CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 2 — Questions and Answers
Question 1: Which of the following is an example of a HIPAA-permitted disclosure of PHI without patient authorization?
- Sharing patient records with a marketing company
- Disclosing PHI to public health authorities to prevent disease spread (Correct answer)
- Providing PHI to an employer for performance reviews
- Releasing records to a patient's neighbor upon request
Correct answer: Disclosing PHI to public health authorities to prevent disease spread
HIPAA permits disclosure of PHI without patient authorization for specific public interest purposes, including public health activities such as disease surveillance and prevention. Marketing, employer use outside treatment, and unauthorized third-party requests do not qualify.
Question 2: What is the minimum necessary standard under HIPAA?
- Employees must receive the minimum required HIPAA training
- Covered entities must share the least amount of PHI needed to accomplish the intended purpose (Correct answer)
- Patients must provide the minimum documentation to access their records
- Security systems must meet the minimum federal encryption standard
Correct answer: Covered entities must share the least amount of PHI needed to accomplish the intended purpose
The minimum necessary standard requires that covered entities make reasonable efforts to limit the use, disclosure, and requests for PHI to the minimum amount needed to accomplish the intended purpose, reducing unnecessary exposure of patient information.
Question 3: Under HIPAA, a Business Associate Agreement (BAA) is required when:
- A patient requests a copy of their own medical records
- A covered entity shares PHI with a vendor who performs services on its behalf (Correct answer)
- An employee discusses a patient's case with a supervising physician
- A hospital transfers a patient to another department internally
Correct answer: A covered entity shares PHI with a vendor who performs services on its behalf
A BAA is a written contract required between a covered entity and a business associate — any third-party vendor or contractor that creates, receives, maintains, or transmits PHI while performing services for the covered entity. Internal staff and patient requests do not require a BAA.
Question 4: Which of the following best describes a 'covered entity' under HIPAA?
- Any business that stores electronic data
- A health plan, healthcare clearinghouse, or healthcare provider that transmits PHI electronically (Correct answer)
- Any employer who provides health insurance to employees
- A government agency that funds Medicare programs
Correct answer: A health plan, healthcare clearinghouse, or healthcare provider that transmits PHI electronically
HIPAA defines covered entities as health plans, healthcare clearinghouses, and healthcare providers that transmit any health information electronically in connection with a covered transaction. General businesses and employers are not automatically covered entities.
Question 5: Which of the following is a required safeguard under the HIPAA Security Rule's physical safeguard standards?
- Encrypting all email communications with patients
- Controlling facility access to systems containing electronic PHI (Correct answer)
- Training staff annually on phishing awareness
- Conducting a workforce HIPAA knowledge survey every two years
Correct answer: Controlling facility access to systems containing electronic PHI
Physical safeguards under the HIPAA Security Rule include measures to control physical access to facilities and workstations where ePHI is stored or processed. Encryption and phishing training fall under technical and administrative safeguards, respectively.
Question 6: A HIPAA breach notification must be sent to affected individuals within how many days of discovering a breach?
- 15 days
- 30 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days following the discovery of a breach of unsecured PHI. For breaches affecting 500 or more residents of a state, media notice and HHS notification are also required within 60 days.
Which of the following is an example of a HIPAA-permitted disclosure of PHI without patient authorization?