← All NCMA Flashcard Decks

HIPAA and Patient Privacy Rights Flashcards

6 cards from real NCMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA and Patient Privacy Rights flashcards as text
  1. Under HIPAA, what does 'PHI' stand for, and what does it include?

    Answer: Protected Health Information — individually identifiable health information held by covered entities

    PHI (Protected Health Information) is individually identifiable health information created, received, or maintained by a covered entity in any form (electronic, paper, verbal) that relates to past, present, or future physical/mental health conditions, healthcare provided, or payment for care.

  2. Which of the following represents a HIPAA-permitted disclosure of PHI WITHOUT the patient's written authorization?

    Answer: Disclosing immunization records to a patient's school for enrollment

    HIPAA permits disclosure of immunization records to schools without patient authorization when state law requires such proof. This falls under the 'required by law' exception. The other options require explicit patient authorization.

  3. What is the HIPAA 'Minimum Necessary' standard, and how does it apply in daily practice?

    Answer: Only the minimum amount of PHI necessary to accomplish the intended purpose should be used, disclosed, or requested

    The Minimum Necessary standard requires covered entities to make reasonable efforts to limit use and disclosure of PHI to the minimum amount needed to accomplish the intended purpose. Staff should only access what they need for their specific job function.

  4. A patient calls the medical office requesting a copy of their own medical records. Under HIPAA, what are the patient's rights?

    Answer: Patients have the right to access and obtain copies of their PHI, typically within 30 days, with a possible 30-day extension

    HIPAA's Privacy Rule grants patients the right to access and obtain copies of their PHI maintained in a designated record set. Covered entities must respond within 30 days, with one 30-day extension allowed with written notice.

  5. What is the correct action when a medical assistant accidentally views a celebrity patient's medical record while searching for another patient with a similar name?

    Answer: Immediately close the record, report the accidental access to the supervisor, and document the incident per facility policy

    Even accidental access to the wrong patient's PHI is a privacy incident. The correct response is to close the record immediately, report to the supervisor/privacy officer, and document the incident per facility policy — which is required for HIPAA breach assessment.

  6. A patient's family member calls the medical office asking for information about the patient's recent laboratory results. Under HIPAA, what should the medical assistant do?

    Answer: Verify whether the patient has authorized release to this specific family member or if they are listed as a personal representative before disclosing any PHI

    HIPAA requires patient authorization for disclosure to third parties including family members, unless the patient is present and has verbally agreed, the patient has previously authorized disclosure to this person, or the caller is a legally designated personal representative.