CTC Regulatory Compliance & Privacy Standards 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a permissible disclosure of PHI without patient authorization?
- Marketing a new telehealth app to the patient
- Sharing PHI with a business associate under a signed BAA (Correct answer)
- Posting de-identified data that still includes zip code and birthdate
- Selling PHI to a third-party analytics firm
Correct answer: Sharing PHI with a business associate under a signed BAA
HIPAA permits disclosure of PHI to business associates when a Business Associate Agreement (BAA) is in place.
Question 2: A telehealth coordinator receives a patient request to access their own medical records within a telehealth portal. Under HIPAA, the covered entity must respond within:
- 10 calendar days
- 30 calendar days, with one 30-day extension if needed (Correct answer)
- 60 calendar days
- 7 business days
Correct answer: 30 calendar days, with one 30-day extension if needed
HIPAA requires covered entities to act on access requests within 30 days, with one permissible 30-day extension.
Question 3: Which federal law specifically governs the confidentiality of substance use disorder patient records in a telehealth context?
- HITECH Act
- 42 CFR Part 2 (Correct answer)
- ADA Title III
- The Mental Health Parity Act
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides stricter confidentiality protections for substance use disorder treatment records than standard HIPAA rules.
Question 4: A telehealth platform vendor stores encrypted patient session recordings. Under HIPAA, this vendor is best classified as a:
- Covered entity
- Business associate (Correct answer)
- Hybrid entity
- Workforce member
Correct answer: Business associate
A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate under HIPAA.
Question 5: When conducting a HIPAA Security Risk Analysis for a telehealth program, which step must be completed FIRST?
- Implement technical safeguards
- Identify all ePHI the organization creates, receives, maintains, or transmits (Correct answer)
- Draft policies and procedures
- Train workforce members
Correct answer: Identify all ePHI the organization creates, receives, maintains, or transmits
The Security Rule requires organizations to first identify where ePHI exists before assessing threats and vulnerabilities.
Question 6: A state law requires telehealth providers to obtain written informed consent before a virtual visit, but HIPAA does not require this. Which standard applies?
- HIPAA always preempts state law
- The state law applies if it provides greater privacy protections to patients (Correct answer)
- Federal law always takes precedence regardless of state protections
- The provider may choose whichever standard is more convenient
Correct answer: The state law applies if it provides greater privacy protections to patients
HIPAA does not preempt state laws that are more protective of patient privacy; the stricter standard must be followed.
Question 7: Which HIPAA safeguard category requires telehealth organizations to implement automatic logoff for portal sessions?
- Administrative safeguards
- Physical safeguards
- Technical safeguards (Correct answer)
- Organizational safeguards
Correct answer: Technical safeguards
Automatic logoff is a technical safeguard under the HIPAA Security Rule designed to prevent unauthorized access to ePHI.
Under HIPAA, which of the following is considered a permissible disclosure of PHI without patient authorization?