HIPAA
TCPA
Medicaid Overview
Real World Combo
100

What does PHI stand for?

What is Protected Health Information

100

TCPA primarily regulates

Phone calls and text messages

100

How is Medicaid funded?

Federal and state 

100

Mbr asks you to text them details re' denied IP stay. You should:

Confirm documented consent before texting PHI

200
Is discussing a mbr's DX in an elevator compliant?
What is not compliant- PHI must be protected from incidental disclosure. 
200

Can you send an automated call to mbr cell w/o consent?

NO- prior express consent is required.

200

Medicaid programs- (what is consistent)

vary by state within federal guidelines

200

Provider faxes clinical records to wrong number. This may be:

A HIPAA breach requiring reporting.

300

Coworker asks you to lookup their cousin's Medicaid coverage status.

Not compliant. You should refuse. Not work related, no need to know this information!


300

Mbr previously gave consent for calls but revokes it today. What do you do?

Stop contacting immediately.

300
In managed Medicaid, UM primarily ensures:

Medical necessity and compliance with state guidelines. 

300

Which situation creates the highest compliance risk?

Discussing PHI in a public space. 

400

Minimum Necessary rule

Access only the PHI needed to perform your job. Only release minimum information needed.

400

You discover a mbr's phone number has been reassigned, what now?

Stop calling that number.
400

Medical necessity decisions must align with-

State Medicaid guidelines and plan criteria
400

Before upholding a Medicaid denial, you must verify:

State guidelines and medical necessity criteria.

500

You accidentally email PHI to wrong provider. First action?

Report to Privacy/Compliance immediately!         Where do you find the report form - for extra points?

500

What requires documented consent?

Texting PHI to member.

500

If a Medicaid service is denied, members must receive:

Written notice with appeal rights. 
500

Mbr says: "I never agreed to receive text msgs" Your best response:

"I'll review consent documentation and stop texts if not authorized"