HIPAA The HIPAA Privacy Rule 4 — Questions and Answers
Question 1: Under the HIPAA Privacy Rule, which of the following entities is considered a 'covered entity'?
- A law firm that occasionally reviews medical records
- A health plan that pays for medical care (Correct answer)
- A software company that builds hospital management tools
- A janitorial service that cleans a hospital
Correct answer: A health plan that pays for medical care
Health plans are one of the three categories of covered entities under HIPAA, along with healthcare providers and healthcare clearinghouses.
Question 2: What is the maximum time a covered entity has to respond to a patient's request to access their PHI?
- 15 calendar days
- 30 calendar days, with one 30-day extension if needed (Correct answer)
- 60 calendar days with no extensions
- 90 days for electronic records only
Correct answer: 30 calendar days, with one 30-day extension if needed
Covered entities must act on access requests within 30 days, with the option to extend by an additional 30 days if they provide written notice of the delay and the reason.
Question 3: Which of the following best describes a 'hybrid entity' under HIPAA?
- An organization that operates as both a covered entity and a business associate
- A single legal entity that performs both covered and non-covered functions (Correct answer)
- A health system that uses both paper and electronic health records
- An entity regulated by both HIPAA and state privacy laws
Correct answer: A single legal entity that performs both covered and non-covered functions
A hybrid entity is a single legal entity whose business activities include both covered functions and non-covered functions, such as a university with a medical center.
Question 4: The HIPAA Privacy Rule permits covered entities to disclose PHI to public health authorities without patient authorization for which purpose?
- Publishing research findings in medical journals
- Preventing or controlling disease, injury, or disability (Correct answer)
- Conducting commercial health surveys
- Sharing data with pharmaceutical marketing firms
Correct answer: Preventing or controlling disease, injury, or disability
Covered entities may disclose PHI to authorized public health authorities for activities like disease surveillance, reporting, and control without patient authorization.
Question 5: A patient requests that their provider not share their PHI with their health plan for a service the patient paid for out-of-pocket. Under HIPAA, the provider must:
- Comply with the restriction request only if the health plan agrees
- Honor the restriction request as required by HITECH-amended HIPAA (Correct answer)
- Deny the request because health plans have a right to all treatment information
- Comply only if the restriction applies to mental health information
Correct answer: Honor the restriction request as required by HITECH-amended HIPAA
Under the HITECH Act amendment to HIPAA, providers must honor a patient's request to restrict disclosure to a health plan when the patient pays out-of-pocket in full.
Question 6: Which of the following uses of PHI requires a specific written patient authorization under the HIPAA Privacy Rule?
- Sharing PHI with a consulting specialist for treatment purposes
- Using PHI for most marketing communications that are not treatment-related (Correct answer)
- Disclosing PHI to a business associate for billing operations
- Reporting a communicable disease to a state health department
Correct answer: Using PHI for most marketing communications that are not treatment-related
Using PHI for most marketing communications requires a valid written authorization because marketing is not within the TPO or other permitted uses.
Question 7: Under the HIPAA Privacy Rule, what is a 'business associate'?
- Any employee of a covered entity who handles PHI
- A person or entity that performs functions or activities on behalf of a covered entity involving PHI (Correct answer)
- A partner organization that shares patients with a covered entity
- A vendor that provides only administrative services unrelated to PHI
Correct answer: A person or entity that performs functions or activities on behalf of a covered entity involving PHI
A business associate is a person or entity that performs functions or activities on behalf of a covered entity that involve creating, receiving, maintaining, or transmitting PHI.
Under the HIPAA Privacy Rule, which of the following entities is considered a 'covered entity'?