STIs) that healthcare providers are legally required to report to public health authorities. Reporting is triggered by the specific diagnosis, not simply by an abnormal result, refusal of care, or insurance status.
Question 6: A medical technician's 'scope of practice' is most authoritatively defined by:
- The personal clinical judgment of the supervising physician on any given shift
- State statutes, administrative regulations, and the standards set by the relevant certification body (Correct answer)
- The number of years of hands-on experience the technician has accumulated
- Internal policies written by the facility's human resources department
Correct answer: State statutes, administrative regulations, and the standards set by the relevant certification body
Scope of practice is legally established through state law and administrative regulations, and further delineated by credentialing and certification organizations. While facility policies and physician direction operate within that framework, they cannot legally expand beyond what state law and certification standards permit.
Under HIPAA, a covered entity may disclose a patient's protected health information (PHI) without written authorization for which of the following purposes?