CHPS Trivia 5 — Questions and Answers
Question 1: What is 'workforce' as defined under HIPAA, and does it include volunteers and trainees?
- Employees only; volunteers and trainees are excluded
- Employees and contractors; volunteers are excluded
- Employees, volunteers, trainees, and other persons under the entity's direct control (Correct answer)
- Anyone who handles PHI regardless of relationship
Correct answer: Employees, volunteers, trainees, and other persons under the entity's direct control
HIPAA defines workforce as employees, volunteers, trainees, and other persons whose conduct is under the direct control of the covered entity, whether or not they are paid.
Question 2: Which term describes the HIPAA concept where a covered entity is accountable for the actions of its Business Associates as if the CE performed the service itself?
- Vicarious liability
- Chain of trust (Correct answer)
- Downstream liability
- Agent accountability
Correct answer: Chain of trust
The chain of trust concept under HIPAA reflects that covered entities must ensure their Business Associates protect PHI, extending accountability throughout the service delivery chain.
Question 3: A nurse accesses the medical records of a celebrity patient out of curiosity without a treatment purpose. Which HIPAA rule does this primarily violate?
- Security Rule — unauthorized access control failure
- Privacy Rule — impermissible use of PHI (Correct answer)
- Breach Notification Rule — undisclosed access
- HITECH — workforce sanction policy
Correct answer: Privacy Rule — impermissible use of PHI
Accessing PHI without a permissible purpose violates the HIPAA Privacy Rule's restrictions on uses and disclosures of PHI.
Question 4: What is the difference between a 'covered entity' and a 'hybrid entity' under HIPAA?
- Covered entities are hospitals; hybrid entities are insurance companies
- A hybrid entity is an organization that performs both covered and non-covered healthcare functions and designates its healthcare components (Correct answer)
- Hybrid entities are exempt from the Security Rule
- There is no regulatory distinction between the two
Correct answer: A hybrid entity is an organization that performs both covered and non-covered healthcare functions and designates its healthcare components
A hybrid entity is a covered entity that performs both covered healthcare functions and non-healthcare business functions, and it may designate which components are subject to HIPAA.
Question 5: Under the HIPAA Security Rule, what is an 'audit control' and why is it required?
- A process to approve user access; required to prevent unauthorized logins
- Hardware, software, or procedural mechanisms to record and examine activity in systems containing ePHI; required to detect and investigate security incidents (Correct answer)
- An annual review of security policies; required for compliance documentation
- Encryption of audit logs; required to prevent tampering
Correct answer: Hardware, software, or procedural mechanisms to record and examine activity in systems containing ePHI; required to detect and investigate security incidents
Audit controls are mechanisms that record and examine activity in systems containing ePHI, enabling organizations to detect, investigate, and respond to security incidents and policy violations.
Question 6: What does 'integrity' mean in the context of the HIPAA Security Rule's protection requirements for ePHI?
- ePHI is kept confidential from unauthorized users
- ePHI has not been altered or destroyed in an unauthorized manner (Correct answer)
- ePHI is accessible when needed by authorized users
- ePHI is encrypted at rest and in transit
Correct answer: ePHI has not been altered or destroyed in an unauthorized manner
Integrity in the HIPAA Security Rule means that ePHI has not been altered or destroyed in an unauthorized manner, ensuring the data is accurate and trustworthy.
Question 7: Which HIPAA enforcement tier applies when a covered entity did not know and could not have reasonably known of a violation?
- Tier 1 — Reasonable cause
- Tier 1 — Did not know (Correct answer)
- Tier 3 — Willful neglect, corrected
- Tier 4 — Willful neglect, not corrected
Correct answer: Tier 1 — Did not know
Tier 1 of HIPAA's civil penalty structure applies to violations where the entity did not know and with reasonable diligence would not have known of the violation, carrying the lowest penalty range.
What is 'workforce' as defined under HIPAA, and does it include volunteers and trainees?