HIPAA - Health Insurance Portability and Accountability Act Protected Health Information (PHI) Questions and Answers — Questions and Answers
Question 1: Which of the following data elements, when combined with a patient's medical condition, would NOT be considered Protected Health Information (PHI) under HIPAA?
- The initial three digits of a zip code for a geographic area containing 25,000 people (Correct answer)
- A patient's full face photograph
- The year of a patient's birth
- A medical record number
Correct answer: The initial three digits of a zip code for a geographic area containing 25,000 people
According to the HIPAA Safe Harbor method for de-identification, the initial three digits of a zip code are not considered a direct identifier if the geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people. The other options—full face photograph, year of birth (for those under 90), and medical record number—are all explicitly listed as identifiers that constitute PHI.
Question 2: A hospital billing department outsources its coding to a third-party company. The coding company requires access to patient charts to perform its function. Under HIPAA, what is the most critical step the hospital must take before granting this access?
- Obtain individual patient authorization for each record shared.
- De-identify all patient data before sending it to the coding company.
- Ensure the coding company has general liability insurance.
- Execute a Business Associate Agreement (BAA) with the coding company. (Correct answer)
Correct answer: Execute a Business Associate Agreement (BAA) with the coding company.
When a covered entity (the hospital) hires a person or entity (the coding company) to perform functions involving the use or disclosure of PHI, that entity is considered a Business Associate. HIPAA requires a formal, written Business Associate Agreement (BAA) to be in place before any PHI is shared. This contract legally requires the business associate to maintain the same level of protection for the PHI as the covered entity.
Question 3: A nurse is discussing a patient's care with a doctor in a semi-private room. A patient in the next bed, separated by a curtain, overhears the doctor mention the first patient's name and diagnosis. Assuming the conversation was conducted in a low voice and was necessary for treatment, how would this situation be classified under HIPAA?
- A reportable breach of unsecured PHI.
- An incidental disclosure. (Correct answer)
- A violation of the Minimum Necessary Rule.
- A permitted disclosure for treatment purposes.
Correct answer: An incidental disclosure.
This scenario describes an incidental disclosure. An incidental disclosure is a secondary, unavoidable exposure of PHI that occurs as a byproduct of an otherwise permissible activity (like a treatment discussion). It is not a violation, provided that reasonable safeguards (speaking in low voices) were in place and the minimum necessary information was shared for the primary purpose of treatment.
Question 4: According to the HIPAA Privacy Rule's 'Minimum Necessary' standard, a covered entity must make reasonable efforts to limit the use and disclosure of PHI. In which of the following scenarios does the Minimum Necessary standard NOT apply?
- A disclosure from one healthcare provider to another for treatment purposes. (Correct answer)
- A disclosure to a business associate for billing operations.
- A use of PHI for internal quality assessment activities.
- A request for PHI from another covered entity for payment purposes.
Correct answer: A disclosure from one healthcare provider to another for treatment purposes.
The HIPAA Privacy Rule explicitly exempts disclosures of PHI for treatment purposes between healthcare providers from the Minimum Necessary standard. This allows providers to freely share information necessary to provide quality care. However, the Minimum Necessary standard does apply to disclosures for payment and healthcare operations, such as billing or quality assessment.
Question 5: A patient discovers an error in their medical record and submits a formal written request to their provider to have it corrected. Under the HIPAA Privacy Rule, what right is the patient exercising?
- The Right to an Accounting of Disclosures
- The Right to Restrict Disclosures
- The Right to Amend PHI (Correct answer)
- The Right of Access
Correct answer: The Right to Amend PHI
The HIPAA Privacy Rule provides patients with the right to request an amendment of their PHI in a designated record set if they believe the information is inaccurate or incomplete. The covered entity must then review the request and either make the amendment or provide a written denial to the patient.
Question 6: A research institution wants to use a large dataset of patient information for a study. To avoid HIPAA constraints, they decide to de-identify the data using the Safe Harbor method. Which of the following must be removed from the dataset?
- The state of residence for all patients.
- The patient's year of birth.
- All patient ages over 89, aggregated into a single category of '90 or older'.
- The first three digits of a zip code if the area has fewer than 20,000 people. (Correct answer)
Correct answer: The first three digits of a zip code if the area has fewer than 20,000 people.
The Safe Harbor method requires the removal of 18 specific identifiers. For geographic subdivisions smaller than a state, zip codes must be handled carefully. The initial three digits of a zip code must be removed (or changed to 000) if the geographic unit contains 20,000 or fewer people. The state of residence and year of birth (for those under 90) are generally permissible, and aggregating ages over 89 is a requirement, not a removal of a valid data point.
Which of the following data elements, when combined with a patient's medical condition, would NOT be considered Protected Health Information (PHI) under HIPAA?