Relias Compliance and Regulatory Training 2 — Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, when sharing PHI, covered entities must:
- Share all available patient information for continuity of care
- Limit disclosures to the least amount of information needed for the purpose (Correct answer)
- Obtain written consent for every single disclosure
- Encrypt all information before any disclosure
Correct answer: Limit disclosures to the least amount of information needed for the purpose
The Minimum Necessary Standard requires limiting PHI disclosures to only what is needed to accomplish the intended purpose.
Question 2: Which federal law requires healthcare organizations to report certain adverse events to the government?
- HITECH Act
- Patient Safety and Quality Improvement Act (PSQIA) (Correct answer)
- Sarbanes-Oxley Act
- Federal Food, Drug, and Cosmetic Act
Correct answer: Patient Safety and Quality Improvement Act (PSQIA)
PSQIA created a voluntary reporting system for patient safety events with legal protections to encourage disclosure.
Question 3: In a healthcare setting, what does 'chain of custody' primarily refer to in compliance?
- Supervision hierarchy for staff disciplinary actions
- Documentation tracking the handling of controlled substances or specimens (Correct answer)
- Patient transfer protocols between departments
- The sequence of approvals for policy changes
Correct answer: Documentation tracking the handling of controlled substances or specimens
Chain of custody documents the chronological handling, transfer, and disposition of items like controlled substances or lab specimens.
Question 4: Which of the following best describes a 'covered entity' under HIPAA?
- Any business that handles personally identifiable information
- Health plans, healthcare clearinghouses, and most healthcare providers (Correct answer)
- Only hospitals and large medical centers
- Any organization with more than 50 employees in healthcare
Correct answer: Health plans, healthcare clearinghouses, and most healthcare providers
HIPAA defines covered entities as health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically.
Question 5: When must a healthcare organization provide a Notice of Privacy Practices (NPP) to a patient?
- Only when the patient requests it in writing
- At first service delivery and upon request thereafter (Correct answer)
- Annually, regardless of patient contact
- Only when disclosing information to third parties
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP no later than the first date of service and must make it available upon request.
Question 6: What is the primary purpose of a compliance hotline or reporting mechanism in healthcare?
- To handle patient billing disputes
- To provide a confidential channel for reporting suspected violations without fear of retaliation (Correct answer)
- To track employee attendance and tardiness
- To manage insurance prior authorization requests
Correct answer: To provide a confidential channel for reporting suspected violations without fear of retaliation
Compliance hotlines give employees a safe, confidential way to report potential violations, which is a core element of an effective compliance program.
Question 7: Under the Emergency Medical Treatment and Labor Act (EMTALA), what must hospitals with emergency departments do?
- Accept all transfer patients regardless of bed availability
- Provide a medical screening examination to anyone seeking emergency care, regardless of ability to pay (Correct answer)
- Offer free treatment to all uninsured patients
- Report all emergency visits to CMS within 24 hours
Correct answer: Provide a medical screening examination to anyone seeking emergency care, regardless of ability to pay
EMTALA requires hospitals to screen and stabilize any patient presenting to the emergency department regardless of their insurance status or ability to pay.
Under HIPAA's Minimum Necessary Standard, when sharing PHI, covered entities must: