CHPS HIPAA Privacy Rule Compliance 2 โ Questions and Answers
Question 1: Under HIPAA's Right of Access, what is the maximum fee a covered entity may charge for electronic copies of PHI maintained electronically?
- A flat fee of $25
- A reasonable cost-based fee for labor, supplies, and postage
- A fee not exceeding $6.50 per request under the safe harbor (Correct answer)
- No fee may be charged for electronic records
Correct answer: A fee not exceeding $6.50 per request under the safe harbor
The OCR established a $6.50 safe harbor fee for providing individuals with electronic copies of their PHI when maintained electronically.
Question 2: Which of the following is considered a permissible purpose for using or disclosing PHI without patient authorization under the HIPAA Privacy Rule?
- Marketing a covered entity's own health services using PHI
- Public health activities such as disease reporting (Correct answer)
- Selling PHI to a data analytics firm
- Sharing PHI with an employer for job performance reviews
Correct answer: Public health activities such as disease reporting
Public health activities, including reporting diseases to public health authorities, are a permissible use of PHI under 45 CFR ยง164.512(b).
Question 3: A Notice of Privacy Practices (NPP) must include which of the following elements?
- A list of all workforce members who may access PHI
- A description of the types of uses and disclosures a covered entity may make (Correct answer)
- The names of all business associates
- Annual audit results of privacy program compliance
Correct answer: A description of the types of uses and disclosures a covered entity may make
The NPP must describe the types of uses and disclosures the covered entity is permitted or required to make, as required by 45 CFR ยง164.520.
Question 4: Under HIPAA, when may a covered entity use PHI for fundraising purposes?
- Never โ fundraising requires explicit written authorization
- Only when the patient has opted in to fundraising communications
- When demographic information and dates of service are used and the patient is given an opportunity to opt out (Correct answer)
- Only with de-identified data
Correct answer: When demographic information and dates of service are used and the patient is given an opportunity to opt out
Covered entities may use limited PHI (demographics and dates of service) for fundraising if the NPP discloses this and patients are given a clear opportunity to opt out.
Question 5: Which of the following best describes the HIPAA concept of 'treatment, payment, and health care operations' (TPO)?
- Three categories requiring written patient authorization before PHI disclosure
- Permitted purposes for PHI use and disclosure that generally do not require patient authorization (Correct answer)
- Administrative safeguards required by the Security Rule
- Breach categories under the Breach Notification Rule
Correct answer: Permitted purposes for PHI use and disclosure that generally do not require patient authorization
TPO represents the core permitted purposes under the Privacy Rule where covered entities can use and disclose PHI without patient authorization.
Question 6: Under the HIPAA Privacy Rule, a covered entity must designate which role to be responsible for developing and implementing its privacy policies?
- Chief Information Officer (CIO)
- Privacy Officer (Correct answer)
- Compliance Officer
- Health Information Manager
Correct answer: Privacy Officer
The HIPAA Privacy Rule at 45 CFR ยง164.530(a) requires covered entities to designate a Privacy Officer responsible for privacy policy development and implementation.
Under HIPAA's Right of Access, what is the maximum fee a covered entity may charge for electronic copies of PHI maintained electronically?