A hospital's billing department shares a patient's diagnosis with the hospital's contracted medical transcription company so notes can be typed up. What is the transcription company considered under the Privacy Rule?
A. A covered entity, because it handles protected health information
B. A business associate, because it performs a service involving PHI on behalf of a covered entity
C. A workforce member of the hospital, because it works exclusively for the hospital
D. Exempt from HIPAA, because transcription is a purely administrative task
Source: 45 CFR 160.103
A billing clerk who processes insurance claims requests full clinical progress notes for a patient's account, even though only the diagnosis and procedure codes are needed to bill the claim. What HIPAA principle does this violate?
A. The minimum necessary standard
B. The right of access
C. The notice of privacy practices requirement
D. The de-identification standard
Source: 45 CFR 164.502(b)
A primary care physician sends a patient's chart to a specialist for a referral consultation. Does the physician need the patient's written authorization first?
A. Yes, any disclosure to another provider always requires authorization
B. Yes, unless the specialist is in the same health system
C. No, because this is a disclosure for treatment purposes, which is permitted without authorization
D. No, but only if the patient verbally agrees on the spot
Source: 45 CFR 164.506(c)
A hospital marketing team wants to use a patient's name and photo, taken during treatment, in an advertisement for the hospital's new maternity wing. What does HIPAA require before this use?
A. Nothing, because the photo was already taken during a covered encounter
B. Verbal permission noted in the chart
C. A general consent for treatment signed at admission
D. A valid, patient-signed authorization that specifically describes this marketing use
Source: 45 CFR 164.508(a)-(c)
A nurse discusses a patient's condition with a colleague in a hospital hallway, using reasonably low voices near the nursing station, and another visitor happens to overhear part of the conversation. Is this a HIPAA violation?
A. Yes, any overheard conversation is automatically a reportable breach
B. No, this is a permissible incidental disclosure because reasonable safeguards were used
C. Yes, because the conversation should have occurred in a locked room
D. No, because visitors have no expectation of privacy in a hospital
Source: 45 CFR 164.502(a)(1)(iii)