HIPAA Healthcare Provider Obligations and Covered Entities 5 — Questions and Answers
Question 1: A covered entity that fails to enter into a BAA with a known business associate and a breach occurs may face penalties under which category?
- Reasonable cause with no knowledge
- Willful neglect — corrected
- Willful neglect — not corrected (Correct answer)
- No penalty if the breach was by the business associate
Correct answer: Willful neglect — not corrected
Failing to obtain a required BAA while knowing the obligation exists constitutes willful neglect, and if uncorrected, the highest penalty tier applies.
Question 2: Under HIPAA, which of the following scenarios requires a covered entity to obtain written patient authorization before using or disclosing PHI?
- Disclosing PHI to a patient's treating specialist
- Using PHI for the covered entity's own fundraising activities (Correct answer)
- Sharing PHI with a business associate for billing services
- Providing PHI to public health authorities for disease reporting
Correct answer: Using PHI for the covered entity's own fundraising activities
Using PHI for fundraising requires patient authorization unless the covered entity limits the information disclosed and provides an opt-out mechanism.
Question 3: A covered healthcare provider wants to share PHI with a patient's family member who is present during a visit. What is required under HIPAA?
- A signed written authorization from the patient must be obtained first
- The provider may share relevant information if the patient does not object (Correct answer)
- The family member must provide proof of relationship before receiving any PHI
- The provider must file a disclosure accounting report with HHS
Correct answer: The provider may share relevant information if the patient does not object
Covered entities may share PHI with persons involved in a patient's care when the patient is present and does not object, or when it is reasonably inferred that the patient would not object.
Question 4: Which of the following must be included in a covered entity's Notice of Privacy Practices (NPP)?
- A list of all employees with PHI access
- A description of the types of uses and disclosures the entity may make (Correct answer)
- The entity's annual HIPAA audit results
- The names of all current business associates
Correct answer: A description of the types of uses and disclosures the entity may make
The NPP must describe the types of uses and disclosures the covered entity may make of PHI, as well as patient rights and the entity's legal duties.
Question 5: A hospital's workforce member discloses PHI by accidentally faxing records to the wrong physician's office. This may qualify as what type of event under HIPAA?
- A permitted disclosure requiring no follow-up
- A breach subject to the Breach Notification Rule unless an exception applies (Correct answer)
- A business associate violation only
- An incidental disclosure that is always exempt from notification
Correct answer: A breach subject to the Breach Notification Rule unless an exception applies
A misdirected fax containing PHI is a potential breach; the covered entity must perform a risk assessment to determine if notification is required.
Question 6: Under HIPAA, which of the following is considered a 'covered transaction' that triggers compliance requirements?
- A verbal referral from one physician to another
- An electronic submission of a health care claim to an insurance plan (Correct answer)
- A paper Explanation of Benefits mailed to a patient
- A phone call to verify patient insurance eligibility
Correct answer: An electronic submission of a health care claim to an insurance plan
Electronic submission of health care claims (Transaction 837) is one of the standard HIPAA-covered transactions that triggers compliance obligations.
Question 7: A covered entity that is also a hybrid entity must ensure that its designated healthcare components comply with HIPAA. What must the entity do with its non-healthcare components?
- Apply full HIPAA standards to all components equally
- Erect firewalls to prevent non-covered components from accessing PHI held by the healthcare components (Correct answer)
- Certify all non-covered components as business associates
- File a hybrid entity election form annually with HHS
Correct answer: Erect firewalls to prevent non-covered components from accessing PHI held by the healthcare components
Hybrid entities must erect appropriate firewalls between covered healthcare components and non-covered components to prevent unauthorized PHI flows.
A covered entity that fails to enter into a BAA with a known business associate and a breach occurs may face penalties under which category?