All questions
Question 1
An unencrypted clinic laptop containing the electronic health records of over 500 patients is stolen. An investigation concludes there is a significant risk that the PHI has been compromised. According to the HITECH Act's Breach Notification Rule, which of the following is the most comprehensive required response?
- Notify all affected individuals via first-class mail and offer complimentary credit monitoring for one year.
- Report the theft to local law enforcement and wait for their official report before notifying any patients or agencies.
- Notify the affected individuals, the Secretary of Health and Human Services, and prominent media outlets serving the area. (correct answer)
- Submit a report of the breach to the Secretary of HHS as part of the clinic's annual compliance documentation.
Explanation: The correct answer is C. The HITECH Act requires notification for breaches of unsecured PHI. For breaches affecting more than 500 individuals, the covered entity must notify the affected individuals without unreasonable delay, notify the Secretary of HHS without unreasonable delay (and within 60 days), and notify prominent media outlets in the state or jurisdiction. A is incomplete as it omits the required notifications to HHS and the media. B is incorrect because notification cannot be unreasonably delayed pending a law enforcement investigation unless specifically requested by law enforcement. D is incorrect because breaches of this magnitude require immediate notification, not just inclusion in an annual report.
Question 2
A patient who has full access to their online patient portal requests a copy of their entire medical record on a USB drive. The clinic manager instructs the medical assistant to deny the request and offer paper copies instead, citing security concerns. Which of the following is the most appropriate response by the medical assistant?
- Follow the manager's instructions and inform the patient that only paper copies can be provided to protect their data.
- Advise the manager that under HIPAA, the patient has the right to receive their records in the requested electronic format if it is readily producible. (correct answer)
- Tell the patient they must submit a formal request to the clinic's legal department for any electronic records.
- Provide the patient with the USB drive but require them to sign a waiver releasing the clinic from all liability for potential data breaches.
Explanation: The correct answer is B. The HIPAA Privacy Rule and HITECH Act affirm a patient's right to access their PHI in the form and format they request, including electronic formats, as long as the covered entity can readily produce it in that format. A clinic's policy cannot override this federal right. A is incorrect as it follows an incorrect instruction. C is incorrect as it creates an unnecessary barrier not required by law. D is incorrect because while a waiver might be used, the primary obligation is to fulfill the patient's right to access, not to shift liability for it.
Question 3
A medical assistant is organizing the medication storage area, which includes a stock bottle of alprazolam (Xanax), a Schedule IV controlled substance. To comply with the Controlled Substances Act, what is the minimum security requirement for storing this medication?
- It must be stored in a substantially constructed, securely locked cabinet or safe. (correct answer)
- It must be stored in a double-locked safe accessible only by the prescribing provider.
- It can be stored on a standard shelf as long as it is placed behind other, non-controlled medications.
- It must be stored under constant video surveillance and logged in a perpetual inventory system.
Explanation: The correct answer is A. Federal regulations (21 CFR §1301.75) require that Schedule III, IV, and V controlled substances be stored in a securely locked, substantially constructed cabinet. An alternative is to disperse them throughout the stock of non-controlled substances. However, a locked cabinet is the primary and most direct method that meets the minimum requirement. B describes a higher level of security often reserved for Schedule II drugs. C is an incomplete description of the dispersal method and is less secure than a locked cabinet. D describes best practices but not the legal minimum requirement.
Question 4
A medical practice that maintains a small inventory of controlled substances for in-office administration is preparing for a potential DEA inspection. According to the Controlled Substances Act, what is the minimum duration for which all inventory and dispensing records must be maintained and be readily retrievable?
- One year from the date of the transaction.
- Two years from the date of the transaction. (correct answer)
- Five years from the date of the transaction.
- Seven years, consistent with medical record retention policies.
Explanation: The correct answer is B. The federal Controlled Substances Act (CSA) requires that every registrant, including a practitioner who dispenses, must maintain all records (inventory, dispensing, receiving) for a period of at least two years from the date of such record. These records must be kept separate from all other records and be readily available for inspection by the DEA. The other timeframes are incorrect for CSA requirements.
Question 5
A patient pays for a lab test entirely with cash and explicitly requests that the clinic not share the results or the record of the test with their health insurance company. According to the HITECH Act, how must the clinic respond?
- The clinic must agree to the request, as patients have the right to restrict disclosures to a health plan for services paid for out-of-pocket in full. (correct answer)
- The clinic can agree to the request but may charge an administrative fee for the service of suppressing the insurance claim.
- The clinic must inform the patient that all services are reported to health plans for quality metrics, regardless of payment source.
- The clinic should document the request but is not obligated to comply if its billing system automatically submits all claims.
Explanation: The correct answer is A. The HITECH Act granted patients a new right under HIPAA to restrict disclosures of PHI to a health plan if the disclosure is for payment or health care operations and the patient has paid for the service or item out-of-pocket in full. The covered entity is required to comply with such a request. B is incorrect as no fee can be charged for exercising this right. C and D are incorrect as the clinic must have a process to accommodate this legal requirement.
Question 6
A pharmaceutical researcher requests a list of all patients in a clinic with a specific diagnosis. To protect patient privacy, the researcher asks for a list containing only the patients' five-digit ZIP codes and dates of service. Is this list considered de-identified according to HIPAA standards?
- Yes, because all names, addresses, and medical record numbers have been removed.
- No, because ZIP codes and dates are two of the 18 specific identifiers that must be removed for data to be de-identified. (correct answer)
- Yes, but only if the researcher signs a Business Associate Agreement with the clinic before receiving the list.
- No, because any information originating from a patient record, regardless of content, is always considered protected health information.
Explanation: The correct answer is B. HIPAA's Safe Harbor de-identification method requires the removal of all 18 specified identifiers. This list includes names, geographic subdivisions smaller than a state (including ZIP codes), and all elements of dates (except year) related to an individual. Since this list contains ZIP codes and full dates of service, it is not de-identified and is still considered PHI. A is incorrect because removing some identifiers is not sufficient. C is incorrect because a BAA is for sharing PHI, it does not de-identify it. D is incorrect because information can be properly de-identified and is then no longer PHI.
Question 7
A clinic is implementing a new patient portal to comply with the HITECH Act's 'Meaningful Use' program (now known as Promoting Interoperability). Which of the following activities performed by a medical assistant would most directly support a core objective of this program?
- Ensuring all office computers have up-to-date antivirus software installed.
- Conducting a security risk analysis to identify potential data breach vulnerabilities.
- Shredding all paper documents that contain protected health information.
- Assisting patients with registering for the portal and showing them how to access their lab results. (correct answer)
Explanation: The correct answer is B. A key objective of the Meaningful Use/Promoting Interoperability program is to improve patient engagement. Providing patients with timely electronic access to their health information, such as lab results, through a patient portal is a specific measure within this objective. A and D are important activities related to the HIPAA Security Rule but are not core objectives of Meaningful Use itself. C relates to the proper disposal of paper PHI, which is also a HIPAA requirement but not central to the Meaningful Use program's goals.
Question 8
A dermatology clinic wants to email patients about a new line of cosmetic skincare products available for purchase at the front desk. Under HIPAA, what is required before sending these promotional emails?
- No special requirement is needed as this is considered patient education about available services.
- Authorization is only required if an external marketing company is being paid to send the emails on the clinic's behalf.
- The email is allowed as long as it includes a clear and easy way for the patient to opt out of future mailings.
- The clinic must obtain specific, prior written authorization from each patient before sending the emails. (correct answer)
Explanation: The correct answer is B. This type of communication is considered 'marketing' under HIPAA because it promotes a product or service from which the clinic profits. HIPAA requires a covered entity to obtain an individual's written authorization before using or disclosing their PHI for marketing purposes. A is incorrect because it is not treatment or health care operations communication. C is incorrect; an opt-out is the standard for fundraising communications, not marketing, which requires an explicit opt-in (authorization). D is incorrect because the rule applies whether the clinic markets directly or through a third party.
Question 9
During check-in, a new patient is given the clinic's Notice of Privacy Practices (NPP). The patient signs the acknowledgment form without reading the document. Later, the patient claims they were not properly informed of their rights. Which of the following demonstrates the clinic fulfilled its primary legal duty regarding the NPP?
- The clinic can prove the patient was provided a copy and made a good faith effort to obtain a signed acknowledgment. (correct answer)
- The clinic is only responsible for posting the NPP in the waiting room, not for providing individual copies.
- The clinic's duty is met only if the medical assistant verbally reviewed the entire NPP with the patient.
- The clinic is not liable because the patient's signature on the form legally proves they read and understood the notice.
Explanation: The correct answer is A. Under HIPAA, a covered entity must provide the NPP to new patients and make a 'good faith effort' to obtain a written acknowledgment of receipt. The law does not require the clinic to force the patient to read it or to prove they understood it. The signed acknowledgment (or documentation of the refusal to sign) is the evidence that the clinic fulfilled its duty. B is incorrect as individual copies must be provided. C is incorrect as a verbal review is not required. D is an overstatement; the signature acknowledges receipt, not necessarily understanding.
