CBCS Regulatory Compliance and HIPAA 2 — Questions and Answers
Question 1: What are the four HIPAA Administrative Simplification standards?
- Privacy, Security, Enforcement, and Breach Notification
- Transactions and Code Sets, Privacy, Security, and National Identifier standards (Correct answer)
- Privacy, Security, Electronic Claims, and Patient Rights
- Covered Entities, Business Associates, PHI Protection, and Audit Controls
Correct answer: Transactions and Code Sets, Privacy, Security, and National Identifier standards
HIPAA's Administrative Simplification provisions include: (1) Transactions and Code Sets, (2) Privacy Rule, (3) Security Rule, and (4) National Identifier standards (NPI, employer identifier).
HIPAA Administrative Simplification: (1) Transactions and Code Sets — mandated standard electronic transaction formats (837, 835, 270/271, etc.) and code sets (ICD-10-CM, CPT, HCPCS, NDC); (2) Privacy Rule — protects PHI, gives patients rights over their information; (3) Security Rule — physical, administrative, and technical safeguards for electronic PHI (ePHI); (4) National Identifier Standards — NPI for providers, EIN for employers. These standards reduced administrative burden and healthcare costs by standardizing electronic health information exchange.
Question 2: What constitutes Protected Health Information (PHI) under HIPAA?
- Only information stored in electronic medical records
- Individually identifiable health information in any form (electronic, paper, oral) held or transmitted by a covered entity or business associate (Correct answer)
- Only information relating to diagnoses and treatment plans
- Health information that a patient has specifically requested be kept private
Correct answer: Individually identifiable health information in any form (electronic, paper, oral) held or transmitted by a covered entity or business associate
PHI is any individually identifiable health information in any format (electronic, paper, verbal) that relates to a person's past, present, or future physical or mental health condition, provision of healthcare, or payment for healthcare.
PHI includes 18 identifiers that can be used to identify an individual: name, geographic data smaller than state, dates (except year), phone, fax, email, SSN, medical record number, health plan beneficiary number, account numbers, certificate/license numbers, VINs, device identifiers, URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifying number or code. When all 18 identifiers are removed, information is considered 'de-identified' and is not subject to HIPAA. De-identification can be done by expert determination or the Safe Harbor method (removing all 18 identifiers).
Question 3: What is a Business Associate Agreement (BAA) under HIPAA?
- A contract between an insurance company and a healthcare provider specifying reimbursement rates
- A written contract between a covered entity and a business associate that specifies permitted uses of PHI and requires the business associate to protect PHI (Correct answer)
- An agreement between two competing healthcare providers not to share patient information
- A consent form signed by patients authorizing their information to be shared with third parties
Correct answer: A written contract between a covered entity and a business associate that specifies permitted uses of PHI and requires the business associate to protect PHI
A BAA is a legally required contract between a covered entity and any business associate who may access, use, or disclose PHI in the course of performing services. It specifies permitted uses and requires appropriate safeguards.
Business associates include: billing companies, coding contractors, IT vendors, clearinghouses, consultants, lawyers, accountants, cloud storage providers — any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. BAA requirements: describe permitted uses and disclosures of PHI, require appropriate safeguards, require reporting of breaches, require return or destruction of PHI at contract end. BAAs must be in place BEFORE sharing PHI. Subcontractors of business associates are also considered business associates and need BAAs. Failure to have BAAs is a common HIPAA compliance gap.
Question 4: What is the HIPAA Security Rule's requirement for electronic PHI (ePHI)?
- ePHI must be stored only on servers within the United States
- Covered entities must implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI (Correct answer)
- ePHI must be encrypted using AES-256 encryption at all times
- ePHI access must be limited to licensed healthcare providers only
Correct answer: Covered entities must implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI
The Security Rule requires covered entities and business associates to implement three types of safeguards — administrative, physical, and technical — to protect ePHI from unauthorized access, use, or disclosure.
Security Rule safeguards: Administrative (policies and procedures — risk analysis, workforce training, access management, contingency plan), Physical (facility controls — workstation placement, server room locks, device/media controls), Technical (ePHI access controls — unique user IDs, automatic logoff, audit controls, encryption and decryption, integrity controls, transmission security). The Security Rule uses 'required' and 'addressable' implementation specifications. Addressable specs must be implemented unless the covered entity documents a reasonable alternative or why it's not applicable. Encryption is 'addressable' but widely considered a best practice standard.
Question 5: What are patients' rights under the HIPAA Privacy Rule?
- The right to have all their medical bills forgiven if information is disclosed without permission
- Rights including access to their PHI, request for amendments, accounting of disclosures, right to restrict certain uses/disclosures, and right to receive confidential communications (Correct answer)
- The exclusive right to decide who can access their complete medical record, with no exceptions
- The right to have all of their PHI destroyed upon request
Correct answer: Rights including access to their PHI, request for amendments, accounting of disclosures, right to restrict certain uses/disclosures, and right to receive confidential communications
The HIPAA Privacy Rule gives patients specific rights: access their health records, request corrections (amendments), obtain an accounting of certain disclosures, request restrictions on use/disclosure, and receive confidential communications.
Patient rights under HIPAA Privacy Rule: (1) Right of Access — request copy of PHI (within 30 days), (2) Right to Amendment — request corrections to inaccurate records (covered entity can deny with written reason), (3) Right to Accounting of Disclosures — list of disclosures for 6 years (excludes treatment, payment, operations), (4) Right to Restrict Use/Disclosure — request limits (covered entity must honor patient-paid, out-of-pocket restrictions to health plans), (5) Right to Confidential Communications — receive communications via alternative means, (6) Right to Notice of Privacy Practices (NPP) — receive at first contact.
Question 6: What is a HIPAA breach and what are the notification requirements?
- Any unauthorized viewing of PHI by a non-clinical staff member, requiring immediate patient notification
- An impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy, requiring notifications to individuals, HHS, and potentially the media (Correct answer)
- Only a cyberattack that exposes ePHI to external hackers, requiring law enforcement notification
- Any accidental mailing of a bill to the wrong address, requiring no notification
Correct answer: An impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy, requiring notifications to individuals, HHS, and potentially the media
A HIPAA breach is an impermissible use or disclosure of unsecured PHI that is presumed to be a breach unless a risk assessment shows low probability that PHI was compromised. Notification to affected individuals, HHS, and (for large breaches) media is required.
Breach notification requirements: (1) Individual notification — written notice within 60 days of discovery (first-class mail or email if patient consented), (2) HHS notification — breaches of 500+ individuals: notify HHS within 60 days; smaller breaches: maintain log and report annually by March 1, (3) Media notice — breaches affecting 500+ individuals in a state/jurisdiction: notify prominent media within 60 days. Penalties for breach notification failures: $100–$50,000 per violation (up to $1.5 million/year per violation category). Business associates must notify covered entities within 60 days of discovering a breach.
What are the four HIPAA Administrative Simplification standards?