Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

Research and HIPAA Privacy Protections (ID 14) Exam Questions and Answers

Rating
-
Sold
-
Pages
3
Grade
A+
Uploaded on
16-11-2022
Written in
2022/2023

Under HIPAA, "retrospective research" (a.k.a., data mining) on collections of PHI generally ... - ANSWER-Is research, and so requires either an authorization or meeting one of the criteria for a waiver of authorization. HHS has reiterated in its guidance that use or disclosure of PHI for retrospective research studies may be done only with patient authorization -- or with a waiver, alteration, or exception determination from an IRB or Privacy Board. However, remember that you generally cannot proceed on your own without some approval from an IRB, Privacy Board, or other designated governing entity. - ANSWER- A covered entity may use or disclose PHI without an authorization, or documentation of a waiver or an alteration of authorization, for all of the following EXCEPT: - ANSWER-Data that does not cross state lines when disclosed by the covered entity. If the data in question meet the definition of PHI and are being used for purposes that fall within HIPAA's definition of research, HIPAA generally requires explicit written authorization (consent) from the data subject for research uses. However, HIPAA provides several alternatives that can bypass such authorizations: The research involves only minimal risk. The research is used solely for activities preparatory to research. Only deceased persons' information is used. Only de-identified data is used. Only a "limited data set" is used, under an approved "data use agreement." It is "grandfathered" research where all legal permissions were in place before HIPAA took effect. - ANSWER- If you're unsure about the particulars of HIPAA research requirements at your organization or have questions, you can usually consult with: - ANSWER-An organizational IRB or Privacy Board, privacy official ("Privacy Officer"), or security official ("Security Officer"), depending on the issue. If you are unsure about the particulars, consult with your organization's IRB, Privacy Board, or privacy official. For data security issues, consult with your organization's security official. Consulting with an experienced colleague can always be helpful, but their advice is not authoritative. Do not assume that a representative of the funder will know all the rules, or that the generic advice of a professional association will be applicable to your organization's particular rules. - ANSWER- HIPAA's protections for health information used for research purposes... - ANSWER-Supplement those of the Common Rule and FDA. Under HIPAA, a "disclosure accounting" is required: - ANSWER-For all human subjects research that uses PHI without an authorization from the data subject, except for limited data sets. HIPAA's relatively new data-focused protections, which took effect starting in 2003, supplement Common Rule and FDA protections; they are not a replacement. Institutional Review Board (IRB) protocol reviews using Common Rule and FDA criteria remain as before, including aspects related to data protection. IRBs may have the responsibility for addressing HIPAA's additional requirements in their reviews when those apply; or some responsibilities may be given to another kind of body that HIPAA permits (a Privacy Board) or to an institutional official that HIPAA requires (a privacy officer). These federal standards complement states' and accreditation bodies' requirements. - ANSWER- In addition to being limited to external disclosures, disclosure accounting is not required for disclosures made under authority of a consent/authorization, on the theory that the data subjects are aware of what they have expressly permitted for that research. Neither is an accounting required for disclosures to the data subject directly about him/herself. Nor is it required for limited data set disclosures subject to a data use agreement. Nor, finally, is any accounting required for de-identified information that no longer qualifies as PHI. - ANSWER- A HIPAA authorization has which of the following characteristics: - ANSWER-Uses "plain language" that the data subject can understand, similar to the requirement for an informed consent document. Authorizations are required unless the proposed use meets one of the exceptions listed in the HIPAA regulation. It is never at the researcher's discretion. When they are required, authorizations must be: In "plain language" so that individuals can understand the information contained in the form, and thus able to make an informed decision. Executed in writing, and signed by the research subject (or an authorized personal representative). Authorizations must include a specific description of the PHI to be used or disclosed, the name(s) or other identification of persons involved in the research, and description of each purpose of the requested use or disclosure. Authorizations can be combined with other documents and can always be revoked by the data subject. - ANSWER- HIPAA includes in its definition of "research," activities related to: - ANSWER-Development of generalizable knowledge. Like the Common Rule, HIPAA defines research as a "systematic investigation, including research development, testing, and evaluation, designed to develop and contribute to generalizable knowledge" (Protection of Human Subjects 2018; Security and Privacy 2013). - ANSWER- The HIPAA "minimum necessary" standard applies... - ANSWER-To all human subjects research that uses PHI without an authorization from the data subject. Uses and disclosures of data for research that are allowed to bypass the authorization requirement are still subject to the "minimum necessary" standard - that is, the uses/disclosures must be no more than the minimum required for the described research purpose. A covered entity may rely on a researcher's documentation - or the assessment of an IRB or Privacy Board - that the information requested is the minimum necessary for the research purpose. By contrast, research information obtained using an authorization is not bound by the minimum necessary standard - on the theory that the data subject has given explicit permission in accordance with the signed authorization. However, be aware that while HIPAA may not require a minimum necessary justification at all times, an IRB's evaluation of risks and burdens on human subjects arguably does. - ANSWER- Recruiting into research ... - ANSWER-Can qualify as an activity "preparatory to research," at least for the initial contact, but data should not leave the covered entity. It is still permissible under HIPAA to discuss recruitment into research with patients for whom such involvement might be appropriate. This common practice is considered to fall within the definition of treatment, at least when the conversation is undertaken by one of the patient's healthcare providers. If the contact will be made by someone other than the patient's healthcare provider, permission will be required. - ANSWER- Where fewer than 50 subjects' records are involved, the listing must be more specific and detailed, commensurate with the requirements for other kinds of PHI disclosure accounting, including: specific date(s) of disclosures; names of entities to which PHI was disclosed; description of the PHI involved in the disclosure; and purpose of the disclosure. - ANSWER- When required, the information provided to the data subject in a HIPAA disclosure accounting ... - ANSWER-mus

Show more Read less
Institution
Research And HIPAA Privacy Protections
Course
Research and HIPAA Privacy Protections








Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Research and HIPAA Privacy Protections
Course
Research and HIPAA Privacy Protections

Document information

Uploaded on
November 16, 2022
Number of pages
3
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$10.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
millyphilip West Virginia University
Follow You need to be logged in order to follow users or courses
Sold
2937
Member since
4 year
Number of followers
1959
Documents
45145
Last sold
1 day ago
white orchid store

EXCELLENCY IN ACCADEMIC MATERIALS ie exams, study guides, testbanks ,case, case study etc

3.6

554 reviews

5
240
4
88
3
104
2
32
1
90

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions