CHP Regulatory Compliance & Standards 2 — Questions and Answers
Question 1: Under HIPAA, which federal agency is primarily responsible for enforcing the Privacy and Security Rules?
- Department of Justice (DOJ)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Federal Trade Commission (FTC)
- Centers for Medicare & Medicaid Services (CMS)
Correct answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services enforces HIPAA's Privacy and Security Rules.
Question 2: Which HIPAA rule specifically requires covered entities to implement administrative, physical, and technical safeguards for electronic PHI?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule mandates that covered entities protect electronic PHI through administrative, physical, and technical safeguards.
Question 3: A covered entity discovers a breach affecting 600 individuals. By what deadline must it notify the Secretary of HHS?
- Within 30 days of discovery
- Within 60 days of the end of the calendar year in which the breach occurred (Correct answer)
- Within 60 days of discovery
- Within 90 days of discovery
Correct answer: Within 60 days of the end of the calendar year in which the breach occurred
Breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which the breach occurred.
Question 4: The HITECH Act expanded HIPAA compliance requirements by making which entities directly liable for HIPAA violations?
- Health insurance exchanges only
- Business associates (Correct answer)
- Clearinghouses only
- State Medicaid agencies only
Correct answer: Business associates
The HITECH Act extended direct HIPAA liability to business associates, who were previously only bound by contract terms.
Question 5: Which of the following is NOT a required element of a HIPAA-compliant Notice of Privacy Practices (NPP)?
- Description of the types of uses and disclosures the covered entity may make
- Statement of the individual's rights
- Name and phone number of the covered entity's HIPAA compliance officer
- A list of all business associates and their specific data access rights (Correct answer)
Correct answer: A list of all business associates and their specific data access rights
NPPs must describe uses/disclosures, patient rights, and contact information for the privacy officer, but do not require listing all business associates and their specific access rights.
Question 6: Under the HIPAA Enforcement Rule, what is the maximum annual penalty cap per violation category for willful neglect that is corrected?
- $10,000
- $50,000
- $100,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
For willful neglect that is corrected within 30 days, the annual cap per identical violation category is $1,900,000 (adjusted for inflation from the original $1,500,000).
Question 7: Which standard specifies that a covered entity may not use or disclose more PHI than is reasonably necessary to accomplish the intended purpose?
- Minimum Necessary Standard (Correct answer)
- De-identification Standard
- Limited Data Set Standard
- Safe Harbor Standard
Correct answer: Minimum Necessary Standard
The Minimum Necessary Standard requires covered entities to limit PHI use and disclosure to the least amount needed to accomplish the purpose.
Under HIPAA, which federal agency is primarily responsible for enforcing the Privacy and Security Rules?