CCCP Healthcare Compliance & HIPAA 2 — Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, what must a covered entity do when requesting PHI from another covered entity?
- Request all available PHI to ensure completeness
- Limit the request to the minimum PHI reasonably needed for the purpose (Correct answer)
- Submit a formal written authorization signed by the patient
- Obtain approval from the HHS Office for Civil Rights
Correct answer: Limit the request to the minimum PHI reasonably needed for the purpose
The Minimum Necessary Standard requires covered entities to limit PHI requests to only what is reasonably necessary to accomplish the intended purpose.
Question 2: A hospital's compliance officer discovers that a nurse accessed the medical records of a celebrity patient out of curiosity. Under HIPAA, this is best characterized as:
- A breach requiring no further action if the data was not shared
- An impermissible use of PHI that may constitute a reportable breach (Correct answer)
- A permitted disclosure under the treatment exception
- A minor infraction exempt from HIPAA penalties
Correct answer: An impermissible use of PHI that may constitute a reportable breach
Accessing PHI without a permissible purpose—even without external disclosure—is an impermissible use that must be evaluated under the Breach Notification Rule.
Question 3: Which HIPAA rule specifically governs the physical, administrative, and technical safeguards for electronic PHI (ePHI)?
- The Privacy Rule
- The Breach Notification Rule
- The Security Rule (Correct answer)
- The Enforcement Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.
Question 4: A Business Associate Agreement (BAA) under HIPAA must include which of the following provisions?
- A requirement that the BA destroy all PHI within 30 days of contract signing
- Obligations of the BA to report breaches of unsecured PHI to the covered entity (Correct answer)
- A cap on HIPAA civil monetary penalties payable by the BA
- Authorization from HHS before the BA may access any PHI
Correct answer: Obligations of the BA to report breaches of unsecured PHI to the covered entity
BAAs must require business associates to report any discovered breach of unsecured PHI to the covered entity within applicable timeframes.
Question 5: Under the HIPAA Breach Notification Rule, covered entities must notify HHS of breaches affecting fewer than 500 individuals:
- Within 60 days of discovery
- Within 30 days of the calendar year end in which the breach occurred
- Within 60 days of the calendar year end in which the breach occurred (Correct answer)
- Within 10 business days of discovery
Correct answer: Within 60 days of the calendar year end in which the breach occurred
For breaches affecting fewer than 500 individuals, covered entities must notify HHS no later than 60 days after the end of the calendar year in which the breach was discovered.
Question 6: Which of the following is NOT considered a covered entity under HIPAA?
- A health insurance company
- A hospital billing department
- A life insurance company that does not conduct standard electronic transactions (Correct answer)
- A Medicare Advantage plan
Correct answer: A life insurance company that does not conduct standard electronic transactions
Life insurance companies that do not conduct covered electronic transactions are not covered entities under HIPAA.
Question 7: The HITECH Act strengthened HIPAA enforcement by:
- Eliminating civil monetary penalties for good-faith violations
- Extending HIPAA obligations directly to business associates and increasing penalty tiers (Correct answer)
- Replacing the Privacy Rule with state-specific privacy laws
- Requiring HHS to issue a warning before imposing any penalties
Correct answer: Extending HIPAA obligations directly to business associates and increasing penalty tiers
HITECH directly extended HIPAA Privacy and Security Rule obligations to business associates and established a tiered penalty structure with higher maximum fines.
Under HIPAA's Minimum Necessary Standard, what must a covered entity do when requesting PHI from another covered entity?