RHIT Healthcare Compliance and Regulations 2 โ Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, a covered entity must limit PHI disclosures to the amount reasonably necessary to accomplish the intended purpose. Which disclosure is EXEMPT from this standard?
- Disclosures to health plans for payment purposes
- Disclosures required by law (Correct answer)
- Disclosures to business associates
- Disclosures for public health activities
Correct answer: Disclosures required by law
Disclosures required by law are exempt from the Minimum Necessary Standard under 45 CFR ยง164.502(b).
Question 2: A hospital receives a subpoena for a patient's medical records. Under HIPAA, which condition must be met before releasing the records without a patient authorization?
- The subpoena must be signed by a federal judge
- Satisfactory assurance that the patient has been notified or a qualified protective order is in place (Correct answer)
- The records must be de-identified first
- The hospital's privacy officer must personally deliver the records
Correct answer: Satisfactory assurance that the patient has been notified or a qualified protective order is in place
HIPAA requires satisfactory assurances that the patient was notified or a protective order exists before releasing records in response to a subpoena.
Question 3: Which federal law established the HITECH Act's requirements for notifying patients of breaches involving unsecured PHI?
- HIPAA Privacy Rule of 1996
- American Recovery and Reinvestment Act of 2009 (Correct answer)
- Affordable Care Act of 2010
- Medicare Access and CHIP Reauthorization Act of 2015
Correct answer: American Recovery and Reinvestment Act of 2009
The HITECH Act was enacted as part of the American Recovery and Reinvestment Act (ARRA) of 2009 and introduced the Breach Notification Rule.
Question 4: A patient requests an amendment to their medical record, stating that a diagnosis is incorrect. The covered entity may deny the request if:
- The record was created more than 6 years ago
- The provider believes the record is accurate and complete (Correct answer)
- The amendment would require changing more than one document
- The patient has already inspected the record
Correct answer: The provider believes the record is accurate and complete
Under 45 CFR ยง164.526, a covered entity may deny an amendment if it reasonably believes the information is accurate and complete.
Question 5: The Conditions of Participation (CoPs) issued by CMS establish standards that hospitals must meet to receive reimbursement from which programs?
- Only Medicaid
- Only Medicare
- Both Medicare and Medicaid (Correct answer)
- Only commercial insurers participating in the ACA marketplace
Correct answer: Both Medicare and Medicaid
CMS Conditions of Participation apply to facilities seeking reimbursement from both Medicare and Medicaid programs.
Question 6: Under the False Claims Act, what term describes an employee who reports employer fraud against the federal government and is protected from retaliation?
- Whistleblower / Qui tam relator (Correct answer)
- Compliance officer
- Sentinel reporter
- Adverse event reporter
Correct answer: Whistleblower / Qui tam relator
The False Claims Act protects employees who report fraud as whistleblowers (qui tam relators) and may award them a portion of recovered funds.
Question 7: When a covered entity discovers a potential HIPAA breach, the Breach Notification Rule requires that the affected individual be notified within how many days?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
The HIPAA Breach Notification Rule requires individual notification without unreasonable delay and no later than 60 calendar days after discovery.
Under HIPAA's Minimum Necessary Standard, a covered entity must limit PHI disclosures to the amount reasonably necessary to accomplish the intended purpose.
Which disclosure is EXEMPT from this standard?