Mental Health and Substance Abuse Privacy Rules Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Mental Health and Substance Abuse Privacy Rules flashcards as text
A behavioral health organization experiences a breach affecting 800 patients' mental health records. Under HIPAA, notifications must be provided to affected individuals within:
Answer: 60 days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach.
A patient in a substance abuse program requests an accounting of disclosures of their 42 CFR Part 2 records. What must the program provide?
Answer: A list of all disclosures made without consent during the past 6 years
Under Part 2 and HIPAA, patients are entitled to an accounting of all disclosures made without consent, generally covering the past 6 years.
Under HIPAA, a covered mental health provider may share PHI with a patient's family member WITHOUT authorization when:
Answer: The patient is present and agrees, or the provider determines it is in the best interest of an incapacitated patient
HIPAA permits sharing PHI with family members when the patient is present and agrees, or when the patient is incapacitated and the provider determines sharing is in the patient's best interest.
Which entity type is subject to 42 CFR Part 2 but would NOT automatically be a HIPAA covered entity?
Answer: A federally assisted non-medical substance abuse counseling program that does not transmit health information electronically
A federally assisted SUD counseling program that doesn't bill electronically or transmit health information electronically is subject to Part 2 but may not meet HIPAA's definition of a covered entity.
A researcher wants access to identifiable mental health records from a covered entity without patient authorization. Under HIPAA, this may be allowed if:
Answer: An IRB or Privacy Board waives the authorization requirement and specific conditions are met
HIPAA permits covered entities to disclose identifiable PHI for research without authorization only when an IRB or Privacy Board has waived the authorization requirement and specific regulatory conditions are satisfied.
A covered entity's business associate stores electronic mental health records. The business associate suffers a ransomware attack. Under HIPAA, who has the primary obligation to notify affected patients?
Answer: The covered entity, after being notified by the business associate
The business associate must notify the covered entity of the breach, and then the covered entity bears the primary obligation to notify affected patients under HIPAA's Breach Notification Rule.
Under the Mental Health Parity and Addiction Equity Act (MHPAEA), health plans must ensure that mental health and SUD benefits are provided at parity with medical benefits. This primarily affects HIPAA by:
Answer: Reinforcing that mental health claims data must be protected with the same rigor as other medical PHI
MHPAEA ensures equal coverage for mental health/SUD benefits, and HIPAA's privacy protections apply equally — reinforcing that mental health claims data receives the same PHI protections as other medical information.