CHP Breach Notification & Legal Enforcement 2 — Questions and Answers
Question 1: A covered entity discovers that a business associate improperly disclosed PHI for 520 individuals. Who must notify the affected individuals?
- The business associate directly
- The covered entity (Correct answer)
- HHS on behalf of the covered entity
- The state attorney general
Correct answer: The covered entity
The covered entity retains responsibility for notifying affected individuals even when the breach is caused by a business associate.
Question 2: Under HIPAA, what is the maximum penalty tier for violations due to willful neglect that are not corrected within the required timeframe?
- $10,000 per violation
- $50,000 per violation (Correct answer)
- $100,000 per violation
- $1,000,000 per violation
Correct answer: $50,000 per violation
Willful neglect not corrected carries a minimum of $10,000 and maximum of $50,000 per identical violation category per year.
Question 3: A hospital's laptop containing unencrypted PHI is stolen. The hospital determines 480 individuals are affected. What is the correct breach notification sequence?
- Notify HHS first, then individuals within 60 days
- Notify individuals within 60 days and HHS within 60 days (Correct answer)
- Notify media first, then individuals, then HHS
- Notify individuals within 60 days and HHS by the next annual reporting deadline
Correct answer: Notify individuals within 60 days and HHS within 60 days
For breaches affecting fewer than 500 individuals, covered entities must notify individuals and HHS within 60 days of discovery.
Question 4: Which of the following constitutes a 'breach' under the HIPAA Breach Notification Rule?
- Accidental access to PHI by an authorized employee who immediately reports it
- Impermissible use or disclosure of PHI that compromises its security or privacy (Correct answer)
- Sharing of de-identified data without authorization
- Accessing aggregated statistical health data without a password
Correct answer: Impermissible use or disclosure of PHI that compromises its security or privacy
A breach is defined as an impermissible use or disclosure of PHI that poses a significant risk of financial, reputational, or other harm to the individual.
Question 5: A covered entity believes a breach occurred but cannot demonstrate a low probability that PHI was compromised. Under HIPAA, what must it do?
- Treat the incident as a breach and provide required notifications (Correct answer)
- File an internal report and monitor for harm
- Wait 90 days before making a determination
- Request HHS guidance before notifying individuals
Correct answer: Treat the incident as a breach and provide required notifications
If the covered entity cannot demonstrate a low probability of compromise using the four-factor risk assessment, it must treat the event as a breach and notify.
Question 6: What is the role of the HHS Office for Civil Rights (OCR) in HIPAA enforcement?
- Prosecuting criminal HIPAA violations directly
- Investigating complaints and enforcing the Privacy and Security Rules (Correct answer)
- Issuing HIPAA licenses to covered entities
- Setting state-level breach notification deadlines
Correct answer: Investigating complaints and enforcing the Privacy and Security Rules
OCR investigates complaints, conducts compliance reviews, and enforces the HIPAA Privacy, Security, and Breach Notification Rules.
Question 7: A nurse accidentally emails PHI for 3 patients to the wrong physician. The information is returned unread and deleted. After a risk assessment, the entity documents a low probability of compromise. What should the covered entity do?
- Notify all 3 patients and HHS immediately
- Document the assessment findings and treat it as a non-breach (Correct answer)
- Report to OCR but not the patients
- Suspend the nurse pending a full investigation
Correct answer: Document the assessment findings and treat it as a non-breach
If all four risk assessment factors support a low probability of compromise, the entity may document its conclusion and forego notification.
A covered entity discovers that a business associate improperly disclosed PHI for 520 individuals.
Who must notify the affected individuals?