HIPAA The HIPAA Privacy Rule 2 — Questions and Answers
Question 1: Which of the following is NOT considered Protected Health Information (PHI) under the HIPAA Privacy Rule?
- A patient's diagnosis recorded in their medical chart
- De-identified health information with all 18 identifiers removed (Correct answer)
- A patient's prescription history linked to their name
- Health information transmitted electronically to an insurer
Correct answer: De-identified health information with all 18 identifiers removed
Once all 18 identifiers are removed using an approved de-identification method, the information is no longer PHI and is not subject to HIPAA Privacy Rule protections.
Question 2: Under the HIPAA Privacy Rule, what is the 'minimum necessary' standard?
- Covered entities must use the least expensive method to protect PHI
- Covered entities must limit PHI use and disclosure to the minimum needed to accomplish the intended purpose (Correct answer)
- Patients must receive the minimum amount of information about their own health records
- Business associates must store only the minimum amount of PHI required by law
Correct answer: Covered entities must limit PHI use and disclosure to the minimum needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI access and disclosure to only what is needed for the intended purpose.
Question 3: A covered entity may disclose PHI without patient authorization for which of the following purposes?
- Marketing a new drug treatment to the patient
- Selling PHI to a data analytics company
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Sharing PHI with an employer for workplace wellness incentives
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosure of PHI without authorization when required by law, such as mandatory reporting of gunshot wounds to law enforcement.
Question 4: How long must a covered entity retain its HIPAA Privacy Rule policies and documentation?
- 3 years from the date of creation or last effective date
- 6 years from the date of creation or last effective date (Correct answer)
- 10 years from the date of creation or last effective date
- Indefinitely, with no expiration
Correct answer: 6 years from the date of creation or last effective date
The HIPAA Privacy Rule requires covered entities to retain policies, procedures, and documentation for 6 years from the date of creation or the date when last in effect.
Question 5: Which individual within a covered entity is specifically required by the HIPAA Privacy Rule?
- Chief Information Security Officer (CISO)
- Privacy Officer (Correct answer)
- Compliance Attorney
- HIPAA Auditor
Correct answer: Privacy Officer
The HIPAA Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Question 6: Under what circumstance may a covered entity deny a patient's request to access their own PHI?
- The patient owes an outstanding balance for services
- A licensed healthcare professional determines access is likely to cause substantial harm to the patient (Correct answer)
- The records are more than 5 years old
- The patient requests records in electronic format
Correct answer: A licensed healthcare professional determines access is likely to cause substantial harm to the patient
A covered entity may deny access if a licensed healthcare professional believes the information could endanger the life or safety of the patient or another person.
Question 7: What must a covered entity include in its Notice of Privacy Practices (NPP)?
- The names of all employees who have accessed patient records
- A description of the types of uses and disclosures the covered entity may make of PHI (Correct answer)
- A complete list of all business associates
- The specific fees charged for releasing medical records
Correct answer: A description of the types of uses and disclosures the covered entity may make of PHI
The NPP must describe how the covered entity may use and disclose PHI, patient rights, and the covered entity's legal duties regarding PHI.
Which of the following is NOT considered Protected Health Information (PHI) under the HIPAA Privacy Rule?