CHC HIPAA Privacy and Security 5 — Questions and Answers
Question 1: A workforce member accesses the records of a celebrity patient out of curiosity without clinical need. This is best described as:
- An incidental disclosure permissible under HIPAA
- A HIPAA Privacy Rule violation due to impermissible access (Correct answer)
- A permissible use for quality improvement purposes
- An authorized disclosure for treatment operations
Correct answer: A HIPAA Privacy Rule violation due to impermissible access
Accessing PHI without a legitimate purpose violates the minimum necessary and permissible use standards of the HIPAA Privacy Rule.
Question 2: Under HIPAA, when must a covered entity obtain a patient's written authorization before disclosing PHI?
- For disclosures to the patient's treating specialists
- For most marketing communications using PHI (Correct answer)
- For reporting communicable diseases to public health authorities
- For disclosures in judicial proceedings pursuant to a court order
Correct answer: For most marketing communications using PHI
Most marketing communications that use PHI require the patient's written authorization under the HIPAA Privacy Rule.
Question 3: Which of the following correctly describes the HIPAA 'Safe Harbor' method of de-identification?
- An expert statistician certifies the risk of re-identification is very small
- 18 specific categories of identifiers are removed and the entity has no actual knowledge the data could re-identify the individual (Correct answer)
- The data is encrypted using AES-256 encryption
- The data is aggregated at the state level to prevent re-identification
Correct answer: 18 specific categories of identifiers are removed and the entity has no actual knowledge the data could re-identify the individual
The Safe Harbor method requires removal of 18 specific identifier categories and a statement that the covered entity has no actual knowledge the remaining information could identify the individual.
Question 4: Under the HITECH Act, which party became directly liable for compliance with certain HIPAA Security Rule provisions?
- Covered entities only
- Business associates directly, not just through BAAs (Correct answer)
- Patients and their authorized representatives
- HHS Office for Civil Rights investigators
Correct answer: Business associates directly, not just through BAAs
HITECH made business associates directly liable for compliance with many HIPAA Security Rule and Privacy Rule provisions, not just contractually liable through BAAs.
Question 5: A hospital workforce member loses an unencrypted laptop containing PHI for 800 patients. Which statement is correct?
- No breach notification is required if the laptop is recovered within 60 days
- This is a presumed breach requiring notification unless the four-factor risk assessment shows low probability of compromise (Correct answer)
- Encryption status is irrelevant to determining whether a breach occurred
- Breach notification is only required if the PHI included financial information
Correct answer: This is a presumed breach requiring notification unless the four-factor risk assessment shows low probability of compromise
Loss of an unencrypted laptop with PHI is a presumed breach under the Omnibus Rule, requiring notification unless a risk assessment demonstrates low probability that PHI was compromised.
Question 6: What is the role of the HIPAA Privacy Officer in a covered entity?
- To conduct all external audits of business associates
- To be responsible for development and implementation of privacy policies and procedures (Correct answer)
- To personally review every request for PHI access
- To negotiate all business associate agreements on behalf of the organization
Correct answer: To be responsible for development and implementation of privacy policies and procedures
The HIPAA Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Question 7: Which of the following scenarios describes a permissible incidental disclosure under HIPAA?
- A nurse loudly announces a patient's HIV status in a crowded waiting room
- A hospital staff member discusses a patient's condition in a hallway while taking reasonable precautions to limit overheard information (Correct answer)
- A receptionist emails a patient's full medical record to the wrong address
- A billing employee shares PHI with an unaffiliated third party for curiosity
Correct answer: A hospital staff member discusses a patient's condition in a hallway while taking reasonable precautions to limit overheard information
Incidental disclosures that occur as a byproduct of otherwise permissible communications are allowed if the covered entity has reasonable safeguards in place and follows minimum necessary standards.
A workforce member accesses the records of a celebrity patient out of curiosity without clinical need.
This is best described as: