CEHRS HIPAA and Patient Confidentiality 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'covered entity'?
- A software developer who sells EHR systems
- A health plan that pays for medical care (Correct answer)
- An employer who manages employee wellness programs internally
- A medical device manufacturer
Correct answer: A health plan that pays for medical care
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
Question 2: What is the maximum civil monetary penalty per violation category for HIPAA violations caused by willful neglect that is not corrected?
- $10,000
- $50,000
- $100,000
- $1,500,000 per year (Correct answer)
Correct answer: $1,500,000 per year
Willful neglect violations that are not corrected carry penalties of up to $50,000 per violation with a $1.5 million annual cap per violation category.
Question 3: A patient requests an amendment to their medical record. Under HIPAA, within how many days must the covered entity respond?
- 30 days
- 60 days (Correct answer)
- 90 days
- 120 days
Correct answer: 60 days
Covered entities must act on a request for amendment within 60 days, with a possible 30-day extension if they notify the individual.
Question 4: Which HIPAA rule specifically requires covered entities to implement technical, administrative, and physical safeguards for electronic PHI?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule requires covered entities and business associates to implement safeguards specifically to protect electronic PHI (ePHI).
Question 5: Under the Minimum Necessary standard, which scenario is EXEMPT from its requirements?
- Disclosures to insurers for payment purposes
- Disclosures to public health authorities
- Disclosures to the patient themselves (Correct answer)
- Disclosures to employers
Correct answer: Disclosures to the patient themselves
The Minimum Necessary standard does not apply to disclosures to or requests by the individual who is the subject of the information.
Question 6: A business associate agreement (BAA) must be established when a covered entity shares PHI with a vendor. Which vendor would NOT require a BAA?
- A billing company that processes claims
- A cloud storage provider hosting ePHI
- A janitorial company that cleans exam rooms (Correct answer)
- A transcription service handling dictated notes
Correct answer: A janitorial company that cleans exam rooms
A janitorial company that cleans exam rooms does not create, receive, maintain, or transmit PHI, so no BAA is required.
Question 7: Which of the following is NOT one of the eight patient rights granted under the HIPAA Privacy Rule?
- Right to access PHI
- Right to request restrictions on disclosures
- Right to receive care at no cost (Correct answer)
- Right to an accounting of disclosures
Correct answer: Right to receive care at no cost
HIPAA grants rights related to privacy and information access, but it does not grant patients the right to receive care at no cost.
Under HIPAA, which of the following is considered a 'covered entity'?