HIPAA Compliance 2 — Questions and Answers
Question 1: Under HIPAA, a covered entity must designate a Privacy Officer responsible for which primary duty?
- Overseeing IT infrastructure security
- Developing and implementing privacy policies and procedures (Correct answer)
- Managing insurance claims processing
- Conducting annual financial audits
Correct answer: Developing and implementing privacy policies and procedures
HIPAA's Privacy Rule requires covered entities to designate a Privacy Official responsible for developing and implementing the entity's privacy policies and procedures.
Question 2: A Business Associate Agreement (BAA) must be executed before a vendor can:
- Access the covered entity's website analytics
- Receive or create PHI on behalf of the covered entity (Correct answer)
- Submit invoices to the covered entity
- Access the covered entity's public marketing materials
Correct answer: Receive or create PHI on behalf of the covered entity
A BAA is required whenever a vendor (business associate) will create, receive, maintain, or transmit PHI on behalf of a covered entity.
Question 3: How long must a covered entity retain its HIPAA policies, procedures, and related documentation?
- 3 years from the date of creation or last effective date
- 6 years from the date of creation or last effective date (Correct answer)
- 10 years from the date of creation
- Indefinitely
Correct answer: 6 years from the date of creation or last effective date
HIPAA requires covered entities to retain documentation of policies and procedures for 6 years from the date of creation or the date it was last in effect, whichever is later.
Question 4: Which of the following is the correct standard for a covered entity to use PHI for marketing purposes under HIPAA?
- Marketing is permitted with a general notice in the NPP
- Marketing using PHI generally requires individual written authorization (Correct answer)
- Marketing is always prohibited under HIPAA
- Marketing is permitted if the individual has not opted out
Correct answer: Marketing using PHI generally requires individual written authorization
HIPAA generally requires individual written authorization before a covered entity can use or disclose PHI for marketing communications.
Question 5: A hospital employee accesses the medical records of a famous patient out of curiosity, without a treatment need. This is a violation of which HIPAA principle?
- The Breach Notification Rule
- The Minimum Necessary standard (Correct answer)
- The Notice of Privacy Practices requirement
- The Safe Harbor de-identification standard
Correct answer: The Minimum Necessary standard
The Minimum Necessary standard requires workforce members to access only the PHI needed to perform their job duties; accessing records out of curiosity violates this principle.
Question 6: Under the HIPAA Security Rule, which category of safeguards includes policies for workforce supervision and information access management?
- Physical safeguards
- Technical safeguards
- Administrative safeguards (Correct answer)
- Operational safeguards
Correct answer: Administrative safeguards
Administrative safeguards are administrative actions and policies designed to manage workforce conduct and protect electronic PHI, including access management and workforce training.
Question 7: Which entity has primary enforcement authority over HIPAA compliance?
- The Federal Bureau of Investigation (FBI)
- The Department of Justice (DOJ) exclusively
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Under HIPAA, a covered entity must designate a Privacy Officer responsible for which primary duty?