HIPAA and Patient Privacy Rights Flashcards
6 cards from real NCMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 HIPAA and Patient Privacy Rights flashcards as text
What does the Office for Civil Rights (OCR) have the authority to do under HIPAA?
Answer: Investigate complaints, conduct compliance audits, impose civil monetary penalties, and refer cases for criminal prosecution
The HHS Office for Civil Rights (OCR) is the HIPAA enforcement agency. It investigates complaints, conducts random and targeted compliance audits, imposes civil monetary penalties (up to $1.9 million per violation category per year), and refers egregious cases to the Department of Justice for criminal prosecution.
A patient asks whether they can request that HIPAA-protected information about their mental health treatment be excluded from their health record if they are concerned about discrimination. What is the patient's right?
Answer: Patients may request an amendment to correct inaccurate information, but cannot require deletion of accurately documented mental health records
HIPAA grants patients the right to request amendments to their PHI to correct inaccuracies, but covered entities are not required to delete accurate, lawfully created records. Patients may add a statement of disagreement to their record.
Which of the following social media actions by a medical assistant would constitute a HIPAA violation?
Answer: Posting a photo of a patient's interesting wound with identifying information partially obscured
Posting any patient-identifiable information on social media — including photos where identifying information is 'partially obscured' — constitutes a HIPAA violation. Partial obscuration does not adequately de-identify PHI. All 18 HIPAA identifiers must be removed.
A physician wants to use a patient's PHI for a research study without the patient's authorization. Under HIPAA, when is this permissible?
Answer: When an Institutional Review Board (IRB) or Privacy Board waives the authorization requirement, or when using a limited data set with a data use agreement
HIPAA permits use of PHI for research without patient authorization when an IRB or Privacy Board grants a waiver of authorization (meeting specific criteria) or when using a limited data set (with most identifying information removed) under a data use agreement.
What is the difference between the HIPAA Privacy Rule and the HIPAA Security Rule?
Answer: The Privacy Rule governs the use and disclosure of all forms of PHI; the Security Rule specifically addresses safeguards for electronic PHI (ePHI)
The Privacy Rule establishes standards for the use and disclosure of PHI in all forms (paper, electronic, verbal). The Security Rule specifically addresses the security of electronic PHI (ePHI) and requires administrative, physical, and technical safeguards.
A patient comes to the front desk of a medical office and overhears the receptionist confirming another patient's appointment and mentioning their name. Is this a HIPAA violation?
Answer: Not necessarily — incidental disclosures that occur despite reasonable safeguards being in place are generally not HIPAA violations
HIPAA recognizes 'incidental disclosures' — limited, unavoidable disclosures that occur as a byproduct of reasonable healthcare operations. Overheard appointment details in a properly managed reception area are generally considered incidental and not violations IF reasonable safeguards are implemented.