HIPAA Medical Information 5 — Questions and Answers
Question 1: Under HIPAA, which entity is primarily responsible for enforcing the Privacy and Security Rules?
- The Centers for Medicare & Medicaid Services (CMS)
- The Office for Civil Rights (OCR) within the Department of HHS (Correct answer)
- The Federal Trade Commission (FTC)
- The Joint Commission on Accreditation of Healthcare Organizations
Correct answer: The Office for Civil Rights (OCR) within the Department of HHS
The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services is the primary federal agency that enforces HIPAA's Privacy and Security Rules.
Question 2: Which of the following best describes a 'hybrid entity' under HIPAA?
- An organization that operates both inpatient and outpatient facilities
- An entity that performs both covered and non-covered functions and designates its health care components (Correct answer)
- A covered entity that uses both paper and electronic health records
- A business associate that also provides direct patient care
Correct answer: An entity that performs both covered and non-covered functions and designates its health care components
A hybrid entity is an organization whose business activities include both HIPAA-covered and non-covered functions, and it designates the covered components subject to HIPAA.
Question 3: A patient exercises their right to an Accounting of Disclosures. Which type of disclosure is EXCLUDED from this accounting?
- Disclosures to public health authorities
- Disclosures for treatment, payment, and healthcare operations (TPO) (Correct answer)
- Disclosures to law enforcement under a court order
- Disclosures required by the Breach Notification Rule
Correct answer: Disclosures for treatment, payment, and healthcare operations (TPO)
Disclosures made for treatment, payment, and healthcare operations are excluded from the required Accounting of Disclosures under the Privacy Rule.
Question 4: Under HIPAA, what is the maximum civil monetary penalty per violation category for violations due to willful neglect that are not corrected?
- $10,000 per violation
- $50,000 per violation with a $1.5 million annual cap (Correct answer)
- $100,000 per violation with no annual cap
- $250,000 per violation with a $5 million annual cap
Correct answer: $50,000 per violation with a $1.5 million annual cap
For willful neglect violations that are not corrected, the penalty is $50,000 per violation with an annual maximum of $1.5 million for identical violations.
Question 5: A researcher wants to use patient medical records for a study without patient authorization. Under HIPAA, this is permissible when:
- The researcher is employed by a federal agency
- An Institutional Review Board (IRB) or Privacy Board waives the authorization requirement (Correct answer)
- The records are more than 10 years old and patients are assumed unavailable
- The study involves fewer than 100 patients and results will be published
Correct answer: An Institutional Review Board (IRB) or Privacy Board waives the authorization requirement
Research use of PHI without authorization is permitted when an IRB or Privacy Board has reviewed the research and waived the authorization requirement under established criteria.
Question 6: Which of the following is TRUE about the HIPAA Security Rule's administrative safeguards?
- They apply only to IT staff and system administrators
- They include a security management process requiring risk analysis and risk management (Correct answer)
- They focus exclusively on physical access controls to data centers
- They are optional for small covered entities with fewer than 10 employees
Correct answer: They include a security management process requiring risk analysis and risk management
Administrative safeguards include a security management process that requires covered entities to conduct a risk analysis and implement risk management measures to protect ePHI.
Question 7: A covered entity shares a patient's HIV status with an employer without authorization. This violates HIPAA because:
- Employers are never permitted to receive any medical information about employees
- HIV status is PHI and disclosure to employers is not a permissible purpose without authorization (Correct answer)
- HIV-related conditions require a separate federal disclosure form beyond HIPAA authorization
- Disclosing HIV status is a criminal act under all state laws regardless of HIPAA
Correct answer: HIV status is PHI and disclosure to employers is not a permissible purpose without authorization
HIV status is PHI, and sharing it with an employer is not a permissible purpose under HIPAA, so patient authorization would be required for such disclosure.
Under HIPAA, which entity is primarily responsible for enforcing the Privacy and Security Rules?