HIPAA HITECH Act and Technology Requirements 5 — Questions and Answers
Question 1: Under HITECH, when a covered entity discovers a breach affecting 500 or more individuals in a state, when must media notification occur?
- Within 24 hours of discovery
- Within 30 days of discovery
- Within 60 days of discovery (Correct answer)
- Within 90 days of discovery
Correct answer: Within 60 days of discovery
Covered entities must notify prominent media outlets in affected states within 60 days of discovering a breach that affects 500 or more state residents.
Question 2: Which standard specifies the encryption requirements for PHI at rest that satisfy HITECH's breach notification safe harbor?
- FIPS 140-2 (Correct answer)
- AES-128 minimum
- SSL/TLS 1.2
- ISO 27001
Correct answer: FIPS 140-2
NIST guidance specifying FIPS 140-2 validated encryption processes is referenced as the standard for PHI at rest to qualify for HITECH's safe harbor.
Question 3: How did HITECH change the HIPAA requirement for covered entities to obtain patient authorization for psychotherapy notes used in treatment?
- HITECH eliminated the authorization requirement for treatment purposes
- HITECH extended the authorization requirement to all mental health records
- HITECH did not change psychotherapy note authorization requirements (Correct answer)
- HITECH allowed sharing psychotherapy notes with business associates without authorization
Correct answer: HITECH did not change psychotherapy note authorization requirements
HITECH did not change HIPAA's existing requirement that psychotherapy notes require authorization even for treatment purposes—that protection predates HITECH.
Question 4: Under HITECH, what must a covered entity do if an individual requests a restriction on disclosure of their PHI to a health plan for a service the individual paid for out-of-pocket?
- The covered entity may grant or deny the restriction at its discretion
- The covered entity must agree to the restriction (Correct answer)
- The covered entity must obtain the health plan's approval first
- The covered entity must notify HHS before agreeing to the restriction
Correct answer: The covered entity must agree to the restriction
HITECH requires covered entities to honor a patient's request to restrict disclosure to a health plan when the patient has paid out-of-pocket in full for the service.
Question 5: A cloud service provider stores encrypted PHI for a covered entity but cannot access the encryption keys. Under HITECH, is this provider a business associate?
- No, because they cannot access the PHI content
- Yes, because they create, receive, maintain, or transmit PHI on behalf of the covered entity (Correct answer)
- Only if they have a written contract with the covered entity
- Only if they store PHI for more than 30 days
Correct answer: Yes, because they create, receive, maintain, or transmit PHI on behalf of the covered entity
HHS has clarified that a cloud service provider handling encrypted PHI is a business associate even without access to decryption keys, because they maintain PHI on behalf of a covered entity.
Question 6: Which HITECH program evolved into the Medicare and Medicaid EHR Incentive Programs and later the Promoting Interoperability Programs?
- Health Information Technology for Economic and Clinical Health initiative
- Meaningful Use program (Correct answer)
- Electronic Prescribing Incentive Program
- Certified EHR Technology initiative
Correct answer: Meaningful Use program
The Meaningful Use program, established under HITECH, evolved through three stages and was eventually rebranded as the Promoting Interoperability Programs.
Question 7: Under HITECH's penalty framework, which scenario would most likely be classified in the 'reasonable cause' tier rather than 'willful neglect'?
- A covered entity deliberately sold patient data for profit
- A covered entity knew about a vulnerability for 18 months but took no action
- A covered entity's security policy had a gap that a reasonable organization would have identified (Correct answer)
- An employee intentionally accessed records of celebrities for personal interest
Correct answer: A covered entity's security policy had a gap that a reasonable organization would have identified
Reasonable cause applies when a violation results from circumstances a covered entity knew or should have known about, but does not rise to the level of willful neglect.
Under HITECH, when a covered entity discovers a breach affecting 500 or more individuals in a state, when must media notification occur?