RHIT - Registered Health Information Technician Healthcare Compliance and Regulations Questions and Answers โ Questions and Answers
Question 1: A hospital discovers that an unencrypted laptop containing the protected health information (PHI) of 600 patients was stolen. According to the HITECH Act Breach Notification Rule, which of the following actions is required?
- Report the breach to the Secretary of HHS on an annual basis with other small breaches.
- Notify only the affected individuals within 60 days of discovering the breach.
- Notify affected individuals, the Secretary of HHS, and prominent media outlets within 60 days. (Correct answer)
- Wait for a law enforcement investigation to conclude before notifying any parties.
Correct answer: Notify affected individuals, the Secretary of HHS, and prominent media outlets within 60 days.
The HITECH Act Breach Notification Rule requires covered entities to notify affected individuals, the Secretary of HHS, and prominent media outlets serving the relevant state or jurisdiction without unreasonable delay, and in no case later than 60 calendar days, following the discovery of a breach affecting more than 500 individuals.
Question 2: Which federal law specifically prohibits a physician from referring Medicare patients for designated health services to an entity where the physician or an immediate family member has a financial interest?
- The Health Insurance Portability and Accountability Act (HIPAA)
- The False Claims Act
- The Anti-Kickback Statute
- The Stark Law (Physician Self-Referral Law) (Correct answer)
Correct answer: The Stark Law (Physician Self-Referral Law)
The Stark Law is a strict liability statute that specifically prohibits physicians from making referrals for certain "designated health services" (DHS) payable by Medicare to an entity with which they or an immediate family member have a financial relationship, unless a specific exception applies.
Question 3: A healthcare organization is conducting a risk analysis as part of its HIPAA Security Rule compliance. Which of the following is an example of a required technical safeguard?
- Implementing audit controls to record and examine activity in information systems containing ePHI. (Correct answer)
- Developing a security awareness and training program for the workforce.
- Positioning computer monitors to prevent viewing by unauthorized persons.
- Establishing a data backup and disaster recovery plan.
Correct answer: Implementing audit controls to record and examine activity in information systems containing ePHI.
Technical safeguards under the HIPAA Security Rule involve the technology and the policies for its use to protect electronic PHI (ePHI). Audit controls, which are mechanisms to record and examine system activity, are a required technical safeguard. Security training and contingency plans are administrative safeguards, while monitor positioning is a physical safeguard.
Question 4: An attorney presents a subpoena duces tecum for a patient's medical records for a civil lawsuit. The subpoena is not accompanied by a court order or patient authorization. What is the most appropriate initial action for the HIM professional?
- Release the records immediately to comply with the legal document.
- Do not release the records until 'satisfactory assurances' are met or a court order is provided. (Correct answer)
- Contact the patient by phone to obtain verbal consent for the release.
- Release a limited summary of the record under the 'minimum necessary' principle.
Correct answer: Do not release the records until 'satisfactory assurances' are met or a court order is provided.
Under HIPAA, a subpoena that is not signed by a judge (i.e., not a court order) is insufficient on its own to compel the release of PHI. The covered entity must first receive 'satisfactory assurances' from the party seeking the information that reasonable efforts were made to notify the patient of the request or that a qualified protective order has been secured. Without these assurances, a court order, or a valid patient authorization, the records cannot be released.
Question 5: In the absence of a more stringent state law, the CMS Conditions of Participation require hospitals to retain medical records for a minimum of how many years?
- 3 years
- 10 years
- 5 years (Correct answer)
- 7 years
Correct answer: 5 years
The Centers for Medicare & Medicaid Services (CMS) Conditions of Participation for Hospitals (42 CFR ยง482.24) mandate that medical records must be retained in their original or a legally reproduced form for at least 5 years. State laws may require a longer period, in which case the stricter rule must be followed.
Question 6: A hospital contracts with an outside company to handle its billing and claims processing. To comply with HIPAA, what must be in place between the hospital and the billing company?
- A verbal agreement confirmed by the CEO of both organizations.
- A signed consent form from every patient whose data will be processed.
- A memorandum of understanding filed with the Office for Civil Rights.
- A Business Associate Agreement (BAA). (Correct answer)
Correct answer: A Business Associate Agreement (BAA).
When a covered entity (like a hospital) uses a third-party vendor (a business associate) to perform functions involving the use or disclosure of PHI, HIPAA requires a written contract called a Business Associate Agreement (BAA). This agreement ensures the business associate will appropriately safeguard the PHI and comply with HIPAA rules.
A hospital discovers that an unencrypted laptop containing the protected health information (PHI) of 600 patients was stolen.
According to the HITECH Act Breach Notification Rule, which of the following actions is required?