Medical Law and Ethics — practice questions

4.7% of the exam ≈7 real questions 7 free questions here

7 scored items — the smallest domain, but the one where a wrong answer in real life is most costly. HIPAA, consent, scope of practice, documentation and mandatory reporting.

Where people lose points

Drill: Medical Law and Ethics

7 free questions from this domain, each with an explanation and a cited source. Timed at real exam pace.

7 questions

Pass line: 78%, same as the real exam

See the answer and explanation right after each question.

Questions and answers, explained

All 2 questions above, with the correct answer and why it is correct. Everything here is on medical law and ethics.

  1. A medical assistant posts a photo of a patient's healing surgical wound on her personal social media account. No name appears, but a distinctive tattoo and the clinic's name are visible in the picture. Is this permissible?

    • ANo — an identifiable image is PHI and needs written authorizationCorrect
    • BYes, because no name, date of birth, or record number appears
    • CYes, if the account is private and only friends can see the post
    • DNo, unless the medical assistant deletes the post within 24 hours

    Why: Full-face photographs and comparable images are one of the 18 safe-harbor identifiers, but an image does not have to show a face to be protected health information: 45 CFR 164.514(b)(2)(i)(R) also covers any other unique identifying characteristic, and a distinctive tattoo paired with the clinic name makes this patient reasonably identifiable. Disclosing the image therefore requires the patient's written authorization under 45 CFR 164.508. Stripping the name is not de-identification, and privacy settings, the near-miss in option C, do not change the legal character of the disclosure. Deleting the post later does not undo it either; the incident must be reported through the practice's breach process.

    Reference Domain 7, task 7E, k214; HIPAA de-identification safe harbor 45 CFR 164.514(b)(2)(i)(Q) and (R); authorization requirement 45 CFR 164.508; HHS OCR de-identification guidance

  2. A paralegal from a law firm comes to the front desk with a subpoena signed by the attorney in a malpractice suit. He asks the medical assistant to confirm that a named person was seen this morning and to print that chart. No court order is attached, and nothing shows the patient was notified. What should the medical assistant do?

    • AConfirm the visit but explain that the chart itself cannot be printed
    • BRelease nothing and refer the request to the provider or privacy officerCorrect
    • CPrint the chart, since a subpoena is a legal demand that must be obeyed
    • DConfirm nothing today and tell him to return with the patient's consent

    Why: Confirming that a named individual was treated is itself a disclosure of protected health information, so both halves of the request get the same answer. A subpoena signed only by an attorney is not a court order: under 45 CFR 164.512(e), protected health information may be released in response to such a subpoena only when the practice has documented satisfactory assurances — notice to the patient with an opportunity to object, or a qualified protective order — while a court order authorizes only the information it expressly names. Judging whether those assurances exist is the privacy officer's or provider's call, not the medical assistant's. Option D sounds appropriately cautious but wrongly implies that patient consent is the only lawful route; a subpoena backed by satisfactory assurances can compel release without it.

    Reference Domain 7, task 7E, k220 (conditions for sharing information/release of information); HIPAA Privacy Rule 45 CFR 164.512(e) (judicial and administrative proceedings; satisfactory assurances; qualified protective order)

Topics inside this domain

Drill other domains

← Back to the full practice exam