CEC Privacy and Security Standards 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- An employee's work schedule
- A patient's diagnosis combined with their name (Correct answer)
- A hospital's annual revenue report
- A generic health tip published in a newsletter
Correct answer: A patient's diagnosis combined with their name
PHI is individually identifiable health information that includes identifiers such as name combined with health data like a diagnosis.
Question 2: A Marketplace Navigator receives a paper application containing an applicant's SSN. What is the most appropriate way to store this document?
- Leave it on the desk for easy access
- Store it in a locked cabinet with restricted access (Correct answer)
- Scan it and email it to a colleague
- File it alphabetically in an open office drawer
Correct answer: Store it in a locked cabinet with restricted access
Sensitive documents containing SSNs must be secured in locked storage with access limited to authorized personnel.
Question 3: Which federal law primarily governs the privacy of student education records and is relevant when assisting student-aged applicants?
- HIPAA
- FERPA (Correct answer)
- COPPA
- ACA Section 1557
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records.
Question 4: An enrollment counselor accidentally sends an applicant's eligibility information to the wrong email address. This is an example of a:
- Permitted disclosure
- Business associate breach
- Unauthorized disclosure requiring notification (Correct answer)
- De-identified data release
Correct answer: Unauthorized disclosure requiring notification
Sending PII or PHI to an unintended recipient constitutes an unauthorized disclosure that may trigger breach notification requirements.
Question 5: What does 'minimum necessary' mean in the context of HIPAA privacy rules for enrollment counselors?
- Only collect data required at the minimum income threshold
- Access or share only the amount of PHI needed to complete the task (Correct answer)
- Provide the minimum number of plan options to applicants
- Enroll only the minimum required number of applicants per month
Correct answer: Access or share only the amount of PHI needed to complete the task
The minimum necessary standard requires that access to PHI be limited to only what is needed to accomplish the intended purpose.
Question 6: Which of the following is a 'safe harbor' de-identification method under HIPAA?
- Encrypting all 18 identifiers with a password
- Removing all 18 specific identifiers defined by HIPAA (Correct answer)
- Replacing names with pseudonyms
- Storing records in a separate secure database
Correct answer: Removing all 18 specific identifiers defined by HIPAA
HIPAA's Safe Harbor method requires removing all 18 specified identifiers to ensure data cannot identify an individual.
Question 7: When an applicant asks who has access to their enrollment application data, the enrollment counselor should:
- Decline to answer to protect security protocols
- Explain the privacy notice and describe authorized data access (Correct answer)
- Refer them only to the federal government website
- Tell them only the Navigator has access
Correct answer: Explain the privacy notice and describe authorized data access
Counselors are required to provide applicants with a privacy notice that explains who may access their information and for what purposes.
Under HIPAA, which of the following is considered Protected Health Information (PHI)?