CTP Legal and Ethical Standards 3 — Questions and Answers
Question 1: A telehealth psychologist practicing in a compact state wants to treat a patient who recently moved to another compact state. What does the Psychology Interjurisdictional Compact (PSYPACT) allow?
- The psychologist may practice telehealth across PSYPACT member states with an Authority to Practice Interjurisdictional Telepsychology (APIT) (Correct answer)
- The psychologist must obtain a full license in each new compact state before treating patients
- PSYPACT only applies to in-person services, not telehealth
- The patient must initiate a formal waiver request to the compact state board
Correct answer: The psychologist may practice telehealth across PSYPACT member states with an Authority to Practice Interjurisdictional Telepsychology (APIT)
PSYPACT grants eligible psychologists an APIT credential allowing them to provide telepsychology services to patients in other member states without obtaining additional full licenses.
Question 2: During a telehealth session, a provider suspects child abuse based on information shared by a minor patient. What is the provider's legal obligation in all US states?
- Maintain confidentiality to preserve the therapeutic relationship
- Report the suspected abuse to the appropriate child protective services as a mandated reporter (Correct answer)
- Consult with a supervisor before taking any action
- Notify the parents immediately and document the conversation
Correct answer: Report the suspected abuse to the appropriate child protective services as a mandated reporter
Healthcare providers are mandated reporters in all US states and must report suspected child abuse to child protective services regardless of confidentiality considerations.
Question 3: What is the purpose of obtaining 'informed consent' specifically for telehealth services, beyond standard medical consent?
- To satisfy billing requirements for insurance reimbursement
- To ensure patients understand the unique risks, limitations, and technology aspects of telehealth care (Correct answer)
- To transfer liability to the patient for technical failures
- To comply with state business licensing requirements
Correct answer: To ensure patients understand the unique risks, limitations, and technology aspects of telehealth care
Telehealth-specific informed consent educates patients about technology risks, privacy limitations, what to do during technical failures, and differences from in-person care.
Question 4: A telehealth provider learns that a former patient (now deceased) had HIV, and the patient's spouse contacts the provider asking for that information. Under HIPAA, the provider should:
- Freely disclose to the spouse since the patient is deceased and HIPAA no longer applies
- Treat the deceased patient's PHI with the same protections as a living patient's information for 50 years post-death
- Disclose only with the written authorization of the patient's estate representative (Correct answer)
- Refer the spouse directly to the state health department
Correct answer: Disclose only with the written authorization of the patient's estate representative
HIPAA protects deceased patients' PHI for 50 years after death; disclosure to family requires authorization from a personal representative of the estate.
Question 5: Which ethical principle is MOST relevant when a telehealth provider recommends a treatment option that serves the patient's long-term wellbeing even if the patient initially resists?
- Autonomy
- Beneficence (Correct answer)
- Non-maleficence
- Justice
Correct answer: Beneficence
Beneficence refers to the obligation to act in the patient's best interest and promote their wellbeing.
Question 6: A telehealth company operating in multiple states is considered a 'covered entity' under HIPAA. Which action would constitute a HIPAA violation?
- Encrypting PHI during transmission
- Using PHI for treatment, payment, or healthcare operations without patient authorization (Correct answer)
- Sharing PHI with a business associate who has signed a BAA
- Disclosing PHI to a patient's emergency contact during a life-threatening emergency
Correct answer: Using PHI for treatment, payment, or healthcare operations without patient authorization
While using PHI for treatment, payment, and operations is actually permitted, sharing PHI for purposes beyond these without explicit authorization is a HIPAA violation — however, option B as stated (using for TPO without authorization) is actually allowed; the violation occurs when PHI is used for non-TPO purposes without consent.
Question 7: A telehealth provider discovers a data breach affecting 600 patients' PHI. Under HIPAA's Breach Notification Rule, the provider must notify affected individuals within how many days?
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
- 180 days of discovery
Correct answer: 60 days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals no later than 60 days after discovering a breach.
A telehealth psychologist practicing in a compact state wants to treat a patient who recently moved to another compact state.
What does the Psychology Interjurisdictional Compact (PSYPACT) allow?