CHP CHP Workforce Training & Sanctions 2 — Questions and Answers
Question 1: Under HIPAA, a covered entity's sanctions policy must apply to which workforce members?
- Only supervisors and managers
- Only employees with access to electronic PHI
- Any workforce member who violates privacy or security policies (Correct answer)
- Only employees who have been previously warned
Correct answer: Any workforce member who violates privacy or security policies
HIPAA requires a sanctions policy that applies to all workforce members who fail to comply with privacy or security policies.
Question 2: What is the primary purpose of a HIPAA workforce sanctions policy?
- To punish employees after a confirmed breach occurs
- To deter violations and demonstrate organizational commitment to compliance (Correct answer)
- To satisfy state law requirements only
- To document employee grievances and complaints
Correct answer: To deter violations and demonstrate organizational commitment to compliance
A sanctions policy primarily deters privacy violations and signals the organization's genuine commitment to HIPAA compliance.
Question 3: If a covered entity materially changes its HIPAA privacy practices, it must:
- Notify HHS within 30 days of the change
- Revise and redistribute its Notice of Privacy Practices (Correct answer)
- Obtain new written consent from each affected patient
- File an amendment with the state health department
Correct answer: Revise and redistribute its Notice of Privacy Practices
Material changes to privacy practices must be reflected in a revised Notice of Privacy Practices that is made available to patients.
Question 4: A workforce member who knowingly violates HIPAA privacy policies may face:
- Civil monetary penalties only
- Both civil and criminal penalties depending on severity (Correct answer)
- Criminal penalties only for senior employees
- No penalty if the breach was unintentional
Correct answer: Both civil and criminal penalties depending on severity
HIPAA provides for both civil monetary penalties and criminal prosecution, with the track depending on intent and severity of the violation.
Question 5: Which of the following is a hallmark of an effective HIPAA sanctions policy?
- Applied uniformly regardless of employee role or tenure (Correct answer)
- Applied only to employees with direct patient contact
- Scaled exclusively based on years of employment
- Applied only to repeat offenders after a warning
Correct answer: Applied uniformly regardless of employee role or tenure
An effective HIPAA sanctions policy must be applied consistently and uniformly to all workforce members to be defensible and credible.
Question 6: How long must a covered entity retain its HIPAA policies and procedures documents?
- 3 years from creation
- 6 years from creation or last date in effect (Correct answer)
- 10 years from creation
- For the life of the organization
Correct answer: 6 years from creation or last date in effect
HIPAA requires covered entities to retain policies and procedures for 6 years from their creation or the last date they were in effect.
Under HIPAA, a covered entity's sanctions policy must apply to which workforce members?