HIPAA Enforcement and Penalties 5 — Questions and Answers
Question 1: A covered entity receives an OCR notice of proposed determination imposing a civil monetary penalty. The entity disagrees. What is its next step?
- Pay the penalty immediately or lose appeal rights
- Request a hearing before an Administrative Law Judge (ALJ) (Correct answer)
- File a complaint with the FTC
- Petition Congress directly for relief
Correct answer: Request a hearing before an Administrative Law Judge (ALJ)
A covered entity that contests an OCR civil monetary penalty may request a hearing before an HHS Administrative Law Judge within 90 days.
Question 2: Which of the following best describes the difference between a 'resolution agreement' and a 'civil monetary penalty' in HIPAA enforcement?
- Resolution agreements are criminal; CMPs are civil
- Resolution agreements are voluntary settlements; CMPs are formally imposed penalties (Correct answer)
- Resolution agreements only apply to business associates; CMPs apply to covered entities
- There is no practical difference between the two
Correct answer: Resolution agreements are voluntary settlements; CMPs are formally imposed penalties
Resolution agreements are negotiated, voluntary settlements between OCR and the covered entity, while civil monetary penalties are formally imposed through an administrative enforcement process.
Question 3: After an ALJ decision in a HIPAA civil penalty case, what further appeal options exist?
- No further appeals are allowed
- Appeal to the HHS Departmental Appeals Board, then federal court (Correct answer)
- Immediate appeal to the U.S. Supreme Court
- Appeal only to the HHS Secretary, with no judicial review
Correct answer: Appeal to the HHS Departmental Appeals Board, then federal court
After an ALJ decision, either party may appeal to the HHS Departmental Appeals Board, and the final agency decision is then subject to review in federal court.
Question 4: A covered entity corrects a HIPAA violation within 30 days of OCR notification. Under which penalty tier does this correction provision NOT eliminate liability?
- Tier 1 — unknowing violations
- Tier 2 — reasonable cause
- Tier 3 — willful neglect, corrected
- Tier 4 — willful neglect, not corrected (Correct answer)
Correct answer: Tier 4 — willful neglect, not corrected
The 30-day correction window provides an affirmative defense for Tiers 1–3, but Tier 4 (willful neglect, not corrected) carries mandatory penalties that cannot be avoided by late correction.
Question 5: Which of the following HIPAA violations would OCR most likely treat as a priority for investigation?
- A one-time accidental fax sent to the wrong number affecting 1 individual
- A systematic failure to provide patients with Notice of Privacy Practices affecting thousands (Correct answer)
- A business associate missing a single BAA signature deadline by one day
- A workforce member who forgot to log out of a workstation once
Correct answer: A systematic failure to provide patients with Notice of Privacy Practices affecting thousands
OCR prioritizes investigations involving systemic failures, large numbers of individuals, or patterns of non-compliance over isolated, low-impact incidents.
Question 6: When HHS imposes a civil monetary penalty, the funds are deposited into:
- The Social Security Trust Fund
- The general fund of the U.S. Treasury (Correct answer)
- The HIPAA Victim Compensation Fund
- The HHS Office for Civil Rights operating budget
Correct answer: The general fund of the U.S. Treasury
Civil monetary penalties collected under HIPAA are deposited into the general fund of the U.S. Treasury (with a portion potentially distributed to harmed individuals per HITECH).
Question 7: A covered entity reports a breach affecting 450 individuals but fails to notify HHS within 60 days of the end of the calendar year. Which HIPAA rule has been violated?
- The Privacy Rule's minimum necessary standard
- The Breach Notification Rule's annual reporting requirement (Correct answer)
- The Security Rule's risk analysis provision
- The Enforcement Rule's self-disclosure protocol
Correct answer: The Breach Notification Rule's annual reporting requirement
For breaches affecting fewer than 500 individuals, covered entities must report to HHS no later than 60 days after the end of the calendar year in which the breaches occurred.
A covered entity receives an OCR notice of proposed determination imposing a civil monetary penalty.
The entity disagrees.
What is its next step?