EC Confidentiality & Data Security 3 — Questions and Answers
Question 1: A client discloses they have a bloodborne illness during intake. Who within the practice may appropriately access this information?
- All staff members as a general precaution
- Only those directly involved in the client's care (Correct answer)
- The front desk receptionist for scheduling purposes
- Any licensed professional in the building
Correct answer: Only those directly involved in the client's care
Sensitive health disclosures should be shared only with staff members directly involved in providing that client's care.
Question 2: Before photographing a client's skin for treatment tracking, the electrologist must:
- Obtain only verbal permission
- Obtain written informed consent specifying how photos will be used and stored (Correct answer)
- Post photos publicly to showcase progress
- Store photos on a personal social media account for reference
Correct answer: Obtain written informed consent specifying how photos will be used and stored
Written consent detailing the purpose, storage, and use of clinical photographs is required to protect client privacy.
Question 3: What is the primary purpose of a Notice of Privacy Practices (NPP) given to clients?
- To collect client payment information
- To inform clients of their rights and how their health information will be used (Correct answer)
- To waive the client's right to privacy
- To authorize insurance billing
Correct answer: To inform clients of their rights and how their health information will be used
The NPP explains how a covered entity uses and discloses protected health information and describes clients' rights under HIPAA.
Question 4: A client asks to see their own treatment records. Under HIPAA, they have the right to:
- Be denied access if records are more than one year old
- Inspect and obtain a copy of their records (Correct answer)
- Access only the billing portion of their file
- View records only with a physician's approval
Correct answer: Inspect and obtain a copy of their records
Clients have a right under HIPAA to inspect and receive copies of their own protected health information.
Question 5: If a practice experiences a data breach affecting more than 500 clients, which agency must be notified?
- The local police department
- The U.S. Department of Health and Human Services (HHS) (Correct answer)
- The state board of cosmetology only
- No notification is required for breaches under 1,000 records
Correct answer: The U.S. Department of Health and Human Services (HHS)
HIPAA requires covered entities to notify HHS and affected individuals promptly when a breach involves 500 or more individuals.
Question 6: Which of the following is a strong password practice for protecting electronic client records?
- Using the clinic's name as the password for easy memory
- Using a combination of uppercase, lowercase, numbers, and symbols with at least 12 characters (Correct answer)
- Sharing one password among all staff for convenience
- Writing the password on a note near the computer
Correct answer: Using a combination of uppercase, lowercase, numbers, and symbols with at least 12 characters
Complex passwords with varied character types and sufficient length significantly reduce the risk of unauthorized system access.
Question 7: A client cancels future appointments and requests all their records be deleted. The electrologist should:
- Delete all records immediately upon request
- Inform the client that records must be retained for the legally required period before destruction (Correct answer)
- Transfer all records to a competitor without client consent
- Ignore the request and keep records indefinitely
Correct answer: Inform the client that records must be retained for the legally required period before destruction
State and federal laws mandate specific record retention periods; records cannot simply be deleted at the client's immediate request.
A client discloses they have a bloodborne illness during intake.
Who within the practice may appropriately access this information?