CHPS Healthcare Data Breach Response 2 — Questions and Answers
Question 1: Which of the following events would NOT qualify as a 'breach' under the HIPAA Breach Notification Rule?
- A workforce member accidentally emails a patient's discharge summary to the wrong provider
- A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose (Correct answer)
- A laptop containing unencrypted ePHI is stolen from a locked car
- A billing clerk views patient records that are unrelated to her job function
Correct answer: A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose
Accessing PHI for legitimate treatment, payment, or operations purposes is not an impermissible use and therefore does not constitute a breach under HIPAA.
Question 2: When a business associate discovers a breach of PHI, within what timeframe must it notify the covered entity?
- Immediately, with no delay
- Within 30 days of discovery
- Without unreasonable delay and within 60 days of discovery (Correct answer)
- Within 24 hours of discovery
Correct answer: Without unreasonable delay and within 60 days of discovery
A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days following discovery.
Question 3: Under HIPAA, which of the following PHI disposal methods is considered a safe harbor that renders a breach not reportable?
- Deleting files from a computer hard drive
- Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable (Correct answer)
- Moving PHI to a secure internal archive
- Applying password protection to PHI files
Correct answer: Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable
PHI that has been rendered unreadable, indecipherable, or destroyed through proper methods (shredding paper, degaussing/purging media) is excluded from breach notification requirements.
Question 4: A covered entity discovers that a workforce member has been snooping on celebrity patient records over the past year. How many breaches does this represent?
- One breach per year
- One breach per patient record impermissibly accessed (Correct answer)
- A single breach because it involves one workforce member
- No breach if the workforce member did not disclose the information to anyone
Correct answer: One breach per patient record impermissibly accessed
Each patient's record that was impermissibly accessed represents a separate potential breach requiring individual analysis under the four-factor risk assessment.
Question 5: Under HIPAA, breach discovery is defined as the date on which which party first knows or reasonably should have known of the breach?
- The individual whose PHI was breached
- The covered entity or business associate, whichever is the data holder (Correct answer)
- The covered entity, regardless of when the business associate discovered it
- The HHS Office for Civil Rights (OCR)
Correct answer: The covered entity or business associate, whichever is the data holder
Discovery date is when the covered entity or business associate (whichever holds the data) first knew or should have known about the breach through reasonable diligence.
Question 6: What type of PHI is specifically excluded from the HIPAA Breach Notification Rule's definition of PHI for breach purposes?
- PHI in oral form
- PHI in paper form
- PHI in a Limited Data Set (Correct answer)
- PHI maintained in EHR systems
Correct answer: PHI in a Limited Data Set
Limited Data Sets (which remove direct identifiers but retain some indirect identifiers like dates and geographic data) are excluded from the Breach Notification Rule's definition of PHI for breach purposes when covered by a DUA.
Which of the following events would NOT qualify as a 'breach' under the HIPAA Breach Notification Rule?