CTC Regulatory Compliance & Standards 2 — Questions and Answers
Question 1: Under 42 CFR Part 2, which category of telehealth records receives heightened confidentiality protections beyond standard HIPAA requirements?
- Mental health records
- Substance use disorder records (Correct answer)
- HIV/AIDS treatment records
- Genetic testing records
Correct answer: Substance use disorder records
42 CFR Part 2 provides special federal protections for substance use disorder (SUD) patient records, requiring specific written consent before disclosure even to other treating providers.
Question 2: Which federal law established the Ryan Haight Online Pharmacy Consumer Protection Act provisions that restrict prescribing controlled substances via telehealth?
- Controlled Substances Act (Correct answer)
- Food, Drug, and Cosmetic Act
- DEA Controlled Substance Ordering System Act
- Combat Methamphetamine Epidemic Act
Correct answer: Controlled Substances Act
The Ryan Haight Act amended the Controlled Substances Act to require an in-person evaluation before prescribing Schedule II-V controlled substances via the internet or telehealth.
Question 3: A telehealth coordinator is auditing a platform that stores PHI. Which technical safeguard under HIPAA Security Rule is specifically required for PHI transmitted over open networks?
- Automatic logoff
- Audit controls
- Encryption and decryption (Correct answer)
- Unique user identification
Correct answer: Encryption and decryption
The HIPAA Security Rule requires encryption as an addressable implementation specification for PHI transmitted over open electronic networks to protect against unauthorized interception.
Question 4: Which CMS condition applies when a Medicare patient receives telehealth services and the originating site is a patient's home?
- The patient must be in a rural HPSA
- The patient must be in a Metropolitan Statistical Area
- No geographic restriction applies under current flexibilities (Correct answer)
- The patient must be in a federally qualified health center
Correct answer: No geographic restriction applies under current flexibilities
Under COVID-19 emergency flexibilities that were extended, Medicare patients can receive telehealth from their homes without geographic restrictions, removing the traditional rural-only limitation.
Question 5: A CTC is reviewing a business associate agreement (BAA). Which entity is NOT required to sign a BAA under HIPAA?
- Cloud storage vendor hosting PHI
- Telehealth platform provider
- Janitorial company with incidental PHI access (Correct answer)
- Medical transcription service
Correct answer: Janitorial company with incidental PHI access
Workforce members and employees of a covered entity, including janitorial staff with only incidental contact, are not business associates and do not require a BAA.
Question 6: Under HIPAA, what is the maximum penalty per violation category for willful neglect that is not corrected?
- $10,000
- $50,000
- $100,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
Violations due to willful neglect not corrected within the required period carry a maximum penalty of $1,919,173 per violation category per year (adjusted for inflation from the original $1.5M cap).
Question 7: Which standard governs the exchange of clinical documents in telehealth encounters for interoperability purposes?
- DICOM
- HL7 CDA / FHIR (Correct answer)
- SNOMED CT only
- ICD-10-CM
Correct answer: HL7 CDA / FHIR
HL7 Clinical Document Architecture (CDA) and the newer FHIR (Fast Healthcare Interoperability Resources) standard govern the structured exchange of clinical documents between systems for interoperability.
Under 42 CFR Part 2, which category of telehealth records receives heightened confidentiality protections beyond standard HIPAA requirements?