AHIMA RHIT (Registered Health Information Technician) — All Questions

← Back to practice

3 questions

Access, Disclosure, Privacy & Security

The HIPAA 'minimum necessary' standard applies to most uses and disclosures of PHI, but it does NOT apply to:

  • a.Disclosures to a health care provider for treatment
  • b.Disclosures to a business associate
  • c.Internal uses for health care operations
  • d.Disclosures to a health plan for payment

The minimum necessary standard requires limiting PHI to the least amount needed, but it expressly does not apply to disclosures to or requests by a provider for treatment, because full information is needed for safe patient care. It also does not apply to disclosures to the individual, uses required by law, or those authorized by the patient. Payment and operations uses are still subject to minimum necessary.

Access, Disclosure, Privacy & Security

Under the HIPAA Privacy Rule, a patient's written authorization is generally NOT required to use or disclose PHI for:

  • a.Treatment, payment, and health care operations (TPO)
  • b.Marketing communications paid for by a third party
  • c.The sale of PHI
  • d.Most research uses without a waiver

The Privacy Rule permits use and disclosure of PHI for treatment, payment, and health care operations (TPO) without patient authorization. Marketing that is paid for by a third party, the sale of PHI, and most research disclosures do require a valid authorization (or an IRB/Privacy Board waiver for research). Knowing what falls inside TPO is essential to correct release-of-information decisions.

Access, Disclosure, Privacy & Security

Under the HITECH breach notification requirements, affected individuals must be notified of a breach of unsecured PHI without unreasonable delay and no later than:

  • a.30 days after discovery
  • b.60 days after discovery
  • c.90 days after discovery
  • d.180 days after discovery

The Breach Notification Rule requires notifying affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. Breaches affecting 500 or more individuals also require prompt notice to HHS and to prominent media in the affected area; smaller breaches are logged and reported to HHS annually. HIM often coordinates breach response.

Report