HIPAA Healthcare Provider Obligations and Covered Entities — Questions and Answers
Question 1: Under HIPAA, which of the following is a 'covered entity'?
- A software company that builds EHR systems
- A healthcare clearinghouse that processes health insurance claims electronically (Correct answer)
- A law firm advising a hospital on HIPAA compliance
- A patient advocacy organization that does not handle billing
Correct answer: A healthcare clearinghouse that processes health insurance claims electronically
Healthcare clearinghouses that process health information from non-standard to standard formats are one of the three categories of HIPAA covered entities.
HIPAA defines three categories of covered entities (45 CFR §160.103): (1) Health Plans — individual/group plans providing or paying for medical care; (2) Healthcare Clearinghouses — entities that process nonstandard health information into standard transactions or vice versa; and (3) Healthcare Providers — providers who transmit health information electronically in connection with HIPAA standard transactions. A software company building EHR systems is a business associate (not a covered entity); a law firm is neither a covered entity nor typically a business associate (attorney-client privilege); a clearinghouse processing claims electronically is definitively a covered entity.
Question 2: A small cash-only family physician practice that has never transmitted any health information electronically is subject to HIPAA under which condition?
- Small cash-only practices are entirely exempt from HIPAA
- The practice becomes covered if it submits even a single electronic claim or electronic transaction covered by HIPAA standards (Correct answer)
- HIPAA applies only to practices with more than 10 employees
- Cash-only practices are covered entities from the day they open regardless of electronic transactions
Correct answer: The practice becomes covered if it submits even a single electronic claim or electronic transaction covered by HIPAA standards
Healthcare providers become HIPAA covered entities only when they conduct electronic transactions using HIPAA standard transactions — a single electronic submission triggers covered entity status.
Under 45 CFR §160.103, a healthcare provider is a covered entity only if they transmit any health information in electronic form in connection with a transaction covered by HIPAA (such as electronic claims submission, eligibility inquiries, or remittance advice). A physician who sees cash-only patients and submits no electronic claims, orders no electronic lab tests, and uses no electronic transactions is technically not a covered entity. However, any single electronic HIPAA transaction makes them a covered entity subject to all HIPAA requirements — making it very rare for modern practices to avoid coverage. The definition of 'electronic' includes all digital transmissions regardless of medium.
Question 3: Which of the following healthcare entities is NOT typically a covered entity under HIPAA?
- An individual physician in private practice who submits claims electronically
- A workers' compensation insurer (Correct answer)
- A hospital emergency department
- A Medicare Advantage plan
Correct answer: A workers' compensation insurer
Workers' compensation insurers are specifically excluded from HIPAA's definition of health plans because they provide coverage for work-related injuries, not health coverage per se.
HIPAA's definition of 'health plan' excludes several insurance types: workers' compensation programs, automobile insurance, liability insurance, and property and casualty insurance. Workers' compensation programs provide benefits for work-related injuries and are governed by state workers' compensation laws, not HIPAA. However, healthcare providers who treat workers' compensation patients must still comply with HIPAA in handling the PHI they create in treating these patients — they are covered entities for their own PHI, even if the payor (workers' comp insurer) is not. Other excluded entities: employment records held by employers, school records covered by FERPA.
Question 4: Under HIPAA, what is a 'hybrid entity'?
- An organization that serves both as a covered entity and a business associate simultaneously
- An organization that performs both covered and non-covered healthcare functions within the same legal entity (Correct answer)
- A for-profit organization that also operates a non-profit health clinic
- An entity with locations in multiple states with different HIPAA obligations
Correct answer: An organization that performs both covered and non-covered healthcare functions within the same legal entity
A hybrid entity is a single legal entity that performs both HIPAA-covered healthcare functions and non-healthcare functions within the same organization.
45 CFR §164.103-105 addresses hybrid entities — legal entities that perform both covered (healthcare) and non-covered functions within the same organization. Examples: a university that operates a hospital (covered) and a business school (not covered); a corporation that owns a health plan subsidiary and non-health businesses; or a large employer with an on-site medical clinic. Hybrid entities may designate their 'healthcare components' — the parts subject to HIPAA — and wall off non-covered components from PHI access. This designation must be documented and access controls implemented to prevent PHI from flowing to non-covered components.
Question 5: What is the primary HIPAA obligation when a healthcare provider refers a patient to a specialist?
- The provider must obtain written patient authorization before sending any information to the specialist
- The provider may share the minimum necessary PHI for treatment purposes without patient authorization (Correct answer)
- The patient's insurance must be notified before any referral PHI is shared
- Referral PHI can only be shared by fax, never electronically
Correct answer: The provider may share the minimum necessary PHI for treatment purposes without patient authorization
Treatment disclosures between healthcare providers are explicitly permitted under HIPAA's Privacy Rule without individual authorization, subject to the minimum necessary standard.
45 CFR §164.506(c)(2) permits covered entities to disclose PHI for treatment purposes to another healthcare provider without individual authorization. A referring physician may share diagnosis, test results, medication lists, and treatment history with a specialist for purposes of treatment coordination. The minimum necessary standard (§164.514(d)) applies — share what the specialist needs to provide care, but not more. This permission is central to enabling coordinated healthcare delivery. Note that while authorization is not required for treatment disclosures between providers, providers must still have appropriate safeguards in place (secure fax, encrypted email, or health information exchange).
