NCMA HIPAA and Patient Privacy Rights 1 — Questions and Answers
Question 1: Under HIPAA, what does 'PHI' stand for, and what does it include?
- Patient Health Index — a numerical score of overall health
- Protected Health Information — individually identifiable health information held by covered entities (Correct answer)
- Private Hospital Information — internal hospital records not accessible to patients
- Public Health Initiative — government programs for disease prevention
Correct answer: Protected Health Information — individually identifiable health information held by covered entities
PHI (Protected Health Information) is individually identifiable health information created, received, or maintained by a covered entity in any form (electronic, paper, verbal) that relates to past, present, or future physical/mental health conditions, healthcare provided, or payment for care.
HIPAA's 18 PHI identifiers: name, geographic data smaller than state, dates (except year), phone numbers, fax numbers, email addresses, SSN, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers, device identifiers, URLs, IP addresses, biometric identifiers (fingerprints), full-face photographs, any unique identifying number or code. De-identified data is not PHI — all 18 identifiers must be removed OR statistical expert certifies re-identification risk is very small. Covered entities under HIPAA: healthcare providers (who transmit PHI electronically), health plans, healthcare clearinghouses. Business Associates: third parties that handle PHI on behalf of covered entities must sign Business Associate Agreements (BAAs).
Question 2: Which of the following represents a HIPAA-permitted disclosure of PHI WITHOUT the patient's written authorization?
- Sharing a patient's diagnosis with their employer for insurance purposes
- Disclosing immunization records to a patient's school for enrollment (Correct answer)
- Providing patient records to the patient's attorney without a court order
- Releasing medical records to a pharmaceutical company for marketing
Correct answer: Disclosing immunization records to a patient's school for enrollment
HIPAA permits disclosure of immunization records to schools without patient authorization when state law requires such proof. This falls under the 'required by law' exception. The other options require explicit patient authorization.
HIPAA permitted disclosures WITHOUT patient authorization: Treatment, payment, and healthcare operations (TPO); Public health activities (disease reporting, FDA reporting); Abuse/neglect reporting (required by law); Health oversight activities (state medical boards, CMS); Judicial/administrative proceedings (court order or subpoena with notice); Law enforcement (limited circumstances); Workers' compensation; Required by law (immunizations to schools per state statute); Decedents (for identification, authorized family); Serious threat to health/safety (imminent harm). Disclosures REQUIRING patient authorization: marketing, sale of PHI, psychotherapy notes, most research, life insurance, employment, law enforcement (without court order). The minimum necessary standard applies to all permitted disclosures.
Question 3: What is the HIPAA 'Minimum Necessary' standard, and how does it apply in daily practice?
- Only the minimum number of staff may access patient files at one time
- Only the minimum amount of PHI necessary to accomplish the intended purpose should be used, disclosed, or requested (Correct answer)
- The minimum necessary medication dose should be prescribed for all patients
- Patient records may only be a minimum number of pages in length
Correct answer: Only the minimum amount of PHI necessary to accomplish the intended purpose should be used, disclosed, or requested
The Minimum Necessary standard requires covered entities to make reasonable efforts to limit use and disclosure of PHI to the minimum amount needed to accomplish the intended purpose. Staff should only access what they need for their specific job function.
Minimum Necessary standard application: Medical assistants should only access records relevant to the patients they are actively caring for; Front desk staff should not view clinical notes beyond appointment scheduling needs; Billing staff needs diagnosis and procedure codes but not full clinical notes; This standard does NOT apply to: disclosures to the patient about their own information; disclosures for treatment purposes (provider-to-provider); required by law disclosures; Implementation: role-based EHR access controls; audit logs track who accesses what records; sanctions for inappropriate access. Minimum necessary is violated by: browsing colleague/celebrity records out of curiosity; sharing patient information at nurse stations where others can hear; using more information than needed for the task.
Question 4: A patient calls the medical office requesting a copy of their own medical records. Under HIPAA, what are the patient's rights?
