HIPAA Medical Information 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- A patient's name combined with their diagnosis (Correct answer)
- A patient's age alone without any other identifiers
- Aggregated statistical health data with no identifiers
- De-identified data released per HIPAA Safe Harbor standards
Correct answer: A patient's name combined with their diagnosis
PHI is individually identifiable health information, meaning a name combined with a diagnosis links a person to their health condition and qualifies as PHI.
Question 2: A hospital shares a patient's medical records with a billing company to process insurance claims. Under HIPAA, this sharing is:
- Prohibited unless the patient signs a HIPAA authorization form
- Permitted as a Treatment, Payment, or Healthcare Operations (TPO) activity (Correct answer)
- Allowed only if the patient is notified in advance each time
- Illegal because billing companies are not covered entities
Correct answer: Permitted as a Treatment, Payment, or Healthcare Operations (TPO) activity
HIPAA permits disclosure of PHI for treatment, payment, and healthcare operations (TPO) without requiring patient authorization.
Question 3: What does the HIPAA Minimum Necessary Standard require when accessing medical information?
- Covered entities must share the least amount of PHI needed to accomplish the intended purpose (Correct answer)
- Only physicians may access a patient's full medical record
- Patients must provide written consent before any staff member views their record
- Electronic health records must be encrypted to minimum AES-128 standards
Correct answer: Covered entities must share the least amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires that only the PHI needed to accomplish a specific purpose be accessed, used, or disclosed.
Question 4: A nurse looks up the medical records of a neighbor out of curiosity, without any treatment purpose. This action violates which HIPAA principle?
- The Breach Notification Rule
- The Minimum Necessary Standard and permissible purpose requirements (Correct answer)
- The Notice of Privacy Practices requirement
- The right of access provision
Correct answer: The Minimum Necessary Standard and permissible purpose requirements
Accessing PHI without a permissible purpose and beyond what is necessary violates the Minimum Necessary Standard and HIPAA's use/disclosure rules.
Question 5: Which of the following best describes 'de-identified' health information under HIPAA's Safe Harbor method?
- Information where a patient's name has been replaced with an alias
- Information from which all 18 specified identifiers have been removed (Correct answer)
- Data encrypted with a government-approved algorithm
- Records accessible only to authorized personnel with a need-to-know
Correct answer: Information from which all 18 specified identifiers have been removed
Under the Safe Harbor method, health information is de-identified when all 18 specific identifiers listed in the HIPAA Privacy Rule have been removed.
Question 6: A patient requests a copy of their medical records. Under the HIPAA Right of Access, how long does a covered entity generally have to fulfill this request?
- 7 calendar days
- 30 calendar days, with one possible 30-day extension (Correct answer)
- 60 calendar days with no extension allowed
- 90 calendar days if the records are stored off-site
Correct answer: 30 calendar days, with one possible 30-day extension
Covered entities must provide access within 30 calendar days of the request, with one 30-day extension allowed if the entity notifies the patient.
Question 7: Under HIPAA, psychotherapy notes receive a higher level of protection than other medical records because:
- They are owned by the therapist, not the healthcare facility
- They require separate patient authorization for most disclosures, beyond standard TPO (Correct answer)
- They may never be disclosed to insurers under any circumstance
- They are exempt from the Breach Notification Rule
Correct answer: They require separate patient authorization for most disclosures, beyond standard TPO
Psychotherapy notes are afforded extra protection and generally require specific patient authorization for disclosure even for treatment, payment, or operations purposes.
Under HIPAA, which of the following is considered Protected Health Information (PHI)?