CTP Legal, Ethical & Regulatory Compliance 5 — Questions and Answers
Question 1: A telehealth company markets its platform as 'HIPAA compliant' but has not signed BAAs with its vendors. This situation represents:
- A minor administrative oversight with no legal consequence
- A potential HIPAA violation and deceptive marketing claim (Correct answer)
- Acceptable if the platform uses end-to-end encryption
- A violation of the FTC Act only, not HIPAA
Correct answer: A potential HIPAA violation and deceptive marketing claim
Claiming HIPAA compliance without required BAAs is both a HIPAA violation and potentially deceptive marketing under FTC standards.
Question 2: Which of the following is an example of a HIPAA minimum necessary standard violation in telehealth?
- Sending a patient their full lab report when they requested it
- A billing coordinator accessing full psychiatric notes to process a payment (Correct answer)
- A treating provider reviewing a patient's medication history before a visit
- A care coordinator viewing appointment records to schedule follow-ups
Correct answer: A billing coordinator accessing full psychiatric notes to process a payment
The minimum necessary standard requires that access to PHI be limited to what is needed for the specific job function; a billing coordinator does not need full psychiatric records.
Question 3: Under CMS telehealth coverage rules (post-2020 waivers), which originating site requirement was temporarily relaxed during the COVID-19 public health emergency?
- Providers no longer needed DEA registration
- Patients could receive Medicare telehealth services from their homes, not just approved facilities (Correct answer)
- Telehealth visits were no longer required to be documented in an EHR
- Audio-only visits were prohibited under the relaxed rules
Correct answer: Patients could receive Medicare telehealth services from their homes, not just approved facilities
During the COVID-19 PHE, CMS waived the originating site restriction, allowing Medicare beneficiaries to receive telehealth services from their homes.
Question 4: A telehealth provider discovers a data breach affecting 600 patients' ePHI. What is the HIPAA breach notification timeline for notifying HHS?
- Within 24 hours of discovery
- Within 60 days of discovery (Correct answer)
- Within 30 days of discovery
- Within 90 days of the end of the calendar year
Correct answer: Within 60 days of discovery
HIPAA requires covered entities to notify HHS of breaches affecting 500 or more individuals within 60 days of discovery.
Question 5: Which professional ethics concept requires a telehealth provider to act in the patient's best interest even when it conflicts with the provider's own financial interests?
- Veracity
- Fiduciary duty (Correct answer)
- Beneficence
- Nonmaleficence
Correct answer: Fiduciary duty
Fiduciary duty obligates providers to prioritize patient welfare over personal financial gain, a critical standard in avoiding conflicts of interest in telehealth.
Question 6: A telehealth provider uses AI-generated diagnostic suggestions. Who bears primary legal and ethical responsibility for the final clinical decision?
- The AI software vendor
- The licensed clinician who acts on the AI output (Correct answer)
- The telehealth platform operator
- Responsibility is shared equally among all three parties
Correct answer: The licensed clinician who acts on the AI output
The licensed clinician retains full professional and legal responsibility for clinical decisions, even when AI tools inform those decisions.
Question 7: Which of the following actions would BEST demonstrate compliance with the ethical principle of justice in a telehealth practice?
- Offering premium services to highest-paying patients only
- Ensuring equitable access to telehealth services regardless of patients' socioeconomic status or geographic location (Correct answer)
- Prioritizing urban patients who have faster internet connections
- Limiting services to patients with private insurance to ensure profitability
Correct answer: Ensuring equitable access to telehealth services regardless of patients' socioeconomic status or geographic location
The principle of justice requires fair distribution of healthcare resources and access, including designing telehealth services that reduce rather than reinforce health disparities.
A telehealth company markets its platform as 'HIPAA compliant' but has not signed BAAs with its vendors.
This situation represents: