CTR Confidentiality & Data Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity' with obligations to protect cancer registry data?
- A tumor registry vendor providing only software
- A healthcare provider that transmits health information electronically (Correct answer)
- A public health researcher receiving de-identified data
- A state cancer registry funded solely by federal grants
Correct answer: A healthcare provider that transmits health information electronically
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers that transmit protected health information electronically.
Question 2: A cancer registry receives a subpoena requesting identifiable patient records. What is the MOST appropriate first step?
- Immediately release all requested records to comply with the legal order
- Notify and consult with the facility's legal counsel before releasing any records (Correct answer)
- Redact all names and release the remaining data without legal review
- Deny the subpoena because cancer registry data is always privileged
Correct answer: Notify and consult with the facility's legal counsel before releasing any records
When served with a subpoena, the registrar should consult legal counsel to determine whether the request is valid and whether a court order or patient authorization is required.
Question 3: Which concept requires that cancer registry employees only access patient data necessary for their specific job functions?
- Data minimization
- Least privilege
- Need-to-know principle (Correct answer)
- Role-based access control
Correct answer: Need-to-know principle
The need-to-know principle restricts access to confidential information to only those individuals whose job duties require it.
Question 4: A tumor registrar discovers that a coworker has been accessing patient records for cases outside their assigned abstracting workload. This MOST likely violates which policy?
- Mandatory reporting requirements
- Minimum necessary use provisions (Correct answer)
- Business associate agreement terms
- Data retention schedules
Correct answer: Minimum necessary use provisions
Accessing more patient information than is necessary for one's duties violates the HIPAA minimum necessary standard.
Question 5: When a cancer registry shares data with an external researcher under a data use agreement, the DUA must specify which of the following?
- The researcher's personal salary and funding source
- Permitted uses of the data and required safeguards (Correct answer)
- The names of all patients whose data will be shared
- The registry's internal quality control procedures
Correct answer: Permitted uses of the data and required safeguards
A data use agreement must define the permitted uses and disclosures of the limited data set and required safeguards to protect it.
Question 6: Which of the following best describes a 'limited data set' as defined by HIPAA?
- Data with all 18 HIPAA identifiers removed
- Data that excludes most direct identifiers but may retain dates and geographic information below state level (Correct answer)
- Data containing only diagnosis codes and no demographic information
- Fully de-identified data approved for unrestricted public release
Correct answer: Data that excludes most direct identifiers but may retain dates and geographic information below state level
A limited data set removes most direct identifiers but may include dates (e.g., admission, discharge, birth) and geographic subdivisions smaller than a state.
Question 7: A cancer registry manager receives a request from a life insurance company asking for a patient's cancer history to assess a policy application. The CORRECT response is to:
- Provide the information because insurance companies are authorized requesters
- Require a signed, valid patient authorization before releasing any information (Correct answer)
- Share de-identified data since it does not reveal the specific patient
- Refer the insurer directly to the treating oncologist
Correct answer: Require a signed, valid patient authorization before releasing any information
Disclosure to a life insurance company requires the patient's valid written authorization because this is not a treatment, payment, or healthcare operations purpose.
Under HIPAA, which of the following is considered a 'covered entity' with obligations to protect cancer registry data?