Question 6: A hospital employed physician has PHI access as part of her clinical role. The same physician's practice is also employed in a non-clinical administrative role at the hospital. Under HIPAA, when she accesses PHI for administrative purposes, what standard applies?
- No restrictions apply since she is a workforce member of the covered entity
- Access for administrative purposes must be limited to the minimum necessary for the administrative function (Correct answer)
- Administrative access to PHI is prohibited under HIPAA
- PHI may only be accessed by clinical staff, not administrative staff
Correct answer: Access for administrative purposes must be limited to the minimum necessary for the administrative function
Even when a clinician performs administrative functions, PHI access for those functions must comply with the minimum necessary standard for administrative purposes.
The minimum necessary standard (45 CFR §164.514(d)) applies to each use or disclosure based on its purpose. Even a physician with clinical PHI access must limit administrative access to PHI to what is needed for the administrative task. A physician reviewing quality metrics for a quality improvement committee needs aggregate data, not full patient records. Accessing full records for an administrative function would violate the minimum necessary standard. Covered entities should implement role-based access controls that distinguish between the same individual's clinical and administrative roles, providing appropriate access for each context.
Question 7: Under HIPAA, what is an 'affiliated covered entity'?
- A covered entity with branches in multiple states
- Two or more legally separate covered entities under common ownership that may designate themselves as a single covered entity for HIPAA purposes (Correct answer)
- Any covered entity that has executed BAAs with business associates
- A covered entity that has undergone HHS-approved merger
Correct answer: Two or more legally separate covered entities under common ownership that may designate themselves as a single covered entity for HIPAA purposes
Affiliated covered entities are legally separate HIPAA-covered organizations under common ownership/control that may elect to be treated as a single covered entity, simplifying PHI sharing among affiliates.
45 CFR §164.105(b) allows legally separate covered entities under common ownership or control to designate themselves as a single affiliated covered entity for HIPAA compliance purposes. Benefits include: simpler PHI sharing between affiliates (no BAAs needed between affiliated entities), streamlined privacy policies and training, and combined compliance programs. Requirements: the designation must be documented; appropriate safeguards must be in place where PHI is shared; and the designation cannot undermine privacy protections. Examples: hospital system with multiple hospitals; health insurer with a medical group subsidiary; large healthcare network.
Question 8: Which of the following represents a covered entity's obligation under HIPAA when receiving a request for PHI from law enforcement?
- Covered entities must provide all requested PHI to law enforcement immediately
- Covered entities may only disclose PHI to law enforcement under specific circumstances without authorization and should disclose only what is required (Correct answer)
- Law enforcement requests always require patient authorization before disclosure
- Police requests for PHI can be denied entirely without any legal consequences
Correct answer: Covered entities may only disclose PHI to law enforcement under specific circumstances without authorization and should disclose only what is required
HIPAA permits (but generally does not require) limited PHI disclosures to law enforcement under specific circumstances, and covered entities should disclose only what is specifically required.
45 CFR §164.512(f) permits (not requires) covered entities to disclose PHI to law enforcement for specific purposes: pursuant to legal process (court order, subpoena); to identify a suspect, fugitive, or missing person; to report crimes on the premises; or in response to an administrative request meeting specified criteria. For each category, only specific information may be disclosed. HIPAA generally does not require disclosure to law enforcement — other laws may. Covered entities should have policies addressing law enforcement requests and consult legal counsel when uncertain. The minimum necessary standard applies: disclose only what is specifically required by the legal instrument or situation.
Question 9: A covered entity's employee discovers that a family member is a patient at their organization. Under HIPAA, what is the employee's obligation?
- The employee may access the family member's records as a courtesy
- The employee must not access the family member's records unless they are directly involved in that person's care (Correct answer)
- Only immediate family members' records can be accessed; extended family requires authorization
- The employee must inform the family member that their records are accessible
Correct answer: The employee must not access the family member's records unless they are directly involved in that person's care
Workforce members may not access PHI of patients they are not involved in treating — 'snooping' on family members' records is a HIPAA violation even with good intentions.
One of the most common HIPAA violations is workforce members accessing records of family members, friends, neighbors, or celebrities out of curiosity or concern — not as part of their care team role. This violates HIPAA's minimum necessary standard and access control requirements. Unless the employee is part of the family member's treatment team, they have no business need for the PHI. Access based on personal relationship rather than job function is an unauthorized disclosure. These incidents are frequently detected through audit log reviews and can result in termination and, for egregious cases, criminal prosecution. Organizations should explicitly address this scenario in workforce training.
Question 10: Under HIPAA, what must a covered entity provide to patients at first service delivery?
- A copy of the entire HIPAA Privacy Rule
- A Notice of Privacy Practices describing how the covered entity uses and discloses PHI (Correct answer)
- Written authorization forms for all potential future uses of their PHI
- A list of all workforce members with access to their PHI
Correct answer: A Notice of Privacy Practices describing how the covered entity uses and discloses PHI
HIPAA requires covered entities to provide patients with a Notice of Privacy Practices (NPP) at first service delivery, explaining how their PHI will be used and protected.