Question 10
A medical assistant at a cardiology practice is asked to send records to a patient's new primary care provider. The patient's file contains extensive cardiology notes as well as unrelated, sensitive genetic testing results. To comply with the HIPAA Minimum Necessary Standard, what information should the MA send?
- The entire medical record to ensure the new provider has a complete picture of the patient's health.
- Only the records pertaining to the patient's cardiac condition and treatments relevant to primary care. (correct answer)
- A summary of the medical record, omitting any information that seems overly sensitive or complex.
- The entire record, but with the genetic testing results redacted unless the patient gives specific verbal consent.
Explanation: The correct answer is B. The HIPAA Minimum Necessary Standard requires that covered entities take reasonable steps to limit the use or disclosure of PHI to the minimum necessary to accomplish the intended purpose. For treatment purposes, while the rule is more lenient, best practice and the principle of the rule dictate sending only what is relevant. Sending the unrelated genetic testing results is not necessary for the PCP to take over care. A violates the standard by sending unnecessary information. C is too vague and subjective. D is better, but the principle is to send only what's needed, not to send everything and redact certain parts.
Question 11
A medical assistant working at a check-out desk needs to briefly step away to retrieve a document from the printer across the room. A patient's electronic health record is open on the computer screen. Which of the following actions is the best way to comply with the HIPAA Security Rule?
- Quickly turn the monitor so it faces the wall, away from public view.
- Ask a nearby colleague to watch the computer until they return.
- Activate a password-protected screen lock before leaving the workstation. (correct answer)
- Minimize the patient's chart but leave the session active for efficiency.
Explanation: The correct answer is C. The HIPAA Security Rule requires covered entities to implement technical safeguards to protect electronic PHI. Locking a computer with a password before stepping away is a critical administrative and technical safeguard that prevents unauthorized access to the information. A is a physical safeguard but is insufficient, as someone could still walk up and use the unlocked computer. B improperly delegates security responsibility. D leaves the system vulnerable as minimizing a window does not secure the session.
Question 12
A patient informs the medical assistant that they were recently denied a new health insurance policy specifically because they have a history of heart disease. The MA should recognize that this action by the insurance company is a likely violation of which major provision of the Affordable Care Act (ACA)?
- The provision establishing health insurance marketplaces.
- The provision allowing young adults to remain on a parent's plan until age 26.
- The provision requiring plans to cover essential health benefits.
- The provision prohibiting denial of coverage due to pre-existing conditions. (correct answer)
Explanation: The correct answer is B. A cornerstone of the Affordable Care Act (ACA) is the protection for patients with pre-existing conditions. The law prohibits health insurance companies from refusing to cover a patient or charging them more simply because they have a pre-existing health condition. The other options are all valid provisions of the ACA but do not directly address the patient's specific situation of being denied coverage based on their health history.
Question 13
A medical assistant is calling a patient's name in a busy waiting room and states, 'John Smith, Cardiology.' Another patient in the waiting room overhears this information. Which of the following accurately describes the legal implications of this situation under HIPAA?
- This is a direct violation of the HIPAA Privacy Rule because protected health information (PHI) was disclosed.
- This is considered an incidental disclosure and is not a violation, provided the clinic has taken reasonable safeguards. (correct answer)
- This is a violation unless the patient has signed a specific consent form allowing their name to be called publicly.
- This is not a violation because HIPAA regulations do not apply to common areas like waiting rooms.
Explanation: The correct answer is B. An 'incidental disclosure' is a secondary disclosure of PHI that cannot reasonably be prevented, is limited in nature, and occurs as a by-product of an otherwise permitted use or disclosure. Calling a patient's name is necessary for operations, and as long as reasonable safeguards are in place (e.g., not shouting sensitive details), it is not a HIPAA violation. A is incorrect because not all disclosures are violations. C is incorrect because a specific, separate consent for this action is not required. D is incorrect as HIPAA applies to all areas where PHI is handled, including semi-public spaces within a covered entity.
Question 14
The office manager needs to order a supply of fentanyl patches (a Schedule II substance) for in-office use. What is the legally required procedure for ordering this medication from a distributor according to the Controlled Substances Act?
- The provider must call the distributor and provide their DEA number to place the order verbally.
- The order can be placed online through the distributor's standard ordering portal with the clinic's account.
- A prescription must be written to the clinic itself and faxed to the distributor for fulfillment.
- The order must be documented on a federally issued DEA Form 222 or its secure electronic equivalent. (correct answer)
Explanation: The correct answer is D. The Controlled Substances Act mandates that any distribution of a Schedule I or II controlled substance requires a specific order form, DEA Form 222. This form creates a closed loop of accountability from manufacturer to distributor to practitioner. Verbal orders (A), standard online orders (B), or prescriptions written to the clinic (C) are not permissible methods for ordering Schedule II substances for office stock.
