HIM422
Ethical & Legal Considerations in HIM
Comprehensive Finals Review (Qns & Ans)
2025
1. Which law regulates the privacy of personal health
information?
A) The Affordable Care Act
B) The Health Insurance Portability and Accountability Act
(HIPAA)
C) The Social Security Act
D) The Privacy Act
ANS: B
©/2025
, Rationale: HIPAA is specifically designed to safeguard the
privacy and security of health information.
2. What is the primary ethical principle that obligates health
information managers to protect patient confidentiality?
A) Autonomy
B) Justice
C) Beneficence
D) Non-maleficence
ANS: A
Rationale: Autonomy involves respecting patients' rights to
control personal information.
3. Which of the following is considered a breach of Protected
Health Information (PHI) under HIPAA?
A) Sharing PHI with a spouse without consent
B) Disclosure to an insurance company for a claim
C) Using PHI for treatment purposes
D) None of the above
ANS: A
Rationale: Disclosures without patient consent can constitute
a breach.
©/2025
,4. Under which circumstances can PHI be disclosed without
patient authorization?
A) Marketing purposes
B) Research with a waiver from an Institutional Review Board
(IRB)
C) Selling PHI to third parties
D) Family inquiries over the phone
ANS: B
Rationale: Research disclosures are allowed with IRB waiver
under specific conditions.
5. Which act amended HIPAA to include the Breach
Notification Rule?
A) Health Information Technology for Economic and Clinical
Health (HITECH) Act
B) Affordable Care Act
C) Medicare Modernization Act
D) Patient Safety and Quality Improvement Act
ANS: A
Rationale: HITECH Act introduced rules about breach
notification.
©/2025
, Fill-in-the-Blank Questions
6. Under HIPAA, covered entities must enter into a ________
agreement with any organization that handles PHI on their behalf.
ANS: Business Associate
Rationale: Business Associate Agreements ensure that
vendors comply with HIPAA regulations.
7. The principle of ________ refers to the need to do no harm to
patients.
ANS: Non-maleficence
Rationale: This principle obliges healthcare providers to
avoid causing harm.
8. The ________ allows patients to request an amendment to
their medical records if they believe information is inaccurate.
ANS: Privacy Rule of HIPAA
Rationale: Patients have rights under HIPAA to request
corrections of their records.
©/2025
Ethical & Legal Considerations in HIM
Comprehensive Finals Review (Qns & Ans)
2025
1. Which law regulates the privacy of personal health
information?
A) The Affordable Care Act
B) The Health Insurance Portability and Accountability Act
(HIPAA)
C) The Social Security Act
D) The Privacy Act
ANS: B
©/2025
, Rationale: HIPAA is specifically designed to safeguard the
privacy and security of health information.
2. What is the primary ethical principle that obligates health
information managers to protect patient confidentiality?
A) Autonomy
B) Justice
C) Beneficence
D) Non-maleficence
ANS: A
Rationale: Autonomy involves respecting patients' rights to
control personal information.
3. Which of the following is considered a breach of Protected
Health Information (PHI) under HIPAA?
A) Sharing PHI with a spouse without consent
B) Disclosure to an insurance company for a claim
C) Using PHI for treatment purposes
D) None of the above
ANS: A
Rationale: Disclosures without patient consent can constitute
a breach.
©/2025
,4. Under which circumstances can PHI be disclosed without
patient authorization?
A) Marketing purposes
B) Research with a waiver from an Institutional Review Board
(IRB)
C) Selling PHI to third parties
D) Family inquiries over the phone
ANS: B
Rationale: Research disclosures are allowed with IRB waiver
under specific conditions.
5. Which act amended HIPAA to include the Breach
Notification Rule?
A) Health Information Technology for Economic and Clinical
Health (HITECH) Act
B) Affordable Care Act
C) Medicare Modernization Act
D) Patient Safety and Quality Improvement Act
ANS: A
Rationale: HITECH Act introduced rules about breach
notification.
©/2025
, Fill-in-the-Blank Questions
6. Under HIPAA, covered entities must enter into a ________
agreement with any organization that handles PHI on their behalf.
ANS: Business Associate
Rationale: Business Associate Agreements ensure that
vendors comply with HIPAA regulations.
7. The principle of ________ refers to the need to do no harm to
patients.
ANS: Non-maleficence
Rationale: This principle obliges healthcare providers to
avoid causing harm.
8. The ________ allows patients to request an amendment to
their medical records if they believe information is inaccurate.
ANS: Privacy Rule of HIPAA
Rationale: Patients have rights under HIPAA to request
corrections of their records.
©/2025