HIPAA Breach Notification Rule 3 — Questions and Answers
Question 1: Under the Breach Notification Rule, when does the 60-day notification clock begin for a business associate who discovers a breach?
- When the covered entity is notified
- When HHS is notified
- When the business associate discovers the breach (Correct answer)
- When the breach actually occurred
Correct answer: When the business associate discovers the breach
The 60-day clock for business associate notification to covered entities begins on the date the business associate discovers the breach, not when the breach occurred.
Question 2: Which of the following breaches would require media notification under the HIPAA Breach Notification Rule?
- A breach affecting 450 patients in a single state
- A breach affecting 600 patients in a single state (Correct answer)
- A breach affecting 400 patients across multiple states
- A breach affecting 100 patients in a large metropolitan area
Correct answer: A breach affecting 600 patients in a single state
Media notification is required when a breach affects more than 500 residents of a state or jurisdiction.
Question 3: An employee accidentally emails PHI to a wrong recipient who is also a healthcare employee and does not open or read it. Under which exception might this NOT be classified as a reportable breach?
- The workforce member good faith exception
- The inadvertent disclosure exception where the recipient could not reasonably retain the information (Correct answer)
- The de minimis harm exception
- The small breach exception for fewer than 10 individuals
Correct answer: The inadvertent disclosure exception where the recipient could not reasonably retain the information
Inadvertent disclosure of PHI between authorized persons where the recipient could not reasonably have retained the information is an exception to the definition of breach.
Question 4: A covered entity conducts a risk assessment after discovering that an employee inappropriately accessed patient records. The assessment determines there is a low probability that PHI was compromised. What should the covered entity do?
- No notification is required if the risk assessment shows low probability of compromise (Correct answer)
- Notification is still required regardless of the risk assessment outcome
- Only notify HHS but not affected individuals
- Only notify affected individuals but not HHS
Correct answer: No notification is required if the risk assessment shows low probability of compromise
If the risk assessment demonstrates low probability that PHI was compromised, the covered entity may determine no breach notification is required.
Question 5: How must a covered entity notify individuals affected by a breach if they have email addresses on file and individuals have agreed to electronic notice?
- Email notification is never permitted for breach notification
- Email is acceptable only if the breach did not involve email addresses
- Email notification is permitted if the individual has agreed to receive electronic notice (Correct answer)
- Email is acceptable only for breaches affecting more than 500 individuals
Correct answer: Email notification is permitted if the individual has agreed to receive electronic notice
Covered entities may use email for breach notification if the individual has previously agreed to receive notices electronically.
Question 6: Which HHS office is responsible for enforcing the HIPAA Breach Notification Rule?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) (Correct answer)
- Office of Inspector General (OIG)
- National Institutes of Health (NIH)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Breach Notification Rule.
Question 7: A covered entity's risk assessment determines PHI was accessed by an unauthorized person. The entity argues the harm is minimal. Can they skip breach notification?
- Yes, if the entity documents that harm is minimal
- Yes, if fewer than 10 individuals are affected
- No, the risk assessment evaluates probability of compromise, not level of harm (Correct answer)
- No, but they can delay notification by 30 days if harm is minimal
Correct answer: No, the risk assessment evaluates probability of compromise, not level of harm
The risk assessment standard evaluates the probability that PHI was compromised, not the severity of harm; if compromise probability is not low, notification is required.
Under the Breach Notification Rule, when does the 60-day notification clock begin for a business associate who discovers a breach?