HIPAA Breach Notification Rule 4 — Questions and Answers
Question 1: A covered entity discovers PHI was sent to an incorrect fax number. The recipient confirms they destroyed the fax without reading it. Which breach exception may apply?
- Workforce member good faith exception
- Inadvertent disclosure exception where recipient could not reasonably retain information (Correct answer)
- The small breach exception
- No exception applies; notification is always required for misdirected faxes
Correct answer: Inadvertent disclosure exception where recipient could not reasonably retain information
If the unintended recipient could not reasonably have retained the information (e.g., confirmed immediate destruction), this may qualify as an inadvertent disclosure that is not a reportable breach.
Question 2: When a breach involves PHI of individuals from multiple states, which state's media outlets must receive notification?
- Only the state where the covered entity is headquartered
- Only the state where the most individuals were affected
- The media outlets in each state where more than 500 residents were affected (Correct answer)
- All 50 states must receive media notification regardless of how many individuals are affected in each
Correct answer: The media outlets in each state where more than 500 residents were affected
Media notification is required in each state or jurisdiction where more than 500 of its residents were affected by the breach.
Question 3: What is the purpose of the HHS 'Wall of Shame' website?
- It publishes the names of individuals who file false breach reports
- It lists covered entities that have been fined for HIPAA violations
- It publicly lists breaches affecting 500 or more individuals currently under investigation (Correct answer)
- It ranks business associates by their number of breaches
Correct answer: It publicly lists breaches affecting 500 or more individuals currently under investigation
The HHS 'Wall of Shame' is an online database listing reported breaches affecting 500 or more individuals that are currently under investigation by OCR.
Question 4: Under the Breach Notification Rule, which of the following correctly describes when a breach is considered 'discovered'?
- When a member of the workforce first suspects a breach may have occurred
- When the covered entity or business associate first knows or reasonably should have known that a breach occurred (Correct answer)
- When the covered entity's legal team confirms a breach occurred
- When the breach is officially reported to HHS
Correct answer: When the covered entity or business associate first knows or reasonably should have known that a breach occurred
A breach is considered discovered on the first day the covered entity or business associate knows or reasonably should have known of the breach.
Question 5: Which of the following types of PHI, if breached, carries the HIGHEST inherent risk in the four-factor risk assessment?
- Name and date of birth only
- Social Security numbers, financial account numbers, or sensitive clinical information (Correct answer)
- General diagnosis codes without other identifying information
- Email addresses without any associated health information
Correct answer: Social Security numbers, financial account numbers, or sensitive clinical information
The nature and extent of PHI, including the type of identifiers involved and the likelihood of re-identification, means SSNs, financial data, and sensitive clinical details carry higher risk.
Question 6: A business associate contract requires the business associate to notify the covered entity of a breach within 30 days. The business associate reports at day 35. Which statement is correct?
- This is acceptable because HIPAA only requires notification within 60 days (Correct answer)
- The business associate has violated both the contractual obligation and acted unreasonably under HIPAA
- HIPAA overrides the contract, so 60 days is always acceptable
- The business associate is in violation of the contract but not HIPAA
Correct answer: This is acceptable because HIPAA only requires notification within 60 days
HIPAA requires business associates to notify covered entities without unreasonable delay and within 60 days, so day 35 satisfies HIPAA even if it violates the stricter contractual deadline.
Question 7: A covered entity sends breach notifications by first-class mail. The affected individual has moved and does not receive the letter. What does HIPAA require the covered entity to do?
- Resend the notification via certified mail immediately
- Attempt email notification as a follow-up
- Provide substitute notification if the covered entity knows the notice was not received
- No additional action is required; mailing first-class mail satisfies the obligation (Correct answer)
Correct answer: No additional action is required; mailing first-class mail satisfies the obligation
Sending breach notifications via first-class mail to the last known address satisfies HIPAA's notification requirement, even if the individual has moved.
A covered entity discovers PHI was sent to an incorrect fax number.
The recipient confirms they destroyed the fax without reading it.
Which breach exception may apply?