Treatment Protocols & Procedures Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Treatment Protocols & Procedures flashcards as text
A covered entity uses a telemedicine platform for treatment. Under HIPAA, the telemedicine vendor must be treated as:
Answer: A Business Associate requiring a signed BAA
A telemedicine vendor that accesses, transmits, or stores PHI on behalf of a covered entity qualifies as a Business Associate and must sign a BAA.
Which of the following actions by a provider BEST demonstrates compliance with HIPAA's treatment disclosure rules?
Answer: Forwarding only the pertinent treatment summary needed by a consulting physician
Sending only the pertinent treatment summary to a consulting physician aligns with both the treatment disclosure permission and the minimum necessary standard.
A mental health provider wishes to share a patient's psychiatric treatment notes with the patient's primary care physician. Under HIPAA, psychotherapy notes:
Answer: Require a separate, specific authorization even for treatment by another provider
Psychotherapy notes receive heightened protection under HIPAA and generally require a separate specific authorization even for treatment disclosures to other providers.
A clinic's treatment protocol requires staff to verify patient identity before administering medication. From a HIPAA perspective, this practice:
Answer: Supports PHI accuracy and patient safety, consistent with HIPAA
Identity verification before treatment protects PHI accuracy and patient safety, which is consistent with HIPAA's intent to safeguard health information quality.
Under HIPAA, which of the following describes when a healthcare provider may share PHI for treatment WITHOUT patient authorization?
Answer: When sharing with another provider involved in the patient's care
HIPAA's Privacy Rule allows providers to share PHI for treatment purposes with other providers involved in the patient's care without obtaining patient authorization.
A hospital creates care protocols that involve sending PHI to a research university analyzing treatment outcomes. This arrangement typically requires:
Answer: A Business Associate Agreement and possibly IRB approval or a data use agreement
Sharing PHI with a research institution typically requires a BAA and may also require IRB approval or a data use agreement depending on the nature of the research.
A provider's treatment protocol inadvertently includes PHI of a patient who was not the intended recipient of a fax. Under HIPAA, this is considered:
Answer: An impermissible disclosure that may require breach analysis
A misdirected fax containing PHI is an impermissible disclosure that must be assessed under the breach notification rule.