NCMA HIPAA and Patient Privacy Rights 2 โ Questions and Answers
Question 1: Under HIPAA, what is a 'Business Associate Agreement' (BAA) and when is it required?
- An agreement between two competing healthcare practices to share patients
- A contract required when a covered entity shares PHI with a third-party vendor or service provider that performs functions on its behalf (Correct answer)
- A financial agreement between a physician and hospital system
- An agreement between the patient and the billing department regarding payment terms
Correct answer: A contract required when a covered entity shares PHI with a third-party vendor or service provider that performs functions on its behalf
A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity and any business associate (third party) that creates, receives, maintains, or transmits PHI on behalf of the covered entity. Examples include EHR vendors, billing companies, and shredding services.
Business Associates (BAs) include: EHR/EMR vendors; Medical transcription services; Billing and coding companies; Attorneys with access to PHI; IT service providers with system access; Medical waste disposal companies; Answering services; Cloud storage providers; Labs processing specimens; Janitorial staff (if access to PHI). BAA requirements: must specify permitted uses/disclosures of PHI; BA must implement safeguards; BA must report breaches; BA must allow HHS audits; BA must return or destroy PHI when contract ends. BAs are directly liable for HIPAA compliance and can be fined directly for violations. Subcontractors of BAs must also sign BAAs. Covered entities must have BAAs in place before sharing PHI โ operating without a BAA when required is a HIPAA violation.
Question 2: What are the three HIPAA safeguard categories under the Security Rule, which applies specifically to electronic PHI (ePHI)?
- Privacy, confidentiality, and integrity safeguards
- Administrative, physical, and technical safeguards (Correct answer)
- Procedural, personnel, and digital safeguards
- Organizational, departmental, and individual safeguards
Correct answer: Administrative, physical, and technical safeguards
HIPAA's Security Rule requires covered entities to implement three types of safeguards for ePHI: Administrative (policies, training, risk analysis), Physical (facility access controls, workstation security, device controls), and Technical (access controls, audit controls, encryption).
HIPAA Security Rule three safeguard categories: Administrative safeguards โ risk analysis and management (required); information access management; security awareness training; security incident procedures; contingency planning; evaluation; Physical safeguards โ facility access controls (locks, badges, cameras); workstation use and security policies; device and media controls (encryption, disposal, off-site storage); Technical safeguards โ access controls (unique user IDs, auto logoff); audit controls (activity logs); integrity controls (data hasn't been altered); transmission security (encryption). Additional: organizational requirements (BAAs); policies and documentation requirements. The Security Rule does NOT apply to paper PHI (Privacy Rule covers all forms). Annual risk analysis is mandatory. Medical assistants: use strong passwords, lock screen when stepping away, don't share login credentials, don't access PHI on personal devices without authorization.
Question 3: A medical assistant overhears a colleague discussing a patient's HIV status in the hospital cafeteria with another colleague. What is the appropriate action?
- Ignore the conversation since it involves only healthcare workers
- Politely remind the colleagues that discussing PHI in public areas violates HIPAA and report the incident to the privacy officer if necessary (Correct answer)
- Join the conversation to gather clinical context
- Write down the patient information in case it is needed clinically later
Correct answer: Politely remind the colleagues that discussing PHI in public areas violates HIPAA and report the incident to the privacy officer if necessary
Discussing identifiable patient information in public spaces (cafeteria, elevators, hallways) violates HIPAA even among healthcare workers. The minimum necessary standard and incidental disclosure rules prohibit unnecessary sharing of PHI in public areas.
HIPAA incidental disclosure: Some inadvertent disclosures are permissible if reasonable safeguards are in place (e.g., calling a patient's name in a waiting room). However, detailed PHI discussions in public spaces are not protected as 'incidental.' Required safeguards: use private areas (closed-door rooms, private hallways) for patient discussions; lower voice in shared spaces; ensure computer screens are not visible to unauthorized persons (screen privacy filters); proper training on minimum necessary principle. HIV status is particularly sensitive โ many states have additional privacy protections for HIV information beyond HIPAA. Additional sensitive categories often with extra protections: mental health, substance abuse (42 CFR Part 2), reproductive health, genetic information (GINA). The medical assistant has an obligation to address the situation professionally.
Question 4: Under HIPAA, what must a covered entity do when a data breach affects 500 or more individuals?
