HIPAA Protected Health Information (PHI) 4 — Questions and Answers
Question 1: Under HIPAA's Safe Harbor de-identification method, geographic data must be limited to:
- City level or smaller
- State level or larger (Correct answer)
- County level or larger
- ZIP code level or larger
Correct answer: State level or larger
The Safe Harbor method requires geographic subdivisions to be no smaller than a state, except that the first three digits of a ZIP code may be retained if the geographic unit contains more than 20,000 people.
Question 2: Which of the following is an example of PHI in a non-electronic format covered by the HIPAA Privacy Rule?
- Anonymous survey responses about general health behaviors
- A paper prescription with a patient's name and medication (Correct answer)
- A hospital's aggregate statistics on patient outcomes
- De-identified insurance claims data
Correct answer: A paper prescription with a patient's name and medication
A paper prescription containing a patient's name (an identifier) linked to medication information (health-related data) constitutes PHI subject to the HIPAA Privacy Rule.
Question 3: A patient's right to request an amendment to their PHI under HIPAA applies when:
- They want their entire record deleted
- They believe the information is inaccurate or incomplete (Correct answer)
- They are disputing a billing charge
- They want to add information from a different provider
Correct answer: They believe the information is inaccurate or incomplete
HIPAA gives patients the right to request amendments to their PHI when they believe the record is inaccurate or incomplete, though covered entities may deny the request under certain conditions.
Question 4: Which HIPAA concept describes a patient's right to receive a list of certain disclosures of their PHI made by a covered entity?
- Right of access
- Accounting of disclosures (Correct answer)
- Notice of privacy practices
- Minimum necessary standard
Correct answer: Accounting of disclosures
The accounting of disclosures provision gives patients the right to receive a list of certain disclosures of their PHI made without their authorization, covering the prior six years.
Question 5: A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon patient request
- No later than the date of first service delivery (Correct answer)
- Annually regardless of changes
- Only when PHI is first disclosed to a third party
Correct answer: No later than the date of first service delivery
Covered entities must provide patients with the NPP no later than the date of first service delivery, and must make a good-faith effort to obtain written acknowledgment of receipt.
Question 6: Under HIPAA, which of the following is true about deceased individuals' PHI?
- PHI protections expire immediately upon death
- PHI protections apply for 50 years after death
- PHI of deceased individuals is protected for 50 years after death (Correct answer)
- Deceased individuals' PHI can be freely shared with any family member
Correct answer: PHI of deceased individuals is protected for 50 years after death
HIPAA protects the PHI of deceased individuals for 50 years following the date of death, after which it is no longer considered protected health information.
Question 7: A covered entity that discovers a breach of unsecured PHI must notify affected individuals within:
- 24 hours of discovery
- 60 calendar days of discovery (Correct answer)
- 30 business days of discovery
- 72 hours, following GDPR standards
Correct answer: 60 calendar days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.
Under HIPAA's Safe Harbor de-identification method, geographic data must be limited to: