HIPAA - Health Insurance Portability and Accountability Act The Omnibus Rule Questions and Answers — Questions and Answers
Question 1: The HIPAA Omnibus Rule of 2013 modified the Breach Notification Rule by replacing the subjective "harm threshold." An impermissible use or disclosure of PHI is now presumed to be a breach unless the covered entity or business associate demonstrates what?
- The individuals affected have been notified and offered credit monitoring.
- A formal risk of harm analysis shows no significant financial impact.
- There is a low probability that the protected health information has been compromised. (Correct answer)
- The data was encrypted after the impermissible disclosure was discovered.
Correct answer: There is a low probability that the protected health information has been compromised.
The Omnibus Rule established that an impermissible use or disclosure of unsecured PHI is presumed to be a breach. This presumption can only be overcome if a risk assessment, considering at least four specific factors, demonstrates a 'low probability that the PHI has been compromised.' The previous 'harm threshold' was considered too subjective.
Question 2: A patient pays for a specific medical procedure entirely out-of-pocket and explicitly requests that the provider not share any information about this service with their health insurance plan. According to the rights expanded by the HIPAA Omnibus Rule, how must the provider respond?
- The provider must agree to the restriction request. (Correct answer)
- The provider can deny the request if it is administratively burdensome.
- The provider only has to agree if the request is submitted in writing 30 days in advance.
- The provider can inform the patient that all services are reported to health plans regardless of payment method.
Correct answer: The provider must agree to the restriction request.
The HIPAA Omnibus Rule strengthened patient rights by requiring covered entities to agree to a patient's request to restrict disclosure of their PHI to a health plan if the disclosure is for payment or healthcare operations and the patient has paid for the service or item out-of-pocket in full.
Question 3: How did the HIPAA Omnibus Rule fundamentally change the liability of a business associate's subcontractors?
- Subcontractors' liability is limited to the terms specified in their contract with the primary business associate.
- Subcontractors are now directly liable for compliance with the HIPAA Rules and can face penalties from the Office for Civil Rights (OCR). (Correct answer)
- The covered entity is solely responsible for any breaches caused by a business associate's subcontractor.
- Subcontractors are only liable if they have direct access to a covered entity's electronic health record system.
Correct answer: Subcontractors are now directly liable for compliance with the HIPAA Rules and can face penalties from the Office for Civil Rights (OCR).
A major change in the Omnibus Rule was extending direct liability to the subcontractors of business associates. If a subcontractor creates, receives, maintains, or transmits PHI on behalf of a business associate, they are also considered a business associate and are directly liable for complying with applicable HIPAA rules.
Question 4: Which of the following provisions was incorporated into the HIPAA Privacy Rule by the Omnibus Final Rule to prohibit its use in underwriting?
- Substance Use Disorder (SUD) information from Part 2 records.
- Information related to psychotherapy notes.
- Protected Health Information used in marketing.
- Genetic Information Nondiscrimination Act (GINA). (Correct answer)
Correct answer: Genetic Information Nondiscrimination Act (GINA).
The HIPAA Omnibus Rule incorporated provisions from the Genetic Information Nondiscrimination Act (GINA). This expressly prohibits health plans from using or disclosing genetic information for underwriting purposes, such as determining eligibility or premium rates.
Question 5: Following the 2013 Omnibus Rule, which of the following statements is a required addition to a covered entity's Notice of Privacy Practices (NPP)?
- A list of all business associates the entity works with.
- A statement that the entity may contact the individual for marketing purposes.
- A statement that the individual has the right to be notified following a breach of their unsecured PHI. (Correct answer)
- The fee schedule for obtaining copies of medical records.
Correct answer: A statement that the individual has the right to be notified following a breach of their unsecured PHI.
The Omnibus Rule mandated several updates to the Notice of Privacy Practices (NPP) to reflect new patient rights and rule changes. Among these is the requirement to include a statement that individuals have a right to, and will be, notified if a breach of their unsecured PHI occurs.
Question 6: A pharmaceutical company pays a hospital to send promotional materials about a new brand-name drug to a specific list of patients with a relevant diagnosis. Under the HIPAA Omnibus Rule, what is required before the hospital can send these materials?
- An opportunity for the patients to opt-out of the communication.
- The hospital must secure each patient's written authorization that acknowledges the remuneration. (Correct answer)
- Approval from the hospital's Institutional Review Board (IRB).
- The communication must be classified as a treatment-related communication.
Correct answer: The hospital must secure each patient's written authorization that acknowledges the remuneration.
The Omnibus Rule significantly tightened the rules around marketing. If a covered entity receives financial remuneration from a third party to make a communication about a product or service, it is considered marketing and requires the patient's prior written authorization. The authorization must also state that remuneration is involved.
The HIPAA Omnibus Rule of 2013 modified the Breach Notification Rule by replacing the subjective "harm threshold." An impermissible use or disclosure of PHI is now presumed to be a breach unless the covered entity or business associate demonstrates what?