RMA Medical Law and Ethics 3 — Questions and Answers
Question 1: When a physician documents 'objective' findings in a SOAP note, which of the following would be considered an objective finding?
- The patient reports sharp, stabbing pain rated 8/10
- The patient states they have had fever for two days
- Lung auscultation reveals bilateral crackles; temperature 38.6°C (Correct answer)
- The patient denies nausea, vomiting, or shortness of breath
Correct answer: Lung auscultation reveals bilateral crackles; temperature 38.6°C
Objective findings are measurable, observable data gathered by the clinician — such as physical exam findings (crackles on auscultation) and vital signs (measured temperature) — as opposed to what the patient reports.
In the SOAP note format, the distinction between Subjective and Objective is critical for accurate clinical documentation. Subjective data is information provided by the patient through their own report — symptoms, pain ratings, duration of illness, and the history of present illness. This is what the patient tells the provider. Objective data is observable, measurable, and reproducible information gathered by the examiner — vital signs (temperature, pulse, respiration, blood pressure, oxygen saturation), physical examination findings (breath sounds, heart sounds, skin appearance, reflexes), lab results, imaging findings, and test results. This is what the provider can see, hear, feel, or measure. The distinction matters because subjective reports depend on patient perception and may be influenced by anxiety, cultural differences, or cognitive impairment, while objective findings provide independent verification. In the examples: 'pain rated 8/10' and 'fever for two days' are subjective (patient reports). 'Bilateral crackles' (heard by the examiner with a stethoscope) and '38.6°C temperature' (measured by thermometer) are objective. 'Denies nausea' is subjective (patient's denial).
Question 2: Which federal act establishes patients' rights to access their medical records, request amendments, and receive an accounting of disclosures?
- The Affordable Care Act (ACA)
- HITECH Act
- HIPAA Privacy Rule (Correct answer)
- The Patient Self-Determination Act
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule (45 CFR Part 164) specifically grants patients the right to access their PHI, request corrections, and receive an accounting of non-routine disclosures made without their authorization.
The HIPAA Privacy Rule (implemented under 45 CFR Part 164) establishes comprehensive federal protections for individually identifiable health information and grants patients specific rights regarding their own PHI. Key patient rights include: 1. Right of Access — patients may inspect and receive a copy of their medical records held by covered entities. 2. Right to Amend — patients may request corrections to their PHI if they believe it is inaccurate or incomplete. 3. Right to an Accounting of Disclosures — patients may request a list of non-routine disclosures of their PHI made without their authorization (not including those made for treatment, payment, or operations). 4. Right to Request Restrictions — patients may request limitations on how their PHI is used or disclosed. 5. Right to Confidential Communications — patients may request to receive communications via alternative means or locations. The HITECH Act (2009) strengthened HIPAA enforcement and extended its application to business associates. The Patient Self-Determination Act requires healthcare facilities to inform patients of advance directive rights. The ACA deals with health insurance expansion, not records rights. Medical assistants must understand these rights to appropriately respond to patient requests.
Question 3: What is the statute of limitations and why is it important in medical malpractice cases?
- The maximum amount of money a plaintiff can recover in a malpractice lawsuit
- The number of expert witnesses required in a malpractice trial
- The time period within which a plaintiff must file a lawsuit after an injury occurs (Correct answer)
- The standard of care that defines negligent medical practice
Correct answer: The time period within which a plaintiff must file a lawsuit after an injury occurs
The statute of limitations is the legally defined window of time — varying by state and case type — within which a patient (plaintiff) must initiate a malpractice lawsuit; failing to file within this period permanently bars the claim.
A statute of limitations is a law that sets the maximum time after an event within which legal proceedings may be initiated. In medical malpractice, this is typically 2–3 years from the date the injury occurred or was discovered (the 'discovery rule' in states that apply it). Some states toll (pause) the statute of limitations for minors until they reach adulthood. The statute of limitations serves several purposes: it protects defendants from defending against stale claims when evidence and witness memories have faded; it encourages plaintiffs to pursue claims promptly; and it promotes judicial efficiency by preventing courts from being perpetually open to old cases. For medical assistants, understanding the statute of limitations reinforces the critical importance of complete, accurate, timely, and unaltered medical record documentation. Records serve as the primary evidence in malpractice litigation. Medical records must never be altered after the fact — if an error is made in documentation, the correct method is to draw a single line through the error, initial and date it, and add the correction — never erase, white-out, or delete entries.
Question 4: A physician delegates a task to a medical assistant that is outside the medical assistant's training and scope of practice. If the patient is harmed, which legal concept holds the physician primarily responsible?
- Contributory negligence
- Comparative negligence
- Negligent delegation (Correct answer)
- Assumption of risk
Correct answer: Negligent delegation
Negligent delegation occurs when a supervisor assigns a task to a person who lacks the competency, training, or legal authority to perform it safely; the delegating physician bears legal responsibility for any resulting patient harm.
Negligent delegation (also called improper delegation) is a form of negligence in which a supervising provider assigns tasks to personnel who are unqualified, untrained, or not legally authorized to perform them. In medical practice, this means a physician must only delegate clinical tasks to a medical assistant that: fall within the MA's scope of practice as defined by state law and facility policy; the MA has been trained and demonstrated competency to perform; and appropriate supervision is provided. If a physician asks a medical assistant to perform a procedure beyond their scope — for example, interpreting ECG results, making a diagnosis, or performing a complex invasive procedure without appropriate training — and the patient is harmed, the physician can be held liable for negligent delegation in addition to the medical assistant being personally liable for practicing outside their scope. Medical assistants have an ethical and legal responsibility to refuse assignments they are not qualified or authorized to perform. Accepting tasks outside one's scope not only exposes the MA to personal liability but also endangers patient safety. If asked to perform an inappropriate task, the medical assistant should respectfully decline and explain the basis for refusal.
Question 5: Which type of consent is typically documented when a patient agrees to have blood drawn for routine lab work?
- Expressed written consent
- Implied consent (Correct answer)
- Informed consent
- Proxy consent
Correct answer: Implied consent
Implied consent is inferred from a patient's actions — such as extending their arm for a blood draw — and is considered sufficient for routine, low-risk procedures with obvious intent.
Consent in healthcare can be expressed or implied. Expressed consent is explicitly communicated — either verbally or in writing. Informed consent is a specific type of expressed consent for significant medical decisions that requires the provider to explain the procedure, its risks, benefits, alternatives, and consequences of refusal, and the patient must demonstrate understanding before signing. Implied consent is inferred from circumstances or behavior — it is presumed when a reasonable person would understand what they are agreeing to by their actions. Classic examples: a patient who extends their arm when the phlebotomist approaches implies consent for venipuncture; a patient who opens their mouth when asked to do so implies consent for a throat examination; emergency treatment of an unconscious patient who cannot consent implies consent based on what a reasonable person in that situation would want. For major procedures, surgeries, anesthesia, clinical trial participation, or treatments with significant risks, expressed written informed consent is legally and ethically required. Routine clinical tasks like vital signs, finger sticks, or injections typically proceed on implied consent after verbal explanation. Medical assistants should always explain what they are about to do before touching a patient — both as a matter of respect and to ensure the patient has the opportunity to object.
Question 6: Which federal agency enforces HIPAA privacy and security compliance and investigates complaints against covered entities?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR), within HHS (Correct answer)
- Food and Drug Administration (FDA)
- Occupational Safety and Health Administration (OSHA)
Correct answer: Office for Civil Rights (OCR), within HHS
The Office for Civil Rights (OCR), a division of the U.S. Department of Health and Human Services (HHS), is the federal authority responsible for enforcing HIPAA privacy, security, and breach notification rules.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is the primary federal enforcement agency for HIPAA. The OCR investigates complaints filed by patients or other parties alleging violations of the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule. It also conducts compliance audits of covered entities and business associates. When a complaint is received, the OCR investigates and may require covered entities to take corrective action. Civil monetary penalties range based on culpability: $100–$50,000 per violation category per year (tiered by whether the violation was unknown, due to reasonable cause, willful neglect corrected, or willful neglect uncorrected), with a maximum of $1.9 million per calendar year for identical violations. Criminal penalties for willful misuse of PHI can reach $250,000 and 10 years imprisonment. Other agencies play related roles: CMS enforces Medicare and Medicaid regulations and HITECH security audits of EHR use; OSHA enforces occupational safety including the Bloodborne Pathogen Standard; the FDA regulates medical devices and drugs. Medical assistants who become aware of a HIPAA breach within their organization are legally and ethically obligated to report it through internal channels, and patients must be notified of breaches affecting their PHI within 60 days.
When a physician documents 'objective' findings in a SOAP note, which of the following would be considered an objective finding?