CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 5 — Questions and Answers
Question 1: Which of the following is NOT considered a covered entity under HIPAA?
- Health insurance companies
- Healthcare clearinghouses
- Medical equipment manufacturers with no patient data access (Correct answer)
- Healthcare providers who transmit health information electronically
Correct answer: Medical equipment manufacturers with no patient data access
Medical equipment manufacturers that do not access, transmit, or maintain PHI are not covered entities under HIPAA. Covered entities are limited to health plans, healthcare clearinghouses, and healthcare providers who conduct covered electronic transactions.
Question 2: Under HIPAA, a patient's right to access their own medical records must generally be fulfilled within how many days?
- 10 days
- 30 days (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days
HIPAA requires covered entities to provide patients access to their PHI within 30 days of the request. A one-time 30-day extension is allowed if the entity notifies the patient of the delay and the reason.
Question 3: What is a Business Associate Agreement (BAA) under HIPAA?
- A contract between two competing hospitals to share patient referrals
- A written contract requiring vendors who handle PHI to protect it according to HIPAA standards (Correct answer)
- An agreement between a patient and provider about billing practices
- A federal registration form submitted to HHS before hiring staff
Correct answer: A written contract requiring vendors who handle PHI to protect it according to HIPAA standards
A BAA is a legally required written contract between a covered entity and a business associate (a vendor or third party that handles PHI on its behalf). It outlines the permitted uses of PHI and the business associate's obligation to safeguard it.
Question 4: Which of the following best describes the 'minimum necessary' standard under the HIPAA Privacy Rule?
- Covered entities must collect the minimum number of patient records per year
- Only the minimum amount of PHI needed to accomplish the intended purpose should be used or disclosed (Correct answer)
- Employees must complete a minimum number of HIPAA training hours annually
- Patients may only request their records once per calendar year
Correct answer: Only the minimum amount of PHI needed to accomplish the intended purpose should be used or disclosed
The minimum necessary standard requires that covered entities make reasonable efforts to limit the use, disclosure, and requests for PHI to only what is needed to accomplish the specific purpose, reducing unnecessary exposure of patient information.
Question 5: Under the HIPAA Breach Notification Rule, if a breach affects 500 or more individuals in a state, the covered entity must notify which of the following within 60 days of discovery?
- The affected patients only
- The Department of Justice and the FBI
- HHS and prominent media outlets in the affected area, in addition to affected individuals (Correct answer)
- The state governor's office and local law enforcement
Correct answer: HHS and prominent media outlets in the affected area, in addition to affected individuals
For breaches affecting 500 or more individuals in a state or jurisdiction, covered entities must notify: the affected individuals, the Secretary of HHS (immediately), and prominent media outlets serving that state — all within 60 days of discovering the breach.
Question 6: Which HIPAA safeguard category requires covered entities to implement policies such as workstation use policies, device disposal procedures, and media re-use controls?
- Administrative safeguards
- Physical safeguards (Correct answer)
- Technical safeguards
- Organizational safeguards
Correct answer: Physical safeguards
Physical safeguards under the HIPAA Security Rule govern the physical access to and protection of electronic PHI and the equipment that stores it. This includes workstation use policies, device and media controls, and facility access controls.
Which of the following is NOT considered a covered entity under HIPAA?