CCT HIPAA Privacy and Security 5 — Questions and Answers
Question 1: What is a 'hybrid entity' under HIPAA?
- An entity that operates both as a covered entity and a business associate for different clients
- A single legal entity that performs both covered and non-covered functions, and has designated its healthcare components (Correct answer)
- A covered entity with both physical and electronic records
- A business associate that also provides direct patient care
Correct answer: A single legal entity that performs both covered and non-covered functions, and has designated its healthcare components
A hybrid entity is a single organization that performs both covered and non-covered functions, and HIPAA applies only to its designated healthcare component(s).
Question 2: Under the HIPAA Security Rule, which of the following is a 'required' (not addressable) implementation specification?
- Encryption of ePHI at rest
- Automatic logoff
- Unique user identification for each system user (Correct answer)
- Encryption and decryption of ePHI
Correct answer: Unique user identification for each system user
Unique user identification is a required implementation specification under the Access Control standard of the HIPAA Security Rule's Technical Safeguards.
Question 3: If a business associate discovers a breach of PHI, they must notify the covered entity within:
- 24 hours
- 60 calendar days of discovery
- 30 calendar days of discovery
- Without unreasonable delay and no later than 60 calendar days of discovery (Correct answer)
Correct answer: Without unreasonable delay and no later than 60 calendar days of discovery
Business associates must notify covered entities of PHI breaches without unreasonable delay and within 60 calendar days of discovering the breach.
Question 4: Which of the following scenarios qualifies as a HIPAA-compliant 'de-identification' method?
- Replacing patient names with pseudonyms while retaining zip codes
- Removing all 18 specific identifiers listed in the Safe Harbor method (Correct answer)
- Encrypting PHI with a key held by the covered entity
- Storing PHI on a password-protected server
Correct answer: Removing all 18 specific identifiers listed in the Safe Harbor method
The Safe Harbor method requires removal of all 18 enumerated identifiers, after which the data is no longer considered PHI under HIPAA.
Question 5: A covered entity may share PHI with a patient's family member without authorization when:
- The family member is a licensed healthcare provider
- The patient is present and does not object, or the covered entity can infer from the circumstances that the patient would not object (Correct answer)
- The family member presents a subpoena
- The patient is over 65 years old
Correct answer: The patient is present and does not object, or the covered entity can infer from the circumstances that the patient would not object
When a patient is present and does not object, or when a provider infers non-objection from circumstances, PHI directly relevant to the family member's involvement in care may be shared.
Question 6: Under HIPAA's 'right to restrict' provision, a covered entity MUST honor a patient's request to restrict disclosure of PHI when:
- The patient submits the request in writing
- The disclosure is to a health plan for payment purposes and the patient paid out-of-pocket in full for the service (Correct answer)
- The restriction applies to TPO disclosures generally
- The patient is a minor
Correct answer: The disclosure is to a health plan for payment purposes and the patient paid out-of-pocket in full for the service
HIPAA requires covered entities to honor restriction requests when a patient pays out-of-pocket in full and asks that the information not be disclosed to their health plan for payment purposes.
Question 7: Which of the following is the correct hierarchy of HIPAA civil monetary penalty tiers (lowest to highest culpability)?
- Willful neglect corrected → Willful neglect uncorrected → Reasonable cause → Unknowing
- Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected (Correct answer)
- Reasonable cause → Unknowing → Willful neglect corrected → Willful neglect uncorrected
- Unknowing → Willful neglect corrected → Reasonable cause → Willful neglect uncorrected
Correct answer: Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected
HIPAA penalty tiers escalate from unknowing violations, to reasonable cause, to willful neglect that is corrected, to willful neglect that is not corrected.
What is a 'hybrid entity' under HIPAA?