CHP HITECH Act & Electronic Health Records Compliance 2 — Questions and Answers
Question 1: What are the four tiers of civil monetary penalties established by HITECH, listed from least to most severe?
- Did not know, reasonable cause, willful neglect corrected, willful neglect not corrected (Correct answer)
- Unaware, negligent, reckless disregard, intentional harm
- Minor, moderate, major, critical violation
- Tier A, Tier B, Tier C, Tier D with escalating fines
Correct answer: Did not know, reasonable cause, willful neglect corrected, willful neglect not corrected
HITECH established four penalty tiers based on culpability: (1) did not know, (2) reasonable cause, (3) willful neglect corrected within 30 days, and (4) willful neglect not corrected.
Question 2: Under HITECH's breach notification rule, what is the maximum timeframe for notifying affected individuals after discovery of a breach?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days following the discovery of a breach of unsecured PHI.
Question 3: Under HITECH, when must breaches affecting fewer than 500 individuals be reported to the Secretary of HHS?
- Within 60 days of discovering each individual breach
- Within 90 days of the end of the fiscal year
- Annually, within 60 days after the end of each calendar year (Correct answer)
- Only upon direct request from HHS investigators
Correct answer: Annually, within 60 days after the end of each calendar year
Small breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, submitting the log within 60 days after the close of each calendar year.
Question 4: Which HITECH provision requires a covered entity to honor a patient's request to restrict disclosure of PHI to a health plan?
- The minimum necessary standard restriction
- The right to restrict disclosures when a patient pays out of pocket in full (Correct answer)
- The notice of privacy practices amendment requirement
- The individual access expansion provision
Correct answer: The right to restrict disclosures when a patient pays out of pocket in full
HITECH requires covered entities to honor a patient's request to restrict disclosure to a health plan if the patient pays out of pocket in full for the item or service.
Question 5: What is the purpose of Health Information Exchanges (HIEs) as promoted under the HITECH Act?
- To replace all paper-based records with digital equivalents by a federal deadline
- To enable secure electronic sharing of patient health information across organizations to improve care coordination (Correct answer)
- To serve as backup data storage for EHR systems during outages
- To process insurance claims and remittance advice electronically
Correct answer: To enable secure electronic sharing of patient health information across organizations to improve care coordination
HIEs facilitate the secure electronic movement of health information among organizations, improving care coordination, reducing duplicate testing, and enhancing patient safety.
Question 6: Which of the following workforce actions would most likely result in criminal penalties under HIPAA as strengthened by HITECH?
- Accidentally sending a patient appointment reminder to the wrong email address
- Intentionally accessing and selling patient records for personal financial gain (Correct answer)
- Failing to encrypt an internal email containing PHI
- Sharing a login password with a trusted colleague temporarily
Correct answer: Intentionally accessing and selling patient records for personal financial gain
Knowingly and intentionally obtaining or disclosing PHI for personal gain, commercial advantage, or malicious harm can result in criminal penalties including fines and imprisonment.
Question 7: Under HITECH, which element is NOT required to be included in a breach notification letter sent to affected individuals?
- A description of what happened and the types of PHI involved
- Steps individuals should take to protect themselves from potential harm
- The name and title of the specific employee responsible for the breach (Correct answer)
- Contact information and toll-free number for individuals to ask questions
Correct answer: The name and title of the specific employee responsible for the breach
Breach notifications must include a description of the breach, the types of PHI involved, protective steps, and contact information, but do not require identifying the responsible employee.
What are the four tiers of civil monetary penalties established by HITECH, listed from least to most severe?