Clinical Informatics Privacy & Ethics Flashcards
7 cards from real Clinical Informatics Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Clinical Informatics Privacy & Ethics flashcards as text
Under HIPAA, which of the following is considered a 'covered entity'?
Answer: A health plan that pays for medical services
Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically are the three types of covered entities under HIPAA.
A researcher wants to use patient data without obtaining individual authorizations. Which HIPAA Privacy Rule provision allows this under specific conditions?
Answer: Waiver of Authorization by an IRB or Privacy Board
An Institutional Review Board (IRB) or Privacy Board can waive the authorization requirement for research when conditions such as minimal risk to privacy are met.
Which concept in clinical informatics ethics refers to a patient's right to make informed decisions about their own health care without coercion?
Answer: Autonomy
Autonomy is the ethical principle that respects an individual's right to make their own informed decisions regarding their health and treatment.
A hospital's EHR system automatically logs all user access to patient records. What is the primary purpose of this audit log?
Answer: To detect and investigate unauthorized access to PHI
Audit logs are a required HIPAA Security Rule safeguard used primarily to detect unauthorized or inappropriate access to protected health information.
Which of the following best describes the ethical principle of 'justice' in the context of health information technology?
Answer: Distributing the benefits and burdens of HIT equitably across populations
Justice in health informatics refers to the fair and equitable distribution of HIT benefits and the avoidance of disparities, such as the digital divide.
A clinician accesses the EHR record of a celebrity patient out of curiosity without clinical need. This is BEST described as a violation of which HIPAA rule?
Answer: Privacy Rule — minimum necessary standard
Accessing PHI without a legitimate need violates the HIPAA Privacy Rule's minimum necessary standard, which limits access to only what is needed for a specific purpose.
Which of the following is an example of a 'secondary use' of health data that raises ethical concerns?
Answer: An insurance company purchasing de-identified data to set premium rates
Secondary use refers to using health data for purposes beyond direct patient care, such as commercial activities, which can raise ethical concerns about consent and exploitation.