Question 15
A medical practice's third-party billing company, which has a Business Associate Agreement in place, experiences a data breach compromising patient PHI. Under the HITECH Act, where does the legal responsibility for patient notification ultimately lie?
- Exclusively with the billing company, as they are the Business Associate where the breach occurred and are directly liable.
- Exclusively with the medical practice, as the Covered Entity, because Business Associates are not responsible for patient notification.
- With both the medical practice and the billing company, as the HITECH Act imposes direct liability on Business Associates while not removing the Covered Entity's ultimate responsibility. (correct answer)
- With neither entity, until it can be proven that the breach has resulted in actual patient harm or financial loss.
Explanation: The correct answer is C. The HITECH Act made Business Associates (BAs) directly liable for HIPAA compliance, including breach notification. However, this does not absolve the Covered Entity (CE) of its responsibility. The CE and BA share responsibility, and the CE is ultimately accountable for ensuring patients are properly notified. A and B are incorrect because they place exclusive blame on one party. D is incorrect because notification is required based on the compromise of PHI, not on proof of subsequent harm.
Question 16
A provider writes a new prescription for zolpidem (Ambien), a Schedule IV drug, and authorizes the maximum number of refills allowed by federal law. The medical assistant should be aware that this prescription can be refilled how many times?
- Up to five times within a six-month period from the date of issue. (correct answer)
- An unlimited number of times within one year of the date of issue.
- Zero times; a new prescription is required for every fill, similar to a Schedule II drug.
- Up to eleven times within a twelve-month period from the date of issue.
Explanation: The correct answer is A. Under the federal Controlled Substances Act, prescriptions for Schedule III and IV substances may be refilled up to five times in six months. After five refills or after six months, whichever comes first, a new prescription is required. B and D are incorrect timeframes and limits. C is incorrect as this rule applies to Schedule II substances, not Schedule IV.
Question 17
A medical practice is notified by the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) that it has been selected for a random compliance audit. The authority for the OCR to conduct such audits was established by which of the following acts?
- The Affordable Care Act (ACA), to ensure equal access to care.
- The Controlled Substances Act (CSA), to monitor prescribing practices.
- The HITECH Act, to strengthen enforcement of HIPAA rules. (correct answer)
- The Patient's Bill of Rights, to investigate patient complaints.
Explanation: The correct answer is C. The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 significantly strengthened the enforcement provisions of HIPAA. It mandated that the OCR implement a program to conduct periodic, random audits of covered entities and business associates to assess their compliance with the HIPAA Privacy, Security, and Breach Notification Rules. The other acts listed established different regulations and are enforced by other agencies (e.g., DEA for the CSA).
Question 18
A medical assistant is preparing a handwritten prescription for oxycodone, a Schedule II controlled substance, for the provider to sign. Which of the following elements is absolutely required on the prescription for it to be considered legally valid by a pharmacy?
- The patient's phone number and insurance ID number.
- The number of refills authorized by the provider.
- The provider's unique DEA registration number. (correct answer)
- The National Drug Code (NDC) for the medication.
Explanation: The correct answer is C. The Controlled Substances Act (CSA) requires that all prescriptions for controlled substances contain the full name and address of the patient, the drug name, strength, dosage form, quantity prescribed, directions for use, and the name, address, and DEA registration number of the issuing practitioner. The DEA number is critical for validity. A is incorrect because insurance information and phone number are useful for pharmacy operations but not legally required for validity. B is incorrect because Schedule II medications cannot have refills by law, so this would not be present. D is incorrect because the NDC number is not required for a prescription to be valid.
Question 19
The adult son of a competent 80-year-old patient calls the clinic and asks the medical assistant for the results of his father's recent MRI. The patient's chart has no documentation authorizing disclosure to the son. What is the MA's most appropriate initial response?
- Ask the son a series of security questions to verify his identity and then provide the MRI results.
- Explain that due to federal privacy laws, information cannot be shared without the patient's express permission. (correct answer)
- Provide a general summary of the results but withhold any specific or sensitive details.
- Place the son on hold and ask the provider if it is acceptable to share the results with him.
Explanation: The correct answer is B. Under HIPAA, an MA cannot disclose PHI to a family member unless the patient has provided consent or is present and does not object. Since the patient is competent and there is no authorization on file, the MA's duty is to protect the patient's privacy by declining the request and explaining the legal basis. A is incorrect because identity verification does not replace the need for patient consent. C is incorrect as it is still a disclosure of PHI. D is incorrect because the provider is also bound by HIPAA and cannot authorize the release without the patient's consent.