Certified Information Privacy Professional HIPAA Privacy Requirements 2 — Questions and Answers
Question 1: Which de-identification method under HIPAA requires a statistician to certify that risk of identification is very small?
- Expert determination method (Correct answer)
- Safe harbor method
- Limited data set method
- Aggregate anonymization method
Correct answer: Expert determination method
The expert determination method requires a qualified statistician to certify that the risk of identifying individuals is very small using generally accepted principles.
Question 2: What is a 'limited data set' under HIPAA?
- PHI with most direct identifiers removed, used for research, public health, or healthcare operations under a data use agreement (Correct answer)
- Any data set with fewer than 50 records
- PHI that has been fully anonymized
- Data restricted to internal use only
Correct answer: PHI with most direct identifiers removed, used for research, public health, or healthcare operations under a data use agreement
A limited data set has direct identifiers like names and SSNs removed but may still include dates and geographic data at the zip code level or above, shared via data use agreement.
Question 3: Under HIPAA, what is required when a covered entity engages a business associate to perform functions involving PHI?
- A Business Associate Agreement (BAA) must be in place (Correct answer)
- A federal license for the business associate
- HHS approval of the business associate
- A patient consent form for each engagement
Correct answer: A Business Associate Agreement (BAA) must be in place
Covered entities must have a Business Associate Agreement with each business associate, establishing PHI use and protection obligations.
Question 4: Which HIPAA right allows a patient to request that a covered entity not disclose their PHI to their health plan for services paid out-of-pocket?
- Right to request restrictions on disclosures to health plans (Correct answer)
- Right to amend PHI
- Right to access and portability
- Right to file a complaint
Correct answer: Right to request restrictions on disclosures to health plans
HIPAA requires covered entities to honor a patient's request to restrict disclosure to a health plan when the patient pays out-of-pocket in full for a service.
Question 5: What is the HIPAA Privacy Rule's general rule on the use of PHI for marketing?
- PHI cannot be used for marketing without written patient authorization (Correct answer)
- PHI can be used freely for marketing if the covered entity benefits patients
- Marketing using PHI requires only an opt-out opportunity
- PHI may be used for marketing under a business associate agreement
Correct answer: PHI cannot be used for marketing without written patient authorization
The HIPAA Privacy Rule requires covered entities to obtain prior written authorization before using PHI for most marketing communications.
Question 6: Under the HIPAA Privacy Rule, which government entity receives patient complaints about HIPAA violations?
- HHS Office for Civil Rights (OCR) (Correct answer)
- FTC Bureau of Consumer Protection
- State Attorney General offices
- Centers for Medicare & Medicaid Services
Correct answer: HHS Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is the primary enforcement agency for HIPAA Privacy and Security Rule complaints and violations.
Which de-identification method under HIPAA requires a statistician to certify that risk of identification is very small?