CHPS Certified in Healthcare Privacy and Security MCQ 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- A patient's diagnosis documented in a medical record
- De-identified health data meeting the Safe Harbor standard (Correct answer)
- A patient's appointment date linked to their name
- An insurance claim containing a patient's date of birth
Correct answer: De-identified health data meeting the Safe Harbor standard
Data that meets the Safe Harbor de-identification standard (removing 18 specified identifiers) is no longer PHI and is not subject to HIPAA protections.
Question 2: A hospital's Security Officer discovers that a workforce member accessed patient records without a valid treatment, payment, or operations reason. This is BEST described as:
- A security incident requiring breach notification
- A workforce sanction policy violation (Correct answer)
- A required disclosure under HIPAA
- A business associate agreement breach
Correct answer: A workforce sanction policy violation
Inappropriate access by workforce members without authorization violates the workforce sanction policy, which covered entities must have in place under the HIPAA Security Rule.
Question 3: Which HIPAA Privacy Rule standard allows covered entities to use or disclose PHI for their own treatment, payment, and healthcare operations without patient authorization?
- Minimum necessary standard
- Permitted uses and disclosures (Correct answer)
- Individual access rights
- Notice of Privacy Practices
Correct answer: Permitted uses and disclosures
The permitted uses and disclosures provision allows covered entities to use or disclose PHI for TPO (treatment, payment, healthcare operations) without individual authorization.
Question 4: A risk analysis under the HIPAA Security Rule must identify threats to the confidentiality, integrity, and availability of ePHI. Which document type formally captures this assessment?
- Notice of Privacy Practices
- Business Associate Agreement
- Risk Assessment Report (Correct answer)
- Workforce Training Record
Correct answer: Risk Assessment Report
The Risk Assessment Report documents identified threats, vulnerabilities, likelihood, and impact, fulfilling the Security Rule's requirement for a formal, documented risk analysis.
Question 5: Under the HITECH Act, which entity tier has a maximum annual civil monetary penalty of $1.9 million per violation category?
- Did not know and could not have known
- Reasonable cause
- Willful neglect – corrected
- Willful neglect – not corrected (Correct answer)
Correct answer: Willful neglect – not corrected
Willful neglect that is not corrected carries the highest penalty tier, up to $1.9 million per identical violation category per calendar year.
Question 6: A covered entity receives a subpoena for a patient's medical records. Under HIPAA, the covered entity may disclose PHI in response to the subpoena only if:
- The request comes from a federal court
- Satisfactory assurances are received that the patient was notified or a protective order is in place (Correct answer)
- The covered entity's legal counsel approves the release
- The patient is a party to the lawsuit
Correct answer: Satisfactory assurances are received that the patient was notified or a protective order is in place
HIPAA permits disclosure in response to a subpoena without a court order only when the covered entity receives satisfactory assurances that the individual was notified or that a qualified protective order is in place.
Question 7: Which access control mechanism grants permissions based on an individual's role within an organization rather than their specific identity?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions according to job roles (e.g., nurse, billing clerk), simplifying administration and supporting the minimum necessary principle required by HIPAA.
Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?