HIPAA Enforcement and Penalties 3 — Questions and Answers
Question 1: Under the HITECH Act, what percentage of collected HIPAA civil monetary penalties must be used for affected individuals?
- 10%
- 25%
- 50%
- A percentage determined by the HHS Secretary (Correct answer)
Correct answer: A percentage determined by the HHS Secretary
The HITECH Act authorizes HHS to distribute a percentage of CMPs to harmed individuals, with the exact percentage determined by the HHS Secretary.
Question 2: Which of the following is NOT a factor OCR considers when determining the amount of a civil monetary penalty?
- The nature and extent of the harm resulting from the violation
- The number of individuals affected
- The financial condition of the covered entity
- The political affiliation of the covered entity's leadership (Correct answer)
Correct answer: The political affiliation of the covered entity's leadership
OCR considers factors such as harm, number of individuals affected, and financial condition, but political affiliation is not a relevant factor.
Question 3: A hospital employee snoops through a celebrity patient's records out of curiosity and shares them with friends. Which criminal tier most likely applies?
- No criminal liability — only civil penalties apply
- Tier 1: up to 1 year in prison
- Tier 2: up to 5 years in prison (Correct answer)
- Tier 3: up to 10 years in prison
Correct answer: Tier 2: up to 5 years in prison
Knowingly obtaining or disclosing PHI under false pretenses (beyond simple curiosity, for personal benefit/sharing) typically falls under Tier 2, carrying up to 5 years imprisonment.
Question 4: The statute of limitations for OCR to impose a civil monetary penalty for a HIPAA violation is:
- 1 year from the date of the violation
- 3 years from when the violation was known or should have been known
- 6 years from the date of the violation (Correct answer)
- No limitation — penalties can be imposed at any time
Correct answer: 6 years from the date of the violation
OCR must impose civil monetary penalties within 6 years of the date the violation occurred.
Question 5: Which scenario would most likely result in OCR finding 'willful neglect — not corrected'?
- A small clinic unaware of the Breach Notification Rule fails to notify once
- A hospital discovers its Risk Analysis has never been done and immediately corrects it
- A practice repeatedly ignores OCR compliance recommendations over two years and makes no changes (Correct answer)
- An employee accidentally emails PHI to the wrong patient
Correct answer: A practice repeatedly ignores OCR compliance recommendations over two years and makes no changes
Willful neglect uncorrected means the entity consciously and intentionally failed to comply without timely correction, making repeated inaction despite warnings the clearest example.
Question 6: What is the annual cap on civil monetary penalties for identical violations under a single HIPAA provision?
- $100,000
- $500,000
- $1,000,000
- $1,919,173 (inflation-adjusted) (Correct answer)
Correct answer: $1,919,173 (inflation-adjusted)
The annual cap per identical violation category is $1.5 million, adjusted periodically for inflation (currently approximately $1.919 million).
Question 7: When a business associate is directly liable for a HIPAA violation, OCR may:
- Only fine the covered entity, not the business associate
- Fine the business associate directly under HIPAA (Correct answer)
- Refer the matter exclusively to the FTC
- Only suspend the business associate's federal contracts
Correct answer: Fine the business associate directly under HIPAA
Since the HITECH Act, business associates are directly subject to HIPAA civil and criminal penalties and OCR can fine them directly.
Under the HITECH Act, what percentage of collected HIPAA civil monetary penalties must be used for affected individuals?