AAPC HIPAA & Healthcare Compliance Regulations 2 — Questions and Answers
Question 1: What is the 'minimum necessary' standard under HIPAA?
- The minimum number of billing staff required
- The principle that only the minimum amount of PHI necessary to accomplish the purpose should be used or disclosed (Correct answer)
- The minimum documentation required for billing
- The smallest co-pay amount allowed
Correct answer: The principle that only the minimum amount of PHI necessary to accomplish the purpose should be used or disclosed
The minimum necessary standard requires that covered entities limit PHI use and disclosure to only what is reasonably necessary for the intended purpose.
Question 2: Under HIPAA, when is a patient authorization required to disclose PHI?
- For treatment purposes between providers
- For disclosures to third parties for purposes other than treatment, payment, or healthcare operations (Correct answer)
- For billing insurance companies
- For public health reporting
Correct answer: For disclosures to third parties for purposes other than treatment, payment, or healthcare operations
A written patient authorization is required for disclosures beyond treatment, payment, healthcare operations, and other permitted purposes outlined in the Privacy Rule.
Question 3: Which federal agency is primarily responsible for enforcing HIPAA?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Department of Justice (DOJ)
- Federal Trade Commission (FTC)
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) enforces the HIPAA Privacy, Security, and Breach Notification Rules.
Question 4: What is a Notice of Privacy Practices (NPP) under HIPAA?
- A government report on data breaches
- A document that informs patients how their health information may be used and their privacy rights (Correct answer)
- An insurance prior authorization form
- A compliance audit report
Correct answer: A document that informs patients how their health information may be used and their privacy rights
Covered entities must provide patients with an NPP describing how PHI is used, patient rights, and the entity's legal duties regarding PHI.
Question 5: What is the maximum civil penalty per violation category under HIPAA for 'willful neglect — not corrected'?
- $100 per violation
- $1,000 per violation
- $10,000 per violation
- $50,000 per violation with a $1.9 million annual cap (Correct answer)
Correct answer: $50,000 per violation with a $1.9 million annual cap
The highest HIPAA penalty tier for willful neglect that is not corrected is $50,000 per violation, with an annual cap of $1.9 million for identical violations.
Question 6: What is the HIPAA Breach Notification Rule?
- A rule requiring providers to notify the IRS of billing errors
- A requirement to notify affected individuals, HHS, and sometimes the media following a breach of unsecured PHI (Correct answer)
- A rule about notifying payers of coding changes
- A requirement to report all claim denials
Correct answer: A requirement to notify affected individuals, HHS, and sometimes the media following a breach of unsecured PHI
The Breach Notification Rule requires covered entities to notify patients within 60 days of discovering a breach, and to notify HHS and possibly media for large breaches.
What is the 'minimum necessary' standard under HIPAA?