45 CFR §164.520 requires covered entities to provide individuals with a Notice of Privacy Practices at first contact or service delivery. For healthcare providers with direct treatment relationships, the NPP must be provided no later than the first service delivery. The NPP must describe: permitted uses and disclosures of PHI; patient rights (access, amendment, restrictions, accounting); duties of the covered entity; how to file complaints; and effective date. Patients must be asked to sign an acknowledgment of receipt (the covered entity must make a good faith effort to obtain signature, but the patient may decline). The NPP must also be posted in the facility and on the website.
Question 11: Under HIPAA, what is a 'workforce member' for compliance purposes?
- Only full-time paid employees of the covered entity
- Employees, volunteers, trainees, and others whose conduct is under the direct control of the covered entity (Correct answer)
- Staff with access to EHR systems regardless of employment relationship
- Only clinical staff who directly access PHI
Correct answer: Employees, volunteers, trainees, and others whose conduct is under the direct control of the covered entity
HIPAA's definition of workforce includes all individuals under the covered entity's direct control — paid or unpaid, full or part-time, including volunteers and trainees.
45 CFR §160.103 defines 'workforce' as 'employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business associate.' This comprehensive definition means HIPAA workforce training, sanction policies, and access controls apply to medical students on rotation, resident physicians, nursing students, administrative volunteers, IT contractors working on-site, and temporary agency staff — not just permanent paid employees. Covered entities must include all these individuals in their compliance programs.
Question 12: A physician wants to share PHI with a patient's family member who is present during an office visit. Under HIPAA, what governs this disclosure?
- Sharing with family is always prohibited without written authorization
- The covered entity may share PHI with the family member if the patient is present and does not object, using professional judgment (Correct answer)
- Only spouses may receive PHI without written authorization
- Family members may receive PHI only if listed in the patient's advance directive
Correct answer: The covered entity may share PHI with the family member if the patient is present and does not object, using professional judgment
HIPAA's Privacy Rule allows PHI disclosure to family members present during care when the patient does not object, using professional judgment about the patient's best interest.
45 CFR §164.510(b) addresses disclosures for involvement in the individual's care and notification. When a patient is present (and has capacity), a covered entity may disclose PHI to family members, close friends, or others involved in care if: (1) the patient agrees; (2) the patient does not object when given the opportunity; or (3) the covered entity infers from the circumstances that sharing is not against the patient's interest. The provider should use professional judgment — for example, if a spouse asks for information and the patient doesn't object, sharing is permitted. If a patient requests that information not be shared with family, that request must be honored. For incapacitated patients, clinical judgment governs.
Question 13: What is the significance of HIPAA's 'treatment exception' to the minimum necessary standard?
- Doctors can share all patient information with any other doctor without restriction
- Healthcare providers are not required to apply the minimum necessary standard when disclosing PHI to other providers for treatment purposes (Correct answer)
- The treatment exception eliminates all HIPAA requirements for clinical communications
- Only specialists qualify for the treatment exception; primary care providers do not
Correct answer: Healthcare providers are not required to apply the minimum necessary standard when disclosing PHI to other providers for treatment purposes
HIPAA explicitly exempts disclosures to other healthcare providers for treatment purposes from the minimum necessary standard, recognizing that clinical care requires comprehensive information access.
45 CFR §164.514(d)(3)(i)(A) explicitly exempts disclosures to or requests from other healthcare providers for treatment from the minimum necessary standard. This exception is based on the understanding that healthcare providers need complete clinical information to provide adequate care — artificially limiting PHI in a referral could harm patients. For example, sending a complete medication list, full problem list, and relevant history to a specialist is appropriate without minimum necessary analysis. Contrast this with non-treatment uses: a billing office request or a researcher's request must comply with the minimum necessary standard. The treatment exception does not eliminate all HIPAA requirements — PHI must still be disclosed through appropriate channels with appropriate safeguards.
Question 14: A hospital patient asks to inspect their own medical records during their admission. Under HIPAA, what is the hospital's obligation?
- Hospitals are not required to allow inspection during admission for operational reasons
- The hospital must provide access within a reasonable timeframe, though access during admission may be deferred until after discharge (Correct answer)
- Patients have no right to inspect records — only copies may be requested post-discharge
- The hospital must provide immediate access to all records upon request
Correct answer: The hospital must provide access within a reasonable timeframe, though access during admission may be deferred until after discharge
While HIPAA gives patients the right to access their records, hospitals may use reasonable operational provisions and provide access within 30 days post-request.
45 CFR §164.524(a)(1) provides the right to inspect and obtain a copy of PHI in designated record sets. However, covered entities have 30 days to act on access requests (with one 30-day extension). For in-patient requests, hospitals should have policies addressing timely access while managing patient care operations. Access may be denied in limited circumstances (e.g., a licensed professional determines access could endanger the individual or another person). In practice, most hospitals provide portal access during admission and fulfill formal record requests within the regulatory timeframe after discharge. The 2020 right of access updates prohibit unreasonable delays and excessive fees.
Question 15: Under HIPAA, what are a covered entity's obligations when receiving a written patient request for amendment of PHI?
- The covered entity must make any amendment requested by the patient without review
- The covered entity must act on the amendment request within 60 days, and may deny it with specific required reasoning if the PHI is accurate and complete (Correct answer)
- Amendment requests may be ignored if the PHI is over 5 years old
- Only the treating physician may approve amendments to clinical records
Correct answer: The covered entity must act on the amendment request within 60 days, and may deny it with specific required reasoning if the PHI is accurate and complete
HIPAA gives patients the right to request amendment of their PHI, but covered entities may deny requests if the information is accurate and complete, acting within 60 days.
