Echocardiogram Security Principles and Practices 2 — Questions and Answers
Question 1: A patient requests that their echocardiogram results not be shared with their employer. Under HIPAA, how should the technician respond?
- Honor the request and document it in the medical record (Correct answer)
- Explain that employers are always entitled to medical records
- Inform the patient that verbal requests are insufficient
- Forward the results to the employer unless the patient provides written refusal
Correct answer: Honor the request and document it in the medical record
HIPAA grants patients the right to restrict disclosure of their PHI, and such restrictions must be honored and documented.
Question 2: Which of the following constitutes a minimum necessary standard violation when accessing echocardiogram records?
- Reviewing only the current study for a patient you are scanning
- Accessing the complete medical histories of all patients on the schedule out of curiosity (Correct answer)
- Viewing prior echo studies to compare findings for a patient under your care
- Checking patient demographics needed to complete the exam report
Correct answer: Accessing the complete medical histories of all patients on the schedule out of curiosity
The minimum necessary standard requires accessing only the PHI needed to perform a specific job function, not browsing records out of curiosity.
Question 3: When an echocardiogram technician suspects a coworker is accessing patient records without authorization, the appropriate first step is to:
- Confront the coworker directly and warn them to stop
- Report the suspicion to the facility's privacy officer or compliance department (Correct answer)
- Monitor the coworker's activity for several weeks before acting
- Notify the patients whose records may have been accessed
Correct answer: Report the suspicion to the facility's privacy officer or compliance department
Suspected privacy violations should be reported to the facility's privacy officer or compliance department, who are responsible for investigating such matters.
Question 4: A referring physician who is NOT involved in a patient's current echocardiogram care requests access to that patient's echo images. The correct action is to:
- Provide access since all physicians have blanket access rights
- Verify the physician has a current treatment relationship with the patient before granting access (Correct answer)
- Deny access without a written court order
- Allow access only if the patient is present in the facility
Correct answer: Verify the physician has a current treatment relationship with the patient before granting access
PHI may be disclosed for treatment purposes to providers with a current treatment relationship; a treating relationship must be verified before granting access.
Question 5: Which security measure best protects echocardiogram workstations from unauthorized access during brief technician absences?
- Posting a sign requesting others not to use the workstation
- Configuring automatic screen lock after a short period of inactivity (Correct answer)
- Logging off only at the end of each shift
- Disabling the monitor when stepping away
Correct answer: Configuring automatic screen lock after a short period of inactivity
Automatic screen lock after inactivity is the most effective technical safeguard against unauthorized access during brief absences.
Question 6: A patient in the emergency department is unconscious and requires emergent echocardiography. No authorized representative is available to provide consent. The technician should:
- Delay the procedure until consent can be obtained
- Proceed with the exam under implied consent for emergency treatment (Correct answer)
- Obtain verbal consent from the paramedics who transported the patient
- Require the ordering physician to sign a waiver before proceeding
Correct answer: Proceed with the exam under implied consent for emergency treatment
Implied consent applies in emergencies when the patient is unable to consent and delay would result in harm; treatment may proceed.
Question 7: Under HIPAA's Breach Notification Rule, how quickly must a covered entity notify the U.S. Department of Health and Human Services of a breach affecting 500 or more individuals?
- Within 24 hours of discovery
- Within 60 days of discovery (Correct answer)
- Within 30 days of the end of the calendar year
- Within 6 months of discovery
Correct answer: Within 60 days of discovery
Breaches affecting 500 or more individuals must be reported to HHS within 60 days of discovery of the breach.
A patient requests that their echocardiogram results not be shared with their employer.
Under HIPAA, how should the technician respond?