CBHT Client Confidentiality and HIPAA 3 — Questions and Answers
Question 1: A client in a residential program asks to review their own behavioral health records. Under HIPAA, the facility must generally provide access within how many days of the request?
- 30 days, with a possible 30-day extension (Correct answer)
- 7 business days with no extension allowed
- 60 days, with a possible 60-day extension
- 14 days, with no extensions permitted
Correct answer: 30 days, with a possible 30-day extension
HIPAA requires covered entities to act on a client's access request within 30 days, with one 30-day extension if the client is notified in writing.
Question 2: Which scenario best illustrates a HIPAA 'minimum necessary' violation?
- A BHT copies an entire psychiatric history to share with a billing clerk who only needs the diagnosis code (Correct answer)
- A nurse provides a treating physician with the client's full medication list
- A therapist shares intake information with a supervised intern involved in the client's treatment
- A case manager sends a client's discharge summary to the receiving residential facility
Correct answer: A BHT copies an entire psychiatric history to share with a billing clerk who only needs the diagnosis code
The minimum necessary standard requires disclosing only the information needed for the specific purpose; sharing a full history when only a code is needed violates this standard.
Question 3: 42 CFR Part 2 provides additional confidentiality protections beyond HIPAA for clients with records related to:
- Substance use disorder treatment (Correct answer)
- Traumatic brain injuries
- Chronic pain management
- Intellectual and developmental disabilities
Correct answer: Substance use disorder treatment
42 CFR Part 2 imposes stricter confidentiality rules on records related to substance use disorder treatment programs that receive federal assistance.
Question 4: A BHT's family member asks about a neighbor who is a client at the BHT's facility. The BHT should:
- Decline to confirm or provide any information and explain they cannot discuss clients (Correct answer)
- Confirm the neighbor is a client but share nothing further
- Share general information since the family member is not affiliated with the facility
- Verify whether the neighbor has authorized disclosure before answering
Correct answer: Decline to confirm or provide any information and explain they cannot discuss clients
BHTs must not disclose any client information to unauthorized individuals, including family members, regardless of the relationship.
Question 5: When a client provides written authorization for the release of their records, which element is NOT required on the authorization form?
- The client's insurance policy number (Correct answer)
- A description of the information to be disclosed
- The name of the person or entity authorized to receive the information
- An expiration date or event
Correct answer: The client's insurance policy number
A valid HIPAA authorization requires a description of the information, the recipient, an expiration date/event, and the client's signature — but does not require an insurance policy number.
Question 6: A BHT working in a group home notices that client charts are left open on a shared computer in a common hallway. This is a concern because:
- It may allow unauthorized individuals to view PHI, violating the HIPAA Security Rule's physical safeguard requirements (Correct answer)
- Paper charts are the only format protected under HIPAA
- Group homes are exempt from HIPAA because they are residential, not clinical settings
- Computer screens do not count as a disclosure medium under HIPAA
Correct answer: It may allow unauthorized individuals to view PHI, violating the HIPAA Security Rule's physical safeguard requirements
Electronic PHI must be protected by physical safeguards including workstation controls that prevent unauthorized viewing.
Question 7: A client expresses suicidal ideation with a specific plan. Disclosing this information to emergency services without the client's consent is:
- Permissible under HIPAA when necessary to prevent a serious and imminent threat to the client's safety (Correct answer)
- Always a HIPAA violation regardless of the level of danger
- Permissible only if the client is under 18 years old
- Permissible only if the client has previously signed a crisis release form
Correct answer: Permissible under HIPAA when necessary to prevent a serious and imminent threat to the client's safety
HIPAA permits disclosure to prevent serious and imminent threats to the health or safety of the individual or others, including to emergency responders.
A client in a residential program asks to review their own behavioral health records.
Under HIPAA, the facility must generally provide access within how many days of the request?