45 CFR §164.526 establishes amendment rights. Covered entities must act on amendment requests within 60 days (one 30-day extension permitted). They may deny requests if: the PHI was not created by the covered entity; the PHI is not part of the designated record set; the PHI would not be available for access under the right of access provisions; or the covered entity determines the PHI is accurate and complete. If denied, the covered entity must provide written notice with the basis for denial, and the patient has the right to submit a statement of disagreement, which the covered entity must include in the record. The covered entity may also prepare a rebuttal statement.
Question 16: A covered entity discloses PHI for public health activities. Under HIPAA, what activities are considered permissible public health disclosures?
- Only annual aggregate statistics reports to state health departments
- Reporting communicable diseases, adverse events from products, child abuse, and vital statistics to authorized public health authorities (Correct answer)
- Publishing individual patient data in public health journals
- Sharing PHI with the general public for health awareness campaigns
Correct answer: Reporting communicable diseases, adverse events from products, child abuse, and vital statistics to authorized public health authorities
HIPAA permits PHI disclosure to public health authorities for disease surveillance, adverse event reporting, child abuse reporting, and vital statistics — without patient authorization.
45 CFR §164.512(b) permits covered entities to disclose PHI to public health authorities authorized by law to collect such information for: (1) preventing or controlling disease, injury, or disability; (2) reporting vital events (births, deaths); (3) conducting public health surveillance, investigation, and intervention; (4) notifying persons who may have been exposed to a communicable disease; (5) reporting adverse events related to FDA-regulated products; (6) reporting suspected child abuse. Mandatory disease reporting laws (e.g., STI reporting, cancer registries) override individual privacy interests. Healthcare providers should be familiar with mandatory reporting requirements in their state, which vary significantly.
Question 17: Under HIPAA, what must a covered entity do to comply with the 'accounting of disclosures' requirement?
- Provide patients with a real-time log of every time their PHI is accessed
- Maintain a record of disclosures made outside of treatment, payment, operations, and other exempt categories, available to patients upon request (Correct answer)
- Provide monthly disclosure reports to HHS for all patients
- Only track disclosures to other covered entities, not to business associates
Correct answer: Maintain a record of disclosures made outside of treatment, payment, operations, and other exempt categories, available to patients upon request
HIPAA requires covered entities to track certain PHI disclosures (outside treatment/payment/operations and other exempt categories) and provide this accounting to patients upon request.
45 CFR §164.528 requires covered entities to provide individuals with an accounting of disclosures of PHI for the 6 years prior to the request date. Exempt from accounting: disclosures for treatment, payment, and operations (TPO); disclosures to the individual; disclosures with authorization; incidental disclosures; disclosures for national security; and disclosures to correctional institutions. Trackable disclosures include: public health, law enforcement (some), judicial proceedings, research without authorization, government oversight, and to avert serious threat. Covered entities must document each trackable disclosure and provide accounting within 60 days. HITECH modified this for EHR-based disclosures to eventually include TPO disclosures.
Question 18: Under HIPAA, which type of healthcare provider is NOT required to provide a Notice of Privacy Practices to patients?
- A licensed physician with an independent practice
- A healthcare clearinghouse that only processes data and has no direct patient relationships (Correct answer)
- A hospital emergency department
- A behavioral health counselor
Correct answer: A healthcare clearinghouse that only processes data and has no direct patient relationships
Healthcare clearinghouses that process data without direct patient relationships are not required to provide NPPs to individuals because they have no patient-facing relationship.
45 CFR §164.520(a)(2) requires covered entities to provide NPPs, but healthcare clearinghouses are specifically treated differently. Clearinghouses that process PHI as a business associate of another covered entity have no direct patient relationship and do not interact with individuals receiving care. The Privacy Rule acknowledges this by requiring clearinghouses to provide NPPs only if they have direct treatment relationships with individuals, which is rare for clearinghouses. Clearinghouses must still comply with HIPAA's substantive requirements for PHI they handle, but the NPP distribution requirement, designed for patient-facing entities, does not apply in the same way.
Question 19: What HIPAA requirement applies when a covered entity uses a specialized messaging system (like a patient portal) that allows patients to communicate with their providers?
- Patient portals are exempt from HIPAA as they are initiated by the patient
- The portal and its vendor must meet HIPAA security requirements, and the vendor must execute a BAA with the covered entity (Correct answer)
- Patients using portals waive their HIPAA rights by accepting terms of service
- Only the data transmitted to the portal needs HIPAA protection, not data at rest
Correct answer: The portal and its vendor must meet HIPAA security requirements, and the vendor must execute a BAA with the covered entity
Patient portal vendors handle PHI on behalf of the covered entity and are business associates requiring a BAA, with the portal itself needing to meet all HIPAA security requirements.
