HIPAA HITECH Act and Technology Requirements 3 — Questions and Answers
Question 1: What technology standard does HITECH specifically reference as a safe harbor for breach notification involving PHI?
- Multi-factor authentication
- Encryption and destruction (Correct answer)
- Firewalls and intrusion detection
- Role-based access control
Correct answer: Encryption and destruction
HITECH's breach notification safe harbor applies when PHI is rendered unusable, unreadable, or indecipherable through encryption or destruction.
Question 2: Which federal agency issued the guidance specifying encryption standards that qualify for HITECH's breach notification safe harbor?
- FDA
- FTC
- NIST (Correct answer)
- NSA
Correct answer: NIST
NIST issued the guidance on encryption standards and destruction methods that qualify PHI for HITECH's breach notification safe harbor.
Question 3: The HITECH Act's Meaningful Use program incentivized healthcare providers to adopt EHRs primarily through which mechanism?
- Tax credits for hardware purchases
- Medicare and Medicaid payment incentives (Correct answer)
- Liability protections for EHR-related breaches
- Reduced HIPAA audit frequency
Correct answer: Medicare and Medicaid payment incentives
Meaningful Use provided Medicare and Medicaid payment incentives to eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology.
Question 4: Under HITECH, what restriction applies to fundraising communications sent using electronic PHI?
- Fundraising using PHI is completely prohibited
- Patients must be given an opportunity to opt out of future fundraising (Correct answer)
- PHI may only be used for fundraising with explicit written consent
- Only demographic data may be used, not clinical information
Correct answer: Patients must be given an opportunity to opt out of future fundraising
HITECH requires that fundraising communications include a clear opportunity for recipients to opt out of receiving future fundraising communications.
Question 5: What does the HITECH Act require covered entities to include in their Notice of Privacy Practices regarding PHI sale?
- A list of all parties to whom PHI has been sold
- A statement that authorization is required before selling PHI (Correct answer)
- The price charged for PHI in recent transactions
- A disclosure of marketing revenue generated from PHI
Correct answer: A statement that authorization is required before selling PHI
HITECH requires covered entities to state in their Notice of Privacy Practices that patient authorization is required before the entity may sell PHI.
Question 6: Which HITECH provision most directly addressed the concern that business associates were not sufficiently accountable for PHI they handled?
- Breach notification requirements for business associates
- Direct application of HIPAA Security Rule to business associates (Correct answer)
- Mandatory annual security risk assessments for BAs
- Encryption requirements for BA data transmission
Correct answer: Direct application of HIPAA Security Rule to business associates
HITECH directly applied the HIPAA Security Rule to business associates, making them independently liable rather than relying solely on contractual obligations.
Question 7: A hospital uses a certified EHR but fails to conduct a required security risk analysis. Under HITECH, which penalty tier most likely applies?
- Did not know ($100–$50,000 per violation)
- Reasonable cause ($1,000–$50,000 per violation)
- Willful neglect corrected within 30 days ($10,000–$50,000) (Correct answer)
- Willful neglect not corrected ($50,000–$1,500,000)
Correct answer: Willful neglect corrected within 30 days ($10,000–$50,000)
Failing to conduct a required security risk analysis while operating an EHR system typically indicates willful neglect, and prompt correction would place it in the $10,000–$50,000 tier.
What technology standard does HITECH specifically reference as a safe harbor for breach notification involving PHI?