- File a report only with local law enforcement within 10 days
- Notify affected individuals, provide notice to prominent media outlets in affected states, and report to HHS (OCR) within 60 days of breach discovery (Correct answer)
- Notify affected individuals within 1 year of discovery at their convenience
- Report only to the state health department within 90 days
Correct answer: Notify affected individuals, provide notice to prominent media outlets in affected states, and report to HHS (OCR) within 60 days of breach discovery
HIPAA's Breach Notification Rule for breaches affecting 500+ individuals requires: notification to affected individuals within 60 days, notice to prominent media outlets in affected states, and immediate notification to HHS OCR (which posts breaches publicly on the 'Wall of Shame').
HIPAA Breach Notification Rule requirements: All breaches: notify affected individuals within 60 days of discovery; include: description of breach, types of PHI involved, steps individuals should take to protect themselves, steps entity is taking, contact information; Small breaches (<500 individuals per state): report to HHS OCR annually; Large breaches (โฅ500 individuals): notify HHS OCR within 60 days of discovery; notify prominent media outlets in affected state/jurisdiction; HHS posts on public 'Wall of Shame' (breach portal); Breach definition: unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises security/privacy; Four-factor risk assessment determines if incident = breach; Penalties by violation tier: unknowing: $127โ$63,973/violation; reasonable cause: $1,280โ$63,973; willful neglect corrected: $12,794โ$63,973; willful neglect uncorrected: $63,973 minimum.
Question 5: A patient requests that the medical office NOT share their PHI with their health insurance plan for a specific service they paid for entirely out of of-pocket. Under HIPAA, what must the covered entity do?
- Inform the patient this is not possible under HIPAA regulations
- Honor the restriction request โ this is a mandatory restriction covered entities must comply with under the HITECH Act (Correct answer)
- Comply only if the patient submits the request in writing notarized by an attorney
- Comply only if the treating physician agrees the restriction is appropriate
Correct answer: Honor the restriction request โ this is a mandatory restriction covered entities must comply with under the HITECH Act
The HITECH Act (2009) amended HIPAA to mandate that covered entities must honor a patient's request to restrict disclosure to a health plan when: (1) the restriction applies to a specific item or service, AND (2) the patient has paid for the service in full out-of-pocket.
HITECH mandatory restriction (45 CFR ยง164.522(a)(1)(vi)): Covered entities MUST agree to restrict disclosure to a health plan for a specific item/service if: the patient requests the restriction; the disclosure would be for payment or healthcare operations (not treatment); the patient has paid in full, out of pocket, for the item/service. This was added by HITECH because patients who pay out of pocket may have legitimate reasons to keep certain services from their insurer (e.g., mental health, substance abuse treatment, sensitive diagnosis). The covered entity must implement systems to honor the restriction across all administrative and billing processes. This is the ONLY mandatory PHI restriction โ generally, covered entities can decline other restriction requests. Medical assistants must document these restrictions and ensure billing staff honors them.
Question 6: Which federal law supplements HIPAA by providing additional privacy protections specifically for substance use disorder (SUD) treatment records?
- The Americans with Disabilities Act (ADA)
- 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) (Correct answer)
- The Family and Medical Leave Act (FMLA)
- The Mental Health Parity and Addiction Equity Act (MHPAEA)
Correct answer: 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records)
42 CFR Part 2 provides stricter privacy protections for records of patients treated in federally assisted substance use disorder (SUD) programs. It generally requires patient consent even for disclosures permitted under HIPAA (e.g., for treatment purposes to other providers).
42 CFR Part 2 vs. HIPAA: Applies to: records from federally assisted SUD treatment programs (programs receiving any federal assistance, including Medicare/Medicaid billing); Stricter than HIPAA: requires patient consent for disclosures that HIPAA would permit without authorization (including treatment purposes); General medical facilities can treat patients with SUD and share those records under HIPAA; but federally assisted SUD programs must comply with 42 CFR Part 2; Key differences: redisclosure is prohibited; law enforcement access is much more restricted; consent must be written and signed. 2020 Update: 42 CFR Part 2 was significantly revised to better align with HIPAA while maintaining stronger protections; patients can now consent to broader disclosures for treatment, payment, and operations. Medical assistants in facilities treating SUD must understand these heightened obligations.
Under HIPAA, what is a 'Business Associate Agreement' (BAA) and when is it required?