HIPAA Protected Health Information (PHI) 3 — Questions and Answers
Question 1: Electronic Protected Health Information (ePHI) differs from PHI in that it:
- Has fewer HIPAA protections than paper-based PHI
- Is specifically governed by the HIPAA Security Rule in addition to the Privacy Rule (Correct answer)
- Only applies to information stored in cloud systems
- Does not include information transmitted via email
Correct answer: Is specifically governed by the HIPAA Security Rule in addition to the Privacy Rule
ePHI is PHI that is created, stored, transmitted, or received electronically, and it is subject to both the HIPAA Privacy Rule and the additional technical safeguards required by the Security Rule.
Question 2: A covered entity may disclose PHI without patient authorization to report a communicable disease to a public health authority. This falls under which HIPAA exception?
- Law enforcement exception
- Public health activities exception (Correct answer)
- Healthcare operations exception
- Emergency circumstances exception
Correct answer: Public health activities exception
HIPAA's public health activities exception permits covered entities to disclose PHI to public health authorities authorized by law to collect data for preventing or controlling disease.
Question 3: Under HIPAA, which of the following workforce members should have access to a patient's complete medical record?
- All hospital employees for quality assurance
- Only those whose job functions require that level of access (Correct answer)
- Any clinician working at the same facility
- Any employee who requests access for patient care purposes
Correct answer: Only those whose job functions require that level of access
HIPAA's minimum necessary standard requires that access to PHI be limited to workforce members whose specific job duties require that information.
Question 4: A patient requests access to their own PHI. Under HIPAA, the covered entity must generally provide access within:
- 7 calendar days
- 30 calendar days, with one possible 30-day extension (Correct answer)
- 60 calendar days
- 10 business days
Correct answer: 30 calendar days, with one possible 30-day extension
HIPAA requires covered entities to provide patients access to their PHI within 30 calendar days, with one permissible 30-day extension if the entity notifies the patient of the delay.
Question 5: Which of the following scenarios would constitute an impermissible disclosure of PHI under HIPAA?
- A physician discussing a patient's care with a consulting specialist
- A nurse telling a patient's employer about their diagnosis without authorization (Correct answer)
- A hospital sharing records with a patient's health plan for claims processing
- A covered entity reporting a gunshot wound to law enforcement as required by law
Correct answer: A nurse telling a patient's employer about their diagnosis without authorization
Disclosing a patient's diagnosis to their employer without authorization violates HIPAA because employment is not a permitted purpose for PHI disclosure under the Privacy Rule.
Question 6: Psychotherapy notes receive special protection under HIPAA because:
- They are not considered PHI
- They require a separate, specific authorization for disclosure beyond standard PHI (Correct answer)
- They may only be disclosed to law enforcement
- Mental health information is exempt from the minimum necessary standard
Correct answer: They require a separate, specific authorization for disclosure beyond standard PHI
Psychotherapy notes are treated as a special category of PHI under HIPAA and require a specific authorization for most disclosures, separate from an authorization that covers other PHI.
Question 7: A business associate agreement (BAA) under HIPAA is required when a covered entity shares PHI with a vendor who:
- Only handles de-identified data
- Creates, receives, maintains, or transmits PHI on behalf of the covered entity (Correct answer)
- Is a government agency with its own HIPAA obligations
- Only accesses aggregated, statistical health data
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of the covered entity
A BAA is legally required whenever a covered entity engages a business associate that will create, receive, maintain, or transmit PHI while performing services on the covered entity's behalf.
Electronic Protected Health Information (ePHI) differs from PHI in that it: