Exam Weight: 17% of the RHIA exam
HIPAA privacy and security compliance, PHI monitoring, breach notification protocols, retention and destruction policies, release of information management, patient rights, consent and authorization.
RHIA Exam Study Guide: Compliance, Privacy, and Security
Compliance is one of the most heavily tested domains on the RHIA certification exam. It encompasses regulatory requirements, privacy and security of health information, legal aspects of health records, and ethical standards for HIM professionals. This guide provides a thorough review of the critical topics, targeted exam strategies, and practice scenarios you will encounter.
HIPAA Privacy Rule Essentials
The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule establishes national standards for the protection of individually identifiable health information. For the RHIA exam, you must know:
- Protected health information (PHI) - individually identifiable health information held or transmitted by a covered entity or business associate, in any form (electronic, paper, or oral)
- Covered entities - health plans, healthcare clearinghouses, and healthcare providers who conduct standard electronic transactions
- Business associates - persons or organizations that perform functions involving PHI on behalf of a covered entity, requiring a business associate agreement (BAA)
- Minimum necessary standard - covered entities must make reasonable efforts to limit PHI access, use, and disclosure to the minimum amount needed to accomplish the intended purpose
- Patient rights under HIPAA - right to access, right to request amendments, right to an accounting of disclosures, right to request restrictions, right to request confidential communications
Be especially familiar with the exceptions to the authorization requirement. HIPAA permits use and disclosure of PHI without patient authorization for treatment, payment, and healthcare operations (TPO), as well as for public health activities, judicial proceedings, law enforcement purposes, research with an IRB waiver, and several other specific circumstances.
HIPAA Security Rule
The Security Rule applies specifically to electronic protected health information (ePHI) and requires covered entities and business associates to implement safeguards in three categories:
- Administrative safeguards - security management processes, workforce security, information access management, security awareness training, contingency planning, and evaluation. These are the largest category and include the requirement to designate a security officer.
- Physical safeguards - facility access controls, workstation use and security policies, and device and media controls governing the receipt, movement, and disposal of hardware and electronic media containing ePHI
- Technical safeguards - access controls (unique user identification, emergency access, automatic logoff, encryption), audit controls, integrity controls, person or entity authentication, and transmission security
A critical distinction for the exam: the Security Rule differentiates between required and addressable implementation specifications. "Addressable" does not mean optional. If a specification is addressable, the organization must implement it, implement an equivalent alternative measure, or document why the specification is not reasonable and appropriate in its environment.
HITECH Act and Breach Notification
The Health Information Technology for Economic and Clinical Health (HITECH) Act strengthened HIPAA enforcement and introduced breach notification requirements:
- Breach definition - the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI
- Risk assessment - organizations must evaluate breaches using a four-factor test: the nature and extent of PHI involved, the unauthorized person who used or received the PHI, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated
- Notification timelines - individuals must be notified within 60 days of discovery; HHS must be notified annually for breaches affecting fewer than 500 individuals, and within 60 days for breaches affecting 500 or more; media notification is required for breaches affecting 500 or more residents of a state
- Increased penalties - HITECH established tiered penalty structures based on the level of culpability
Legal Aspects of Health Information
The RHIA exam tests your understanding of the legal framework surrounding health records:
- Ownership vs. access - the healthcare organization generally owns the physical or electronic record, while the patient has the right to access the information within it
- Consent vs. authorization - consent is a general agreement for TPO (required in some states), while authorization is a specific, detailed permission for uses and disclosures beyond TPO
- Valid authorization elements - description of information, who may disclose, who may receive, purpose, expiration date, signature and date, right to revoke, and other required statements
- Subpoenas and court orders - a subpoena duces tecum requests production of documents; a court order compels production. Responding to a subpoena typically requires satisfactory assurances that the patient has been notified, while a court order generally must be obeyed
- State preemption - HIPAA sets the federal floor; state laws that are more stringent or more protective of patient privacy preempt HIPAA
Compliance Programs and Fraud Prevention
Healthcare compliance programs are designed to prevent, detect, and correct violations of law and organizational policy. Key components include:
- Written standards of conduct and policies and procedures
- Designation of a compliance officer and compliance committee
- Effective training and education
- Effective lines of communication (such as a hotline for reporting)
- Internal monitoring and auditing
- Consistent enforcement through disciplinary guidelines
- Prompt response to detected offenses and corrective action
Understand the key fraud and abuse laws: the False Claims Act (prohibits submitting false claims to government payers), the Anti-Kickback Statute (prohibits offering or receiving anything of value to induce referrals for services covered by federal healthcare programs), and the Stark Law (prohibits physician self-referrals for designated health services to entities with which the physician has a financial relationship, with specific exceptions).
Ethical Standards in HIM
The AHIMA Code of Ethics guides the professional conduct of HIM professionals. Core principles include:
- Advocating for the best interests of patients and the public
- Protecting the confidentiality and security of health information
- Promoting the integrity and quality of health data
- Advancing HIM knowledge through education and research
- Refusing to participate in or conceal unethical practices
Exam Strategies for Compliance
- Default to the most protective answer. When in doubt between two plausible options, choose the one that better protects patient privacy. HIPAA is designed to protect patients, and the exam reflects that priority.
- Know your timelines. Memorize key deadlines: 60 days for breach notification, 30 days (with possible 30-day extension) for responding to patient access requests, and specific timelines for amendment requests.
- Distinguish required from addressable. The exam may test whether you understand that addressable specifications are not optional and require documented assessment.
- Watch for state preemption traps. If a question presents a conflict between federal and state law, the more stringent or more protective standard applies.
- Apply the minimum necessary standard carefully. Remember that it does not apply to disclosures for treatment purposes, disclosures to the individual, or disclosures required by law.
Common Exam Questions and Scenarios
Scenario 1: A patient requests access to their psychotherapy notes. Under HIPAA, is the provider required to grant this request?
No. Psychotherapy notes are explicitly excluded from the individual right of access under HIPAA. These are the personal notes of a mental health professional kept separate from the medical record. However, other mental health records that are part of the medical record are subject to the right of access.
Scenario 2: A hospital employee accesses the medical record of a celebrity patient out of curiosity. What type of violation is this, and what should happen?
This is a workforce violation of the minimum necessary standard and the organization's access policies. The organization should follow its sanctions policy, which may include disciplinary action up to termination. If the access constitutes a breach, the organization must conduct a risk assessment and follow breach notification procedures as required.
Scenario 3: A researcher requests access to patient records for a study. The researcher has not obtained an IRB waiver of authorization. What should the HIM department do?
The HIM department should not release the records without either individual patient authorization or documentation of an IRB or privacy board waiver of authorization. The department should direct the researcher to obtain the appropriate approval through the IRB process before releasing any PHI.
Scenario 4: An organization discovers that an unencrypted laptop containing ePHI of 750 patients was stolen from an employee's car. What are the notification obligations?
Because the breach involves unsecured PHI (unencrypted) and affects more than 500 individuals, the organization must notify affected individuals within 60 days, notify HHS within 60 days, and notify prominent media outlets serving the state. The organization should also conduct a thorough risk assessment and implement corrective actions.
Compliance is a domain where precise knowledge of regulations, timelines, and exceptions is critical. Study the actual rule language and understand how the rules apply in real-world healthcare scenarios to perform well on this section of the exam.