Patient portal platforms typically involve a third-party vendor providing the portal infrastructure. This vendor creates, receives, maintains, and transmits PHI on behalf of the covered entity — making them a business associate under HIPAA. A BAA is required before deployment. The portal itself must comply with all Security Rule requirements: encryption in transit and at rest, access controls, audit logging, automatic session timeout, and multi-factor authentication. Patient use of the portal does not waive their HIPAA rights; in fact, portal interactions are covered by HIPAA privacy protections. Covered entities should ensure their BAA with the portal vendor addresses all security and breach notification obligations.
Question 20: Under HIPAA, what is the covered entity's obligation when a patient requests their records be sent directly to a third party?
- The covered entity must send records directly to the third party only with a notarized request
- The covered entity must transmit records directly to the designated third party when the patient directs it, in a timely manner (Correct answer)
- Direct transmission to third parties requires the third party to execute a BAA first
- Patients may only receive records directly; they cannot direct records to third parties
Correct answer: The covered entity must transmit records directly to the designated third party when the patient directs it, in a timely manner
HIPAA's right of access includes the right for patients to direct covered entities to transmit their PHI directly to a designated third party, which the covered entity must honor.
45 CFR §164.524(c)(3)(ii) requires covered entities to transmit PHI directly to another person designated by the individual if the request is in writing, signed by the individual, and clearly identifies the designated person and where to send the PHI. This right is increasingly important as patients seek to share records with new providers, care management services, or personal health apps. The covered entity must comply with the same 30-day timeline as direct patient access requests. The 2020 API-based access rules extended this to enable patient-facing apps to directly access electronic PHI through standardized APIs, making patient-directed data sharing interoperable.
Question 21: What HIPAA obligation applies when a covered entity wants to use patient PHI for a research study?
- Research is always permitted without authorization as a treatment activity
- Research uses of PHI require individual authorization, an IRB waiver, or another HIPAA-compliant research pathway (Correct answer)
- Covered entities cannot use PHI for research under any circumstances
- A BAA with the research institution is sufficient to permit PHI use for research
Correct answer: Research uses of PHI require individual authorization, an IRB waiver, or another HIPAA-compliant research pathway
Using PHI for research requires patient authorization, an IRB/privacy board waiver of authorization, or another HIPAA research pathway such as use of de-identified data or a limited data set.
45 CFR §164.512(i) and §164.508 govern research uses of PHI. Options include: individual authorization (patient signs specific research authorization); waiver by an IRB or privacy board (allowed when authorization is impractical, risk is minimal, study could not be done without waiver); preparatory to research (accessing PHI solely to prepare a research protocol, without removing PHI); or using de-identified data or limited data sets. Clinical care that is also research (combined treatment/research activities) requires carefully structured authorizations. A BAA with a research institution does not itself authorize PHI use for research — it governs the security of PHI sharing, while authorization or waiver governs the privacy permission.
Question 22: Under HIPAA, what is a 'covered entity's' obligation when it receives a request from a public health authority to share PHI about a potential disease outbreak?
- The covered entity must obtain patient authorization before sharing with public health authorities
- The covered entity may share the minimum necessary PHI to assist in public health activities without patient authorization (Correct answer)
- Public health disclosures require a court order or subpoena
- Only hospitals, not physician practices, may respond to public health authority requests
Correct answer: The covered entity may share the minimum necessary PHI to assist in public health activities without patient authorization
HIPAA explicitly permits disclosures to public health authorities authorized by law to collect information for public health activities without individual authorization.
45 CFR §164.512(b) permits covered entities to disclose PHI to public health authorities (CDC, state health departments, local health departments) authorized by law to collect the information for disease prevention and control, vital statistics reporting, and public health investigation. This is a permissive standard — HIPAA allows the disclosure; other laws (mandatory reporting statutes) may require it. During the COVID-19 pandemic, HHS OCR issued guidance specifically addressing permissible disclosures for public health purposes. Minimum necessary applies: share what the public health authority needs to address the outbreak, not the patient's full medical history. Covered entities should have policies addressing how to respond to public health authority requests.
Question 23: Under HIPAA, what is the maximum time a covered entity has to respond to a patient's request to restrict the use or disclosure of their PHI?
- HIPAA doesn't specify a timeline for responding to restriction requests
- HIPAA doesn't establish a specific timeline, but the covered entity must respond promptly and before making any restricted disclosures (Correct answer)
- 30 days, with a 30-day extension
- 60 days for all privacy requests
Correct answer: HIPAA doesn't establish a specific timeline, but the covered entity must respond promptly and before making any restricted disclosures
HIPAA doesn't set a specific timeline for restriction request responses, but the covered entity must act promptly — particularly before making any disclosure the patient has requested to restrict.
45 CFR §164.522 establishes the right to request restrictions on uses and disclosures. Unlike the 30-day timeline for access requests, HIPAA doesn't establish a specific response timeline for restriction requests. However, the covered entity must inform the patient of its decision and honor any restriction it agrees to. Best practice is to respond within 30 days. The covered entity is not required to agree to restrictions (except for out-of-pocket payment restrictions under HITECH §13405(a)), but if it agrees, it must comply. Restrictions must be maintained until the individual revokes them or the covered entity informs the individual it is terminating the restriction (with prior notice).
Question 24: A covered entity receives a valid HIPAA authorization from a patient to disclose PHI to an attorney. What conditions must the authorization meet?
