CHISSP CHISSP HIPAA Compliance & Healthcare Data Privacy 2 โ Questions and Answers
Question 1: Under the HIPAA Breach Notification Rule, what is the deadline for notifying affected individuals after discovery of a breach affecting fewer than 500 patients?
- Within 60 days of end of the calendar year in which the breach was discovered (Correct answer)
- Within 60 days of breach discovery
- Within 30 days of breach discovery
- Within 90 days of breach discovery
Correct answer: Within 60 days of end of the calendar year in which the breach was discovered
For breaches affecting fewer than 500 individuals, covered entities must notify affected patients within 60 days of the end of the calendar year, though prompt notification is encouraged.
Question 2: A ransomware attack encrypts ePHI on a hospital's servers. Under HIPAA Breach Notification Rule guidance, how should this be treated?
- Presumed a reportable breach unless the entity can demonstrate low probability of PHI compromise (Correct answer)
- Not a breach because no data left the organization's control
- A breach only if the attacker publicly released the data
- Not a breach if the encrypted data is restored from backup within 72 hours
Correct answer: Presumed a reportable breach unless the entity can demonstrate low probability of PHI compromise
HHS OCR guidance states ransomware attacks presumptively constitute breaches because unauthorized access occurred; the covered entity must conduct a four-factor risk assessment to rebut this presumption.
Question 3: Which federal agency is primarily responsible for enforcing HIPAA Privacy and Security Rules?
- HHS Office for Civil Rights (OCR) (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
- Federal Trade Commission (FTC)
- Department of Justice (DOJ)
Correct answer: HHS Office for Civil Rights (OCR)
HHS OCR is the primary HIPAA enforcement agency, investigating complaints, conducting audits, and imposing civil monetary penalties for Privacy and Security Rule violations.
Question 4: What is a 'Notice of Privacy Practices' (NPP) under HIPAA, and when must it be provided to patients?
- A document describing how PHI is used and disclosed, provided at first service delivery (Correct answer)
- A consent form patients must sign before any PHI can be used
- An annual security report sent to all patients
- A legal notice sent only when a breach occurs
Correct answer: A document describing how PHI is used and disclosed, provided at first service delivery
The NPP is required by HIPAA ยง164.520 and must be provided no later than the first date of service, informing patients of their rights and the covered entity's privacy practices.
Question 5: Under HITECH's breach notification provisions, what threshold triggers the requirement for media notification in addition to individual notification?
- Breaches affecting 500 or more residents of a state or jurisdiction (Correct answer)
- Any breach affecting more than 100 individuals
- Breaches affecting 1,000 or more individuals nationwide
- All breaches regardless of size
Correct answer: Breaches affecting 500 or more residents of a state or jurisdiction
When a breach affects 500 or more residents of a state or jurisdiction, HIPAA requires prominent media notification (e.g., press release) in addition to individual and HHS notification.
Question 6: Which HIPAA right allows a patient to request that a covered entity correct inaccurate information in their medical record?
- Right to amend (Correct answer)
- Right to access
- Right to an accounting of disclosures
- Right to restrict disclosures
Correct answer: Right to amend
HIPAA ยง164.526 grants patients the right to request amendments to their PHI if they believe it is inaccurate or incomplete, though covered entities may deny the request with justification.
Under the HIPAA Breach Notification Rule, what is the deadline for notifying affected individuals after discovery of a breach affecting fewer than 500 patients?