CHP Breach Notification & Legal Enforcement 3 — Questions and Answers
Question 1: Which federal agency handles criminal prosecution of knowing HIPAA violations?
- HHS Office for Civil Rights
- Federal Trade Commission
- Department of Justice (Correct answer)
- Centers for Medicare & Medicaid Services
Correct answer: Department of Justice
The Department of Justice (DOJ) is responsible for prosecuting knowing violations of HIPAA that rise to the level of criminal conduct.
Question 2: A breach affects 600 patients at a hospital. In addition to notifying individuals and HHS, what additional step is required?
- Notify the state medical board
- Provide notice to prominent media outlets in the affected area (Correct answer)
- Notify law enforcement within 24 hours
- Issue a press release on the hospital's social media
Correct answer: Provide notice to prominent media outlets in the affected area
Breaches affecting 500 or more individuals in a state or jurisdiction require notice to prominent media outlets serving that area.
Question 3: Under HIPAA, what is the annual cap on civil monetary penalties for identical violations within the same calendar year?
- $100,000
- $500,000
- $1,500,000 (Correct answer)
- $2,000,000
Correct answer: $1,500,000
The annual cap for civil monetary penalties for violations of the same provision is $1,500,000 per calendar year.
Question 4: A covered entity discovers a breach on March 1. The 60-day notification clock begins on which date?
- The date the breach actually occurred
- The date the breach was discovered (Correct answer)
- The date HHS is notified
- The date individuals are notified
Correct answer: The date the breach was discovered
The 60-day notification period runs from the date of discovery of the breach, not the date the breach occurred.
Question 5: Which of the following is NOT one of the four factors in the HIPAA breach risk assessment?
- The nature and extent of the PHI involved
- The unauthorized person who used the PHI or to whom disclosure was made
- The financial net worth of the covered entity (Correct answer)
- Whether the PHI was actually acquired or viewed
Correct answer: The financial net worth of the covered entity
The four-factor risk assessment does not include the financial status of the covered entity; it focuses on the nature of the PHI, the recipient, acquisition/viewing, and mitigation.
Question 6: An individual files a HIPAA complaint with OCR against a covered entity. OCR investigates and finds no violation. What is the most likely outcome?
- OCR issues a corrective action plan regardless
- OCR closes the case with a finding of no violation (Correct answer)
- The case is automatically referred to the DOJ
- The covered entity is fined a minimum baseline penalty
Correct answer: OCR closes the case with a finding of no violation
When OCR finds no violation after investigation, it closes the case and notifies both the complainant and the covered entity.
Question 7: A business associate experiences a breach of PHI it holds on behalf of a covered entity. Under the HIPAA Breach Notification Rule, when must the business associate notify the covered entity?
- Within 24 hours of discovery
- Without unreasonable delay and no later than 60 days from discovery (Correct answer)
- Within 30 days of discovery
- At the same time it notifies HHS
Correct answer: Without unreasonable delay and no later than 60 days from discovery
Business associates must notify the covered entity without unreasonable delay and within 60 calendar days of discovering the breach.
Which federal agency handles criminal prosecution of knowing HIPAA violations?