MT HIPAA Privacy & Security Rules 3 — Questions and Answers
Question 1: Which HIPAA Security Rule safeguard category includes policies for workstation use and device and media controls?
- Administrative Safeguards
- Physical Safeguards (Correct answer)
- Technical Safeguards
- Organizational Safeguards
Correct answer: Physical Safeguards
Physical Safeguards under the HIPAA Security Rule include workstation use policies, workstation security, and device and media controls.
Question 2: What does the HIPAA 'Right of Access' give patients the ability to do?
- Amend any inaccuracy in their medical record at any time
- Request that a covered entity restrict PHI disclosures to insurers
- Inspect and obtain a copy of their own protected health information (Correct answer)
- Revoke a business associate agreement at will
Correct answer: Inspect and obtain a copy of their own protected health information
The HIPAA Right of Access allows individuals to inspect and receive a copy of their PHI held by covered entities, generally within 30 days of the request.
Question 3: Which of the following is an example of an Administrative Safeguard under the HIPAA Security Rule?
- Installing a firewall on the transcription server
- Placing a privacy screen on a computer monitor
- Conducting a workforce security awareness training program (Correct answer)
- Using automatic logoff settings on workstations
Correct answer: Conducting a workforce security awareness training program
Security awareness and training programs are explicitly listed Administrative Safeguards required by the HIPAA Security Rule.
Question 4: Under HIPAA, which disclosure of PHI is permitted WITHOUT patient authorization?
- Sharing a patient's records with their employer for productivity review
- Disclosing PHI to a life insurance company for underwriting purposes
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Providing PHI to a marketing firm for targeted health advertisements
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosures required by law, such as mandatory reporting of gunshot wounds to law enforcement, without patient authorization.
Question 5: A transcription company stores encrypted ePHI on a laptop that is stolen. Under HIPAA's Safe Harbor provision, how is this incident classified?
- A reportable breach requiring patient notification
- A presumed breach unless the encryption meets NIST standards
- Not a breach, because the PHI is rendered unreadable through valid encryption (Correct answer)
- A security incident requiring immediate OCR reporting regardless of encryption
Correct answer: Not a breach, because the PHI is rendered unreadable through valid encryption
Under the Breach Notification Safe Harbor, loss or theft of properly encrypted ePHI does not constitute a reportable breach because the data is unreadable.
Question 6: Which entity enforces HIPAA compliance and investigates complaints?
- The Centers for Medicare & Medicaid Services (CMS)
- The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (Correct answer)
- The Federal Trade Commission (FTC)
- The American Health Information Management Association (AHIMA)
Correct answer: The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services
The Office for Civil Rights (OCR) within HHS is the primary federal agency responsible for enforcing HIPAA Privacy and Security Rules.
Question 7: In HIPAA terminology, what is a 'covered entity'?
- Any company that processes credit card payments for healthcare services
- Health plans, healthcare clearinghouses, and healthcare providers who transmit PHI electronically (Correct answer)
- Any business that employs more than 50 healthcare workers
- A patient advocacy group certified by the federal government
Correct answer: Health plans, healthcare clearinghouses, and healthcare providers who transmit PHI electronically
Covered entities under HIPAA are health plans, healthcare clearinghouses, and healthcare providers who transmit PHI in electronic form in connection with a HIPAA-covered transaction.
Which HIPAA Security Rule safeguard category includes policies for workstation use and device and media controls?