← All HIPAA Flashcard Decks

Breach Notification Rule Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Breach Notification Rule flashcards as text
  1. Which HITECH Act provision established the Breach Notification Rule requirements that are now part of HIPAA?

    Answer: Title XIII — Health Information Technology for Economic and Clinical Health

    The HITECH Act (Title XIII of ARRA) established breach notification requirements that were later incorporated into the HIPAA Breach Notification Rule.

  2. A healthcare clearinghouse discovers that a subcontractor improperly accessed PHI it was processing. Who is responsible for notifying affected individuals?

    Answer: The healthcare clearinghouse notifies the covered entity, who notifies individuals

    Subcontractors (business associates of business associates) must notify the business associate, who notifies the covered entity, who is ultimately responsible for notifying affected individuals.

  3. A health plan mails an Explanation of Benefits to a member's former address, revealing PHI to an unknown person. How is this classified under the Breach Notification Rule?

    Answer: A breach requiring full risk assessment to determine if notification is needed

    Misdirected EOBs involving PHI disclosure to unauthorized individuals require a four-factor risk assessment to determine whether breach notification is required.

  4. A ransomware attack encrypts a covered entity's servers containing PHI. Under HHS guidance, how is this typically classified?

    Answer: A breach unless the covered entity can demonstrate a low probability of PHI compromise

    HHS guidance indicates ransomware typically constitutes a breach, but covered entities may conduct a risk assessment and if they can demonstrate low probability of compromise, notification may not be required.

  5. What must a covered entity include in the annual breach log submitted to HHS for breaches affecting fewer than 500 individuals?

    Answer: The date of each breach, type of PHI involved, description, and number of individuals affected

    The annual log for small breaches must include the date of the breach, type of PHI, a description of what happened, and the approximate number of individuals affected.

  6. A covered entity provides breach notification to affected individuals 45 days after discovery. Is this compliant with HIPAA?

    Answer: Yes, notification within 60 days of discovery satisfies the requirement

    HIPAA requires individual breach notification without unreasonable delay and within 60 days of discovery, so 45 days is compliant.

  7. Which of the following is NOT a required element of the contact information a covered entity must provide in a breach notification letter?

    Answer: The name and title of the privacy officer who authorized the notification

    Breach notifications must include a toll-free number, email address, or website for questions, but HIPAA does not require the name and title of the privacy officer who authorized the notification.