AHIMA HIPAA Privacy and Security 3 — Questions and Answers
Question 1: Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of a breach within:
- 24 hours of discovery
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
Correct answer: 60 days of discovery
Covered entities must provide breach notifications to affected individuals without unreasonable delay and no later than 60 days following discovery of the breach.
Question 2: A 'small breach' affecting fewer than 500 individuals in a state must be reported to HHS:
- Within 60 days of the breach
- Annually, no later than 60 days after the end of the calendar year (Correct answer)
- Only if the patient requests it
- Within 30 days and simultaneously to local media
Correct answer: Annually, no later than 60 days after the end of the calendar year
Breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, within 60 days of the end of the calendar year.
Question 3: Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?
- Workstation use policies
- Facility access controls
- Security management process (Correct answer)
- Transmission security
Correct answer: Security management process
The security management process is a required administrative safeguard that includes risk analysis, risk management, sanction policy, and information system activity review.
Question 4: Which of the following best describes 'workforce' under HIPAA?
- Only full-time employees of a covered entity
- Employees, volunteers, trainees, and others under the direct control of the covered entity (Correct answer)
- Only licensed healthcare professionals
- Contractors who sign a BAA
Correct answer: Employees, volunteers, trainees, and others under the direct control of the covered entity
HIPAA defines workforce broadly to include all persons whose conduct is under the direct control of the covered entity, whether or not they are paid.
Question 5: Which right does HIPAA give patients regarding their health records?
- The right to demand deletion of all their PHI
- The right to access and obtain a copy of their PHI (Correct answer)
- The right to prohibit any disclosure including for treatment
- The right to alter clinical notes without provider consent
Correct answer: The right to access and obtain a copy of their PHI
HIPAA's Privacy Rule grants individuals the right to access, inspect, and receive copies of their PHI held by a covered entity.
Question 6: What is the purpose of a HIPAA Risk Analysis?
- To identify all employees who have accessed PHI
- To assess potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- To determine the financial penalties for a breach
- To create a list of all business associates
Correct answer: To assess potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI
A risk analysis identifies and evaluates potential threats and vulnerabilities to ePHI to determine the likelihood and impact of potential risks.
Question 7: Under HIPAA, which entity is primarily responsible for enforcement and imposing civil money penalties?
- The Joint Commission
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
- The American Health Information Management Association
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing HIPAA's Privacy, Security, and Breach Notification Rules.
Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of a breach within: