CCT - Certified Compliance Technician HIPAA Privacy and Security Questions and Answers — Questions and Answers
Question 1: A hospital's billing department is preparing to send a patient's invoice to a third-party collection agency. According to the HIPAA Privacy Rule's 'minimum necessary' standard, which of the following Protected Health Information (PHI) is most appropriate for the hospital to disclose?
- Patient's name, address, dates of service, and the total outstanding balance. (Correct answer)
- Patient's entire medical record, including treatment history and physician's notes.
- Patient's name, Social Security Number, and primary diagnosis code.
- Patient's name, insurance policy number, and the name of their primary care physician.
Correct answer: Patient's name, address, dates of service, and the total outstanding balance.
The HIPAA 'minimum necessary' standard requires covered entities to make reasonable efforts to limit the use and disclosure of PHI to the minimum necessary to accomplish the intended purpose. For a collection agency, the purpose is to collect a debt. This requires demographic information to identify and contact the patient and the specific amount owed from the dates of service, but not detailed clinical information like diagnoses or the entire medical record.
Question 2: A small medical clinic is implementing its HIPAA Security Rule compliance plan. When addressing the implementation specifications for its administrative safeguards, what is the key difference between 'required' and 'addressable' specifications?
- Required specifications must be implemented exactly as stated, while addressable specifications are optional.
- Addressable specifications must be assessed; if not implemented, the decision and rationale must be documented. (Correct answer)
- Required specifications apply only to large healthcare systems, while addressable ones apply to small clinics.
- Addressable specifications are technical in nature, while required specifications are purely administrative policies.
Correct answer: Addressable specifications must be assessed; if not implemented, the decision and rationale must be documented.
Under the HIPAA Security Rule, 'addressable' does not mean optional. A covered entity must assess whether an addressable specification is a reasonable and appropriate safeguard in its environment. If it is not, the entity must document why and may implement an equivalent alternative measure if reasonable and appropriate. Required specifications must be implemented as the rule states.
Question 3: A business associate discovers a breach of unsecured PHI affecting 450 individuals of a covered entity on March 1st. What is the latest date by which the business associate must notify the covered entity?
- Within 24 hours of discovery.
- Within 60 days of the end of the calendar year.
- Without unreasonable delay, and in no case later than 60 days following discovery. (Correct answer)
- Immediately, as all breaches require instant notification to the covered entity.
Correct answer: Without unreasonable delay, and in no case later than 60 days following discovery.
The HIPAA Breach Notification Rule requires a business associate to notify the covered entity of a breach 'without unreasonable delay and in no case later than 60 days' from the discovery of the breach. This allows the covered entity to then fulfill its own notification duties to the affected individuals and HHS.
Question 4: Which of the following is an example of a HIPAA Security Rule 'technical safeguard'?
- Developing a security incident response plan.
- Positioning computer monitors to prevent public viewing of ePHI.
- Implementing a security awareness and training program for the workforce.
- Using encryption to render electronic protected health information (ePHI) unreadable. (Correct answer)
Correct answer: Using encryption to render electronic protected health information (ePHI) unreadable.
The HIPAA Security Rule's technical safeguards involve the technology used to protect ePHI and control access to it. Encryption is a specific example of a technical safeguard that renders ePHI unusable, unreadable, or indecipherable to unauthorized individuals. A security incident response plan and training are administrative safeguards, while monitor positioning is a physical safeguard.
Question 5: A patient submits a written request to their healthcare provider for a copy of their medical records. Under the HIPAA Privacy Rule, the provider must generally provide access to the records within what timeframe?
- 10 business days
- 30 calendar days (Correct answer)
- 60 calendar days
- Immediately upon request
Correct answer: 30 calendar days
The HIPAA Privacy Rule gives individuals the right to access and receive a copy of their PHI. A covered entity must act on the request within 30 days of receipt. If necessary, the entity can extend the time for no more than 30 additional days, provided they inform the individual in writing of the reasons for the delay.
Question 6: A hospital experiences a data breach of unsecured PHI that affects 600 residents of a single state. In addition to notifying the affected individuals and the Secretary of HHS, what other notification is required by the HIPAA Breach Notification Rule?
- Notifying the local police department.
- Purchasing credit monitoring services for all affected individuals.
- Notifying prominent media outlets serving the state or jurisdiction. (Correct answer)
- Reporting the breach to the Federal Trade Commission (FTC).
Correct answer: Notifying prominent media outlets serving the state or jurisdiction.
When a breach of unsecured PHI affects more than 500 residents of a state or jurisdiction, the HIPAA Breach Notification Rule requires the covered entity to provide notice to prominent media outlets serving that area. This is in addition to individual notices and notification to the HHS Secretary. This notice must be provided without unreasonable delay and no later than 60 days following the discovery of the breach.
A hospital's billing department is preparing to send a patient's invoice to a third-party collection agency.
According to the HIPAA Privacy Rule's 'minimum necessary' standard, which of the following Protected Health Information (PHI) is most appropriate for the hospital to disclose?