Free CPMS HIPAA and Compliance Rules Questions and Answers — Questions and Answers
Question 1: A medical scribe is working in a busy emergency department. After a patient encounter, the scribe jots down the patient's name and medical record number on a piece of scrap paper to remember to complete the chart later. The scribe then places the paper in their pocket and forgets about it until the end of their shift. Which core HIPAA principle has been violated?
- The Minimum Necessary Rule
- The Patient's Right of Access
- Safeguarding Protected Health Information (PHI) (Correct answer)
- The Breach Notification Rule
Correct answer: Safeguarding Protected Health Information (PHI)
Writing down personally identifiable patient information on non-secure media like scrap paper and removing it from the clinical area is a violation of the fundamental requirement to safeguard PHI. HIPAA requires physical and administrative safeguards to be in place to protect patient information from unauthorized disclosure. The other options are incorrect because the Minimum Necessary Rule pertains to accessing only the data needed for a task, the Right of Access relates to a patient's ability to get their records, and the Breach Notification Rule applies after a breach has been confirmed.
Question 2: Which of the following scenarios BEST illustrates the HIPAA 'Minimum Necessary' standard as it applies to a medical scribe?
- Reading the entire patient chart, including records from 10 years ago, to gain a full understanding of their history.
- Accessing only the current encounter notes and the lab results ordered by the physician during today's visit to complete the chart. (Correct answer)
- Discussing the patient's interesting diagnosis with another scribe in the breakroom.
- Using a personal, unsecured laptop to finish charts at home to be more efficient.
Correct answer: Accessing only the current encounter notes and the lab results ordered by the physician during today's visit to complete the chart.
The 'Minimum Necessary' rule requires that access to Protected Health Information (PHI) be limited to only what is needed to accomplish a specific task. For a scribe, this means accessing the information directly relevant to the current patient encounter they are documenting, not the entire medical history unless instructed. Browsing old records out of curiosity, discussing cases in non-secure areas, and using unsecured personal devices are all violations of HIPAA principles.
Question 3: A medical scribe is employed by a third-party scribe service company, not directly by the hospital. In the context of HIPAA, what is the scribe service company's relationship to the hospital?
- Covered Entity
- Business Associate (Correct answer)
- Healthcare Clearinghouse
- Unaffiliated Third Party
Correct answer: Business Associate
A Business Associate is a person or entity that performs certain functions or activities on behalf of a Covered Entity (like a hospital) that involve the use or disclosure of Protected Health Information (PHI). Since the scribe service handles PHI on behalf of the hospital, it is considered a Business Associate and must have a signed Business Associate Agreement (BAA) in place.
Question 4: A patient at a clinic discovers that their medical record contains an error documented by a scribe. According to the HIPAA Privacy Rule, what right does the patient have regarding this information?
- The right to have the entire entry deleted immediately.
- The right to sue the medical scribe for malpractice.
- The right to request an amendment to their medical record. (Correct answer)
- The right to write their own note directly in the electronic health record.
Correct answer: The right to request an amendment to their medical record.
The HIPAA Privacy Rule grants patients the right to request an amendment to their protected health information in a designated record set. While they can request a correction, it does not guarantee the original entry will be deleted; instead, an addendum or correction is typically made to the record. The other options are incorrect; patients cannot directly delete or add notes to the EHR, and a documentation error does not automatically constitute grounds for a malpractice suit against the scribe.
Question 5: Under the HIPAA Security Rule, which of the following is considered a critical TECHNICAL safeguard for a medical scribe using an Electronic Health Record (EHR) system?
- Signing a confidentiality agreement upon being hired.
- Positioning the computer screen to prevent public viewing.
- Using a unique, strong password and enabling two-factor authentication. (Correct answer)
- Shredding any papers with patient information at the end of a shift.
Correct answer: Using a unique, strong password and enabling two-factor authentication.
The HIPAA Security Rule specifies three types of safeguards: administrative, physical, and technical. Unique user identification, such as a username and strong password, is a fundamental technical safeguard required to control access to electronic PHI (ePHI). Signing a confidentiality agreement is an administrative safeguard, while screen positioning and shredding documents are physical safeguards.
Question 6: A hospital discovers that a scribe's unencrypted work laptop, containing the PHI of 600 patients, was stolen. According to the HIPAA Breach Notification Rule, which of the following actions is the hospital required to take?
- Notify all affected individuals, the local media, and the Secretary of HHS within 60 days of discovery. (Correct answer)
- Post a notice in the hospital lobby and report the breach in their annual compliance report.
- Notify only the affected individuals via first-class mail within 90 days.
- Wait for law enforcement to recover the laptop before taking any notification action.
Correct answer: Notify all affected individuals, the local media, and the Secretary of HHS within 60 days of discovery.
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay, and in no case later than 60 days following the discovery of a breach. Because this breach affects more than 500 individuals, the rule also mandates notifying prominent media outlets in the state or jurisdiction and notifying the Secretary of Health and Human Services (HHS) concurrently with the individual notifications.
A medical scribe is working in a busy emergency department.
After a patient encounter, the scribe jots down the patient's name and medical record number on a piece of scrap paper to remember to complete the chart later.
The scribe then places the paper in their pocket and forgets about it until the end of their shift.
Which core HIPAA principle has been violated?