CHP HIPAA Privacy & Security Rules 3 — Questions and Answers
Question 1: Under the HIPAA Security Rule, which of the following is classified as a Physical Safeguard?
- Access control
- Integrity controls
- Workstation use policy (Correct answer)
- Audit controls
Correct answer: Workstation use policy
Workstation use is a physical safeguard standard that governs the proper functions performed at workstations and the physical environment of those workstations.
Question 2: The Minimum Necessary Standard under HIPAA requires covered entities to:
- Share only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Encrypt all PHI before sharing it
- Obtain written authorization for every disclosure
- Train staff annually on the Privacy Rule
Correct answer: Share only the minimum amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires covered entities to make reasonable efforts to limit PHI access and disclosures to the minimum needed to accomplish the intended purpose.
Question 3: Which entity enforces the HIPAA Privacy and Security Rules against covered entities?
- The Federal Trade Commission (FTC)
- The Department of Justice (DOJ)
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary enforcer of the HIPAA Privacy and Security Rules and investigates complaints and conducts audits.
Question 4: A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon request
- At the time of first service delivery (Correct answer)
- Annually, regardless of service
- Only when PHI is disclosed to a third party
Correct answer: At the time of first service delivery
Covered entities must provide the NPP no later than the date of first service delivery and make a good-faith effort to obtain written acknowledgment of receipt.
Question 5: Under the HITECH Act, business associates became directly liable for HIPAA compliance in which year?
- 2003
- 2009
- 2013 (Correct answer)
- 2015
Correct answer: 2013
The HIPAA Omnibus Rule (2013) implemented HITECH Act provisions making business associates directly liable for compliance with applicable HIPAA Privacy and Security Rule requirements.
Question 6: Which of the following is an example of PHI under the HIPAA Privacy Rule?
- De-identified health information shared publicly
- A patient's name combined with their diagnosis (Correct answer)
- Aggregate statistics with no individual identifiers
- Health information in education records covered by FERPA
Correct answer: A patient's name combined with their diagnosis
PHI is individually identifiable health information, and combining a patient's name (an identifier) with their diagnosis (health information) creates PHI.
Question 7: A Security Risk Analysis under the HIPAA Security Rule must assess:
- Only electronic PHI stored on portable devices
- Potential threats and vulnerabilities to all ePHI the entity creates, receives, maintains, or transmits (Correct answer)
- The cost of implementing encryption for all systems
- Business associate agreements for all vendors
Correct answer: Potential threats and vulnerabilities to all ePHI the entity creates, receives, maintains, or transmits
The Security Rule requires a thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI in the entity's environment.
Under the HIPAA Security Rule, which of the following is classified as a Physical Safeguard?