CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 7 — Questions and Answers
Question 1: Under HIPAA, which of the following entities is considered a 'covered entity' required to comply with the Privacy and Security Rules?
- A marketing firm that purchases patient data for advertising
- A hospital that provides treatment and submits claims electronically (Correct answer)
- A janitorial company that cleans a physician's office
- A software vendor that sells scheduling software to clinics
Correct answer: A hospital that provides treatment and submits claims electronically
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers (such as hospitals) that transmit health information electronically. Marketing firms, janitorial companies, and software vendors are not covered entities, though some may be business associates.
Question 2: What is the 'minimum necessary' standard under HIPAA?
- Patients must provide only the minimum information needed to register
- Covered entities must limit PHI use and disclosure to the least amount needed to accomplish the intended purpose (Correct answer)
- Employees must receive at least a minimum number of HIPAA training hours annually
- Healthcare providers must keep records for a minimum of five years
Correct answer: Covered entities must limit PHI use and disclosure to the least amount needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to use, disclose, or request only the amount of PHI needed to accomplish the purpose, reducing unnecessary exposure of patient information.
Question 3: A patient requests a copy of their own medical records. Under HIPAA, the covered entity must generally provide access within how many days?
- 10 days
- 30 days (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days
HIPAA's Privacy Rule requires covered entities to provide individuals access to their PHI within 30 days of the request, with one possible 30-day extension if the entity notifies the individual in writing.
Question 4: Which of the following best describes a Business Associate Agreement (BAA) under HIPAA?
- A contract between a patient and their insurance provider outlining coverage terms
- A written contract requiring a vendor who handles PHI on behalf of a covered entity to protect that information (Correct answer)
- An internal policy document outlining employee privacy responsibilities
- A government-issued license allowing a healthcare provider to share patient data
Correct answer: A written contract requiring a vendor who handles PHI on behalf of a covered entity to protect that information
A BAA is a legally required contract between a covered entity and a business associate (such as a billing company or IT vendor) that handles PHI. It specifies how the business associate must safeguard the information.
Question 5: Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of an unsecured PHI breach within how many days of discovery?
- 15 days
- 30 days
- 60 days (Correct answer)
- 60 days for small breaches, 30 days for large ones
Correct answer: 60 days
The Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering an unsecured PHI breach. Breaches affecting 500 or more individuals also require media and HHS notification.
Question 6: Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
- Encrypting electronic PHI during transmission
- Using unique usernames and passwords for each workforce member
- Installing locked doors and access controls to limit entry to areas where ePHI is stored (Correct answer)
- Conducting a periodic risk analysis of the organization's information systems
Correct answer: Installing locked doors and access controls to limit entry to areas where ePHI is stored
Physical safeguards under the HIPAA Security Rule refer to physical measures and policies to protect electronic systems and related buildings and equipment from unauthorized access. Locked doors and access controls are classic examples. Encryption and unique logins are technical safeguards; risk analysis is an administrative safeguard.
Under HIPAA, which of the following entities is considered a 'covered entity' required to comply with the Privacy and Security Rules?