HIPAA The HIPAA Privacy Rule 5 — Questions and Answers
Question 1: Under the HIPAA Privacy Rule, which of the following is a permissible disclosure of PHI in judicial proceedings?
- Providing PHI to any attorney who requests it for litigation
- Disclosing PHI in response to a court order or a subpoena with satisfactory assurances (Correct answer)
- Releasing PHI whenever a case involves a healthcare provider as a party
- Sharing all PHI requested during discovery without restriction
Correct answer: Disclosing PHI in response to a court order or a subpoena with satisfactory assurances
PHI may be disclosed in judicial proceedings in response to a court order or a subpoena accompanied by satisfactory assurances of patient notification or a protective order.
Question 2: What distinguishes 'psychotherapy notes' from other mental health records under the HIPAA Privacy Rule?
- They are subject to the same rules as all other PHI
- They receive heightened protection and generally require specific authorization for disclosure separate from other PHI (Correct answer)
- They are excluded from HIPAA protections entirely
- They can only be shared with other mental health providers
Correct answer: They receive heightened protection and generally require specific authorization for disclosure separate from other PHI
Psychotherapy notes are given special protection under HIPAA and generally require separate, specific patient authorization to disclose, even for TPO purposes.
Question 3: A covered entity's workforce member improperly accesses a celebrity patient's records out of curiosity. This is an example of:
- An incidental disclosure permitted by HIPAA
- An impermissible use of PHI that violates the Privacy Rule (Correct answer)
- A permitted use for healthcare operations
- A minor infraction that does not require documentation
Correct answer: An impermissible use of PHI that violates the Privacy Rule
Accessing PHI for personal curiosity without a legitimate purpose is an impermissible use that violates the HIPAA Privacy Rule's minimum necessary and permissible use standards.
Question 4: Under HIPAA, which of the following correctly describes the relationship between HIPAA and state privacy laws?
- HIPAA always preempts state law in all situations
- State laws that provide greater privacy protections than HIPAA are generally not preempted (Correct answer)
- State laws are only enforced when HIPAA does not apply
- HIPAA and state laws cannot apply to the same covered entity simultaneously
Correct answer: State laws that provide greater privacy protections than HIPAA are generally not preempted
HIPAA sets a federal floor; state laws that provide stronger privacy protections are generally not preempted and may also apply to covered entities.
Question 5: When must a covered entity provide a patient with its Notice of Privacy Practices (NPP)?
- Only upon a patient's written request
- At the first service delivery and upon request thereafter (Correct answer)
- Once per calendar year regardless of patient contact
- Only when there is a material change to privacy practices
Correct answer: At the first service delivery and upon request thereafter
Covered entities must provide the NPP no later than the date of first service delivery and must make it available to any person who requests it.
Question 6: Which federal agency enforces the HIPAA Privacy Rule?
- The Federal Trade Commission (FTC)
- The Office for Civil Rights (OCR) within the Department of Health and Human Services (Correct answer)
- The Centers for Medicare & Medicaid Services (CMS)
- The National Institutes of Health (NIH)
Correct answer: The Office for Civil Rights (OCR) within the Department of Health and Human Services
The Office for Civil Rights (OCR) within HHS is responsible for enforcing the HIPAA Privacy Rule and investigating complaints of violations.
Question 7: A covered entity uses PHI to train new staff on privacy procedures using real patient cases without removing identifiers. This is:
- Permitted as a healthcare operations activity under HIPAA (Correct answer)
- A violation because training requires de-identified or simulated data
- Permitted only if patients sign a general consent at admission
- Permitted as long as no more than 10 staff members view the records
Correct answer: Permitted as a healthcare operations activity under HIPAA
Using PHI for workforce training and quality assurance activities qualifies as a healthcare operations purpose under HIPAA and does not require patient authorization.
Under the HIPAA Privacy Rule, which of the following is a permissible disclosure of PHI in judicial proceedings?