CVS Patient Confidentiality and HIPAA 3 — Questions and Answers
Question 1: A law enforcement officer requests a patient's prescription fill history without a court order. Under HIPAA, a pharmacy may:
- Always provide the full fill history immediately upon any officer's verbal request
- Refuse all law enforcement requests regardless of circumstances
- Disclose limited information in specific circumstances such as identifying a suspect or responding to a valid legal process (Correct answer)
- Share the records only if the patient is present and verbally consents
Correct answer: Disclose limited information in specific circumstances such as identifying a suspect or responding to a valid legal process
HIPAA permits certain disclosures to law enforcement under defined conditions, such as court orders, subpoenas, or specific crime-related situations.
Question 2: Which of the following is NOT an element of protected health information (PHI)?
- A patient's date of birth linked to their diagnosis
- A patient's zip code combined with their prescription
- A de-identified aggregate statistic about flu vaccine uptake with no individual identifiers (Correct answer)
- A patient's phone number associated with their refill reminder
Correct answer: A de-identified aggregate statistic about flu vaccine uptake with no individual identifiers
Information that has been properly de-identified and contains no individual identifiers is not considered PHI under HIPAA.
Question 3: How long must covered entities retain HIPAA-related policies and documentation?
- 2 years from creation or last effective date
- 6 years from creation or last effective date (Correct answer)
- 10 years from creation or last effective date
- Indefinitely until the entity closes
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain documentation of policies and procedures for six years from creation or when it was last in effect.
Question 4: A pharmacy's electronic health records system is hacked and patient data is exposed. What is the pharmacy's obligation under the HIPAA Breach Notification Rule?
- Notify affected individuals, HHS, and potentially media if the breach affects 500 or more individuals in a state (Correct answer)
- Notify only the pharmacy's corporate legal team and keep the breach internal
- Report the breach to local police within 24 hours as the sole requirement
- No action is required if encrypted backups exist
Correct answer: Notify affected individuals, HHS, and potentially media if the breach affects 500 or more individuals in a state
The Breach Notification Rule requires notifying affected individuals, HHS, and local media (for large breaches) within specific timeframes.
Question 5: Which federal agency is responsible for enforcing HIPAA Privacy and Security Rules?
- The Centers for Medicare & Medicaid Services (CMS)
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Drug Enforcement Administration (DEA)
- The Food and Drug Administration (FDA)
Correct answer: The Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary enforcer of HIPAA Privacy and Security Rules.
Question 6: A patient requests an accounting of disclosures of their PHI. Which disclosures are included in this accounting?
- Disclosures for treatment, payment, and operations
- Disclosures made without the patient's authorization, except those for TPO (Correct answer)
- All disclosures including those for treatment purposes over 10 years
- Only disclosures made to government agencies
Correct answer: Disclosures made without the patient's authorization, except those for TPO
HIPAA's right to an accounting covers disclosures made without authorization, but disclosures for treatment, payment, and healthcare operations are excluded.
Question 7: Under HIPAA, which of the following represents a permissible use of PHI without patient authorization?
- Sharing a patient's prescription list with their life insurance company
- Using patient data to market unrelated health products
- Disclosing PHI to a public health authority for disease surveillance (Correct answer)
- Selling de-identified data that still includes birth dates and zip codes
Correct answer: Disclosing PHI to a public health authority for disease surveillance
HIPAA permits disclosure of PHI to public health authorities for activities such as disease surveillance without patient authorization.
A law enforcement officer requests a patient's prescription fill history without a court order.
Under HIPAA, a pharmacy may: