CMRT Privacy & Security 5 — Questions and Answers
Question 1: What is a 'designated record set' under HIPAA?
- Only the documents signed by the patient during registration
- The medical and billing records used to make decisions about an individual (Correct answer)
- Any document bearing the patient's name or date of birth
- Records older than seven years that must be archived
Correct answer: The medical and billing records used to make decisions about an individual
A designated record set includes the medical, billing, and other records a covered entity uses to make decisions about individuals, which patients have rights to access and amend.
Question 2: Under HIPAA, psychotherapy notes are treated differently from other medical records because:
- They are not considered PHI
- They require specific patient authorization for most disclosures, separate from the general authorization (Correct answer)
- They can be disclosed to law enforcement without any restrictions
- They must be retained for a minimum of 25 years
Correct answer: They require specific patient authorization for most disclosures, separate from the general authorization
Psychotherapy notes held separately from the medical record receive special protection and generally require patient authorization even for disclosures that are otherwise permissible.
Question 3: A 'chain of trust' agreement in health information exchange ensures that:
- Patients consent to all secondary uses of their data
- Each entity in a data-sharing network agrees to protect PHI consistently (Correct answer)
- Only physicians can access shared health information networks
- Data is destroyed after it is no longer needed for treatment
Correct answer: Each entity in a data-sharing network agrees to protect PHI consistently
Chain of trust agreements require all participants in a health information network to maintain equivalent privacy and security protections for PHI.
Question 4: Which action best demonstrates the 'physical safeguard' requirements of the HIPAA Security Rule?
- Using strong passwords on all workstations
- Installing firewall software on the hospital network
- Restricting access to server rooms with key card entry (Correct answer)
- Encrypting emails containing ePHI
Correct answer: Restricting access to server rooms with key card entry
Physical safeguards include facility access controls such as key card entry, locks, and workstation use policies that physically protect electronic PHI.
Question 5: When must a covered entity report a breach affecting 500 or more individuals to HHS and the media?
- Within 30 days of discovery
- Within 60 days of discovery (Correct answer)
- Within 90 days of discovery
- Annually at year-end
Correct answer: Within 60 days of discovery
Breaches affecting 500 or more individuals in a state or jurisdiction require notification to HHS and prominent media outlets within 60 calendar days of discovery.
Question 6: Under HIPAA, which of the following is a permissible disclosure of PHI without patient authorization?
- Sharing records with the patient's employer upon employer request
- Disclosing records to a coroner or medical examiner (Correct answer)
- Providing records to a marketing company to target health products
- Sending records to a family member who requests them verbally
Correct answer: Disclosing records to a coroner or medical examiner
HIPAA permits disclosures to coroners and medical examiners for purposes such as identifying a deceased person or determining cause of death.
Question 7: The HIPAA 'Safe Harbor' de-identification method requires removal of how many specific identifiers?
- 12
- 16
- 18 (Correct answer)
- 21
Correct answer: 18
HIPAA's Safe Harbor method requires removal of 18 specific identifiers (such as names, geographic data, dates, phone numbers, SSNs) to consider data de-identified.
What is a 'designated record set' under HIPAA?