HIPAA The HIPAA Privacy Rule 3 — Questions and Answers
Question 1: A hospital shares a patient's PHI with a collection agency to recover an unpaid bill. Under HIPAA, this is considered:
- A violation because financial matters are not a permitted use of PHI
- A permitted disclosure for payment purposes under HIPAA (Correct answer)
- A permitted disclosure only if the patient signed a specific authorization
- A violation unless the collection agency is a covered entity
Correct answer: A permitted disclosure for payment purposes under HIPAA
Disclosing PHI to a collection agency for payment purposes is a permitted use under HIPAA, provided the agency signs a Business Associate Agreement.
Question 2: Which of the following scenarios describes a valid authorization under the HIPAA Privacy Rule?
- A blanket authorization signed at the time of hospital admission covering all future uses
- A specific written authorization for releasing records to a life insurance company, signed by the patient with an expiration date (Correct answer)
- An oral agreement by the patient to allow their employer to receive their diagnosis
- An authorization obtained under duress to receive treatment
Correct answer: A specific written authorization for releasing records to a life insurance company, signed by the patient with an expiration date
A valid HIPAA authorization must be specific, written, signed, include an expiration date or event, and cannot be conditioned on receiving treatment.
Question 3: Under the HIPAA Privacy Rule, 'treatment' as a permitted use of PHI includes:
- Only disclosures made by the treating physician
- Sharing PHI among healthcare providers for coordination and management of a patient's care (Correct answer)
- Any use of PHI by a health plan for disease management programs
- Disclosures to public health authorities for population monitoring
Correct answer: Sharing PHI among healthcare providers for coordination and management of a patient's care
Treatment includes the coordination and management of care among multiple providers, including consultations and referrals.
Question 4: What is an 'Organized Health Care Arrangement' (OHCA) under the HIPAA Privacy Rule?
- A managed care organization that contracts with insurers
- A clinically integrated care setting where multiple entities share PHI for treatment (Correct answer)
- An arrangement where patients authorize sharing of records between providers
- A network of business associates with shared HIPAA compliance programs
Correct answer: A clinically integrated care setting where multiple entities share PHI for treatment
An OHCA is a clinically integrated care setting where individuals receive care from multiple providers who share PHI to manage and coordinate patient treatment.
Question 5: When a patient requests an amendment to their PHI and the covered entity denies it, what must the covered entity do?
- Delete the disputed information from the record
- Provide the patient with a written denial and inform them of their right to submit a statement of disagreement (Correct answer)
- Immediately notify the Department of Health and Human Services (HHS)
- Refer the patient to the Privacy Officer for arbitration
Correct answer: Provide the patient with a written denial and inform them of their right to submit a statement of disagreement
When denying an amendment request, the covered entity must provide written notice of the denial and inform the patient of their right to submit a statement of disagreement.
Question 6: Which of the following is an example of incidental disclosure that is permissible under HIPAA?
- A receptionist discussing a patient's HIV status loudly in a crowded waiting room
- A physician discussing a patient's case with a colleague in a hallway while taking reasonable precautions (Correct answer)
- A nurse emailing a patient's full record to the wrong provider without verifying the address
- A hospital selling patient lists to pharmaceutical companies
Correct answer: A physician discussing a patient's case with a colleague in a hallway while taking reasonable precautions
Incidental disclosures that occur as a byproduct of reasonable communications are permitted under HIPAA, provided the covered entity has implemented appropriate safeguards.
Question 7: Under the HIPAA Privacy Rule, a patient's right to an accounting of disclosures covers disclosures made for which purpose?
- Treatment, payment, and healthcare operations
- Purposes other than treatment, payment, and healthcare operations (Correct answer)
- Only disclosures made to law enforcement agencies
- All disclosures made in the past 10 years
Correct answer: Purposes other than treatment, payment, and healthcare operations
Patients have the right to an accounting of disclosures made for purposes other than TPO, such as public health activities or law enforcement, covering the past 6 years.
A hospital shares a patient's PHI with a collection agency to recover an unpaid bill.
Under HIPAA, this is considered: