HIPAA Electronic Health Records (EHR) Compliance 4 — Questions and Answers
Question 1: Under HIPAA, which of the following EHR data exchanges does NOT require a patient's authorization?
- Selling de-identified data to a marketing firm
- Sharing records with the patient's attorney
- Disclosing records for public health reporting to state authorities (Correct answer)
- Providing records to a life insurance company
Correct answer: Disclosing records for public health reporting to state authorities
HIPAA permits covered entities to disclose ePHI to public health authorities for authorized public health activities without patient authorization.
Question 2: A hospital implements a new EHR module. Under HIPAA's Security Rule, what process must be conducted before go-live?
- Patient notification of the new system
- Security risk analysis of the new module (Correct answer)
- OCR pre-approval of the module
- Staff certification in the new software
Correct answer: Security risk analysis of the new module
HIPAA requires covered entities to conduct a security risk analysis before implementing any new system or module that handles ePHI.
Question 3: What is the maximum civil monetary penalty per violation category under HIPAA for a covered entity that demonstrates willful neglect and does not correct the violation?
- $10,000
- $50,000
- $100,000
- $1,900,000 (adjusted for inflation, annually) (Correct answer)
Correct answer: $1,900,000 (adjusted for inflation, annually)
For willful neglect not corrected, HIPAA penalties can reach $1.9 million per violation category per calendar year under the tiered penalty structure.
Question 4: An EHR system sends an appointment reminder via text message that includes the patient's diagnosis. Which HIPAA principle does this violate?
- Minimum necessary standard (Correct answer)
- Breach notification rule
- Right of access rule
- Accounting of disclosures
Correct answer: Minimum necessary standard
Including a diagnosis in a text reminder violates the minimum necessary standard because only the appointment time and location are needed for a reminder.
Question 5: Which of the following best describes a contingency plan requirement under HIPAA's Security Rule for EHR systems?
- A plan to notify patients about system downtime
- A documented data backup plan and disaster recovery procedure (Correct answer)
- A vendor contract requiring 99.9% uptime
- A printed copy of all patient records kept off-site
Correct answer: A documented data backup plan and disaster recovery procedure
HIPAA's contingency plan standard requires covered entities to have documented data backup plans and disaster recovery procedures to ensure ePHI availability during emergencies.
Question 6: A patient requests that their EHR be amended to correct an error in their medical history. Under HIPAA, when may a covered entity deny this request?
- When the record is more than 2 years old
- When the record was not created by the covered entity (Correct answer)
- When amending would delay care
- When the patient cannot explain why the record is wrong
Correct answer: When the record was not created by the covered entity
A covered entity may deny an amendment request if the ePHI was not created by that entity, as they typically cannot verify or change records created elsewhere.
Question 7: Under the HITECH Act's EHR Meaningful Use requirements, what additional HIPAA obligation was strengthened regarding business associates?
- Business associates became directly liable for HIPAA Security Rule compliance (Correct answer)
- Business associates must now obtain patient consent before accessing ePHI
- Business associates are exempt from breach notification requirements
- Business associates must be licensed healthcare providers
Correct answer: Business associates became directly liable for HIPAA Security Rule compliance
The HITECH Act extended direct HIPAA Security Rule liability to business associates, meaning they can be penalized directly by OCR for violations.
Under HIPAA, which of the following EHR data exchanges does NOT require a patient's authorization?