CCT HIPAA Privacy and Security 3 — Questions and Answers
Question 1: A hospital's employee inappropriately accesses the medical records of a celebrity patient. Which type of HIPAA breach is this?
- Environmental breach
- Unauthorized internal access (Correct answer)
- Physical theft
- Accidental disclosure
Correct answer: Unauthorized internal access
Accessing PHI without a valid treatment, payment, or operations reason by an insider constitutes unauthorized internal access, a common HIPAA violation.
Question 2: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within:
- 10 calendar days
- 30 calendar days
- 60 calendar days (Correct answer)
- 1 year
Correct answer: 60 calendar days
The Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 calendar days of discovering the breach.
Question 3: What is 'minimum necessary' under HIPAA?
- Using only the minimum number of employees to handle PHI
- Disclosing only the PHI needed to accomplish the intended purpose (Correct answer)
- Storing PHI on the smallest possible server
- Encrypting the minimum number of files required
Correct answer: Disclosing only the PHI needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to limit PHI use and disclosure to what is needed for the specific purpose.
Question 4: Which of the following is a permitted use of PHI WITHOUT patient authorization under HIPAA?
- Marketing a health product
- Disclosing PHI to an employer for employment decisions
- Public health activities to control disease (Correct answer)
- Selling PHI to a data broker
Correct answer: Public health activities to control disease
HIPAA permits disclosure of PHI for public health activities, such as reporting disease outbreaks, without patient authorization.
Question 5: A covered entity discovers a breach on March 1. By what date must it notify the Secretary of HHS if fewer than 500 individuals are affected?
- Within 60 days of discovery
- Within 60 days of the following calendar year (by March 1 of the next year) (Correct answer)
- By March 31 of the same year
- Within 30 days of discovery
Correct answer: Within 60 days of the following calendar year (by March 1 of the next year)
For breaches affecting fewer than 500 individuals, covered entities must log and report to HHS annually, no later than 60 days after the end of the calendar year in which the breach occurred.
Question 6: Under HIPAA, which of the following is a physical safeguard required by the Security Rule?
- Audit controls on ePHI access logs
- Facility access controls to limit physical access to systems containing ePHI (Correct answer)
- Encryption of data in transit
- Automatic logoff after inactivity
Correct answer: Facility access controls to limit physical access to systems containing ePHI
Facility access controls are a required physical safeguard under the HIPAA Security Rule, governing who may physically enter areas housing ePHI.
Question 7: A covered entity may deny a patient's request to amend their PHI if:
- The amendment would increase the size of the medical record
- The PHI was not created by the covered entity (Correct answer)
- The patient submits the request verbally
- More than 15 days have passed since the original record was created
Correct answer: The PHI was not created by the covered entity
A covered entity may deny an amendment request if it did not create the PHI and the originating entity is available to act on the request.
A hospital's employee inappropriately accesses the medical records of a celebrity patient.
Which type of HIPAA breach is this?