MS Medical Scribe Compliance & HIPAA Regulations 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity'?
- A hospital billing department
- A health insurance company (Correct answer)
- A medical device manufacturer
- A pharmaceutical company
Correct answer: A health insurance company
Health insurance companies are covered entities under HIPAA because they transmit health information electronically in covered transactions.
Question 2: A medical scribe overhears a physician discussing a celebrity patient's diagnosis in the elevator. What is the scribe's primary obligation?
- Report it to hospital administration immediately
- Ignore it since they are hospital employees
- Remind the physician that PHI should not be discussed in public areas (Correct answer)
- Document the conversation in the patient's chart
Correct answer: Remind the physician that PHI should not be discussed in public areas
Medical scribes have a duty to uphold HIPAA standards and may gently remind colleagues when PHI is being discussed in inappropriate locations.
Question 3: What is the maximum penalty per violation category per year for willful neglect of HIPAA that is not corrected?
- $10,000
- $50,000
- $100,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
Willful neglect not corrected carries a maximum penalty of $1,900,000 per violation category per calendar year (adjusted for inflation).
Question 4: Which HIPAA rule specifically addresses the security of electronic protected health information (ePHI)?
- The Privacy Rule
- The Breach Notification Rule
- The Security Rule (Correct answer)
- The Enforcement Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect ePHI that is created, received, used, or maintained by a covered entity.
Question 5: A patient requests an amendment to their medical record claiming the physician's note contains inaccurate information. Under HIPAA, the covered entity may deny the request if:
- The amendment would be too lengthy to process
- The record was not created by the covered entity (Correct answer)
- The patient cannot provide written documentation
- The patient is under the age of 18
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if the PHI was not created by the covered entity, as they cannot verify the accuracy of records they did not generate.
Question 6: What does 'minimum necessary' standard require of a medical scribe when documenting in the EHR?
- Document only information necessary for the current visit's treatment (Correct answer)
- Use the fewest possible words in every note
- Only access records from the past 30 days
- Limit documentation to one page per encounter
Correct answer: Document only information necessary for the current visit's treatment
The minimum necessary standard requires that only PHI reasonably necessary to accomplish the intended purpose be used or disclosed.
Question 7: Which of the following is NOT one of the 18 HIPAA identifiers that must be removed to de-identify patient information?
- Zip codes (all digits)
- Dates directly related to an individual (except year)
- Patient's chief complaint (Correct answer)
- Geographic data smaller than a state
Correct answer: Patient's chief complaint
A patient's chief complaint is clinical information and not one of the 18 specific identifiers listed under HIPAA's de-identification standards.
Under HIPAA, which of the following is considered a 'covered entity'?