RHIT Healthcare Compliance and Regulations 5 — Questions and Answers
Question 1: A facility discovers that an employee accessed the electronic health records of a celebrity patient out of curiosity, without a treatment relationship. Under HIPAA, this is classified as:
- An impermissible use resulting in a presumed breach, unless a low probability of compromise analysis clears it (Correct answer)
- An authorized incidental disclosure
- An excepted treatment disclosure
- A permissible workforce training activity
Correct answer: An impermissible use resulting in a presumed breach, unless a low probability of compromise analysis clears it
Unauthorized snooping by a workforce member is an impermissible use that is presumed to be a breach unless a four-factor risk assessment demonstrates low probability of compromise.
Question 2: The Genetic Information Nondiscrimination Act (GINA) Title II prohibits employers from using genetic information in employment decisions. In the context of HIPAA, genetic information is classified as:
- Excluded from PHI protections
- A type of PHI that is generally prohibited from use for underwriting purposes by health plans (Correct answer)
- Freely disclosable with patient authorization
- Protected only if it relates to a current diagnosis
Correct answer: A type of PHI that is generally prohibited from use for underwriting purposes by health plans
HIPAA, as amended by GINA, prohibits health plans from using genetic information for underwriting and treats it as a type of PHI.
Question 3: A release of information specialist receives a request for records from a patient's attorney. Which document is essential before releasing records in a non-litigation context?
- A court order
- A valid written HIPAA-compliant authorization signed by the patient (Correct answer)
- A subpoena signed by the attorney
- Verbal confirmation from the treating physician
Correct answer: A valid written HIPAA-compliant authorization signed by the patient
Without a court order or subpoena, a valid patient authorization is required to release records to an attorney.
Question 4: Which type of Medicare audit uses sophisticated data analysis to identify providers with unusual billing patterns before conducting a review?
- Comprehensive Error Rate Testing (CERT)
- Recovery Audit Contractor (RAC) automated review
- Zone Program Integrity Contractor (ZPIC) data analysis (Correct answer)
- Targeted Probe and Educate (TPE)
Correct answer: Zone Program Integrity Contractor (ZPIC) data analysis
ZPICs (now unified under UPICs) use data analysis and statistical modeling to detect fraud patterns before initiating field investigations.
Question 5: A state law grants patients broader access rights to their mental health records than HIPAA provides. Under the principle of federal preemption, which standard applies?
- HIPAA always preempts state law
- The state law applies because it provides greater patient protections (Correct answer)
- The federal standard applies only for Medicare patients
- Neither law applies; the provider uses professional judgment
Correct answer: The state law applies because it provides greater patient protections
HIPAA establishes a floor, not a ceiling; state laws providing greater privacy protections or patient rights are not preempted and must be followed.
Question 6: Under the Health Care Quality Improvement Act (HCQIA), the National Practitioner Data Bank (NPDB) must be queried by hospitals when:
- Any physician applies for medical staff privileges and at least every two years thereafter (Correct answer)
- Only when a physician is suspected of malpractice
- Only at initial credentialing, not at re-credentialing
- When a physician is reported to the state medical board
Correct answer: Any physician applies for medical staff privileges and at least every two years thereafter
HCQIA requires hospitals to query the NPDB when practitioners apply for clinical privileges and at least every two years for ongoing credentialing.
Question 7: Which of the following BEST describes the purpose of a Corporate Integrity Agreement (CIA) negotiated between a healthcare provider and the OIG?
- It grants immunity from future False Claims Act prosecutions
- It establishes compliance obligations a provider must fulfill as part of a settlement to avoid exclusion from federal programs (Correct answer)
- It replaces the provider's internal compliance program entirely
- It is a voluntary self-disclosure mechanism with no enforcement consequences
Correct answer: It establishes compliance obligations a provider must fulfill as part of a settlement to avoid exclusion from federal programs
A CIA is a settlement tool requiring a provider to implement specific compliance measures in exchange for remaining eligible to participate in Medicare and Medicaid.
A facility discovers that an employee accessed the electronic health records of a celebrity patient out of curiosity, without a treatment relationship.
Under HIPAA, this is classified as: