HIPAA Medical Information 3 — Questions and Answers
Question 1: A patient wants to amend an error in their medical record. Under HIPAA, a covered entity may deny the amendment request if:
- The record was created more than 5 years ago
- The record was not created by the covered entity receiving the request (Correct answer)
- The patient does not provide a reason for the amendment
- The record is stored in an electronic health record system
Correct answer: The record was not created by the covered entity receiving the request
A covered entity may deny an amendment request if it did not create the record in question, among other valid grounds for denial listed in the Privacy Rule.
Question 2: Which scenario represents an incidental disclosure that is permissible under HIPAA?
- A receptionist emails a patient's full chart to the wrong provider
- A patient overhears a nurse calling a name from a waiting room list (Correct answer)
- A staff member posts a patient's diagnosis on social media
- A hospital sells patient contact data to a pharmaceutical company
Correct answer: A patient overhears a nurse calling a name from a waiting room list
Incidental disclosures that occur as a byproduct of permissible communication—such as calling out a patient's name—are allowed if reasonable safeguards are in place.
Question 3: Under HIPAA's Privacy Rule, a covered entity must provide patients with a Notice of Privacy Practices (NPP). What must this notice include?
- A complete list of every employee who may access the patient's records
- A description of how PHI may be used and disclosed, and patient rights (Correct answer)
- Pricing information for obtaining copies of medical records
- The names of all business associates the entity contracts with
Correct answer: A description of how PHI may be used and disclosed, and patient rights
The NPP must describe how the covered entity uses and discloses PHI, patient rights regarding their information, and the entity's legal duties to protect PHI.
Question 4: A covered entity discloses PHI to a public health authority to report a communicable disease. This disclosure is:
- Prohibited without a signed patient authorization
- Permitted under HIPAA's public health activities exception (Correct answer)
- Allowed only if the patient is notified within 24 hours
- Restricted to situations where the patient poses an imminent threat
Correct answer: Permitted under HIPAA's public health activities exception
HIPAA permits disclosure to public health authorities for activities such as disease reporting without patient authorization under the public health activities exception.
Question 5: What is the primary purpose of a Business Associate Agreement (BAA) under HIPAA?
- To set the pricing terms for medical record retrieval services
- To ensure business associates contractually agree to protect PHI they handle (Correct answer)
- To grant business associates full access to a covered entity's EHR system
- To replace the need for a covered entity's own HIPAA compliance program
Correct answer: To ensure business associates contractually agree to protect PHI they handle
A BAA is a contract requiring business associates to appropriately safeguard PHI they create, receive, maintain, or transmit on behalf of a covered entity.
Question 6: Under HIPAA, which of the following represents a 'use' of PHI rather than a 'disclosure'?
- A physician faxes a patient's records to a specialist outside the practice
- A billing department internally accesses patient records to submit claims (Correct answer)
- A hospital reports a gunshot wound to local law enforcement
- A lab sends test results to a patient's primary care provider
Correct answer: A billing department internally accesses patient records to submit claims
A 'use' occurs when PHI is accessed or shared within the same covered entity, while a 'disclosure' involves sharing PHI with external parties.
Question 7: A healthcare provider may share a patient's PHI with a family member without patient authorization when:
- The family member is listed as an emergency contact in the record
- The patient is present and does not object, or the provider determines it is in the patient's best interest (Correct answer)
- The patient has signed a general consent-to-treatment form
- The family member provides a notarized letter confirming their relationship
Correct answer: The patient is present and does not object, or the provider determines it is in the patient's best interest
HIPAA permits sharing PHI with family members when the patient is present, given the opportunity to agree or object, and does not object, or when the provider deems it in the patient's best interest.
A patient wants to amend an error in their medical record.
Under HIPAA, a covered entity may deny the amendment request if: