AHIMA AHIMA Release of Information 1 โ Questions and Answers
Question 1: What federal law primarily governs the release of protected health information (PHI) by covered entities in the US?
- The Freedom of Information Act (FOIA)
- The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (Correct answer)
- The Health Information Technology for Economic and Clinical Health (HITECH) Act only
- The Americans with Disabilities Act (ADA)
Correct answer: The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule
The HIPAA Privacy Rule (45 CFR Parts 160 and 164) is the primary federal regulation governing disclosure of PHI by covered entities and business associates.
Question 2: What elements are required in a valid HIPAA authorization for release of PHI?
- Patient name and date only
- Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke (Correct answer)
- Physician signature and facility stamp
- Insurance ID number and diagnosis code
Correct answer: Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke
A valid HIPAA authorization must include core elements such as a description of the PHI, the purpose of disclosure, the recipient, an expiration date/event, patient signature, and notice of the right to revoke.
Question 3: Under HIPAA, what is the 'minimum necessary' standard for release of information?
- Releasing only the first and last page of the record
- Limiting PHI disclosures to the least amount necessary to accomplish the intended purpose (Correct answer)
- Releasing only data from the past 12 months
- Providing only the discharge summary for all requests
Correct answer: Limiting PHI disclosures to the least amount necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI disclosure to what is needed for the specific purpose of the request.
Question 4: What is the timeframe a covered entity has to provide a patient access to their own PHI under the HIPAA Access Rule?
- 7 business days
- 30 calendar days, with one 30-day extension if needed (Correct answer)
- 60 calendar days
- 14 calendar days
Correct answer: 30 calendar days, with one 30-day extension if needed
HIPAA requires covered entities to provide patient access to PHI within 30 calendar days of the request, with the option of a single 30-day extension with written notice.
Question 5: Which type of PHI disclosure does NOT require a patient's authorization under HIPAA?
- Release to a marketing firm
- Release to the patient's employer for personnel decisions
- Release for treatment, payment, or healthcare operations (TPO) (Correct answer)
- Release to a life insurance company
Correct answer: Release for treatment, payment, or healthcare operations (TPO)
HIPAA permits covered entities to disclose PHI without patient authorization for treatment, payment, and healthcare operations purposes.
Question 6: What is a 'breach' under HIPAA's Breach Notification Rule?
- Any access to an electronic health record by unauthorized staff
- An impermissible use or disclosure of unsecured PHI that compromises its security or privacy (Correct answer)
- Sending a fax to the wrong number regardless of content
- Any complaint filed with the covered entity
Correct answer: An impermissible use or disclosure of unsecured PHI that compromises its security or privacy
A HIPAA breach is an impermissible acquisition, access, use, or disclosure of unsecured PHI that is presumed to compromise the privacy or security of the information unless the covered entity demonstrates low probability of compromise.
What federal law primarily governs the release of protected health information (PHI) by covered entities in the US?