CHP HIPAA Privacy & Security Rules 2 — Questions and Answers
Question 1: Under the HIPAA Privacy Rule, what is the maximum period a covered entity may maintain an authorization form signed by an individual?
- 1 year from the date signed
- 6 years from the date of creation or last effective date (Correct answer)
- 3 years from the date signed
- Indefinitely, with no expiration requirement
Correct answer: 6 years from the date of creation or last effective date
The Privacy Rule requires covered entities to retain documentation, including signed authorizations, for 6 years from the date of creation or the date it was last in effect, whichever is later.
Question 2: Which of the following constitutes a valid expiration for a HIPAA authorization?
- A specific date
- Occurrence of a specific event
- Completion of the study for which authorization was given
- All of the above (Correct answer)
Correct answer: All of the above
A valid authorization must include an expiration date, event, or condition, and any of these three options satisfies that requirement under the Privacy Rule.
Question 3: A hospital's Privacy Officer discovers a workforce member improperly accessed 15 patient records out of curiosity with no malicious intent. What is the FIRST step the Privacy Officer should take?
- Terminate the employee immediately
- Conduct a workforce sanction
- Document the breach and assess whether notification is required (Correct answer)
- Notify the media
Correct answer: Document the breach and assess whether notification is required
The first step is to document the incident and perform a breach risk assessment to determine if notification obligations under the Breach Notification Rule are triggered.
Question 4: Under the Security Rule, which of the following is an ADDRESSABLE implementation specification?
- Unique user identification
- Emergency access procedure
- Automatic logoff (Correct answer)
- Audit controls
Correct answer: Automatic logoff
Automatic logoff is an addressable specification, meaning covered entities must implement it if reasonable and appropriate, or document why an equivalent alternative was chosen.
Question 5: A business associate experiences a ransomware attack that encrypts ePHI. Under HIPAA, when does the covered entity's breach notification clock typically start?
- When the BA discovers the breach
- When the BA notifies the covered entity (Correct answer)
- When the covered entity notifies HHS
- 60 days after the attack
Correct answer: When the BA notifies the covered entity
Under the Breach Notification Rule, the 60-day notification clock for the covered entity starts when the business associate notifies the covered entity of the breach.
Question 6: Which of the following is NOT one of the five titles of HIPAA?
- Health Care Access, Portability, and Renewability
- Preventing Health Care Fraud and Abuse
- Tax-Related Health Provisions
- Electronic Health Record Mandate (Correct answer)
Correct answer: Electronic Health Record Mandate
HIPAA's five titles cover portability, fraud prevention, tax provisions, group health plan requirements, and revenue offsets — there is no EHR mandate title.
Question 7: A patient requests an amendment to their medical record. The covered entity may deny the amendment if:
- The information was not created by the covered entity (Correct answer)
- The record is more than 5 years old
- The patient cannot provide a written reason for the amendment
- The record is stored electronically
Correct answer: The information was not created by the covered entity
A covered entity may deny an amendment request if the information was not created by that entity and the originating entity is still available to process the amendment.
Under the HIPAA Privacy Rule, what is the maximum period a covered entity may maintain an authorization form signed by an individual?