- A signed release of any kind is sufficient for any disclosure
- The authorization must include: specific description of PHI, who may receive it, purpose, expiration, and patient signature — and must not be combined with other documents as a condition of treatment (Correct answer)
- Authorizations must be notarized to be valid under HIPAA
- Only the Privacy Officer may verify authorization validity
Correct answer: The authorization must include: specific description of PHI, who may receive it, purpose, expiration, and patient signature — and must not be combined with other documents as a condition of treatment
A valid HIPAA authorization has six required elements and three required statements, including that treatment cannot be conditioned on signing the authorization.
45 CFR §164.508(c) specifies that a valid authorization must contain: (1) specific description of the PHI to be used/disclosed; (2) name/description of the person/organization authorized to make the disclosure; (3) name/description of the recipient; (4) description of the purpose; (5) expiration date or event; and (6) patient signature and date. The authorization must also contain three required statements: right to revoke and how; whether treatment is conditioned on signing; and that the recipient may re-disclose information (if applicable). Authorizations cannot condition treatment/payment on signing (with narrow exceptions). For attorneys, the authorization should specifically identify the legal matter to prevent overly broad disclosures.
Question 25: Under HIPAA, what is the covered entity's obligation when it receives a patient's valid revocation of a previously granted authorization?
- The covered entity must continue to fulfill disclosures already scheduled under the authorization
- The covered entity must stop future disclosures; it cannot reverse actions already taken in reliance on the authorization before revocation (Correct answer)
- Revocations are only valid if made in writing to the Privacy Officer by certified mail
- Revocations take effect 30 days after receipt
Correct answer: The covered entity must stop future disclosures; it cannot reverse actions already taken in reliance on the authorization before revocation
Upon receiving a valid authorization revocation, the covered entity must stop future disclosures but is not required to reverse actions already completed in reliance on the authorization.
45 CFR §164.508(b)(5) requires covered entities to honor revocations of authorizations with two exceptions: (1) the covered entity has already acted in reliance on the authorization (e.g., already disclosed PHI to the attorney before receiving the revocation); and (2) the authorization was obtained as a condition of obtaining insurance coverage and the insurer has a right to contest a claim. Upon receiving a valid revocation, the covered entity must stop all future disclosures under that authorization. Revocations should be acknowledged in writing and documented. Best practice is to process revocations promptly — same day receipt if possible — to minimize disclosures made between receipt and processing.
Question 26: Under HIPAA, what is a 'designated record set' for a health plan, and what patient rights apply?
- Health plans have no designated record sets because they don't provide direct care
- A health plan's designated record set includes enrollment, payment, claims adjudication, and case management records used to make decisions about individuals (Correct answer)
- Health plans only maintain billing records, which are not subject to HIPAA access rights
- Designated record sets for health plans are limited to the most recent 12 months of coverage
Correct answer: A health plan's designated record set includes enrollment, payment, claims adjudication, and case management records used to make decisions about individuals
Health plans' designated record sets include enrollment, payment, claims, and case management records used to make coverage decisions, and patients have access and amendment rights to these records.
45 CFR §164.501 defines a designated record set for a health plan as: enrollment records, payment records, claims adjudication records, and case management records used to make decisions about the individual. Patients have full right of access (45 CFR §164.524) to their designated record set maintained by health plans, including: eligibility determinations, claim status, claim payments, appeals decisions, prior authorization records, and case management notes. Amendment rights (§164.526) also apply — patients may request correction of incorrect enrollment information or claim adjudication errors. Health plan members frequently exercise these rights when challenging coverage denials or billing discrepancies.
Question 27: Under HIPAA, what obligation does a covered entity have when it discovers it made an impermissible disclosure that does not constitute a 'breach'?
- No action is required if the disclosure is not a reportable breach
- The covered entity must still document the incident, mitigate harm to the extent possible, and apply sanctions if workforce misconduct was involved (Correct answer)
- Small impermissible disclosures can be ignored if they involve fewer than 10 patients
- Only breaches require documentation; non-breach disclosures need no record
Correct answer: The covered entity must still document the incident, mitigate harm to the extent possible, and apply sanctions if workforce misconduct was involved
Even disclosures that don't meet the breach threshold require documentation, harm mitigation, and appropriate sanctions — HIPAA requires comprehensive response to all policy violations.
The breach determination only governs notification obligations — whether the covered entity must notify patients, HHS, and media. Regardless of breach status, impermissible disclosures require: (1) documentation of the incident and the four-factor risk assessment leading to the non-breach determination; (2) mitigation efforts to reduce harm (requesting return or destruction of improperly received PHI, notifying the recipient they should not use it); (3) investigation to identify root cause; (4) sanctions if workforce misconduct contributed; and (5) policy/procedure updates to prevent recurrence. HIPAA (§164.530(f)) specifically requires covered entities to mitigate, to the extent practicable, harmful effects of violations. OCR audits examine both breach response and non-breach incident management.
Question 28: What HIPAA requirement applies when a healthcare provider wants to use PHI in communications with a patient by email?
- Email communication with patients about their PHI is prohibited under HIPAA
- If a patient requests email communication after being informed of risks, the provider may communicate via unencrypted email honoring the patient's choice (Correct answer)
- All patient emails must be encrypted regardless of patient preference
- HIPAA requires providers to use only postal mail for PHI communications to patients
Correct answer: If a patient requests email communication after being informed of risks, the provider may communicate via unencrypted email honoring the patient's choice
When a patient explicitly requests email communication and is informed of the security risks, the covered entity may honor that request — patient preference governs the communication method.
