CHPS Healthcare Data Breach Response 1 — Questions and Answers
Question 1: Under the HIPAA Breach Notification Rule, what is the presumption when an impermissible use or disclosure of PHI occurs?
- The event is presumed to be a security incident requiring criminal referral
- The event is presumed to be a breach unless the covered entity demonstrates low probability of PHI compromise (Correct answer)
- The event requires immediate notification to all affected individuals
- The event is presumed harmless unless the patient files a complaint
Correct answer: The event is presumed to be a breach unless the covered entity demonstrates low probability of PHI compromise
Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless a covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 2: The four-factor risk assessment under the HIPAA Breach Notification Rule includes all of the following EXCEPT:
- Nature and extent of PHI involved including types of identifiers
- Likelihood that PHI was actually acquired or viewed
- The unauthorized person who used or received PHI
- Whether the affected individual has experienced actual identity theft (Correct answer)
Correct answer: Whether the affected individual has experienced actual identity theft
Actual identity theft is not one of the four factors — the assessment focuses on probability of compromise, not actual harm after the fact.
Question 3: When must a covered entity notify the Secretary of HHS of a breach affecting fewer than 500 individuals in a single state?
- Within 60 days of discovery
- Within 60 days of the end of the calendar year in which the breach was discovered (Correct answer)
- Within 30 days of breach discovery
- Within 60 days of the breach occurrence date
Correct answer: Within 60 days of the end of the calendar year in which the breach was discovered
Small breaches (fewer than 500 individuals) must be logged and reported to HHS annually no later than 60 days after the end of the calendar year in which they were discovered.
Question 4: A hospital discovers a breach on March 15. Under HIPAA, individual breach notifications must be sent no later than:
- April 14 (30 days after discovery)
- May 14 (60 days after discovery) (Correct answer)
- June 14 (90 days after discovery)
- March 30 (15 days after discovery)
Correct answer: May 14 (60 days after discovery)
Individual notifications must be provided without unreasonable delay and no later than 60 days following discovery of the breach.
Question 5: When a breach affects 500 or more residents of a state or jurisdiction, a covered entity must notify which additional party?
- The state Attorney General only
- Prominent media outlets serving the state or jurisdiction (Correct answer)
- The local police department
- The Federal Trade Commission (FTC)
Correct answer: Prominent media outlets serving the state or jurisdiction
When a breach affects 500 or more residents of a state, the covered entity must provide notice to prominent media outlets in addition to individual and HHS notification.
Question 6: Under the HIPAA Breach Notification Rule, which of the following is NOT a required element of individual breach notification?
- A brief description of what happened and the date of breach and discovery
- The types of PHI involved in the breach
- A description of the covered entity's security vulnerabilities that caused the breach (Correct answer)
- Steps individuals should take to protect themselves from potential harm
Correct answer: A description of the covered entity's security vulnerabilities that caused the breach
While entities must provide breach details and mitigation guidance, disclosing the specific internal security vulnerabilities that caused the breach is not a required element of individual notification.
Under the HIPAA Breach Notification Rule, what is the presumption when an impermissible use or disclosure of PHI occurs?