HIPAA Healthcare Provider Obligations and Covered Entities 3 — Questions and Answers
Question 1: A covered entity discovers that a business associate has experienced a breach of PHI. Who is primarily responsible for notifying affected individuals?
- The business associate must notify all affected individuals directly
- The covered entity is responsible for notifying affected individuals (Correct answer)
- HHS notifies affected individuals on behalf of both parties
- The state attorney general handles all breach notifications
Correct answer: The covered entity is responsible for notifying affected individuals
Under the HIPAA Breach Notification Rule, the covered entity bears primary responsibility for notifying affected individuals, even when the breach occurred at a business associate.
Question 2: A covered healthcare provider may share PHI with another provider for treatment purposes without patient authorization. This is an example of which type of HIPAA disclosure?
- Required disclosure
- Permitted disclosure (Correct answer)
- Incidental disclosure
- Prohibited disclosure
Correct answer: Permitted disclosure
Treatment disclosures between providers are permitted disclosures under HIPAA and do not require patient authorization.
Question 3: Under HIPAA, what is the minimum necessary standard?
- PHI must be encrypted with the minimum necessary encryption strength
- Covered entities must limit PHI access to the minimum necessary to accomplish the intended purpose (Correct answer)
- Staff must receive the minimum necessary HIPAA training hours annually
- Audit logs must be retained for the minimum necessary period
Correct answer: Covered entities must limit PHI access to the minimum necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to what is needed for the intended purpose.
Question 4: Which of the following is an example of a covered entity's 'healthcare operations' that permits PHI use without patient authorization?
- Selling patient data to a pharmaceutical company for marketing
- Conducting quality assessment and improvement activities (Correct answer)
- Sharing PHI with an employer for employment decisions
- Providing PHI to a law enforcement agency without a warrant
Correct answer: Conducting quality assessment and improvement activities
Quality assessment and improvement activities are specifically listed as healthcare operations under HIPAA, permitting PHI use without authorization.
Question 5: A nurse accesses the medical records of a celebrity patient out of curiosity without a treatment need. This violates which HIPAA principle?
- The accounting of disclosures requirement
- The minimum necessary standard and authorized access controls (Correct answer)
- The Notice of Privacy Practices requirement
- The right to amend PHI
Correct answer: The minimum necessary standard and authorized access controls
Accessing PHI without a legitimate purpose violates the minimum necessary standard and workforce access control requirements under HIPAA.
Question 6: How long must covered entities retain HIPAA-related documentation, such as policies and procedures?
- 3 years from creation or last effective date
- 6 years from creation or last effective date (Correct answer)
- 7 years from creation or last effective date
- 10 years from creation or last effective date
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain documentation of policies, procedures, and actions for 6 years from the date of creation or the date it was last in effect.
Question 7: A covered entity that operates both HIPAA-covered and non-covered components is known as what type of entity?
- A business associate
- A hybrid entity (Correct answer)
- A dual-status entity
- An affiliated covered entity
Correct answer: A hybrid entity
A hybrid entity is a single legal entity that performs both covered and non-covered functions and must designate its healthcare components for HIPAA compliance purposes.
A covered entity discovers that a business associate has experienced a breach of PHI.
Who is primarily responsible for notifying affected individuals?