CHPC - Certified in Healthcare Privacy Compliance Healthcare Privacy Laws and Regulations Questions and Answers — Questions and Answers
Question 1: A research institution wants to use a dataset containing PHI for a study. To comply with HIPAA, they must de-identify the data. Which of the following methods relies on a qualified statistician to apply scientific principles to determine that the risk of re-identification is 'very small'?
- The Safe Harbor Method
- The Expert Determination Method (Correct answer)
- The Minimum Necessary Standard
- The Data Use Agreement Method
Correct answer: The Expert Determination Method
The HIPAA Privacy Rule provides two methods for de-identification. The Expert Determination Method involves a qualified expert applying statistical or scientific principles to determine that the risk is 'very small' that the information could be used to identify an individual. The Safe Harbor method involves removing 18 specific identifiers.
Question 2: A patient discovers an error in their medical record and submits a written request to their provider to correct it. Under the HIPAA Privacy Rule, what is the covered entity's primary obligation regarding the patient's right to amend their PHI?
- To immediately delete the incorrect information from the record.
- To inform the patient that medical records cannot be altered once created.
- To review the request and, if granted, append the correction to the record. (Correct answer)
- To charge the patient a fee for the administrative cost of the amendment.
Correct answer: To review the request and, if granted, append the correction to the record.
The HIPAA Privacy Rule gives individuals the right to request amendment of their PHI in a designated record set. The covered entity is not required to delete the original information but must, if it accepts the amendment, append the corrected information and notify relevant parties. The entity can deny the request for specific reasons, such as if it determines the record is accurate and complete.
Question 3: A hospital's business associate, a billing company, experiences a data breach involving unsecured PHI. According to the HITECH Act's Breach Notification Rule, what is the business associate's direct responsibility?
- Notify all affected individuals within 60 days of discovering the breach.
- Report the breach directly to the media if more than 500 individuals are affected.
- Notify the covered entity of the breach without unreasonable delay and no later than 60 days following discovery. (Correct answer)
- Wait for the covered entity to discover the breach independently before taking any action.
Correct answer: Notify the covered entity of the breach without unreasonable delay and no later than 60 days following discovery.
Under the HITECH Act, a business associate must notify the covered entity of a breach of unsecured PHI 'without unreasonable delay and in no case later than 60 calendar days' after discovery. The covered entity is ultimately responsible for notifying the affected individuals, HHS, and, if applicable, the media.
Question 4: A state has a law requiring that patients provide specific consent for the release of mental health records, a standard more stringent than HIPAA's general authorization requirements. A provider in this state receives a request that is compliant with HIPAA but not with the stricter state law. Which of the following is the correct course of action?
- Follow the HIPAA standard because federal law always supersedes state law.
- Disregard both laws and use professional judgment.
- Follow the more stringent state law. (Correct answer)
- Inform the requestor that the laws are in conflict and no information can be released.
Correct answer: Follow the more stringent state law.
The HIPAA Privacy Rule acts as a federal floor for privacy protection. It does not preempt state laws that are 'more stringent,' meaning those that provide greater privacy protections to individuals. In this case, the provider must comply with the state law that offers greater protection to the patient's information.
Question 5: A covered entity wishes to send promotional materials to its former patients about a new, non-health-related service, such as a financial planning workshop hosted by a third party. Under the HIPAA Privacy Rule, which of the following is required before using PHI for this purpose?
- A notice posted in the provider's waiting room.
- A valid, written authorization from each individual. (Correct answer)
- An updated Notice of Privacy Practices.
- No specific action, as this is considered a healthcare operation.
Correct answer: A valid, written authorization from each individual.
Using or disclosing PHI for marketing purposes generally requires a specific, written authorization from the individual. This authorization must be in plain language and clearly state how the information will be used. Communications about third-party products or services that involve remuneration are considered marketing and are not covered under treatment, payment, or healthcare operations exceptions.
Question 6: Which of the following is a mandatory component that must be included in a HIPAA Business Associate Agreement (BAA)?
- A requirement for the business associate to carry a minimum level of cybersecurity insurance.
- The specific names of the business associate's privacy and security officers.
- A provision requiring the business associate to make its internal practices available to the Secretary of HHS for compliance determination. (Correct answer)
- A fixed fee schedule for all services provided by the business associate.
Correct answer: A provision requiring the business associate to make its internal practices available to the Secretary of HHS for compliance determination.
A compliant Business Associate Agreement must include several key elements, one of which is establishing that the business associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the Department of Health and Human Services (HHS) to determine compliance with HIPAA. While insurance and fee schedules are good business practices, they are not explicitly required elements of a BAA by HIPAA.
A research institution wants to use a dataset containing PHI for a study.
To comply with HIPAA, they must de-identify the data.
Which of the following methods relies on a qualified statistician to apply scientific principles to determine that the risk of re-identification is 'very small'?