MT Privacy Regulations & Ethical Practices 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity' required to comply with privacy regulations?
- A medical transcription service provider working as a business associate
- A health plan that pays for medical care (Correct answer)
- A pharmaceutical company that manufactures drugs
- A medical equipment retailer
Correct answer: A health plan that pays for medical care
Health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically are the three types of covered entities under HIPAA.
Question 2: A medical transcriptionist discovers a physician dictated incorrect medication dosages. What is the ethical obligation?
- Transcribe exactly as dictated and add a personal note in the report
- Flag the discrepancy through the appropriate facility protocol without altering the transcription (Correct answer)
- Correct the dosage silently to protect the patient
- Refuse to transcribe the report until the physician re-dictates
Correct answer: Flag the discrepancy through the appropriate facility protocol without altering the transcription
MTs must transcribe accurately and flag potential errors through established facility channels rather than making unauthorized changes.
Question 3: Which HIPAA rule specifically addresses the security of electronic protected health information (ePHI)?
- The Privacy Rule
- The Breach Notification Rule
- The Security Rule (Correct answer)
- The Enforcement Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect electronic PHI that is created, received, used, or maintained by a covered entity.
Question 4: When a patient requests access to their own medical records under HIPAA, a covered entity must generally respond within:
- 10 calendar days
- 30 calendar days (Correct answer)
- 60 calendar days
- 90 calendar days
Correct answer: 30 calendar days
HIPAA requires covered entities to act on a patient's request for access to their PHI within 30 calendar days, with one possible 30-day extension.
Question 5: A medical transcriptionist working from home should NOT do which of the following regarding their workstation?
- Use a password-protected screen saver
- Allow family members to use the work computer for personal browsing (Correct answer)
- Position the monitor away from windows visible to passersby
- Enable automatic software updates for security patches
Correct answer: Allow family members to use the work computer for personal browsing
Sharing a work computer used to access PHI with family members violates HIPAA Security Rule requirements for access control and workstation security.
Question 6: The minimum necessary standard under HIPAA requires that covered entities:
- Share only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Obtain minimum training before accessing patient records
- Use only the minimum number of employees to handle PHI
- Maintain only the minimum required documentation
Correct answer: Share only the minimum amount of PHI needed to accomplish the intended purpose
The minimum necessary standard limits uses and disclosures of PHI to the least amount needed to accomplish the intended purpose.
Question 7: Which organization issues the AHDI Code of Ethics that guides medical transcriptionists?
- American Medical Association (AMA)
- Association for Healthcare Documentation Integrity (AHDI) (Correct answer)
- American Health Information Management Association (AHIMA)
- Joint Commission on Accreditation of Healthcare Organizations (JCAHO)
Correct answer: Association for Healthcare Documentation Integrity (AHDI)
The Association for Healthcare Documentation Integrity (AHDI) is the professional association for medical transcriptionists that publishes the MT Code of Ethics.
Under HIPAA, which of the following is considered a 'covered entity' required to comply with privacy regulations?