โ† All HIPAA Flashcard Decks

Breach Notification Rule Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Breach Notification Rule flashcards as text
  1. A covered entity discovers PHI was sent to an incorrect fax number. The recipient confirms they destroyed the fax without reading it. Which breach exception may apply?

    Answer: Inadvertent disclosure exception where recipient could not reasonably retain information

    If the unintended recipient could not reasonably have retained the information (e.g., confirmed immediate destruction), this may qualify as an inadvertent disclosure that is not a reportable breach.

  2. When a breach involves PHI of individuals from multiple states, which state's media outlets must receive notification?

    Answer: The media outlets in each state where more than 500 residents were affected

    Media notification is required in each state or jurisdiction where more than 500 of its residents were affected by the breach.

  3. What is the purpose of the HHS 'Wall of Shame' website?

    Answer: It publicly lists breaches affecting 500 or more individuals currently under investigation

    The HHS 'Wall of Shame' is an online database listing reported breaches affecting 500 or more individuals that are currently under investigation by OCR.

  4. Under the Breach Notification Rule, which of the following correctly describes when a breach is considered 'discovered'?

    Answer: When the covered entity or business associate first knows or reasonably should have known that a breach occurred

    A breach is considered discovered on the first day the covered entity or business associate knows or reasonably should have known of the breach.

  5. Which of the following types of PHI, if breached, carries the HIGHEST inherent risk in the four-factor risk assessment?

    Answer: Social Security numbers, financial account numbers, or sensitive clinical information

    The nature and extent of PHI, including the type of identifiers involved and the likelihood of re-identification, means SSNs, financial data, and sensitive clinical details carry higher risk.

  6. A business associate contract requires the business associate to notify the covered entity of a breach within 30 days. The business associate reports at day 35. Which statement is correct?

    Answer: This is acceptable because HIPAA only requires notification within 60 days

    HIPAA requires business associates to notify covered entities without unreasonable delay and within 60 days, so day 35 satisfies HIPAA even if it violates the stricter contractual deadline.

  7. A covered entity sends breach notifications by first-class mail. The affected individual has moved and does not receive the letter. What does HIPAA require the covered entity to do?

    Answer: No additional action is required; mailing first-class mail satisfies the obligation

    Sending breach notifications via first-class mail to the last known address satisfies HIPAA's notification requirement, even if the individual has moved.