CMAA HIPAA and Patient Confidentiality 2 — Questions and Answers
Question 1: Under HIPAA, which is considered Protected Health Information (PHI)?
- A patient's favorite color
- De-identified statistical data
- A medical record number linked to a diagnosis (Correct answer)
- General health tips on a clinic website
Correct answer: A medical record number linked to a diagnosis
PHI includes any individually identifiable health information, such as a medical record number linked to a diagnosis.
PHI under HIPAA encompasses health information linkable to an individual via 18 identifiers including names, dates, medical record numbers, and SSNs. A medical record number linked to a diagnosis clearly qualifies. De-identified data has all identifiers removed. General tips and personal preferences unrelated to health are not PHI.
Question 2: How long must a covered entity retain HIPAA-related documentation?
- 3 years
- 6 years from creation or last effective date (Correct answer)
- 10 years
- Indefinitely
Correct answer: 6 years from creation or last effective date
HIPAA requires retaining policies, procedures, and authorization forms for 6 years from creation or last effective date, whichever is later.
HIPAA requires 6-year retention for policies, procedures, communications, and designations. State laws may require longer retention for actual medical records (often 7-10 years for adults). CMAAs must understand both federal and state requirements.
Question 3: A pharmaceutical rep asks for a list of patients on a specific medication. What is the correct response?
- Provide it with a signed confidentiality agreement
- Decline as it violates HIPAA (Correct answer)
- Share with physician verbal approval
- Provide it without addresses
Correct answer: Decline as it violates HIPAA
Sharing medication lists with pharmaceutical reps violates HIPAA as unauthorized disclosure for non-treatment, payment, or operations purposes.
HIPAA limits PHI disclosure to treatment, payment, healthcare operations, or with patient authorization. Sharing medication lists with reps is marketing use requiring individual patient authorization. No confidentiality agreement or verbal approval overrides this. CMAAs must firmly decline such requests.
Question 4: What does the HIPAA Security Rule primarily protect?
- All patient health information
- Electronic PHI (ePHI) (Correct answer)
- Paper records only
- Financial information only
Correct answer: Electronic PHI (ePHI)
The Security Rule specifically addresses electronic PHI through administrative, physical, and technical safeguards.
The Security Rule establishes standards for protecting ePHI with three safeguard categories: administrative (risk analysis, training), physical (facility access, workstation security), and technical (access controls, encryption, audit trails). The Privacy Rule covers all PHI regardless of format.
Question 5: Which exemplifies the HIPAA minimum necessary standard?
- Giving billing staff only financial data needed for claims (Correct answer)
- Allowing all staff full access to every record
- Sharing complete histories with every department
- Posting schedules in the waiting room
Correct answer: Giving billing staff only financial data needed for claims
The minimum necessary standard limits PHI access to only what is needed for the intended purpose.
The minimum necessary standard requires organizations to limit PHI access to what is needed for the task. For billing staff, that means diagnosis codes, procedure codes, demographics, and insurance, but not clinical notes or lab results. This is implemented through role-based access controls in EHR systems.
Question 6: A patient requests an amendment to their record. The provider must respond within what timeframe?
- 30 days with one 30-day extension
- 60 days with one 30-day extension (Correct answer)
- 14 business days, no extensions
- 90 days, no extensions
Correct answer: 60 days with one 30-day extension
Covered entities must respond to amendment requests within 60 days, with one optional 30-day extension with written notice.
HIPAA gives patients the right to request amendments to their PHI. Response is due within 60 days; one 30-day extension requires written notice. Denial is allowed if the information wasn't created by the provider, isn't in the designated record set, is accurate, or wouldn't be available for inspection. Patients may submit a written disagreement.
Under HIPAA, which is considered Protected Health Information (PHI)?