CHC HIPAA Privacy and Security 4 — Questions and Answers
Question 1: Under HIPAA's Security Rule, 'integrity' of ePHI means:
- Only authorized users can access ePHI
- ePHI is not altered or destroyed in an unauthorized manner (Correct answer)
- ePHI is available and accessible when needed by authorized users
- ePHI is encrypted during transmission
Correct answer: ePHI is not altered or destroyed in an unauthorized manner
Integrity under the Security Rule means ensuring that ePHI is not altered or destroyed in an unauthorized manner.
Question 2: A Business Associate Agreement (BAA) must include which of the following provisions?
- A requirement for the BA to obtain malpractice insurance
- Permitted and required uses and disclosures of PHI by the business associate (Correct answer)
- The business associate's annual revenue disclosures
- A provision limiting the BA's subcontractors to US-based firms only
Correct answer: Permitted and required uses and disclosures of PHI by the business associate
A BAA must describe the permitted and required uses and disclosures of PHI that the business associate may make on behalf of the covered entity.
Question 3: Which HIPAA standard governs the electronic exchange of health information for claims and remittance advice?
- The Privacy Rule
- The Security Rule
- The Transactions and Code Sets Rule (Correct answer)
- The Breach Notification Rule
Correct answer: The Transactions and Code Sets Rule
The HIPAA Transactions and Code Sets Rule establishes standards for electronic health care transactions, including claims and remittance advice using ASC X12 standards.
Question 4: A covered entity discovers a breach on March 1. By what date must affected individuals be notified?
- March 31 (within 30 days)
- April 30 (within 60 days) (Correct answer)
- June 1 (within 90 days)
- December 31 (end of calendar year)
Correct answer: April 30 (within 60 days)
Individuals must be notified of a breach without unreasonable delay and no later than 60 days following discovery of the breach.
Question 5: Under HIPAA, which of the following represents a permissible secondary use of PHI for research without patient authorization?
- Sharing identified PHI with a pharmaceutical company for drug marketing
- Using a limited data set with a data use agreement for research (Correct answer)
- Posting patient case studies on a public research website
- Selling de-identified data to a research broker for profit
Correct answer: Using a limited data set with a data use agreement for research
A covered entity may share a limited data set (with certain direct identifiers removed) for research under a data use agreement without patient authorization.
Question 6: Which of the following is an example of a 'physical safeguard' required under the HIPAA Security Rule?
- Automatic logoff after a period of user inactivity
- Policies governing workforce access to ePHI
- Facility access controls limiting physical access to systems containing ePHI (Correct answer)
- Encryption of ePHI during electronic transmission
Correct answer: Facility access controls limiting physical access to systems containing ePHI
Facility access controls, such as locked server rooms and badge access, are physical safeguards under the Security Rule.
Question 7: Under the HIPAA Privacy Rule, which of the following is a required element of a valid patient authorization?
- Witness signature from a licensed clinician
- A statement that the individual may revoke the authorization in writing (Correct answer)
- Notarization of the authorization document
- The specific dollar amount of any payment for the disclosure
Correct answer: A statement that the individual may revoke the authorization in writing
A valid HIPAA authorization must include a statement that the individual has the right to revoke the authorization in writing.
Under HIPAA's Security Rule, 'integrity' of ePHI means: