Electronic Health Records and HIPAA: The CCMA's Confidentiality Discipline
Why EHR and HIPAA are on the CCMA exam
The NHA CCMA exam content outline places both electronic health records (EHRs) and the Health Insurance Portability and Accountability Act (HIPAA) in the administrative domain. The exam tests the candidate's ability to navigate the EHR accurately and to handle protected health information (PHI) in compliance with federal law. These are not abstract questions — every patient encounter involves the EHR, and every action with PHI is governed by HIPAA. A candidate who can demonstrate competence in both passes the exam and protects every patient in their care.
This post covers the EHR functionality the CCMA uses daily, the HIPAA Privacy Rule and Security Rule, the practical safeguards the CCMA applies at every encounter, and the exam's favorite questions on confidentiality.
EHR fundamentals
An electronic health record is a digital version of a patient's paper chart. The EHR is used by providers, nurses, medical assistants, billing staff, and other authorized personnel to document care, communicate, and bill for services. EHRs vary by vendor (Epic, Cerner, Athena, eClinicalWorks, etc.), but the core functions are similar.
Core functions
- Patient registration — demographics, insurance, allergies, problem list, medication list.
- Encounter documentation — chief complaint, history of present illness, review of systems, physical exam, assessment and plan. The provider documents the visit; the CCMA may document portions (vital signs, intake questions, screenings, patient education).
- Order entry (CPOE) — computerized provider order entry. The provider enters orders for medications, labs, imaging, and referrals; the CCMA may enter orders per protocol or under provider direction.
- Results review — lab results, imaging reports, and consult notes are reviewed and signed by the provider.
- E-prescribing — prescriptions sent electronically to the pharmacy.
- Clinical decision support — alerts for drug interactions, allergies, preventive care gaps, and abnormal results.
- Patient portal — secure messaging, appointment scheduling, test result review, and access to portions of the medical record for patients.
- Billing and coding — integrated with the practice management system to generate claims.
- Reporting — quality measures, public health reporting, registry data.
CCMA documentation in the EHR
The CCMA typically documents:
- Patient intake — chief complaint, vital signs, allergies, medications, smoking status, screening questionnaire responses.
- Procedures performed — injections, EKGs, ear lavage, wound care.
- Patient education provided.
- Communication with the patient — phone calls, portal messages, no-shows.
- Care coordination — referrals, pre-authorizations, prior authorizations, durable medical equipment orders.
The CCMA's entries are authenticated with a unique password and may be co-signed by the provider for certain elements (e.g., the medication reconciliation or the patient education).
HIPAA: the law and the rules
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the federal law that governs the privacy and security of protected health information. The Department of Health and Human Services (HHS) enforces HIPAA through two main rules:
The Privacy Rule
Establishes the standards for the protection of individually identifiable health information. Applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically) and their business associates.
Protected health information (PHI) is any individually identifiable health information held or transmitted by a covered entity or its business associate. PHI includes 18 identifiers:
- Names.
- Geographic subdivisions smaller than a state (street, city, county, ZIP, except first three digits for populations over 20,000).
- Dates (birth, admission, discharge, death; ages over 89).
- Telephone numbers.
- Fax numbers.
- Email addresses.
- Social Security numbers.
- Medical record numbers.
- Health plan beneficiary numbers.
- Account numbers.
- Certificate and license numbers.
- Vehicle identifiers and serial numbers, including license plate.
- Device identifiers and serial numbers.
- URLs.
- IP addresses.
- Biometric identifiers (fingerprints, voice prints).
- Full-face photographs.
- Any other unique identifying number, characteristic, or code.
De-identified information (with all 18 identifiers removed) is not PHI and is not subject to HIPAA.
The Security Rule
Establishes the standards for protecting electronic PHI (ePHI). Three categories of safeguards:
- Administrative safeguards — workforce training, access management, security policies, contingency planning.
- Physical safeguards — facility access controls, workstation use and security, device and media controls.
- Technical safeguards — access control (unique user IDs, automatic logoff, encryption), audit controls, integrity controls, transmission security.
What the Privacy Rule permits
PHI may be used or disclosed by a covered entity without the patient's written authorization for three purposes:
- Treatment — providing care to the patient. The CCMA may share PHI with other providers involved in the patient's care.
- Payment — billing and collection activities. The CCMA may share PHI with the insurance company.
- Healthcare operations — quality improvement, training, credentialing, audits. The CCMA may use PHI for internal operations.
Any other use or disclosure requires the patient's written authorization. Examples requiring authorization:
- Marketing communications (with exceptions).
- Sale of PHI.
- Psychotherapy notes (in most cases).
- Release to an employer, attorney, or other third party not involved in TPO.
- Most research (with exceptions).
Patient rights under HIPAA
The Privacy Rule grants patients these rights:
- Right to access — the patient may request a copy of their PHI. The provider must respond within 30 days.
- Right to amend — the patient may request corrections to their PHI. The provider must respond within 60 days.
- Right to an accounting of disclosures — the patient may request a list of disclosures of their PHI for purposes other than TPO.
- Right to request restrictions — the patient may request that the provider limit uses or disclosures of PHI. The provider is not required to agree unless the patient pays out of pocket and requests restriction of disclosure to the insurance company.
- Right to confidential communications — the patient may request to be contacted at a specific location or by a specific method (e.g., cell phone only, work phone only).
- Right to a copy of the Notice of Privacy Practices — the patient must receive the NPP at the first encounter and upon request.
