Breach Notification & Legal Enforcement Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Breach Notification & Legal Enforcement flashcards as text
A covered entity mails breach notification letters to affected individuals but the letters are returned as undeliverable for 50 individuals. What is the required substitute notice method?
Answer: Post a notice on the covered entity's website for 90 days
When fewer than 10 individuals have insufficient contact information, alternative individual-specific contact is required; for 10 or more, a conspicuous website posting for at least 90 days is required.
Which of the following is a required element in the breach notification letter sent to affected individuals?
Answer: Steps individuals should take to protect themselves from potential harm
The notification must include steps individuals should take to protect themselves from potential harm resulting from the breach.
A health plan unknowingly has a misconfigured server exposing PHI for 18 months before discovery. How does HIPAA's 'willful neglect' tier apply?
Answer: It may apply if the entity failed to implement required safeguards it should have known about
Willful neglect can apply when an entity fails to implement required safeguards it knew or should have known were necessary, even without deliberate intent to violate HIPAA.
State breach notification laws and HIPAA may both apply to the same breach. Which law governs in cases of conflict?
Answer: The stricter law that provides greater privacy protection
HIPAA preempts state laws unless the state law is more stringent (i.e., provides greater privacy protections), in which case the stricter state law applies.
OCR may impose civil monetary penalties (CMPs) when which of the following conditions is met?
Answer: A covered entity fails to comply with HIPAA and the violation is not timely corrected
OCR may impose CMPs when a covered entity has violated HIPAA and, depending on the tier, has not timely corrected the violation after being given an opportunity to do so.
A covered entity sends breach notifications on day 58 after discovery. Are they compliant with HIPAA's Breach Notification Rule?
Answer: Yes, because the 60-day deadline has not passed
HIPAA requires breach notifications to be provided without unreasonable delay and no later than 60 calendar days after discovery, so day 58 is compliant.
A covered entity discovers that an employee accessed PHI out of curiosity with no intent to harm or disclose. What HIPAA enforcement tier most likely applies?
Answer: Reasonable cause — should have known with reasonable diligence
Employees accessing PHI without a job-related need is a reasonably foreseeable risk; failure to prevent it through training and access controls typically qualifies as 'reasonable cause.'