HIPAA - Health Insurance Portability and Accountability Act HIPAA Breach Notification Rule Questions and Answers — Questions and Answers
Question 1: A hospital discovers that a server containing the electronic protected health information (ePHI) of 350 patients was improperly decommissioned and sold. The data was not encrypted. According to the HIPAA Breach Notification Rule, what is the hospital's deadline for notifying the Secretary of Health and Human Services (HHS)?
- Without unreasonable delay, and in no case later than 60 days after the discovery of the breach.
- Within 30 days of notifying the affected individuals.
- No later than 60 days after the end of the calendar year in which the breach was discovered. (Correct answer)
- Immediately upon discovery, via the HHS online portal.
Correct answer: No later than 60 days after the end of the calendar year in which the breach was discovered.
For breaches affecting fewer than 500 individuals, a covered entity must notify the Secretary of HHS by submitting a report no later than 60 days after the end of the calendar year in which the breach was discovered. The 60-day deadline from the date of discovery applies to notifying individuals and to notifying the Secretary for breaches affecting 500 or more individuals.
Question 2: A business associate of a covered entity experiences a data breach involving unsecured PHI. According to the HIPAA Breach Notification Rule, what is the primary responsibility of the business associate?
- To notify the affected individuals directly within 60 days.
- To notify the Secretary of HHS and prominent media outlets.
- To conduct a risk assessment and determine if notification is necessary.
- To notify the covered entity of the breach without unreasonable delay. (Correct answer)
Correct answer: To notify the covered entity of the breach without unreasonable delay.
The HIPAA Breach Notification Rule requires a business associate to notify the covered entity after discovering a breach of unsecured PHI. This notification must occur without unreasonable delay and no later than 60 days from discovery. The covered entity is ultimately responsible for notifying affected individuals, the Secretary, and the media, as applicable.
Question 3: Which of the following situations would NOT be considered a 'breach' under the HIPAA Breach Notification Rule, thereby exempting the organization from notification requirements?
- A hacker gains access to a hospital's patient database containing unencrypted PHI.
- A billing employee unintentionally accesses the record of a patient they are not treating, realizes the mistake immediately, and does not further use or disclose the information. (Correct answer)
- An unencrypted laptop containing PHI is stolen from an employee's locked office.
- A former employee accesses patient records from home using their still-active login credentials.
Correct answer: A billing employee unintentionally accesses the record of a patient they are not treating, realizes the mistake immediately, and does not further use or disclose the information.
The HIPAA Breach Notification Rule includes three exceptions to the definition of a breach. One exception is for the unintentional acquisition, access, or use of PHI by a workforce member acting in good faith and within the scope of their authority, provided the information is not further used or disclosed. The other scenarios represent clear breaches requiring notification.
Question 4: A large health insurance company experiences a breach affecting 1,000 members residing in the same state. In addition to notifying the affected individuals and the Secretary of HHS, what other notification is required by the HIPAA Breach Notification Rule?
- Notify the Federal Trade Commission (FTC) within 60 days.
- Notify prominent media outlets serving the state or jurisdiction. (Correct answer)
- Post a notice in all company facilities for at least 90 days.
- Notify the local police department where the company is headquartered.
Correct answer: Notify prominent media outlets serving the state or jurisdiction.
For breaches of unsecured PHI that affect more than 500 residents of a single state or jurisdiction, the covered entity is required to provide notice to prominent media outlets serving that area. This must be done without unreasonable delay and no later than 60 days after the discovery of the breach.
Question 5: A covered entity is preparing a breach notification letter for affected individuals. Which of the following elements is explicitly required to be included in the notice according to the Breach Notification Rule?
- An offer of complimentary credit monitoring services for one year.
- The names of the employees responsible for the breach.
- A detailed technical report of the forensic investigation.
- A brief description of what the entity is doing to investigate the breach and prevent future breaches. (Correct answer)
Correct answer: A brief description of what the entity is doing to investigate the breach and prevent future breaches.
The HIPAA Breach Notification Rule specifies several required elements for individual notifications. These include a brief description of the breach, the types of information involved, steps individuals should take to protect themselves, what the entity is doing to investigate, mitigate harm, and prevent future breaches, and contact information.
Question 6: A medical clinic discovers a breach on January 15th. They complete their investigation and have all necessary information by January 30th. According to the HIPAA Breach Notification Rule's requirement to notify individuals 'without unreasonable delay,' what is the most appropriate course of action?
- Wait until March 15th, the 60-day deadline, to send all notifications at once.
- Send the notifications shortly after January 30th, as soon as they can be mailed. (Correct answer)
- Send the notifications within 10 business days of the discovery on January 15th.
- Request an extension from HHS before sending the notifications.
Correct answer: Send the notifications shortly after January 30th, as soon as they can be mailed.
The rule requires notification to be made 'without unreasonable delay' and in no case later than 60 days following the discovery of a breach. Waiting until the 60-day deadline when all information is available sooner would be considered an unreasonable delay. Therefore, the clinic should send the notices as soon as possible after completing its investigation.
A hospital discovers that a server containing the electronic protected health information (ePHI) of 350 patients was improperly decommissioned and sold.
The data was not encrypted.
According to the HIPAA Breach Notification Rule, what is the hospital's deadline for notifying the Secretary of Health and Human Services (HHS)?