CPCA CPCA Medical Records and HIPAA Privacy 1 — Questions and Answers
Question 1: Under HIPAA, what is the term for health information that can identify an individual?
- Protected Health Information (PHI) (Correct answer)
- Electronic Data Interchange (EDI)
- Covered Entity Data
- Minimum Necessary Information
Correct answer: Protected Health Information (PHI)
PHI is individually identifiable health information created, received, or maintained by a covered entity that is protected under HIPAA.
Question 2: Which of the following is NOT considered a HIPAA-covered entity?
- Health insurance plan
- Dermatology practice that bills electronically
- Life insurance company (Correct answer)
- Healthcare clearinghouse
Correct answer: Life insurance company
Life insurance companies are not HIPAA covered entities because they do not conduct covered healthcare transactions.
Question 3: How long must a covered entity retain HIPAA-related policies and procedures?
- 3 years
- 5 years
- 6 years (Correct answer)
- 10 years
Correct answer: 6 years
HIPAA requires covered entities to retain documentation of policies, procedures, and actions for at least 6 years from creation or last effective date.
Question 4: What is the 'minimum necessary' standard under HIPAA?
- The smallest claim amount that can be submitted
- Using only the minimum PHI needed to accomplish the intended purpose (Correct answer)
- The fewest staff allowed access to patient records
- The minimum documentation required for billing
Correct answer: Using only the minimum PHI needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to limit PHI use and disclosure to only what is needed for a specific purpose.
Question 5: A patient requests access to their own medical record. Under HIPAA, how many days does the covered entity generally have to respond?
- 10 days
- 30 days (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days
HIPAA requires covered entities to act on a patient's record access request within 30 days, with a possible 30-day extension.
Question 6: Which office is responsible for enforcing HIPAA Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) (Correct answer)
- Office of Inspector General (OIG)
- State Medical Board
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is the federal agency responsible for investigating HIPAA complaints and enforcing compliance.
Under HIPAA, what is the term for health information that can identify an individual?