CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A hospital configures its cloud-based billing application so that billing staff can view only the patient's name, insurance ID, and charges, but cannot view clinical notes or diagnosis details unrelated to billing. This configuration is designed to comply with which HIPAA Privacy Rule requirement?
- ABreach notification rule
- BMinimum necessary standard
- CRight to erasure
- DBusiness associate agreement
Show answer & explanationAnswer & explanation
Correct answer: B. Minimum necessary standard
The HIPAA minimum necessary standard requires that access to protected health information be limited to only the information needed to accomplish a specific task, such as billing staff seeing only billing-relevant fields. A business associate agreement governs vendor relationships, right to erasure is a GDPR concept, and the breach notification rule addresses reporting after a data breach.
Why the other options are wrong
- A. The breach notification rule concerns reporting a data breach, not limiting routine access.
- C. Right to erasure is a GDPR right for individuals to request deletion of personal data, unrelated to field-level access.
- D. A BAA is a contract with a vendor handling ePHI, not a data field restriction.
HIPAA Minimum Necessary Standard
A HIPAA Privacy Rule requirement that limits access, use, and disclosure of protected health information to the minimum needed to accomplish the intended purpose.
- Applies to workforce access, disclosures, and requests for PHI
- Encourages role-based restrictions on data fields
- Does not apply to treatment-related disclosures between providers
Memory trick: Only take the slice of pie you need, not the whole cake of patient data.