CHC HIPAA Privacy and Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- A patient's name combined with their diagnosis
- De-identified health data that meets Safe Harbor standards (Correct answer)
- A patient's medical record number
- A patient's date of birth combined with their ZIP code
Correct answer: De-identified health data that meets Safe Harbor standards
De-identified data that meets HIPAA's Safe Harbor or Expert Determination standards is not PHI and is not subject to HIPAA protections.
Question 2: A covered entity experiences a breach affecting 600 individuals. What is the notification deadline to the Secretary of HHS?
- Immediately upon discovery
- Within 60 days of discovery (Correct answer)
- Within 60 days of the end of the calendar year
- Within 30 days of discovery
Correct answer: Within 60 days of discovery
Breaches affecting 500 or more individuals must be reported to HHS within 60 days of discovery.
Question 3: What is the HIPAA Security Rule's requirement for a covered entity's risk analysis?
- It must be conducted only at initial implementation
- It must be conducted annually regardless of changes
- It must be an accurate and thorough assessment of risks to ePHI (Correct answer)
- It must be performed by an outside third-party auditor
Correct answer: It must be an accurate and thorough assessment of risks to ePHI
The Security Rule requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability.
Question 4: Under the HIPAA Privacy Rule, a patient's right to request restrictions on use or disclosure of their PHI means the covered entity:
- Must honor all patient restriction requests without exception
- Must honor requests to restrict disclosures to health plans for services paid out-of-pocket in full (Correct answer)
- Must honor requests only if the restriction is in writing
- May deny all restriction requests at its discretion
Correct answer: Must honor requests to restrict disclosures to health plans for services paid out-of-pocket in full
Covered entities must agree to a patient's request to restrict disclosures to health plans when the patient pays for the service entirely out-of-pocket.
Question 5: Which HIPAA Security Rule safeguard category includes policies and procedures to manage the selection and use of technical security measures?
- Physical safeguards
- Administrative safeguards (Correct answer)
- Technical safeguards
- Organizational requirements
Correct answer: Administrative safeguards
Administrative safeguards include policies and procedures that govern the selection and use of technical and physical security measures to protect ePHI.
Question 6: A healthcare provider shares PHI with a medical billing company. Under HIPAA, the billing company is classified as a:
- Covered entity
- Business associate (Correct answer)
- Hybrid entity
- Downstream contractor
Correct answer: Business associate
A medical billing company that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate under HIPAA.
Question 7: The HIPAA Breach Notification Rule's 'harm threshold' was eliminated by which regulation, requiring notification for all breaches unless the low probability of compromise is demonstrated?
- The HITECH Act of 2009
- The Omnibus Rule of 2013 (Correct answer)
- The Privacy Rule of 2003
- The Security Rule of 2005
Correct answer: The Omnibus Rule of 2013
The 2013 Omnibus Rule replaced the harm threshold with a four-factor risk assessment, requiring notification unless the covered entity demonstrates a low probability that PHI was compromised.
Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?