RHIT Release of Information and Privacy Practices 1 — Questions and Answers
Question 1: Which federal regulation primarily governs the release of patient health information by covered entities?
- The False Claims Act
- The HITECH Act
- The HIPAA Privacy Rule (Correct answer)
- The Stark Law
Correct answer: The HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards for the protection of individually identifiable health information and governs when and how it may be disclosed.
Question 2: A patient requests access to their own medical records. Under HIPAA, the covered entity must provide access within:
- 7 calendar days
- 30 calendar days, with one possible 30-day extension (Correct answer)
- 60 calendar days
- 10 business days
Correct answer: 30 calendar days, with one possible 30-day extension
HIPAA requires covered entities to act on a patient's request for access to their PHI within 30 days, with one permitted 30-day extension if the entity notifies the individual.
Question 3: Which of the following is NOT required on a valid HIPAA-compliant authorization form for release of information?
- A description of the information to be used or disclosed
- An expiration date or event
- The patient's insurance policy number (Correct answer)
- The purpose of the disclosure
Correct answer: The patient's insurance policy number
HIPAA authorization forms require specific elements including description of information, purpose, expiration, and patient signature, but not the patient's insurance policy number.
Question 4: Under HIPAA, which of the following disclosures does NOT require patient authorization?
- Disclosure to the patient's employer
- Disclosure for treatment, payment, and healthcare operations (TPO) (Correct answer)
- Disclosure to a marketing company
- Disclosure to the patient's attorney
Correct answer: Disclosure for treatment, payment, and healthcare operations (TPO)
HIPAA permits covered entities to use and disclose PHI for treatment, payment, and healthcare operations without patient authorization.
Question 5: What is the 'minimum necessary' standard under HIPAA?
- Covered entities must disclose the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Covered entities must always share complete records with requesting parties
- Patients may only request a minimum of five pages of records
- Records must be redacted to one page before release
Correct answer: Covered entities must disclose the minimum amount of PHI needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI disclosure to the minimum needed for the intended purpose.
Question 6: A hospital receives a subpoena for patient records without a court order. What is the appropriate response?
- Release records immediately without review
- Review the subpoena and follow applicable state law and HIPAA requirements before releasing (Correct answer)
- Deny all subpoenas without exception
- Release only billing records, not clinical records
Correct answer: Review the subpoena and follow applicable state law and HIPAA requirements before releasing
A subpoena alone does not automatically override HIPAA; the facility must review applicable state law and HIPAA requirements to determine the appropriate response.
Which federal regulation primarily governs the release of patient health information by covered entities?