Certified Information Privacy Professional HIPAA Privacy Requirements 1 — Questions and Answers
Question 1: Which of the following is NOT a permitted use or disclosure of PHI under the HIPAA Privacy Rule without patient authorization?
- Marketing campaigns selling health products (Correct answer)
- Treatment of the patient
- Payment for health services
- Healthcare operations like quality improvement
Correct answer: Marketing campaigns selling health products
Marketing activities that use PHI to encourage purchase of products require patient authorization; treatment, payment, and healthcare operations are permitted without it.
Question 2: What is the HIPAA 'minimum necessary' standard?
- Covered entities must make reasonable efforts to use only the minimum PHI necessary for the intended purpose (Correct answer)
- Patients can only access the minimum amount of their own records
- Only the minimum number of employees may handle PHI
- Business associates must delete PHI within a minimum timeframe
Correct answer: Covered entities must make reasonable efforts to use only the minimum PHI necessary for the intended purpose
The minimum necessary standard requires covered entities to limit PHI use and disclosure to the least amount needed to accomplish the intended purpose.
Question 3: Under HIPAA, patients have the right to access their PHI within how many days of requesting it?
- 30 days, extendable once by 30 additional days (Correct answer)
- 7 days
- 60 days with no extension
- 90 days with one 30-day extension
Correct answer: 30 days, extendable once by 30 additional days
Covered entities must provide access to PHI within 30 days, with the ability to extend once by an additional 30 days with written explanation.
Question 4: Which type of entity is directly covered by HIPAA's Privacy Rule?
- Covered entities (health plans, providers, clearinghouses) (Correct answer)
- Any company that collects health data
- All employers who maintain employee health records
- All software companies handling health data
Correct answer: Covered entities (health plans, providers, clearinghouses)
HIPAA directly covers 'covered entities': health plans, healthcare providers that transmit PHI electronically, and healthcare clearinghouses.
Question 5: What does a HIPAA Notice of Privacy Practices (NPP) require?
- A description of how the covered entity uses and discloses PHI and patients' rights (Correct answer)
- A complete list of every employee with PHI access
- A financial statement of PHI processing costs
- Proof that all PHI is encrypted
Correct answer: A description of how the covered entity uses and discloses PHI and patients' rights
The NPP must inform patients how their PHI may be used and disclosed, their privacy rights, and the covered entity's legal duties regarding PHI.
Question 6: Under HIPAA, a covered entity must provide an individual an accounting of disclosures of their PHI for a period of up to how many years?
- 6 years prior to the date of the request (Correct answer)
- 3 years prior to the date of the request
- 1 year prior to the date of the request
- 10 years prior to the date of the request
Correct answer: 6 years prior to the date of the request
Individuals have the right to an accounting of PHI disclosures made in the 6 years prior to the request, excluding disclosures for TPO.
Which of the following is NOT a permitted use or disclosure of PHI under the HIPAA Privacy Rule without patient authorization?