Clinical Informatics Certification Privacy & Security Regulations 2 — Questions and Answers
Question 1: Under HIPAA, which type of agreement is required when a covered entity shares PHI with a third-party vendor?
- Data Use Agreement
- Business Associate Agreement (Correct answer)
- Service Level Agreement
- Memorandum of Understanding
Correct answer: Business Associate Agreement
A Business Associate Agreement (BAA) is required by HIPAA when a covered entity discloses PHI to a third party performing services on its behalf.
Question 2: The HIPAA Breach Notification Rule requires covered entities to notify affected individuals of an unsecured PHI breach within how many days?
- 30 days
- 45 days
- 60 days (Correct answer)
- 72 hours
Correct answer: 60 days
HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Question 3: Which HIPAA rule specifically establishes standards for protecting electronic PHI (ePHI) at rest and in transit?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule establishes national standards for protecting electronic PHI through administrative, physical, and technical safeguards.
Question 4: A hospital's EHR system logs every user access to patient records. This is an example of which HIPAA Security Rule safeguard category?
- Physical safeguards
- Administrative safeguards
- Technical safeguards (Correct answer)
- Organizational safeguards
Correct answer: Technical safeguards
Audit controls and access logging are technical safeguards under the HIPAA Security Rule that record and examine activity in systems containing ePHI.
Question 5: Which federal law governs the privacy of substance use disorder treatment records and is more restrictive than HIPAA?
- FERPA
- 42 CFR Part 2 (Correct answer)
- HITECH Act
- Gramm-Leach-Bliley Act
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides stricter confidentiality protections for substance use disorder patient records than HIPAA, requiring patient consent for most disclosures.
Question 6: Under the HITECH Act, business associates are directly liable for HIPAA compliance. Which provision created this direct liability?
- Safe Harbor provision
- Omnibus Rule (Correct answer)
- Meaningful Use requirement
- Minimum Necessary standard
Correct answer: Omnibus Rule
The 2013 HIPAA Omnibus Rule, implementing HITECH provisions, made business associates directly liable for HIPAA compliance and extended requirements to their subcontractors.
Question 7: A patient requests an amendment to their medical record because they believe it contains an error. Under HIPAA, the provider may deny this request if:
- The record was created more than 7 years ago
- The provider did not create the record (Correct answer)
- The patient is requesting deletion rather than amendment
- The record is stored electronically
Correct answer: The provider did not create the record
HIPAA permits denial of an amendment request when the covered entity did not create the information and the originating entity is available to handle the amendment.
Under HIPAA, which type of agreement is required when a covered entity shares PHI with a third-party vendor?