Deck 10: Access to Health Information

Full screen (f)
exit full mode
Question
A patient's friend or family may be given access to medical records in the event that the _____.

A) Family member is the custodial parent of a minor child
B) Friend is the patient's local church pastor or minister
C) Health care facility has no policy regarding ROI
D) Patient would otherwise unreasonably object to access
Use Space or
up arrow
down arrow
to flip the card.
Question
Authority for release of information can be granted by a(n) _____.

A) executor of an estate
B) mentally disabled 18-year-old
C) minor child
D) plaintiff's attorney
Question
The release of information _____.

A) is enforceable past the expiration date
B) may be denied by the provider for any reason
C) permits removal of records from the provider's control
D) requires the express consent of the patient
Question
Third parties are required to obtain the patient's permission when _____ wish to access the patient's protected health information.

A) Children of elderly parents
B) Accrediting and licensing agents
C) Health care facility's legal attorneys
D) Medicare and Medicaid payers
Question
Which is an example of a valid reason for restricting access to a patient's medical record?

A) Access to information in the patient record is never restricted, regardless of reason.
B) Information revealed during litigation would adversely impact a person's marriage.
C) Patient information obtained via court order would reveal criminal behavior.
D) Releasing information might have a detrimental effect on the patient's mental health.
Question
According to HIPAA, the _____ has the right to access patient information in the complete medical record.

A) government
B) patient
C) payer
D) transferring facility
Question
The minimum necessary standard refers to the healthcare provider's effort to _____.

A) Invoice third-party payers for the least reasonable amount associated with care provided to the patient
B) Limit patient-specific health information released to that which is needed to accomplish the intended purpose only
C) Minimalize the risk of negligence that would result in becoming involved in a malpractice lawsuit
D) Provide the patient with the minimum amount of procedures and medications to maintain reasonable insurance costs
Question
With regards to the method of disclosure, the law requires that it be made by:

A) Any method consistent with professional guidelines and institutional practices.
B) Electronic transmission that includes the application of encryption software.
C) Mail or other shipping method that verifies the receipt of the patient records.
D) Portable media such as CD-ROM, DVD, portable hard drive, or thumb drive.
Question
The Federal Privacy Act _____.

A) Allows a patient greater access to records than is provided for by HIPAA
B) Allows a patient less access to records than is provided for by HIPAA
C) Applies to all facilities that receive Medicaid and Medicare reimbursement only
D) Applies to facilities operated by state governments, but not federal governments
Question
The Declaration of Helsinki applies to _____.

A) Freedom of patient access to medical records relative to research
B) Guidelines followed when conducting research involving human subjects
C) Protection of human and non-human subjects involved in medical research
D) Legal consequences of ethical violations occurring during research
Question
A release of information (ROI) authorization signed and dated by the patient is considered invalid when it _____.

A) Contains information that may implicate the provider in negligence
B) Includes medical information about unnamed family members
C) Lacks a specific description of the information requested
D) Meets the facility's ROI policy as well as HIPAA requirements
Question
Health care information is owned by the _____.

A) facility
B) government agency
C) patient
D) treating physician
Question
Third parties have the right to access a person's information if _____.

A) Previous access to records was granted
B) Proper release of information is authorized
C) The requesting parties are third-party payers
D) The requestors are the patient's caregivers
Question
A parent will not be granted access to the health care record of his or her child who has not yet reached the age of majority when the minor child _____.

A) Can lawfully obtain health care without parental consent
B) Is pursuing her GED online and living with her parents
C) Seeks treatment for an injury sustained in an auto accident
D) Violates terms of her court-assigned probation and runs away
Question
An emancipated minor is one who is _____.

A) Actively serving in the US armed forces
B) Engaged to be married
C) Not living with his or her parents
D) Quitting high school
Question
A redisclosure notice _____.

A) Allows information released by a facility to be submitted to RHIO agencies.
B) Is optional when the patient information pertains to drug and alcohol abuse treatment.
C) Protects information from the patient record from being shared with a third party.
D) Prohibits information from being only for the stated purpose included on ROI form.
Question
When determining which entity's federal or state law concerning the control of health information control is preemptive, the health information manager must understand that the _____.

A) Federal or state law that is more stringent is followed
B) HIPAA privacy rules always preempts state and local laws
C) Language in federal laws preempts state and local laws
D) State mandates result from mandates determined to be federal
Question
HIPAA regulations establish a "floor" of patient rights, which means _____.

A) Facilities of multi-state hospital systems abide by state laws granting the least access
B) Multi-state hospital systems are bound by the federal HIPAA requirements only
C) States may enact legislation that provides for additional patient access to records
D) States must restrict patient access to records according to minimum HIPAA
Question
Which method is associated with an evolving trend regarding the maintenance of health care records?

A) Attorneys must submit a subpoena duces tecum to receive copies of records.
B) Government entities serve as custodians of information in the health care record.
C) Health care facilities can establish charges for copying health care records.
D) Patients are permitted to access their own information in the health care record.
Question
Which is an advantage of housing health care records in a central repository?

A) Control of health care records is granted directly to patients.
B) Fragmentation of medical data is increased (instead of eliminated).
C) Privacy violations result in the enforcement of penalties to guilty parties.
D) Third-party payers can access health care records without patient notification.
Question
The role of an Institutional Review Board involves:

A) Approving an informed consent that accurately describes the risks and benefits to the subject associated with any research to be conducted.
B) Developing means and methods of obtaining financial resources that positively impact research, even if adversely impacting subjects.
C) Maintaining the confidentiality of all of the subjects is optional when the results of research benefit society as a whole.
D) Reviewing the research protocols to be sure that they comply with federal regulations only, regardless of the facility's location.
Question
Which is a direct identifier that must be removed from research subjects' records in order to comply with the use of a limited data set?

A) Account number
B) Age
C) Gender
D) Race
Question
In the modern view of ownership of health information, the health care provider owns the medium in which the patient health information is created and stored, and the patient possesses right of access.
Question
A reasonable fee for the copying of health information is established by the state.
Question
HIPAA provides for two exceptions in which approval for research does not require full IRB review. They include _____.

A) Identified information and waiver or authorization
B) Limited data set and de-identified information
C) Minimum data set and UHDDS information
D) Research that meets criteria for emergency review
Question
A personal health record is a collection of the patient's important health information " that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual."
Question
An authorization for use or disclosure of patient-specific health information that has been combined with any other document is called a(n) _____ authorization.

A) Admissibility
B) Beneficence
C) Certiorari
D) Compound
Question
Adoption records are considered confidential and can only be released _____.

A) In accordance with HIPAA mandates and regulations related to such records
B) Pursuant to legal procedures of the state in which the records are maintained
C) Upon the express request from the adoptee, adoptee's parent(s), or birth parent(s)
D) When an emergency requires that birth parent's medical data be obtained
Question
The Belmont Report established guidelines for research projects, which promotes _____.

A) Choosing subjects equitably to avoid exploitation of vulnerable populations
B) Fiduciary laws and statutes for conducting research on human subjects
C) Research that doesn't benefit subjects if it benefits society as a whole
D) Selecting subjects from just one ethnic group due to difficult processes
Question
Which is a method used by the health information manager to protect patient information from identity theft?

A) Performing background checks on anyone requesting information.
B) Permitting access by representatives of physician offices only.
C) Redacting portions of credit card and social security numbers.
D) Restricting password access to all hospital staff members.
Question
Lacking a core element and an authorization not being filled out completely are both common defects of an invalid release of information form.
Question
Reporting of public health threats include _____.

A) Breaches of confidentiality
B) Child abuse
C) Domestic violence
D) Terminations of pregnancy
Question
Which is an agreement constructed to authorize a business associate's access to protected health information (PHI) under the HIPAA Privacy Rule?

