HIPAA Electronic Health Records (EHR) Compliance 5 — Questions and Answers
Question 1: A physician group uses an EHR system with a shared login for all nurses. Which HIPAA requirement does this violate?
- Automatic logoff
- Unique user identification (Correct answer)
- Encryption at rest
- Audit controls
Correct answer: Unique user identification
HIPAA's Security Rule requires that each user of an EHR system have a unique identifier to enable individual accountability and accurate audit trails.
Question 2: A patient's EHR is subpoenaed in a malpractice case. Under HIPAA, what must the covered entity do before releasing records?
- Release records immediately to comply with the court
- Notify OCR before releasing any records
- Obtain a qualified protective order or patient authorization before release (Correct answer)
- Redact all diagnoses before providing the record
Correct answer: Obtain a qualified protective order or patient authorization before release
HIPAA requires a qualified protective order or patient authorization before releasing ePHI in response to a subpoena that is not accompanied by a court order.
Question 3: Which of the following scenarios represents a HIPAA-compliant use of de-identified EHR data?
- Sharing records with the patient's name replaced by initials with a researcher
- Providing data with all 18 HIPAA identifiers removed to a pharmaceutical company for research (Correct answer)
- Sending records with only the birth year removed to a marketing firm
- Disclosing diagnosis codes linked to zip codes to a data broker
Correct answer: Providing data with all 18 HIPAA identifiers removed to a pharmaceutical company for research
De-identification under HIPAA's Safe Harbor method requires removing all 18 specified identifiers, after which the data is no longer considered PHI.
Question 4: An EHR system experiences a ransomware attack that encrypts all patient records. Under HIPAA, is this automatically a reportable breach?
- No, because the data was never viewed by attackers
- No, because ransomware only locks data and does not steal it
- Yes, unless the covered entity can demonstrate low probability of ePHI compromise (Correct answer)
- Yes, but only if patients complain about delayed care
Correct answer: Yes, unless the covered entity can demonstrate low probability of ePHI compromise
OCR guidance states that ransomware attacks are presumed breaches unless the covered entity demonstrates through a risk assessment that ePHI was not compromised.
Question 5: Under HIPAA, what is required when a covered entity terminates a workforce member who had EHR access?
- Notify the terminated employee's patients within 30 days
- Revoke the employee's EHR access as part of a termination procedure (Correct answer)
- File a report with HHS about the termination
- Conduct a full audit of all records the employee ever accessed
Correct answer: Revoke the employee's EHR access as part of a termination procedure
HIPAA's Security Rule requires covered entities to have workforce clearance procedures that include revoking EHR access promptly upon termination.
Question 6: A mobile health app that connects to a hospital's EHR is developed by a third party. Under HIPAA, when does the app developer become a business associate?
- Only if the app stores data on the developer's servers
- When the developer has access to ePHI on behalf of the covered entity (Correct answer)
- Only if the app is used by more than 500 patients
- When the app is distributed through an app store
Correct answer: When the developer has access to ePHI on behalf of the covered entity
A third-party app developer becomes a business associate the moment they create, receive, maintain, or transmit ePHI on behalf of a covered entity.
Question 7: Which HIPAA standard requires EHR systems to record who accessed, modified, or deleted a patient record and when?
- Integrity controls
- Audit controls (Correct answer)
- Person authentication
- Transmission security
Correct answer: Audit controls
Audit controls are a required HIPAA technical safeguard mandating that EHR systems record and examine activity in systems containing ePHI.
A physician group uses an EHR system with a shared login for all nurses.
Which HIPAA requirement does this violate?