CHAA - Certified Healthcare Access Associate HIPAA Privacy and Security 8 — Questions and Answers
Question 1: Which of the following is NOT one of the three safeguard categories required by the HIPAA Security Rule?
- Administrative safeguards
- Physical safeguards
- Technical safeguards
- Financial safeguards (Correct answer)
Correct answer: Financial safeguards
The HIPAA Security Rule requires covered entities to implement three categories of safeguards: administrative, physical, and technical. Financial safeguards are not a recognized category under the Security Rule.
Question 2: Under HIPAA, a 'covered entity' includes which of the following?
- A patient's employer
- A health plan that pays for medical services (Correct answer)
- A law firm that does not handle health records
- A janitorial company that cleans a hospital lobby
Correct answer: A health plan that pays for medical services
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. Employers, law firms without health data, and unrelated service vendors are generally not covered entities.
Question 3: What is the maximum period a patient generally has to request their own medical records from a covered entity under the HIPAA Privacy Rule?
- 15 days
- 30 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
The HIPAA Privacy Rule requires covered entities to provide access to a patient's records within 30 days, with a possible 30-day extension if needed, making the outer limit 60 days. Patients do not have to wait 90 days.
Question 4: Which HIPAA concept allows a covered entity to share PHI for treatment, payment, and healthcare operations WITHOUT obtaining the patient's written authorization?
- Minimum necessary standard
- Permitted disclosure (Correct answer)
- Business associate agreement
- Notice of Privacy Practices
Correct answer: Permitted disclosure
HIPAA allows 'permitted disclosures' — sharing PHI for treatment, payment, and healthcare operations (TPO) without written patient authorization. This is distinct from voluntary disclosures that do require authorization.
Question 5: A hospital employee accesses the medical record of a celebrity patient out of curiosity, even though they are not involved in that patient's care. This is a violation of which HIPAA principle?
- The breach notification rule
- The minimum necessary standard (Correct answer)
- The business associate rule
- The de-identification standard
Correct answer: The minimum necessary standard
The minimum necessary standard requires employees to access only the PHI needed to perform their job duties. Accessing records out of curiosity — with no treatment, payment, or operations purpose — violates this core HIPAA principle.
Question 6: Under the HIPAA Breach Notification Rule, how soon must a covered entity notify affected individuals after discovering a breach of unsecured PHI?
- Within 24 hours
- Within 30 days
- Within 60 days (Correct answer)
- Within 90 days
Correct answer: Within 60 days
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.
Which of the following is NOT one of the three safeguard categories required by the HIPAA Security Rule?