A) Description of the permitted uses of released patient information.
B) Government agencies that will be impacted by release of PHI.
C) Methods for notifying the provider whenever the information is accessed.
D) Name of primary business associate who will view the patient record.
Question
A business associate agreement is defined as one who performs or assists in performing a function or activity involving the use or disclosure of individually identifiable health information on behalf of a covered entity.
Question
The HIPAA Privacy Rule _____.

A) Authorizes the publication of protected health information (PHI) by having subjects sign informed consents, even when a subject voluntarily participates in research
B) Mandates that HIPAA regulations apply to whatever extent protected health information (PHI) may be used during research, including publication of results
C) Requires that an IRB review to etermine whether PHI can be used as the researcher suggests in his protocol or whether a waiver of authorization is warranted
D) States that maintaining the confidentiality of protected health information is not an issue during research because all publications include the results of blinded data only
Question
Which is categorized as a business associate, as defined by HIPAA regulations?

A) Government entities
B) Health care providers
C) Patients and family members
D) Third-party payers
Question
Identity theft is guaranteed at all large health care facilities.
Question
Which is a government agency that is responsible for assuring compliance with ethical conduct of research in humans?

A) CMS
B) FDA
C) IRB
D) OIG
Question
A healthcare provider's obligation regarding a business associate's compliance with the HIPAA Privacy Rule includes _____.

A) An obligation to monitor the business associate's compliance with HIPAA
B) Maintaining documentation of compliance with the HIPAA privacy rule
C) Provider responsibility when the business associate complies with the rule
D) Treatment, payment, and other operations' (TPO) mandates and requirements
Question
Which is a HIPAA Privacy Rule exceptions to the requirement that consent to release protected health information (PHI) be obtained prior to disclosure?

A) Adverse events involving provider negligence.
B) Contained accidental chemical exposure.
C) Instances concerning victims of abuse or neglect.
D) Non-violent trauma that results in emergency care.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/40
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 10: Access to Health Information
1
A patient's friend or family may be given access to medical records in the event that the _____.

A) Family member is the custodial parent of a minor child
B) Friend is the patient's local church pastor or minister
C) Health care facility has no policy regarding ROI
D) Patient would otherwise unreasonably object to access
Family member is the custodial parent of a minor child
2
Authority for release of information can be granted by a(n) _____.

A) executor of an estate
B) mentally disabled 18-year-old
C) minor child
D) plaintiff's attorney
executor of an estate
3
The release of information _____.

A) is enforceable past the expiration date
B) may be denied by the provider for any reason
C) permits removal of records from the provider's control
D) requires the express consent of the patient
requires the express consent of the patient
4
Third parties are required to obtain the patient's permission when _____ wish to access the patient's protected health information.

A) Children of elderly parents
B) Accrediting and licensing agents
C) Health care facility's legal attorneys
D) Medicare and Medicaid payers
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
5
Which is an example of a valid reason for restricting access to a patient's medical record?

A) Access to information in the patient record is never restricted, regardless of reason.
B) Information revealed during litigation would adversely impact a person's marriage.
C) Patient information obtained via court order would reveal criminal behavior.
D) Releasing information might have a detrimental effect on the patient's mental health.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
6
According to HIPAA, the _____ has the right to access patient information in the complete medical record.

A) government
B) patient
C) payer
D) transferring facility
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
7
The minimum necessary standard refers to the healthcare provider's effort to _____.

A) Invoice third-party payers for the least reasonable amount associated with care provided to the patient
B) Limit patient-specific health information released to that which is needed to accomplish the intended purpose only
C) Minimalize the risk of negligence that would result in becoming involved in a malpractice lawsuit
D) Provide the patient with the minimum amount of procedures and medications to maintain reasonable insurance costs
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
8
With regards to the method of disclosure, the law requires that it be made by:

A) Any method consistent with professional guidelines and institutional practices.
B) Electronic transmission that includes the application of encryption software.
C) Mail or other shipping method that verifies the receipt of the patient records.
D) Portable media such as CD-ROM, DVD, portable hard drive, or thumb drive.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
9
The Federal Privacy Act _____.

