HIPAA Breach Notification Rule 5 — Questions and Answers
Question 1: Which HITECH Act provision established the Breach Notification Rule requirements that are now part of HIPAA?
- Title I — Quality, Affordable Health Care for All Americans
- Title XIII — Health Information Technology for Economic and Clinical Health (Correct answer)
- Title II — The Role of Public Programs
- Title IV — Application and Enforcement of Group Health Plan Requirements
Correct answer: Title XIII — Health Information Technology for Economic and Clinical Health
The HITECH Act (Title XIII of ARRA) established breach notification requirements that were later incorporated into the HIPAA Breach Notification Rule.
Question 2: A healthcare clearinghouse discovers that a subcontractor improperly accessed PHI it was processing. Who is responsible for notifying affected individuals?
- The subcontractor directly notifies affected individuals
- The healthcare clearinghouse notifies the covered entity, who notifies individuals (Correct answer)
- The subcontractor notifies HHS, who then notifies individuals
- The healthcare clearinghouse directly notifies all affected individuals
Correct answer: The healthcare clearinghouse notifies the covered entity, who notifies individuals
Subcontractors (business associates of business associates) must notify the business associate, who notifies the covered entity, who is ultimately responsible for notifying affected individuals.
Question 3: A health plan mails an Explanation of Benefits to a member's former address, revealing PHI to an unknown person. How is this classified under the Breach Notification Rule?
- Not a breach because it was a mailing error, not an intentional disclosure
- A breach requiring full risk assessment to determine if notification is needed (Correct answer)
- Not a breach because EOBs are required by law to be mailed
- Always exempt from notification because it involves mailing errors
Correct answer: A breach requiring full risk assessment to determine if notification is needed
Misdirected EOBs involving PHI disclosure to unauthorized individuals require a four-factor risk assessment to determine whether breach notification is required.
Question 4: A ransomware attack encrypts a covered entity's servers containing PHI. Under HHS guidance, how is this typically classified?
- Not a breach because the data was not viewed, only encrypted
- A breach unless the covered entity can demonstrate a low probability of PHI compromise (Correct answer)
- Always a breach requiring immediate notification with no risk assessment needed
- Only a breach if the attacker demands and receives payment
Correct answer: A breach unless the covered entity can demonstrate a low probability of PHI compromise
HHS guidance indicates ransomware typically constitutes a breach, but covered entities may conduct a risk assessment and if they can demonstrate low probability of compromise, notification may not be required.
Question 5: What must a covered entity include in the annual breach log submitted to HHS for breaches affecting fewer than 500 individuals?
- Only the number of breaches and total individuals affected
- The date of each breach, type of PHI involved, description, and number of individuals affected (Correct answer)
- The names and contact information of all affected individuals
- Only breaches that resulted in financial harm to individuals
Correct answer: The date of each breach, type of PHI involved, description, and number of individuals affected
The annual log for small breaches must include the date of the breach, type of PHI, a description of what happened, and the approximate number of individuals affected.
Question 6: A covered entity provides breach notification to affected individuals 45 days after discovery. Is this compliant with HIPAA?
- No, notification must occur within 30 days of discovery
- Yes, notification within 60 days of discovery satisfies the requirement (Correct answer)
- No, notification must occur within 10 days of discovery for large breaches
- Yes, but only if fewer than 100 individuals were affected
Correct answer: Yes, notification within 60 days of discovery satisfies the requirement
HIPAA requires individual breach notification without unreasonable delay and within 60 days of discovery, so 45 days is compliant.
Question 7: Which of the following is NOT a required element of the contact information a covered entity must provide in a breach notification letter?
- A toll-free phone number active for at least 90 days
- An email address for individuals to ask questions
- The name and title of the privacy officer who authorized the notification (Correct answer)
- A website address where individuals can get more information
Correct answer: The name and title of the privacy officer who authorized the notification
Breach notifications must include a toll-free number, email address, or website for questions, but HIPAA does not require the name and title of the privacy officer who authorized the notification.
Which HITECH Act provision established the Breach Notification Rule requirements that are now part of HIPAA?