HHS guidance clarifies that covered entities may communicate with patients by email if the individual requests it, even if the email lacks encryption. If the patient requests unencrypted email after being informed of the risk, the covered entity may honor that request. This is sometimes called the 'right of unrestricted communications' — individuals have the right to receive communications by alternative means and at alternative locations (§164.522(b)). The provider should document the patient's request and preference. This contrasts with provider-to-provider communications about PHI, which must use appropriate security regardless of the recipient's preference. The patient's own right to receive their PHI in their preferred manner trumps the security concern.
Question 29: A hospital discovers it cannot comply with a patient's access request within the initial 30-day period. Under HIPAA, what action is required?
- The hospital may simply take the additional time needed without notifying the patient
- The hospital must notify the patient before the initial 30-day period expires, stating the reasons for delay and providing a new deadline no later than 60 days after the original request (Correct answer)
- The access request is automatically denied after 30 days without extension
- The hospital must report the delay to HHS before granting the extension
Correct answer: The hospital must notify the patient before the initial 30-day period expires, stating the reasons for delay and providing a new deadline no later than 60 days after the original request
HIPAA permits one 30-day extension for access requests, but the covered entity must notify the patient before the initial 30 days expire with the reason for delay and the expected completion date.
45 CFR §164.524(b)(2)(ii) permits a one-time 30-day extension if the covered entity 'is unable to take the required action within the time required.' Before the initial 30-day period expires, the covered entity must provide the individual with: (1) written notice of the reason for the delay; and (2) the date by which the covered entity will complete its action. The extension period gives the covered entity up to 60 days total from the original request date. Failure to provide timely notice of the extension and simply taking additional time is a HIPAA violation. OCR enforcement data shows that slow response to access requests is among the most frequently cited violations in enforcement actions.
Question 30: Under HIPAA, what is a 'health care clearinghouse' and what are its specific Privacy Rule obligations?
- A warehouse where paper medical records are stored for multiple providers
- An entity that processes nonstandard health information into HIPAA-standard transactions or vice versa, with HIPAA privacy obligations for the PHI it handles (Correct answer)
- A government agency that clears providers to participate in Medicare
- A billing office shared among multiple physician practices
Correct answer: An entity that processes nonstandard health information into HIPAA-standard transactions or vice versa, with HIPAA privacy obligations for the PHI it handles
Healthcare clearinghouses process health data between standard and nonstandard formats; as covered entities, they must comply with HIPAA's Privacy Rule for all PHI they handle.
45 CFR §160.103 defines a healthcare clearinghouse as a public or private entity that processes health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or vice versa. Examples: claim clearinghouses that convert provider billing data into standard ANSI X12 format for submission to health plans; coding services that translate clinical descriptions into standard ICD-10 codes. As covered entities, clearinghouses must comply with HIPAA's Privacy and Security Rules for all PHI they process. However, clearinghouses often function as business associates for their covered entity clients — they must execute BAAs with those clients in addition to their own covered entity obligations.
Question 31: What is HIPAA's requirement when a covered entity uses PHI for quality improvement activities?
- Quality improvement requires individual patient authorization for each activity
- Quality improvement is a permitted healthcare operations activity that may use PHI without patient authorization, subject to minimum necessary (Correct answer)
- Quality improvement activities are treated the same as research and require IRB review
- PHI may only be used for quality improvement if the patient is no longer a patient of the organization
Correct answer: Quality improvement is a permitted healthcare operations activity that may use PHI without patient authorization, subject to minimum necessary
Quality improvement is explicitly included in HIPAA's definition of healthcare operations — a permissible use of PHI without patient authorization, subject to minimum necessary.
HIPAA's definition of 'healthcare operations' (45 CFR §164.501) explicitly includes quality assessment and improvement activities, case management and care coordination, reviewing the competence or qualifications of health care professionals, conducting training programs, and fraud and abuse detection. These activities are permissible uses of PHI without authorization under §164.506(c). The minimum necessary standard applies — quality teams should access only the PHI needed for the specific quality activity. This exception enables critical activities like mortality and morbidity conferences, peer review, infection control monitoring, and HEDIS/quality measure calculation without burdening these activities with authorization requirements.
Question 32: Under HIPAA, what standard of care applies when a covered entity must choose between providing a patient electronic access to records or a paper copy?
- Covered entities must always provide both formats simultaneously
- Covered entities must provide records in the format requested, including electronic format when PHI is maintained electronically and the requested format is readily producible (Correct answer)
- Paper copies must always be provided because they are more secure
- The covered entity may provide whichever format it prefers regardless of patient request
Correct answer: Covered entities must provide records in the format requested, including electronic format when PHI is maintained electronically and the requested format is readily producible
HIPAA requires providing records in the format the patient requests, including electronic format for electronically maintained records, if the format is readily producible.
45 CFR §164.524(c)(2) requires covered entities to provide access in the form and format requested by the individual, if it is readily producible. If the PHI is maintained electronically and the requested electronic format is readily producible, the covered entity must provide it. If not readily producible, the covered entity must provide it in a readable electronic form and format agreed upon with the individual, or if they cannot agree, in hard copy. The 2020 right of access rule updates reinforced that covered entities must be capable of producing common electronic formats (PDF, commonly used EHR formats) and cannot claim formats 'aren't readily producible' for standard outputs that their systems obviously support.
