HIPAA Compliance 5 — Questions and Answers
Question 1: The HIPAA Breach Notification Rule defines 'unsecured PHI' as PHI that has NOT been:
- Stored in a locked cabinet or encrypted server room
- Rendered unusable, unreadable, or indecipherable through approved methods such as encryption or destruction (Correct answer)
- Accessed exclusively by workforce members with proper credentials
- Anonymized using the Safe Harbor method
Correct answer: Rendered unusable, unreadable, or indecipherable through approved methods such as encryption or destruction
Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through encryption or destruction per HHS guidance.
Question 2: Which of the following scenarios would most likely qualify for the 'limited data set' exception under HIPAA?
- Sharing fully identified patient records with a pharmaceutical company for drug trials
- Sharing PHI with direct geographic identifiers removed (but zip codes retained) under a data use agreement for research (Correct answer)
- Sharing de-identified data with no data use agreement for public health purposes
- Sharing PHI with a business associate without a BAA for research analysis
Correct answer: Sharing PHI with direct geographic identifiers removed (but zip codes retained) under a data use agreement for research
A limited data set removes most direct identifiers but may retain zip codes and dates; it requires a data use agreement and is permissible for research, public health, and health care operations.
Question 3: A healthcare clearinghouse processes claims for multiple covered entities. Under HIPAA, the clearinghouse is classified as:
- A business associate only if it has a signed BAA
- A covered entity subject to HIPAA directly (Correct answer)
- A hybrid entity combining covered and non-covered functions
- Not covered by HIPAA because it does not provide care
Correct answer: A covered entity subject to HIPAA directly
Healthcare clearinghouses are directly defined as covered entities under HIPAA because they process nonstandard health information into standard formats (or vice versa).
Question 4: Under HIPAA, an individual's right to an accounting of disclosures applies to disclosures made for which of the following purposes?
- Treatment, payment, and health care operations made after January 1, 2011
- Disclosures required by law, for public health purposes, and other non-TPO disclosures (Correct answer)
- All disclosures regardless of purpose, going back 10 years
- Only disclosures made to law enforcement agencies
Correct answer: Disclosures required by law, for public health purposes, and other non-TPO disclosures
The right to an accounting covers disclosures other than those for TPO, to the individual themselves, or pursuant to an authorization, for the 6 years prior to the request.
Question 5: A covered entity that is also a hybrid entity must:
- Apply HIPAA to all components of the organization equally
- Designate its health care component(s) and apply HIPAA only to those components (Correct answer)
- Obtain separate HIPAA certification for each business unit
- Apply HIPAA only to components that bill Medicare or Medicaid
Correct answer: Designate its health care component(s) and apply HIPAA only to those components
A hybrid entity must designate its health care component(s) in writing and ensure HIPAA applies to those components; non-health care components of the organization are generally not covered.
Question 6: When a covered entity imposes a fee for providing an individual with access to their PHI, HIPAA limits that fee to:
- A flat $25 administrative charge per request
- A reasonable, cost-based fee covering labor, supplies, and postage only (Correct answer)
- No more than $0.10 per page for paper copies
- Whatever the state medical records law allows without limitation
Correct answer: A reasonable, cost-based fee covering labor, supplies, and postage only
HIPAA limits fees for PHI access to a reasonable, cost-based fee that covers the cost of labor for copying, supplies, postage, and preparing an explanation or summary if requested.
Question 7: Which of the following best describes the 'conditioned' vs. 'unconditioned' authorization distinction under HIPAA?
- Conditioned authorizations tie treatment to signing a research consent; unconditioned ones do not (Correct answer)
- Conditioned authorizations require IRB approval; unconditioned ones do not
- Conditioned authorizations allow marketing use; unconditioned ones restrict it
- Conditioned authorizations apply only to mental health records; unconditioned ones apply to all PHI
Correct answer: Conditioned authorizations tie treatment to signing a research consent; unconditioned ones do not
HIPAA prohibits conditioning treatment on an individual signing an authorization for a use unrelated to treatment (such as research), making such bundled authorizations 'conditioned' and generally impermissible.
The HIPAA Breach Notification Rule defines 'unsecured PHI' as PHI that has NOT been: