HIPAA Healthcare Provider Obligations and Covered Entities 4 — Questions and Answers
Question 1: A patient requests access to their electronic health record. Under the HIPAA Right of Access, the covered entity must provide access within how many days?
- 10 days
- 20 days
- 30 days (Correct answer)
- 60 days
Correct answer: 30 days
Covered entities must act on a patient's request for access to PHI within 30 days, with a possible 30-day extension if notified in advance.
Question 2: Which of the following is a permissible reason for a covered entity to deny a patient's request to amend their PHI?
- The patient is not a US citizen
- The provider believes the PHI is accurate and complete (Correct answer)
- The amendment would increase the provider's liability
- The patient is requesting amendment via email
Correct answer: The provider believes the PHI is accurate and complete
A covered entity may deny an amendment request if it determines the PHI is accurate and complete as originally recorded.
Question 3: Under the HIPAA Security Rule, which type of safeguard includes conducting a risk analysis?
- Physical safeguards
- Technical safeguards
- Administrative safeguards (Correct answer)
- Operational safeguards
Correct answer: Administrative safeguards
Conducting a risk analysis is a required implementation specification under the Administrative Safeguards section of the HIPAA Security Rule.
Question 4: A group health plan sponsor wants to access PHI held by its insurer for plan administration. What must the plan documents include to permit this access?
- A HIPAA waiver signed by all plan participants
- Specific language restricting and controlling the sponsor's use of PHI (Correct answer)
- An annual attestation from the plan administrator
- A separate authorization from each affected individual
Correct answer: Specific language restricting and controlling the sponsor's use of PHI
Plan documents must be amended to include specific provisions limiting the plan sponsor's use and disclosure of PHI received from the group health plan.
Question 5: Which of the following is NOT a covered transaction under HIPAA's Transaction and Code Set standards?
- Electronic claims submission (837)
- Electronic remittance advice (835)
- Eligibility inquiry and response (270/271)
- Paper prescription routing between providers (Correct answer)
Correct answer: Paper prescription routing between providers
HIPAA's Transaction and Code Set Rule applies only to electronic transactions; paper-based processes are not covered by these standards.
Question 6: A covered entity voluntarily reports a potential HIPAA violation to OCR before being investigated. How may this affect the outcome?
- It has no effect; penalties are fixed by statute
- It can be considered a mitigating factor that reduces civil monetary penalties (Correct answer)
- It automatically results in a criminal referral
- OCR is required to dismiss the complaint upon voluntary disclosure
Correct answer: It can be considered a mitigating factor that reduces civil monetary penalties
The OCR considers voluntary reporting a mitigating factor when determining civil monetary penalties under HIPAA.
Question 7: Which federal agency is responsible for investigating HIPAA Privacy and Security Rule complaints against covered entities?
- The Centers for Medicare & Medicaid Services (CMS)
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Federal Trade Commission (FTC)
- The Department of Justice (DOJ)
Correct answer: The Office for Civil Rights (OCR) within HHS
HHS Office for Civil Rights (OCR) is the primary enforcement body for HIPAA Privacy and Security Rule complaints.
A patient requests access to their electronic health record.
Under the HIPAA Right of Access, the covered entity must provide access within how many days?