EHR Health Information Privacy & Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- A patient's medical diagnosis stored in the EHR
- De-identified data that cannot reasonably identify an individual (Correct answer)
- A patient's prescription history linked to their name
- Lab results associated with a patient's date of birth
Correct answer: De-identified data that cannot reasonably identify an individual
De-identified health information that cannot reasonably be used to identify an individual is not considered PHI under HIPAA.
Question 2: A covered entity must provide patients with a Notice of Privacy Practices (NPP) at which point?
- Only when a patient requests it
- At first service delivery and upon request thereafter (Correct answer)
- Annually every January regardless of patient visits
- Only when the privacy policy changes
Correct answer: At first service delivery and upon request thereafter
HIPAA requires covered entities to provide the NPP at first service delivery and make it available upon request at any subsequent visit.
Question 3: Which access control model grants permissions based on a user's job function within the organization?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns system access based on the user's organizational role or job function.
Question 4: What is the maximum penalty per violation category per year under HIPAA's tiered civil monetary penalty structure?
- $100,000
- $250,000
- $1,000,000
- $1,500,000 (Correct answer)
Correct answer: $1,500,000
HIPAA civil monetary penalties are capped at $1,500,000 per violation category per calendar year.
Question 5: An EHR audit log should capture which of the following at minimum?
- User ID, timestamp, and record accessed (Correct answer)
- Only records that were modified
- Login times only
- Patient name and diagnosis code only
Correct answer: User ID, timestamp, and record accessed
A compliant EHR audit log must capture at minimum who accessed the record (user ID), when (timestamp), and which record was accessed.
Question 6: Which HIPAA rule specifically governs the electronic transmission of health information between covered entities?
- Privacy Rule
- Security Rule
- Transactions and Code Sets Rule (Correct answer)
- Enforcement Rule
Correct answer: Transactions and Code Sets Rule
The HIPAA Transactions and Code Sets Rule mandates standard formats (such as EDI X12) for electronic healthcare transactions.
Question 7: A hospital employee accesses a celebrity patient's record out of curiosity without a clinical need. This is an example of:
- Incidental disclosure
- Minimum necessary violation
- Snooping — unauthorized access (Correct answer)
- A permitted use under treatment exception
Correct answer: Snooping — unauthorized access
Accessing patient records without a legitimate clinical or administrative purpose is considered snooping and is an unauthorized HIPAA violation.
Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?