HIPAA Patient Rights Under HIPAA 2 — Questions and Answers
Question 1: Under HIPAA, within how many days must a covered entity respond to a patient's request to amend their health information?
- 30 days
- 60 days (Correct answer)
- 90 days
- 120 days
Correct answer: 60 days
Covered entities must act on an amendment request within 60 days, with one possible 30-day extension.
Question 2: A patient requests an accounting of disclosures. Which type of disclosure is generally EXCLUDED from this accounting?
- Disclosures to public health authorities
- Disclosures made for treatment, payment, and operations (Correct answer)
- Disclosures to law enforcement under a court order
- Disclosures required by the Secretary of HHS
Correct answer: Disclosures made for treatment, payment, and operations
Disclosures for treatment, payment, and healthcare operations are excluded from the required accounting of disclosures.
Question 3: A patient who paid out-of-pocket for a service asks their provider NOT to share that information with their health plan. Under HIPAA, the provider must:
- Comply if it is technically feasible (Correct answer)
- Refuse because it complicates billing coordination
- Comply only if the plan is Medicare or Medicaid
- Share anyway because the plan has a right to know
Correct answer: Comply if it is technically feasible
HIPAA requires providers to honor such a restriction request when the patient paid in full out-of-pocket.
Question 4: Which of the following BEST describes a patient's right to request confidential communications?
- The right to keep all PHI completely secret from everyone
- The right to receive communications by alternative means or at an alternative location (Correct answer)
- The right to demand encrypted email for all correspondence
- The right to prohibit providers from contacting them by phone
Correct answer: The right to receive communications by alternative means or at an alternative location
HIPAA's right to confidential communications lets patients request PHI be sent to a different address or via a different method.
Question 5: When can a covered entity DENY a patient's request to restrict disclosure of their PHI?
- When the restriction would make records harder to maintain
- When the disclosure is required for emergency treatment (Correct answer)
- When the patient has not provided a written reason for the request
- Both A and B
Correct answer: When the disclosure is required for emergency treatment
A covered entity may deny a restriction request if the PHI is needed to provide emergency treatment to the patient.
Question 6: A patient submits a written request to access their medical records. The covered entity believes releasing the records could endanger the patient. What may the entity do?
- Deny access and provide no further recourse
- Deny access and allow the patient to have the denial reviewed by a licensed professional (Correct answer)
- Deny access and report the request to law enforcement
- Approve access but redact all clinical notes
Correct answer: Deny access and allow the patient to have the denial reviewed by a licensed professional
An unreviewable denial based on endangerment risk allows the patient to have the denial reviewed by another licensed health care professional.
Question 7: How long must a covered entity retain the written accounting of disclosures it provides to patients?
- 1 year
- 3 years
- 6 years (Correct answer)
- 10 years
Correct answer: 6 years
HIPAA requires covered entities to retain accountings of disclosures for 6 years from the date of creation.
Under HIPAA, within how many days must a covered entity respond to a patient's request to amend their health information?