HIPAA The Omnibus Rule 3 — Questions and Answers
Question 1: Under the Omnibus Rule, which of the following uses of PHI by a covered entity requires an individual's written authorization?
- Using PHI for treatment purposes
- Selling PHI to a third party for remuneration (Correct answer)
- Disclosing PHI to a public health authority
- Using PHI for healthcare operations quality reviews
Correct answer: Selling PHI to a third party for remuneration
The Omnibus Rule requires written authorization for the sale of PHI, prohibiting covered entities from receiving remuneration for PHI without patient authorization.
Question 2: The Omnibus Rule addressed the use of genetic information for underwriting purposes. What did it establish?
- Health plans may use genetic information for underwriting with individual consent
- Genetic information may be used for underwriting only if de-identified
- Health plans are prohibited from using genetic information for underwriting purposes (Correct answer)
- Genetic information is excluded entirely from HIPAA protections
Correct answer: Health plans are prohibited from using genetic information for underwriting purposes
The Omnibus Rule implemented GINA provisions by prohibiting health plans from using or disclosing genetic information for underwriting purposes.
Question 3: Under the Omnibus Rule, a business associate may use PHI for its own purposes if:
- The covered entity has not explicitly prohibited it in the BAA
- The use is permitted by the Privacy Rule and the BAA (Correct answer)
- The business associate has a legitimate business need
- The information is aggregated with data from multiple covered entities
Correct answer: The use is permitted by the Privacy Rule and the BAA
Business associates may only use PHI in ways that are permitted by the HIPAA Privacy Rule and specifically authorized in the business associate agreement.
Question 4: A research organization conducts a study and previously collected PHI under a valid HIPAA authorization. Under the Omnibus Rule, can the same authorization cover future research?
- No, each new research study always requires a fresh authorization
- Yes, authorizations can cover future research studies if sufficiently described (Correct answer)
- Only if the future research is unrelated to the original purpose
- Only if the research is conducted by a different covered entity
Correct answer: Yes, authorizations can cover future research studies if sufficiently described
The Omnibus Rule clarified that a single authorization can cover future research studies as long as the future purposes are adequately described in the authorization.
Question 5: Which of the following is an example of a 'hybrid entity' under HIPAA as clarified by the Omnibus Rule?
- A business associate that also operates as a covered entity
- An organization that performs both covered and non-covered healthcare functions (Correct answer)
- A health plan that contracts with multiple business associates
- A clearinghouse that processes PHI for multiple covered entities
Correct answer: An organization that performs both covered and non-covered healthcare functions
A hybrid entity is one that performs both covered healthcare-related functions and non-covered functions, and it must designate its healthcare component for HIPAA compliance purposes.
Question 6: Under the Omnibus Rule's four-factor test to determine whether a breach occurred, which factor is NOT part of the assessment?
- The nature and extent of the PHI involved
- The unauthorized person who used or received the PHI
- The number of individuals who were affected by the breach (Correct answer)
- Whether the PHI was actually acquired or viewed
Correct answer: The number of individuals who were affected by the breach
The four-factor test assesses the nature and extent of PHI, the unauthorized person involved, whether PHI was acquired or viewed, and the extent to which risk was mitigated — not the number of individuals affected.
Question 7: Under the Omnibus Rule, if a covered entity discovers that its business associate has been in violation of the BAA, what is the covered entity's obligation?
- Immediately terminate the BAA and report to HHS
- Take reasonable steps to cure the breach or end the violation, and terminate the BAA if unsuccessful (Correct answer)
- Report the violation to HHS within 24 hours of discovery
- Notify affected individuals before taking any action against the business associate
Correct answer: Take reasonable steps to cure the breach or end the violation, and terminate the BAA if unsuccessful
When a covered entity becomes aware of a BAA violation, it must take reasonable steps to cure the breach or end the violation, and if not resolved, terminate the BAA.
Under the Omnibus Rule, which of the following uses of PHI by a covered entity requires an individual's written authorization?