A) Allows a patient greater access to records than is provided for by HIPAA
B) Allows a patient less access to records than is provided for by HIPAA
C) Applies to all facilities that receive Medicaid and Medicare reimbursement only
D) Applies to facilities operated by state governments, but not federal governments
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
10
The Declaration of Helsinki applies to _____.

A) Freedom of patient access to medical records relative to research
B) Guidelines followed when conducting research involving human subjects
C) Protection of human and non-human subjects involved in medical research
D) Legal consequences of ethical violations occurring during research
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
11
A release of information (ROI) authorization signed and dated by the patient is considered invalid when it _____.

A) Contains information that may implicate the provider in negligence
B) Includes medical information about unnamed family members
C) Lacks a specific description of the information requested
D) Meets the facility's ROI policy as well as HIPAA requirements
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
12
Health care information is owned by the _____.

A) facility
B) government agency
C) patient
D) treating physician
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
13
Third parties have the right to access a person's information if _____.

A) Previous access to records was granted
B) Proper release of information is authorized
C) The requesting parties are third-party payers
D) The requestors are the patient's caregivers
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
14
A parent will not be granted access to the health care record of his or her child who has not yet reached the age of majority when the minor child _____.

A) Can lawfully obtain health care without parental consent
B) Is pursuing her GED online and living with her parents
C) Seeks treatment for an injury sustained in an auto accident
D) Violates terms of her court-assigned probation and runs away
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
15
An emancipated minor is one who is _____.

A) Actively serving in the US armed forces
B) Engaged to be married
C) Not living with his or her parents
D) Quitting high school
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
16
A redisclosure notice _____.

A) Allows information released by a facility to be submitted to RHIO agencies.
B) Is optional when the patient information pertains to drug and alcohol abuse treatment.
C) Protects information from the patient record from being shared with a third party.
D) Prohibits information from being only for the stated purpose included on ROI form.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
17
When determining which entity's federal or state law concerning the control of health information control is preemptive, the health information manager must understand that the _____.

A) Federal or state law that is more stringent is followed
B) HIPAA privacy rules always preempts state and local laws
C) Language in federal laws preempts state and local laws
D) State mandates result from mandates determined to be federal
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
18
HIPAA regulations establish a "floor" of patient rights, which means _____.

A) Facilities of multi-state hospital systems abide by state laws granting the least access
B) Multi-state hospital systems are bound by the federal HIPAA requirements only
C) States may enact legislation that provides for additional patient access to records
D) States must restrict patient access to records according to minimum HIPAA
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
19
Which method is associated with an evolving trend regarding the maintenance of health care records?

A) Attorneys must submit a subpoena duces tecum to receive copies of records.
B) Government entities serve as custodians of information in the health care record.
C) Health care facilities can establish charges for copying health care records.
D) Patients are permitted to access their own information in the health care record.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
20
Which is an advantage of housing health care records in a central repository?

A) Control of health care records is granted directly to patients.
B) Fragmentation of medical data is increased (instead of eliminated).
C) Privacy violations result in the enforcement of penalties to guilty parties.
D) Third-party payers can access health care records without patient notification.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
21
The role of an Institutional Review Board involves:

A) Approving an informed consent that accurately describes the risks and benefits to the subject associated with any research to be conducted.
B) Developing means and methods of obtaining financial resources that positively impact research, even if adversely impacting subjects.
C) Maintaining the confidentiality of all of the subjects is optional when the results of research benefit society as a whole.
D) Reviewing the research protocols to be sure that they comply with federal regulations only, regardless of the facility's location.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
22
Which is a direct identifier that must be removed from research subjects' records in order to comply with the use of a limited data set?

