PAR Regulatory Compliance & Health Privacy Laws 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'limited data set' that requires a data use agreement?
- Data with all 18 identifiers removed
- Data with most direct identifiers removed but may include dates and geographic subdivisions (Correct answer)
- Data that includes name and address but no diagnosis
- Data that includes only zip codes and no clinical information
Correct answer: Data with most direct identifiers removed but may include dates and geographic subdivisions
A limited data set removes most direct identifiers but may retain dates, geographic subdivisions larger than a street address, and other indirect identifiers, requiring a data use agreement.
Question 2: A patient requests an amendment to their medical record because they believe it contains an error. Under HIPAA, how long does a covered entity have to act on this request?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
HIPAA requires covered entities to act on a request for amendment within 60 days, with one possible 30-day extension if the entity notifies the individual in writing.
Question 3: Which federal law specifically governs the privacy of substance use disorder treatment records at federally assisted programs?
- HIPAA Privacy Rule
- 42 CFR Part 2 (Correct answer)
- HITECH Act
- The Confidentiality Act of 1972
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides stricter confidentiality protections for substance use disorder patient records at federally assisted programs than HIPAA.
Question 4: A Patient Access Representative receives a subpoena for a patient's medical records. What is the MOST appropriate first action?
- Immediately release the records to comply with the legal order
- Notify the patient and wait for their authorization
- Forward the subpoena to the facility's legal counsel or privacy officer (Correct answer)
- Refuse to release records without a court order signed by a judge
Correct answer: Forward the subpoena to the facility's legal counsel or privacy officer
Subpoenas require legal review before release; the privacy officer or legal counsel determines whether the subpoena meets HIPAA requirements for disclosure.
Question 5: Under the HITECH Act, which of the following organizations are directly liable for HIPAA compliance?
- Only covered entities
- Only business associates
- Both covered entities and business associates (Correct answer)
- Only healthcare providers, not health plans
Correct answer: Both covered entities and business associates
The HITECH Act extended direct HIPAA liability to business associates, not just covered entities, making both directly subject to enforcement.
Question 6: The EMTALA law requires hospitals with emergency departments to provide what to all patients regardless of insurance status?
- Free care for all emergency conditions
- A medical screening examination and stabilizing treatment (Correct answer)
- Admission to the hospital for any presenting complaint
- A payment plan before services are rendered
Correct answer: A medical screening examination and stabilizing treatment
EMTALA mandates that hospitals provide a medical screening examination to all patients and stabilizing treatment for emergency medical conditions, regardless of ability to pay.
Question 7: Which of the following is NOT one of the four HIPAA enforcement tiers of civil monetary penalties?
- Violation where the entity did not know and could not have known
- Violation due to reasonable cause but not willful neglect
- Violation due to willful neglect, corrected within 30 days
- Violation due to criminal intent with personal financial gain (Correct answer)
Correct answer: Violation due to criminal intent with personal financial gain
Criminal intent with personal financial gain is addressed under HIPAA criminal penalties, not civil monetary penalty tiers, which range from unknowing violations to uncorrected willful neglect.
Under HIPAA, which of the following is considered a 'limited data set' that requires a data use agreement?