Assessment 2 | Capella | 26/27 Actual (PDF)
1. Which federal regulation establishes national standards for the protection of protected health
information (PHI) in healthcare?
A) The Joint Commission standards
B) Health Insurance Portability and Accountability Act (HIPAA)
C) Centers for Medicare & Medicaid Services (CMS) Conditions of Participation
D) Occupational Safety and Health Administration (OSHA) regulations
Correct Answer: Health Insurance Portability and Accountability Act (HIPAA)
Rationale: HIPAA is the federal law enacted in 1996 that establishes national standards for the privacy
and security of protected health information. The Joint Commission, CMS, and OSHA address other
aspects of healthcare regulation, but HIPAA is the primary legislation governing PHI protection.
2. What is the primary purpose of the HIPAA Privacy Rule?
A) To establish standards for electronic health record interoperability
B) To regulate the use and disclosure of protected health information
C) To set reimbursement rates for healthcare services
D) To mandate reporting of communicable diseases
Correct Answer: To regulate the use and disclosure of protected health information
Rationale: The HIPAA Privacy Rule governs how covered entities may use and disclose PHI, giving
patients rights over their health information. Interoperability standards, reimbursement rates, and
disease reporting are addressed by other regulations and agencies.
,3. Which of the following is considered protected health information (PHI)?
A) A hospital's annual budget report
B) A patient's name and diagnosis
C) A nurse's shift schedule
D) A public health statistic without identifiers
Correct Answer: A patient's name and diagnosis
Rationale: PHI includes individually identifiable health information such as a patient's name,
diagnosis, treatment, and payment data. Hospital budgets, staff schedules, and de-identified public
health statistics are not PHI because they do not contain individually identifiable patient information.
4. A nurse informaticist is reviewing safeguards required by the HIPAA Security Rule. Which category
of safeguards includes encryption and unique user identification?
A) Administrative safeguards
B) Physical safeguards
C) Technical safeguards
D) Environmental safeguards
Correct Answer: Technical safeguards
Rationale: The HIPAA Security Rule categorizes safeguards into administrative, physical, and technical.
Technical safeguards include access controls, encryption, audit controls, and unique user
identification. Administrative safeguards involve policies and training, while physical safeguards
address facility access and workstation security.
5. Which action by a nurse would constitute a breach of patient confidentiality?
A) Discussing a patient's condition in a private staff break room
, B) Posting a photo of a patient's wound on a personal social media account
C) Accessing a patient's record to provide direct care
D) Documenting a patient's vital signs in the electronic health record
Correct Answer: Posting a photo of a patient's wound on a personal social media account
Rationale: Sharing patient images or information on personal social media without authorization is a
clear breach of confidentiality and HIPAA. Discussing patient care in a private staff area, accessing
records for direct care, and documenting in the EHR are appropriate professional activities.
6. What is the primary difference between privacy and confidentiality in healthcare?
A) Privacy applies to electronic data only, while confidentiality applies to paper records
B) Privacy is the patient's right to control their information, while confidentiality is the provider's
obligation to protect it
C) Privacy applies to verbal communication, while confidentiality applies to written communication
D) Privacy is a legal requirement, while confidentiality is an ethical guideline
Correct Answer: Privacy is the patient's right to control their information, while confidentiality is the
provider's obligation to protect it
Rationale: Privacy refers to the patient's right to control access to their health information, while
confidentiality is the healthcare provider's duty to safeguard that information. Both apply to all
formats and are grounded in legal and ethical standards.
7. A nurse informaticist is developing a staff update on social media use. Which recommendation is
most appropriate?
A) Nurses may post patient stories as long as they do not use the patient's name
B) Nurses should never post any work-related content on social media
C) Nurses should follow their organization's social media policy and never share PHI