HIPAA Lesson 5 Flashcards
A disclosure of PHI to the Office of Civil Rights for enforcement purposes is what kind of disclosure? o Permitted disclosure. o Internal disclosure. o Routine disclosure. o Required disclosure.
Required Disclosure
If a passerby overhears two doctors conferring about a patient, what kind of PHI disclosure would this be? o Incidental disclosure. o Required disclosure. o Nonroutine disclosure. o Routine disclosure.
Incidental Disclosure
Under what circumstances would the conditions of minimum necessary apply?
o Disclosure of PHI to the individual who is the subject of the information.
o Disclosure of PHI to a health care provider for treatment purposes.
o Disclosure of PHI within the workforce.
o Disclosure of PHI as a result of a signed authorization.
Disclosure of PHI within the workforce.
If a researcher with documented approval from an institutional review board requests PHI, which Privacy Rule provision would allow disclosure? o Reasonable effort. o Verification. o Reasonable reliance. o Minimum necessary.
Reasonable reliance.
When an individual is legally unable to exercise his or her own rights, who is authorized to make that person's health care decisions? o A physician. o A personal representative. o An executor. o The OCR.
A personal representative.
Does the Privacy Rule allow me to pick up a prescription for a friend? What if my friend wants me to go to the doctor with her?
The Privacy Rule allows both of these. If you take a friend or a family member with you to the doctor, the doctor can reasonably assume that he or she can talk to you about your healthcare in front of your friend. If your friend calls back later and asks the doctor a question about your appointment or your condition on your behalf, the doctor can share information with your friend because she was present at your appointment. However, the doctor wouldn’t be able to discuss other health matters or other conditions with your friend.
What two entities does the Privacy Rule require disclosure of PHI?
- The Patient
2. OCR
What is DRS?
Designated Record Set
What information is in a DRS?
- Medical and billing records
- Enrollment, payment, claims adjudication
- Health plan or healthcare provider records used to make healthcare decisions.
What information is not part of the DRS and does not have to be released to anyone for any reason?
Psychotherapy Notes
The OCR is granted rights to PHI to:
- Investigate Complaints
- Determine Compliance Status
- For Enforcement
The Privacy Rule permits some disclosures without ______ under certain circumstances
Authorization
Name two conditions in which disclosures are permitted without authorization.
- When state and other law requires the disclosure
2. When the disclosure meets certain conditions specified by the Privacy Rule.
List the permitted disclosures:
- TPO
- Limited marketing & fund-raising
- When required by law
- Public health activities
- Health oversight activities
- Victims of abuse, neglect, or domestic violence
- Court order or subpoena
- Limited law enforcement purposes
- Information about decedents to a coroner, medical examiner, or funeral director
- Organ, eye, or tissue donation from a cadaver
- Research, if approved by an institutional review board (an ethics committee that monitors experiments on people)
- Averting serious threat to health or safety
- Specialized government functions related to military, veterans, armed forces, correctional institutions, and custodial situations
- Government programs providing public benefits
- Workers’ compensation
_______ is always subject to minimum necessary requirements.
Disclosure
What type of disclosure requires a CE to first evaluate all workforce members’ need to access PHI and establish mechanisms to reasonably limit access to the specific PHI necessary for the job.
Internal Disclosures