CEHRS Information Management and Privacy 3 — Questions and Answers
Question 1: A breach of unsecured PHI affecting 600 patients requires notification to which entities under the HIPAA Breach Notification Rule?
- Affected individuals only
- Affected individuals and HHS only
- Affected individuals, HHS, and prominent local media outlets (Correct answer)
- HHS and the state attorney general only
Correct answer: Affected individuals, HHS, and prominent local media outlets
Breaches affecting 500 or more individuals in a state require notification to affected individuals, HHS, and prominent media outlets in that state.
Question 2: Which factor is NOT part of the four-factor risk assessment used to determine if a breach of PHI requires notification?
- Nature and extent of PHI involved
- Who accessed or could have accessed the PHI
- The financial cost of the breach investigation (Correct answer)
- Likelihood that PHI was actually compromised
Correct answer: The financial cost of the breach investigation
The HIPAA breach risk assessment evaluates the type of PHI, who accessed it, whether it was actually acquired or viewed, and the extent of mitigation — not investigation costs.
Question 3: Under HITECH, business associates are directly liable for HIPAA compliance. Which of the following is a business associate?
- A patient's family member helping manage care
- A billing company that processes claims containing PHI (Correct answer)
- A hospital board member who never accesses PHI
- A health insurance exchange navigator
Correct answer: A billing company that processes claims containing PHI
A billing company that handles PHI on behalf of a covered entity is a business associate and must sign a Business Associate Agreement.
Question 4: Which encryption standard is most commonly referenced as making PHI 'unusable, unreadable, or indecipherable' under the HIPAA Safe Harbor method?
- MD5 hashing
- NIST-validated encryption processes (Correct answer)
- ROT-13 encoding
- Base64 encoding
Correct answer: NIST-validated encryption processes
HHS guidance specifies that PHI encrypted using NIST-validated cryptographic algorithms qualifies for the breach notification Safe Harbor.
Question 5: A patient's psychotherapy notes are held to a stricter standard than general medical records under HIPAA because they:
- Are always stored separately and require specific authorization for most disclosures (Correct answer)
- Must be destroyed after five years by federal law
- Can only be accessed by psychiatrists, not psychologists
- Are excluded from the EHR system entirely
Correct answer: Are always stored separately and require specific authorization for most disclosures
Psychotherapy notes are specifically protected under HIPAA and generally require patient authorization for disclosure even for TPO purposes, unlike most other PHI.
Question 6: Which organization enforces the HIPAA Privacy and Security Rules for most covered entities?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Drug Enforcement Administration (DEA)
- Joint Commission on Accreditation of Healthcare Organizations
Correct answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services investigates HIPAA complaints and enforces civil monetary penalties.
Question 7: A covered entity discovers a workforce member has been snooping in celebrity patient records out of curiosity. Under HIPAA, this most likely constitutes:
- A minor policy violation requiring only verbal counseling
- A breach of unsecured PHI requiring formal assessment (Correct answer)
- An acceptable use since the employee is authorized to use the EHR
- A disclosure that requires patient notification only if the celebrity requests it
Correct answer: A breach of unsecured PHI requiring formal assessment
Unauthorized access to PHI without a treatment, payment, or operations purpose is a potential breach requiring the four-factor risk assessment and possible notification.
A breach of unsecured PHI affecting 600 patients requires notification to which entities under the HIPAA Breach Notification Rule?