HIPAA Medical Information 4 — Questions and Answers
Question 1: Which of the following is an example of PHI in electronic form (ePHI) that must be protected under HIPAA's Security Rule?
- A verbal conversation between two physicians about a patient
- A patient's diagnosis stored in an electronic health record system (Correct answer)
- A handwritten prescription left on a physician's desk
- A patient's paper insurance card stored in a physical filing cabinet
Correct answer: A patient's diagnosis stored in an electronic health record system
ePHI is protected health information that is created, stored, transmitted, or received in electronic form, such as data in an EHR system.
Question 2: A covered entity discovers a breach of unsecured PHI. Under the Breach Notification Rule, when must affected individuals be notified?
- Within 24 hours of discovery
- Without unreasonable delay and no later than 60 calendar days after discovery (Correct answer)
- Within 30 business days after the breach is fully investigated
- Only after the Department of Health and Human Services (HHS) is first notified
Correct answer: Without unreasonable delay and no later than 60 calendar days after discovery
The Breach Notification Rule requires notification to affected individuals without unreasonable delay and within no more than 60 calendar days of discovery.
Question 3: A large breach affecting more than 500 residents of a state must also be reported to:
- The FBI Cyber Division within 30 days
- Prominent media outlets serving the affected area (Correct answer)
- The state attorney general's office within 15 days
- The Joint Commission for accreditation review
Correct answer: Prominent media outlets serving the affected area
Breaches affecting more than 500 residents of a state or jurisdiction must be reported to prominent media outlets in that area in addition to HHS and affected individuals.
Question 4: Which of the following is NOT one of the 18 identifiers that must be removed for health information to be considered de-identified under the HIPAA Safe Harbor method?
- Full geographic data smaller than a state
- A patient's blood type (Correct answer)
- Account numbers
- Certificate and license numbers
Correct answer: A patient's blood type
Blood type is not one of the 18 identifiers listed in the HIPAA Safe Harbor method; it is a clinical data element, not a direct identifier.
Question 5: Under HIPAA, a covered entity may use or disclose PHI without patient authorization for which of the following purposes?
- Marketing a new drug directly to the patient on behalf of a pharmaceutical company
- Conducting health care operations such as quality improvement activities (Correct answer)
- Selling de-identified patient lists to a data analytics firm for profit
- Creating patient testimonials for the covered entity's advertising campaign
Correct answer: Conducting health care operations such as quality improvement activities
Healthcare operations, including quality improvement, training, and accreditation, are permissible uses of PHI that do not require patient authorization.
Question 6: A patient has the right under HIPAA to request a restriction on PHI use or disclosure. When is a covered entity REQUIRED to honor such a restriction?
- Whenever the patient submits the request in writing
- When the patient requests that information not be disclosed to a health plan and the service was paid out-of-pocket in full (Correct answer)
- Only when the patient's attorney formally requests the restriction
- Whenever the restriction relates to psychotherapy notes or HIV status
Correct answer: When the patient requests that information not be disclosed to a health plan and the service was paid out-of-pocket in full
Covered entities must honor a restriction request when the patient asks that information about a service not be shared with a health plan and the patient paid for the service out-of-pocket in full.
Question 7: Which HIPAA provision allows a covered entity to disclose PHI to a correctional institution for a patient who is an inmate?
- The law enforcement exception
- The correction and law enforcement provision within the Privacy Rule (Correct answer)
- The public health activities exception
- The minimum necessary waiver for government entities
Correct answer: The correction and law enforcement provision within the Privacy Rule
The Privacy Rule includes a specific provision permitting disclosure of inmate PHI to correctional institutions or law enforcement officials for health and safety purposes.
Which of the following is an example of PHI in electronic form (ePHI) that must be protected under HIPAA's Security Rule?