HIPAA Compliance 4 โ Questions and Answers
Question 1: Which of the following HIPAA Security Rule safeguards requires covered entities to implement automatic logoff on workstations?
- Administrative safeguards โ access management
- Physical safeguards โ workstation use
- Technical safeguards โ automatic logoff (Correct answer)
- Physical safeguards โ device and media controls
Correct answer: Technical safeguards โ automatic logoff
Automatic logoff is an addressable implementation specification under the Technical Safeguards section of the HIPAA Security Rule (45 CFR ยง 164.312).
Question 2: What does the HIPAA 'Safe Harbor' de-identification method require?
- Removal of 17 specific categories of identifiers and no actual knowledge of re-identification (Correct answer)
- Expert certification that re-identification risk is very small
- Encryption of all remaining data fields
- Conversion of PHI into aggregate statistics only
Correct answer: Removal of 17 specific categories of identifiers and no actual knowledge of re-identification
The Safe Harbor method requires removing all 18 categories of specified identifiers (one category covers geographic data down to three-digit ZIP codes) and that the covered entity has no actual knowledge that the remaining information could re-identify an individual.
Question 3: A subcontractor of a business associate handles ePHI as part of its work. Under HIPAA, the subcontractor is:
- Not covered by HIPAA because it has no direct relationship with the covered entity
- Considered a business associate and must comply with the Security Rule directly (Correct answer)
- Only liable if the original business associate fails to supervise them
- Subject to HIPAA only if they also handle paper records
Correct answer: Considered a business associate and must comply with the Security Rule directly
The HITECH Act extended direct HIPAA liability to subcontractors of business associates; they are treated as business associates and must comply with applicable HIPAA Rules.
Question 4: A patient requests access to their PHI in an electronic format. If the covered entity maintains the records electronically, it must:
- Provide the records in any format the covered entity prefers
- Provide the records in the electronic format requested by the individual if readily producible (Correct answer)
- Convert all records to paper before providing them
- Deny the request if the records contain clinical notes
Correct answer: Provide the records in the electronic format requested by the individual if readily producible
Under HIPAA and HITECH, if a covered entity maintains PHI electronically, it must provide that PHI in the electronic format requested by the individual if it is readily producible in that format.
Question 5: Which of the following is NOT a permissible disclosure of PHI without individual authorization under the HIPAA Privacy Rule?
- Disclosure to public health authorities for disease reporting
- Disclosure to a marketing firm for a drug manufacturer's campaign (Correct answer)
- Disclosure to law enforcement in response to a court order
- Disclosure to a coroner for purposes of identifying a deceased person
Correct answer: Disclosure to a marketing firm for a drug manufacturer's campaign
HIPAA does not permit disclosure of PHI to marketing firms for commercial purposes without individual authorization; the other listed disclosures are recognized exceptions.
Question 6: Under HIPAA, the term 'incidental disclosure' refers to:
- Any unauthorized disclosure that results in a breach
- A secondary disclosure that occurs as a byproduct of a permissible use or disclosure, when reasonable safeguards are in place (Correct answer)
- A disclosure made to an unintended recipient via email
- Any disclosure made without the patient's written authorization
Correct answer: A secondary disclosure that occurs as a byproduct of a permissible use or disclosure, when reasonable safeguards are in place
An incidental disclosure is a secondary disclosure that cannot be reasonably prevented, is limited in nature, and occurs as a by-product of an otherwise permissible use or disclosure; it is not a violation when reasonable safeguards are in place.
Question 7: A covered entity wants to use PHI for a research study. Which of the following satisfies HIPAA requirements for this use?
- Verbal consent from the patient at the time of treatment
- An IRB waiver of authorization or individual written authorization from each subject (Correct answer)
- A general opt-out provision in the entity's Notice of Privacy Practices
- A data use agreement between the covered entity and the researcher only
Correct answer: An IRB waiver of authorization or individual written authorization from each subject
Research use of PHI requires either individual written authorization or an IRB (Institutional Review Board) waiver/alteration of authorization, or the PHI must be de-identified.
Which of the following HIPAA Security Rule safeguards requires covered entities to implement automatic logoff on workstations?