Question 33: Under HIPAA, what is an 'incidental disclosure' and when does it not constitute a violation?
- Any unintended disclosure is an incidental disclosure and always a HIPAA violation
- An incidental disclosure is an inadvertent secondary disclosure that occurs as a result of a permitted use or disclosure, and is not a violation if reasonable safeguards were in place (Correct answer)
- Incidental disclosures are only excused for verbal communications, not written
- Only disclosures of fewer than 5 patients' information qualify as incidental
Correct answer: An incidental disclosure is an inadvertent secondary disclosure that occurs as a result of a permitted use or disclosure, and is not a violation if reasonable safeguards were in place
Incidental disclosures — like overhearing a name in a waiting room — are permitted if they result from a permitted use/disclosure and the covered entity had reasonable safeguards in place.
45 CFR §164.502(a)(1)(iii) permits incidental uses and disclosures that occur as a result of another use or disclosure that is otherwise permitted or required, provided the covered entity has applied reasonable safeguards and implemented minimum necessary. Examples: a visitor overhearing a nurse calling a patient's name in the ED; a passerby glimpsing a patient record on a screen before it's turned; or a fax containing PHI occasionally going to a wrong number despite correct dialing processes. The test: (1) was the primary disclosure/use permitted; (2) were reasonable safeguards in place (lowered voices, screen positioning, confirmed fax numbers); and (3) was minimum necessary applied? If all three are met, the incidental disclosure is not a violation.
Question 34: Under HIPAA, what must a covered entity include in its Notice of Privacy Practices regarding patient rights?
- Only the right to access records needs to be listed in the NPP
- The NPP must describe all applicable individual rights: access, amendment, accounting of disclosures, restriction requests, confidential communications, and complaint procedures (Correct answer)
- NPPs only need to describe what the covered entity can do with PHI, not patient rights
- Patient rights in the NPP are optional — only required uses and disclosures must be disclosed
Correct answer: The NPP must describe all applicable individual rights: access, amendment, accounting of disclosures, restriction requests, confidential communications, and complaint procedures
HIPAA requires the Notice of Privacy Practices to describe all individual rights, how to exercise them, and how to file complaints — not just the covered entity's uses of PHI.
45 CFR §164.520(b)(1)(iv) requires the NPP to contain 'a statement of the individual's rights with respect to protected health information and a brief description of how the individual may exercise these rights.' Required rights disclosures include: right to inspect and obtain copies of PHI; right to request amendment; right to an accounting of disclosures; right to request restrictions; right to request confidential communications; right to receive a paper copy of the NPP (even with electronic distribution); and right to file complaints with the covered entity and HHS. The NPP must also describe the covered entity's duties and how to contact the Privacy Officer. An NPP that omits required rights descriptions is non-compliant with §164.520.
Question 35: Under HIPAA, when may a covered entity use patient PHI for marketing without authorization?
- Marketing of the covered entity's own services never requires authorization
- A covered entity may market its own health-related services in face-to-face communications without authorization; most other marketing uses require authorization (Correct answer)
- All marketing is prohibited under HIPAA regardless of who benefits
- Marketing is permitted as a healthcare operations activity without any restrictions
Correct answer: A covered entity may market its own health-related services in face-to-face communications without authorization; most other marketing uses require authorization
HIPAA permits face-to-face marketing communications about the covered entity's own services without authorization; most other marketing uses — especially those involving payment from third parties — require authorization.
45 CFR §164.508(a)(3) defines marketing as making a communication that encourages the recipient to purchase or use a product or service. Exceptions not requiring authorization: (1) face-to-face communications by the covered entity (e.g., physician recommending a specific pharmacy during an office visit); (2) promotional gifts of nominal value. After HITECH, if the covered entity receives financial remuneration from a third party for making marketing communications, authorization is required even for communications that might otherwise be permitted as health communications (e.g., subsidized treatment alternative recommendations). Health plans marketing their own coverage improvements to members generally require authorization when using PHI for targeted marketing rather than general enrollment communications.
Question 36: Under HIPAA, what is the covered entity's responsibility when a patient requests access to records that were created by a prior provider and are now held by the current provider?
- The current provider is only responsible for records it created
- The current provider must provide access to records it holds, even if created by a prior provider, if they are in its designated record set (Correct answer)
- Prior provider records should be redirected to the original creator for the patient to access
- Records from prior providers require the prior provider's authorization before access can be granted
Correct answer: The current provider must provide access to records it holds, even if created by a prior provider, if they are in its designated record set
Covered entities must provide access to all PHI in their designated record sets, including records received from prior providers that they now hold.
45 CFR §164.524 grants individuals the right to access PHI in 'designated record sets maintained by or for the covered entity.' The designated record set includes all records used to make decisions about the individual, regardless of who created them. When a patient transfers to a new provider who receives prior medical records, those records become part of the new provider's designated record set. The patient may request access to them from the new provider. The new provider must provide access within the standard 30-day timeframe. This is an important practical point for practices that maintain comprehensive patient histories including records from prior providers — all of this is subject to patient access rights.
Under HIPAA, which of the following is a 'covered entity'?