HAC Healthcare Analytics Policy & Compliance 2 โ Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, a healthcare analyst requesting a full patient dataset for a quality improvement project should:
- Request only the data elements needed to accomplish the specific analytical purpose (Correct answer)
- Request all available data fields to ensure completeness
- Obtain verbal consent from each patient before accessing records
- Submit the request to the Office for Civil Rights for pre-approval
Correct answer: Request only the data elements needed to accomplish the specific analytical purpose
The Minimum Necessary Standard requires that access to PHI be limited to only the information needed to accomplish the intended purpose.
Question 2: Which federal law governs the privacy and security of substance use disorder patient records, often requiring stricter protections than HIPAA?
- 42 CFR Part 2 (Correct answer)
- 21 CFR Part 11
- 45 CFR Part 164
- 38 CFR Part 17
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides special confidentiality protections for records of patients treated for substance use disorders, requiring explicit patient consent for most disclosures.
Question 3: A healthcare organization experiences a breach affecting 600 patients' PHI. Under HIPAA Breach Notification Rule, the covered entity must notify HHS:
- Within 60 days of the end of the calendar year in which the breach was discovered (Correct answer)
- Within 60 days of breach discovery
- Within 30 days of breach discovery
- Within 72 hours of breach discovery
Correct answer: Within 60 days of the end of the calendar year in which the breach was discovered
For breaches affecting fewer than 500 individuals, HIPAA allows covered entities to log and report to HHS annually, within 60 days after the calendar year ends.
Question 4: The HITECH Act enhanced HIPAA enforcement by:
- Increasing civil monetary penalties and extending HIPAA obligations to business associates (Correct answer)
- Creating the Office of the National Coordinator for Health IT
- Establishing the Medicare Access and CHIP Reauthorization Act
- Mandating electronic health record adoption for all providers
Correct answer: Increasing civil monetary penalties and extending HIPAA obligations to business associates
HITECH strengthened HIPAA by raising penalties (up to $1.9M per violation category per year) and making business associates directly liable for HIPAA compliance.
Question 5: A data analytics team wants to use patient data for research without individual patient authorization. Which HIPAA pathway allows this if an IRB waives authorization requirements?
- Research exception under 45 CFR ยง164.512(i) (Correct answer)
- Treatment operations exception
- Public interest exception under ยง164.512(b)
- De-identification safe harbor provision
Correct answer: Research exception under 45 CFR ยง164.512(i)
HIPAA permits use of PHI for research without authorization when an IRB or Privacy Board waives the authorization requirement under 45 CFR ยง164.512(i).
Question 6: Under the CMS Promoting Interoperability Program, eligible hospitals that fail to demonstrate meaningful use of certified EHR technology face:
- A payment adjustment (reduction) to their Medicare reimbursements (Correct answer)
- Exclusion from Medicaid programs
- Civil monetary penalties up to $50,000
- Mandatory audit by the Office of Inspector General
Correct answer: A payment adjustment (reduction) to their Medicare reimbursements
Hospitals that do not meet Promoting Interoperability requirements face a downward payment adjustment applied to their Medicare inpatient prospective payment system rates.
Question 7: Which standard framework specifically addresses electronic health information exchange security controls and is frequently referenced alongside HIPAA compliance programs?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ISO 9001 Quality Management
- SOC 2 Type II
- PCI DSS
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework is widely adopted by healthcare organizations to supplement HIPAA Security Rule requirements and manage cybersecurity risk systematically.
Under HIPAA's Minimum Necessary Standard, a healthcare analyst requesting a full patient dataset for a quality improvement project should: