CTR Confidentiality & Data Security 3 — Questions and Answers
Question 1: Which federal law specifically establishes the foundation for cancer registry confidentiality protections in relation to public health reporting?
- The Freedom of Information Act (FOIA)
- The Cancer Registries Amendment Act (CCRAA) (Correct answer)
- The Affordable Care Act (ACA)
- The Federal Records Act
Correct answer: The Cancer Registries Amendment Act (CCRAA)
The Cancer Registries Amendment Act of 1992 established the National Program of Cancer Registries (NPCR) and includes provisions for the confidentiality of cancer registry data.
Question 2: A registrar is asked to present aggregate cancer incidence statistics at a public health conference. Which of the following presentations would pose the GREATEST re-identification risk?
- State-level incidence rates for common cancers
- Five-year age-grouped rates for a large metropolitan area
- Single-year data for a rare cancer in a small rural county (Correct answer)
- National SEER incidence trends over a 10-year period
Correct answer: Single-year data for a rare cancer in a small rural county
Small cell sizes for rare cancers in small geographic areas create a high risk of re-identification and should be suppressed or aggregated.
Question 3: Physical security measures for a cancer registry office should include which of the following?
- Allowing visitors to wait unescorted in abstracting areas to save staff time
- Locking workstations when not in use and restricting badge access to the registry area (Correct answer)
- Posting a list of currently abstracted cases near the entrance for quick reference
- Storing paper patient records in open shelving in a common hallway
Correct answer: Locking workstations when not in use and restricting badge access to the registry area
Locking workstations and controlling physical access to registry areas are essential physical safeguards for protecting PHI.
Question 4: Under the HIPAA Privacy Rule, which of the following is a required element of a valid authorization for release of cancer registry information?
- The patient's insurance policy number
- An expiration date or expiration event (Correct answer)
- The name of the requesting facility's chief medical officer
- A description of all other facilities that hold the patient's records
Correct answer: An expiration date or expiration event
A valid HIPAA authorization must include an expiration date or event that relates to the individual or the purpose of the use or disclosure.
Question 5: A state cancer registry is subject to a public records request under the state's open records law. The registry MOST likely:
- Must release all requested records because public records laws override HIPAA
- Is exempt from disclosure because state cancer registry data is typically protected by state statute (Correct answer)
- Must release aggregate data only after removing all geographic identifiers
- Has no legal basis to withhold any records from the public
Correct answer: Is exempt from disclosure because state cancer registry data is typically protected by state statute
Most states have enacted specific statutes exempting cancer registry data from public records laws to protect patient confidentiality.
Question 6: When a cancer registrar suspects that a breach of unsecured PHI has occurred, what is the MINIMUM timeframe for notifying affected individuals under the HIPAA Breach Notification Rule?
- Within 24 hours of discovery
- Within 60 days of discovery of the breach (Correct answer)
- Within 6 months of the end of the calendar year
- Within 30 days of verifying the breach
Correct answer: Within 60 days of discovery of the breach
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach.
Question 7: Which activity would be considered a HIPAA-permitted disclosure of cancer registry PHI for public health purposes WITHOUT requiring patient authorization?
- Releasing patient records to an employer to verify an employee's cancer diagnosis
- Reporting cases to a state cancer registry as required by state law (Correct answer)
- Providing a patient's cancer history to their attorney for litigation purposes
- Sharing identified records with a pharmaceutical company conducting market research
Correct answer: Reporting cases to a state cancer registry as required by state law
HIPAA permits disclosure of PHI to public health authorities, including mandatory reporting to state cancer registries authorized by law, without patient authorization.
Which federal law specifically establishes the foundation for cancer registry confidentiality protections in relation to public health reporting?