A) Account number
B) Age
C) Gender
D) Race
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
23
In the modern view of ownership of health information, the health care provider owns the medium in which the patient health information is created and stored, and the patient possesses right of access.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
24
A reasonable fee for the copying of health information is established by the state.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
25
HIPAA provides for two exceptions in which approval for research does not require full IRB review. They include _____.

A) Identified information and waiver or authorization
B) Limited data set and de-identified information
C) Minimum data set and UHDDS information
D) Research that meets criteria for emergency review
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
26
A personal health record is a collection of the patient's important health information " that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual."
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
27
An authorization for use or disclosure of patient-specific health information that has been combined with any other document is called a(n) _____ authorization.

A) Admissibility
B) Beneficence
C) Certiorari
D) Compound
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
28
Adoption records are considered confidential and can only be released _____.

A) In accordance with HIPAA mandates and regulations related to such records
B) Pursuant to legal procedures of the state in which the records are maintained
C) Upon the express request from the adoptee, adoptee's parent(s), or birth parent(s)
D) When an emergency requires that birth parent's medical data be obtained
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
29
The Belmont Report established guidelines for research projects, which promotes _____.

A) Choosing subjects equitably to avoid exploitation of vulnerable populations
B) Fiduciary laws and statutes for conducting research on human subjects
C) Research that doesn't benefit subjects if it benefits society as a whole
D) Selecting subjects from just one ethnic group due to difficult processes
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
30
Which is a method used by the health information manager to protect patient information from identity theft?

A) Performing background checks on anyone requesting information.
B) Permitting access by representatives of physician offices only.
C) Redacting portions of credit card and social security numbers.
D) Restricting password access to all hospital staff members.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
31
Lacking a core element and an authorization not being filled out completely are both common defects of an invalid release of information form.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
32
Reporting of public health threats include _____.

A) Breaches of confidentiality
B) Child abuse
C) Domestic violence
D) Terminations of pregnancy
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
33
Which is an agreement constructed to authorize a business associate's access to protected health information (PHI) under the HIPAA Privacy Rule?

A) Description of the permitted uses of released patient information.
B) Government agencies that will be impacted by release of PHI.
C) Methods for notifying the provider whenever the information is accessed.
D) Name of primary business associate who will view the patient record.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
34
A business associate agreement is defined as one who performs or assists in performing a function or activity involving the use or disclosure of individually identifiable health information on behalf of a covered entity.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
35
The HIPAA Privacy Rule _____.

A) Authorizes the publication of protected health information (PHI) by having subjects sign informed consents, even when a subject voluntarily participates in research
B) Mandates that HIPAA regulations apply to whatever extent protected health information (PHI) may be used during research, including publication of results
C) Requires that an IRB review to etermine whether PHI can be used as the researcher suggests in his protocol or whether a waiver of authorization is warranted
D) States that maintaining the confidentiality of protected health information is not an issue during research because all publications include the results of blinded data only
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
36
Which is categorized as a business associate, as defined by HIPAA regulations?

A) Government entities
B) Health care providers
C) Patients and family members
D) Third-party payers
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
37
Identity theft is guaranteed at all large health care facilities.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
38
Which is a government agency that is responsible for assuring compliance with ethical conduct of research in humans?

A) CMS
B) FDA
C) IRB
D) OIG
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
39
A healthcare provider's obligation regarding a business associate's compliance with the HIPAA Privacy Rule includes _____.

A) An obligation to monitor the business associate's compliance with HIPAA
B) Maintaining documentation of compliance with the HIPAA privacy rule
C) Provider responsibility when the business associate complies with the rule
D) Treatment, payment, and other operations' (TPO) mandates and requirements
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
40
Which is a HIPAA Privacy Rule exceptions to the requirement that consent to release protected health information (PHI) be obtained prior to disclosure?

A) Adverse events involving provider negligence.
B) Contained accidental chemical exposure.
C) Instances concerning victims of abuse or neglect.
D) Non-violent trauma that results in emergency care.
Unlock Deck
Unlock for access to all 40 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 40 flashcards in this deck.