HIPAA HITECH Act and Technology Requirements 4 — Questions and Answers
Question 1: Under HITECH, which type of health information technology must be 'certified' to qualify for Meaningful Use incentive payments?
- Any commercially available EHR product
- ONC-certified Electronic Health Record Technology (CEHRT) (Correct answer)
- State-approved health information systems
- HIPAA-compliant practice management software
Correct answer: ONC-certified Electronic Health Record Technology (CEHRT)
Meaningful Use incentives require use of ONC-certified Electronic Health Record Technology (CEHRT) that meets federal functionality and interoperability standards.
Question 2: What HITECH requirement applies when a covered entity uses an EHR and a patient requests their PHI be sent to a third party?
- The CE must print and mail a paper copy to the third party
- The CE must transmit the PHI electronically if the patient requests it (Correct answer)
- The CE may charge a fee equal to actual labor costs for the transmission
- The CE can decline if the third party is not a covered entity
Correct answer: The CE must transmit the PHI electronically if the patient requests it
HITECH requires covered entities using EHRs to transmit PHI electronically to a designated third party when a patient makes that specific request.
Question 3: Which HITECH provision most significantly expanded state attorneys general authority regarding HIPAA enforcement?
- Authorization to conduct HIPAA audits on behalf of HHS
- Power to bring civil actions on behalf of state residents for HIPAA violations (Correct answer)
- Authority to impose criminal penalties for willful neglect
- Right to approve business associate agreements
Correct answer: Power to bring civil actions on behalf of state residents for HIPAA violations
HITECH granted state attorneys general the authority to bring civil actions on behalf of state residents harmed by HIPAA violations, creating a new enforcement pathway.
Question 4: Under the HITECH Act, what is required of covered entities regarding the use of PHI for marketing communications sent via electronic means?
- Written authorization is required for all electronic marketing using PHI (Correct answer)
- Opt-out is sufficient for electronic marketing as long as PHI use is limited
- Electronic marketing using PHI is permitted with verbal consent
- No additional requirements apply beyond standard HIPAA marketing rules
Correct answer: Written authorization is required for all electronic marketing using PHI
HITECH requires written authorization before covered entities may use PHI for marketing communications, including those delivered electronically.
Question 5: A business associate discovers a breach on March 1 and notifies the covered entity on April 20. Is this compliant with HITECH?
- Yes, notification within 60 days of discovery is compliant (Correct answer)
- No, BAs must notify within 30 days of discovery
- No, BAs must notify within 24 hours of discovery
- Yes, as long as the covered entity notifies patients within 60 days
Correct answer: Yes, notification within 60 days of discovery is compliant
April 20 is 50 days after March 1, which falls within the 60-day window business associates have to notify covered entities under HITECH.
Question 6: Which HITECH provision prohibits covered entities from conditioning treatment on a patient's agreement to receive fundraising communications?
- Right of Access provision
- Minimum necessary standard
- Prohibition on conditioning treatment (Correct answer)
- Fundraising opt-out requirement
Correct answer: Prohibition on conditioning treatment
HITECH explicitly prohibits covered entities from making treatment conditional on a patient's agreement to receive fundraising communications.
Question 7: What is the primary purpose of the ONC Health IT Certification Program established under HITECH?
- To train healthcare workers on HIPAA compliance
- To certify that EHR technology meets standards for security, functionality, and interoperability (Correct answer)
- To audit covered entities for Meaningful Use compliance
- To approve business associate agreements for health IT vendors
Correct answer: To certify that EHR technology meets standards for security, functionality, and interoperability
The ONC certification program ensures EHR products meet established standards for security, functionality, and interoperability before providers can use them for Meaningful Use incentives.
Under HITECH, which type of health information technology must be 'certified' to qualify for Meaningful Use incentive payments?