Practical safeguards the CCMA applies
At the workstation
- Screen lock — lock the workstation when stepping away, even for a moment. Most EHRs have an automatic lockout after a short period of inactivity (e.g., 5 minutes).
- Position the screen away from public view. Use privacy screens in high-traffic areas.
- Log out at the end of the shift.
- Never share your password with anyone, including coworkers. The audit log will show your user ID on every entry.
- Use only your own login — never document under another user's credentials.
In communication
- Phone — verify the patient's identity before sharing PHI. Use only the contact numbers the patient has authorized.
- Email — use only secure, encrypted email for PHI. Verify the recipient's address before sending.
- Texting — avoid texting PHI unless using a secure messaging platform approved by the practice. SMS is not HIPAA-compliant.
- Voicemail — leave only the minimum necessary information (e.g., "Please call the office" without details about the reason). Some practices have a policy of not leaving messages at all without specific consent.
- Patient portal — encourage patients to use the portal for non-urgent communication. The portal is encrypted and audit-trailed.
In the office
- Verbal conversations — conducted in private areas, away from waiting rooms. Lower your voice. Do not discuss PHI in elevators, hallways, or break rooms.
- Paper records — stored in secure areas, not left unattended at the front desk. Turn charts face-down. Do not leave PHI on counters.
- Shredding — PHI on paper is shredded before disposal. Many offices use locked shred bins emptied by a shredding service.
- Faxing — verify the fax number before sending. Call the recipient to confirm receipt. Use a fax cover sheet that includes a confidentiality notice.
In the EHR
- Minimum necessary — access, use, and disclose only the minimum PHI necessary to accomplish the purpose. This is a fundamental HIPAA principle the exam tests repeatedly.
- Audit logs — the EHR tracks every access to PHI. Unauthorized access is a HIPAA violation and may be grounds for termination and legal action.
- Breach notification — if PHI is compromised (lost laptop, hacked system, unauthorized access), the covered entity must notify the patient, HHS, and in some cases the media. Breach notification requirements are part of the HITECH Act (part of the American Recovery and Reinvestment Act of 2009).
Special situations
Minors
A minor's PHI is generally controlled by the parent or legal guardian, with exceptions for certain types of care (e.g., reproductive health, mental health, substance abuse treatment) where state law may allow the minor to consent and control access. The exam tests that the CCMA knows to verify state-specific minor consent laws.
Family members
The CCMA may share PHI with family members if the patient is present and does not object. If the patient is not present or is incapacitated, the CCMA may share PHI with family members involved in the patient's care, but only the minimum necessary. The CCMA may not share PHI with family members against the patient's expressed wishes.
Public health
PHI may be disclosed to public health authorities for the reporting of certain diseases, injuries, and vital events (births, deaths). Examples: tuberculosis, hepatitis, sexually transmitted infections, gunshot wounds. The CCMA reports per state law.
Law enforcement
PHI may be disclosed to law enforcement under specific circumstances: in response to a court order, subpoena, or warrant; to identify or locate a suspect, fugitive, or missing person under specific conditions; to alert law enforcement of a crime; and in response to a medical emergency.
Abuse, neglect, or domestic violence
HIPAA permits disclosure of PHI to authorities if the provider reasonably believes the patient is a victim of abuse, neglect, or domestic violence. State laws vary on mandatory reporting; the CCMA follows the state's requirements and the practice's policy.
HIPAA violations and penalties
Violations may be civil or criminal:
- Civil penalties — $100 to $50,000 per violation, with annual caps based on culpability.
- Criminal penalties — fines up to $250,000 and imprisonment up to 10 years for the most serious violations (knowingly obtaining or disclosing PHI for personal gain or malicious harm).
Common violations include unauthorized access (looking up a celebrity or a friend's record without a need), lost or stolen devices with unencrypted PHI, and disposal of PHI without proper safeguards.
The exam's favorite HIPAA questions
Question type 1: "A CCMA accesses the medical record of a coworker who is not under their care. What is the HIPAA consequence?" — Answer: this is an unauthorized access and a violation. The CCMA may be disciplined by the employer, sanctioned by the OCR, and in some cases face criminal charges.
Question type 2: "A patient's spouse calls to ask about the patient's lab results. The patient has not authorized this disclosure. What is the CCMA's response?" — Answer: inform the spouse that the patient must give written authorization before PHI can be released. Do not share any PHI without authorization.
Question type 3: "A CCMA steps away from the workstation without logging out, and a patient in the waiting room sees another patient's PHI on the screen. What is the consequence?" — Answer: this is a HIPAA violation and a breach. The CCMA and the practice may be subject to sanctions. The CCMA must lock the workstation when stepping away.
Question type 4: "Under what circumstances may PHI be released without the patient's authorization?" — Answer: for treatment, payment, and healthcare operations (TPO), and as required by law (public health reporting, court orders, abuse reporting).
A practical closing note
HIPAA is the discipline that protects every patient. The CCMA who locks the workstation, verifies identity before sharing PHI, and applies the minimum-necessary standard at every encounter practices the standard the exam rewards and the law requires.
Practice the safeguards until they are habit. Practice the patient rights until you can recite them. Practice the breach scenarios until the response is reflex. The CCMA who owns confidentiality owns the patient's trust.
For EHR and HIPAA practice — privacy rule, security rule, patient rights, and breach scenarios — visit the ExamReady CCMA prep site. Every question is mapped to the NHA CCMA content outline so you study exactly what the exam will ask.