Clinical Informatics Certification Clinical Informatics Privacy & Ethics 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity'?
- A marketing firm that analyzes de-identified health trends
- A health plan that pays for medical services (Correct answer)
- A cloud storage vendor storing encrypted PHI on behalf of a hospital
- A medical device manufacturer selling devices directly to consumers
Correct answer: A health plan that pays for medical services
Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically are the three types of covered entities under HIPAA.
Question 2: A researcher wants to use patient data without obtaining individual authorizations. Which HIPAA Privacy Rule provision allows this under specific conditions?
- Minimum Necessary Standard
- Waiver of Authorization by an IRB or Privacy Board (Correct answer)
- Notice of Privacy Practices
- Business Associate Agreement
Correct answer: Waiver of Authorization by an IRB or Privacy Board
An Institutional Review Board (IRB) or Privacy Board can waive the authorization requirement for research when conditions such as minimal risk to privacy are met.
Question 3: Which concept in clinical informatics ethics refers to a patient's right to make informed decisions about their own health care without coercion?
- Beneficence
- Non-maleficence
- Autonomy (Correct answer)
- Justice
Correct answer: Autonomy
Autonomy is the ethical principle that respects an individual's right to make their own informed decisions regarding their health and treatment.
Question 4: A hospital's EHR system automatically logs all user access to patient records. What is the primary purpose of this audit log?
- To improve clinical decision support accuracy
- To detect and investigate unauthorized access to PHI (Correct answer)
- To satisfy billing and coding requirements
- To generate quality improvement reports
Correct answer: To detect and investigate unauthorized access to PHI
Audit logs are a required HIPAA Security Rule safeguard used primarily to detect unauthorized or inappropriate access to protected health information.
Question 5: Which of the following best describes the ethical principle of 'justice' in the context of health information technology?
- Ensuring EHR systems do not cause patient harm
- Distributing the benefits and burdens of HIT equitably across populations (Correct answer)
- Obtaining patient consent before collecting health data
- Disclosing only the minimum necessary information
Correct answer: Distributing the benefits and burdens of HIT equitably across populations
Justice in health informatics refers to the fair and equitable distribution of HIT benefits and the avoidance of disparities, such as the digital divide.
Question 6: A clinician accesses the EHR record of a celebrity patient out of curiosity without clinical need. This is BEST described as a violation of which HIPAA rule?
- Security Rule — access control requirements
- Privacy Rule — minimum necessary standard (Correct answer)
- Breach Notification Rule — timeliness requirement
- Omnibus Rule — business associate provisions
Correct answer: Privacy Rule — minimum necessary standard
Accessing PHI without a legitimate need violates the HIPAA Privacy Rule's minimum necessary standard, which limits access to only what is needed for a specific purpose.
Question 7: Which of the following is an example of a 'secondary use' of health data that raises ethical concerns?
- A physician reviewing a patient's lab results to adjust medication
- An insurance company purchasing de-identified data to set premium rates (Correct answer)
- A nurse updating medication administration records in the EHR
- A pharmacist verifying drug interactions before dispensing a prescription
Correct answer: An insurance company purchasing de-identified data to set premium rates
Secondary use refers to using health data for purposes beyond direct patient care, such as commercial activities, which can raise ethical concerns about consent and exploitation.
Under HIPAA, which of the following is considered a 'covered entity'?