CRSS Documentation and Confidentiality 5 — Questions and Answers
Question 1: Which of the following scenarios describes a breach of confidentiality?
- An RSS discusses a de-identified client case in a group supervision session
- An RSS mentions to a neighbor that a mutual friend is enrolled in a recovery program (Correct answer)
- An RSS shares a client's progress note with the client's treatment team under a signed release
- An RSS documents a client's relapse disclosure in the clinical record
Correct answer: An RSS mentions to a neighbor that a mutual friend is enrolled in a recovery program
Disclosing that a specific individual is enrolled in a recovery program to an unauthorized person violates confidentiality, even without sharing clinical details.
Question 2: A mandatory reporting law requires an RSS to report suspected child abuse. After making the report, the RSS should:
- Document the report, including what information was shared, to whom, and when (Correct answer)
- Keep the report confidential and not note it in the client's record
- Notify the client about the report only after the investigation concludes
- Destroy the evidence of the report to protect the client's privacy
Correct answer: Document the report, including what information was shared, to whom, and when
Mandatory reports must be documented in the record, including the nature of the concern, who was notified, and when the report was made.
Question 3: How long must a recovery support agency typically retain client records after the last date of service?
- One year
- The period specified by applicable state law and agency policy, commonly 7–10 years for adults (Correct answer)
- Six months
- Records must be destroyed immediately after services end to protect confidentiality
Correct answer: The period specified by applicable state law and agency policy, commonly 7–10 years for adults
Record retention periods vary by state law and funding requirements but commonly range from 7 to 10 years for adult client records.
Question 4: A client's consent for release of information has expired. The RSS receives a request for records from the consented recipient. The RSS should:
- Release the records since the original consent was valid when signed
- Obtain a new, current consent from the client before releasing any records (Correct answer)
- Release records for the period covered by the original consent only
- Contact the recipient and explain the agency's billing procedures
Correct answer: Obtain a new, current consent from the client before releasing any records
An expired consent is no longer valid; a new consent must be obtained before any additional disclosures can be made.
Question 5: Which statement about 42 CFR Part 2 and HIPAA is accurate?
- 42 CFR Part 2 and HIPAA provide identical protections for all health records
- 42 CFR Part 2 provides stricter protections specifically for substance use disorder records than HIPAA's general privacy rule (Correct answer)
- HIPAA supersedes 42 CFR Part 2 in all circumstances
- 42 CFR Part 2 applies only to inpatient treatment programs, not outpatient or peer support services
Correct answer: 42 CFR Part 2 provides stricter protections specifically for substance use disorder records than HIPAA's general privacy rule
42 CFR Part 2 imposes stricter consent and disclosure requirements for substance use disorder records than HIPAA's general health information protections.
Question 6: An RSS is asked to sign as a witness on a client's consent form. By signing, the RSS is attesting that:
- The client's decision is clinically appropriate
- The client signed the form voluntarily and the RSS witnessed the signature (Correct answer)
- The RSS agrees with the content of the disclosure
- The agency approves the release of information
Correct answer: The client signed the form voluntarily and the RSS witnessed the signature
A witness signature on a consent form attests only that the person signed voluntarily; it does not imply the witness endorses the decision.
Question 7: What is the recommended practice when an RSS receives a fax containing another client's records by mistake?
- File the misdirected records in the agency's general filing system for future reference
- Notify the sender, document the misdirected fax, and follow agency policy for secure destruction of the records (Correct answer)
- Read the records to determine if they relate to any current clients before deciding what to do
- Forward the fax to the appropriate provider without notifying anyone
Correct answer: Notify the sender, document the misdirected fax, and follow agency policy for secure destruction of the records
Misdirected records must be reported to the sender immediately, documented, and securely destroyed according to agency policy to prevent unauthorized disclosure.
Which of the following scenarios describes a breach of confidentiality?