Breach Notification Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Breach Notification Rule flashcards as text
Under the Breach Notification Rule, when does the 60-day notification clock begin for a business associate who discovers a breach?
Answer: When the business associate discovers the breach
The 60-day clock for business associate notification to covered entities begins on the date the business associate discovers the breach, not when the breach occurred.
Which of the following breaches would require media notification under the HIPAA Breach Notification Rule?
Answer: A breach affecting 600 patients in a single state
Media notification is required when a breach affects more than 500 residents of a state or jurisdiction.
An employee accidentally emails PHI to a wrong recipient who is also a healthcare employee and does not open or read it. Under which exception might this NOT be classified as a reportable breach?
Answer: The inadvertent disclosure exception where the recipient could not reasonably retain the information
Inadvertent disclosure of PHI between authorized persons where the recipient could not reasonably have retained the information is an exception to the definition of breach.
A covered entity conducts a risk assessment after discovering that an employee inappropriately accessed patient records. The assessment determines there is a low probability that PHI was compromised. What should the covered entity do?
Answer: No notification is required if the risk assessment shows low probability of compromise
If the risk assessment demonstrates low probability that PHI was compromised, the covered entity may determine no breach notification is required.
How must a covered entity notify individuals affected by a breach if they have email addresses on file and individuals have agreed to electronic notice?
Answer: Email notification is permitted if the individual has agreed to receive electronic notice
Covered entities may use email for breach notification if the individual has previously agreed to receive notices electronically.
Which HHS office is responsible for enforcing the HIPAA Breach Notification Rule?
Answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Breach Notification Rule.
A covered entity's risk assessment determines PHI was accessed by an unauthorized person. The entity argues the harm is minimal. Can they skip breach notification?
Answer: No, the risk assessment evaluates probability of compromise, not level of harm
The risk assessment standard evaluates the probability that PHI was compromised, not the severity of harm; if compromise probability is not low, notification is required.