- Patients have no automatic right to their records — this is at physician discretion
- Patients have the right to access and obtain copies of their PHI, typically within 30 days, with a possible 30-day extension (Correct answer)
- Patients can only access records if they have an attorney present
- Patients may only view records in the office but cannot obtain copies
Correct answer: Patients have the right to access and obtain copies of their PHI, typically within 30 days, with a possible 30-day extension
HIPAA's Privacy Rule grants patients the right to access and obtain copies of their PHI maintained in a designated record set. Covered entities must respond within 30 days, with one 30-day extension allowed with written notice.
HIPAA patient rights under the Privacy Rule: Access — right to inspect and copy PHI in designated record sets (medical records, billing records); 30-day response time + 30-day extension with notice; reasonable cost-based fees for copies; Amendments — request corrections to PHI; covered entity must respond within 60 days; can deny if record is accurate; Accounting of disclosures — list of disclosures for non-TPO purposes for prior 6 years; Restrictions — request limits on how PHI is used/disclosed (covered entity doesn't have to agree except to restrict disclosure to health plan for self-pay services fully paid out-of-pocket); Confidential communications — request PHI via alternative means (e.g., 'send to PO box, not home address'); Complaint — right to file complaint with OCR without retaliation.
Question 5: What is the correct action when a medical assistant accidentally views a celebrity patient's medical record while searching for another patient with a similar name?
- Ignore the incident since it was accidental
- Immediately close the record, report the accidental access to the supervisor, and document the incident per facility policy (Correct answer)
- Share with the celebrity's publicist to ensure information accuracy
- Make note of the information for potential future reference
Correct answer: Immediately close the record, report the accidental access to the supervisor, and document the incident per facility policy
Even accidental access to the wrong patient's PHI is a privacy incident. The correct response is to close the record immediately, report to the supervisor/privacy officer, and document the incident per facility policy — which is required for HIPAA breach assessment.
HIPAA incident response for accidental PHI access: (1) Close the record immediately upon realizing the error; (2) Do not copy, share, or use any information accessed; (3) Report to supervisor/privacy officer promptly; (4) Document the incident: when access occurred, what information was viewed, how the error occurred; (5) The privacy officer conducts a breach risk assessment: Was PHI accessed by unauthorized person? Could it compromise privacy/security? Was there actual acquisition, access, use, or disclosure? (6) If breach confirmed: notification to patient within 60 days; breach of 500+ individuals: notification to HHS and media within 60 days of discovery; Penalties: civil (up to $1.9 million/violation category/year); criminal (willful neglect with intent: up to $250,000 + 10 years imprisonment). VIP patients are among the most frequently breached records — curiosity is never a valid reason for access.
Question 6: A patient's family member calls the medical office asking for information about the patient's recent laboratory results. Under HIPAA, what should the medical assistant do?
- Provide the results since family members have an inherent right to patient information
- Verify whether the patient has authorized release to this specific family member or if they are listed as a personal representative before disclosing any PHI (Correct answer)
- Refuse to confirm whether the patient is even a patient at the practice
- Ask the family member to have the patient call back themselves
Correct answer: Verify whether the patient has authorized release to this specific family member or if they are listed as a personal representative before disclosing any PHI
HIPAA requires patient authorization for disclosure to third parties including family members, unless the patient is present and has verbally agreed, the patient has previously authorized disclosure to this person, or the caller is a legally designated personal representative.
HIPAA disclosure to family and friends: Requires patient authorization OR: patient is present and given opportunity to agree/object (can verbally consent in physician's presence); patient is incapacitated — professional judgment that disclosure is in patient's best interest and consistent with any prior expressed preferences; patient has designated family member as authorized contact (documented in chart); personal representative (legal guardian, healthcare proxy, durable power of attorney holder); Verification steps: check the chart for documented authorizations; if the patient has signed a Release of Information authorizing this family member, disclose only what is authorized; if no authorization on file, ask the patient directly or request written authorization; Minimum necessary applies even with authorization — provide only what is needed. Note: HIPAA does NOT require refusal to confirm the patient is a patient in all cases — it is permissible to confirm basic facts consistent with professional courtesy.
Under HIPAA, what does 'PHI' stand for, and what does it include?