HIPAA Breach Notification Rule 2 — Questions and Answers
Question 1: Under the Breach Notification Rule, what is the deadline for notifying the HHS Secretary about a breach affecting 500 or more individuals?
- Within 30 days of discovery
- Within 60 days of discovery (Correct answer)
- Within 90 days of the end of the calendar year
- Within 60 days after the end of the calendar year in which the breach occurred
Correct answer: Within 60 days of discovery
Covered entities must notify HHS within 60 days of discovering a breach affecting 500 or more individuals.
Question 2: A hospital's laptop containing unencrypted PHI is stolen. Which factor is NOT part of the four-factor risk assessment used to determine if a breach occurred?
- The nature and extent of the PHI involved
- The unauthorized person who used or could access the PHI
- The financial cost of the breach to the covered entity (Correct answer)
- Whether the PHI was actually acquired or viewed
Correct answer: The financial cost of the breach to the covered entity
The four-factor risk assessment does not include financial cost; it focuses on nature of PHI, the unauthorized person, whether PHI was accessed, and extent of risk mitigation.
Question 3: Which of the following is an exception to the Breach Notification Rule that does NOT require notification?
- A ransomware attack that encrypts PHI
- An unintentional acquisition of PHI by a workforce member acting in good faith (Correct answer)
- A stolen laptop with unencrypted PHI
- An email containing PHI sent to the wrong patient
Correct answer: An unintentional acquisition of PHI by a workforce member acting in good faith
Unintentional acquisition, access, or use of PHI by a workforce member acting in good faith and within scope of authority is an exception to breach notification.
Question 4: If a breach affects fewer than 500 individuals in a state, when must the covered entity notify HHS?
- Within 60 days of discovery
- Within 30 days of discovery
- Within 60 days after the end of the calendar year (Correct answer)
- Within 90 days after the end of the calendar year
Correct answer: Within 60 days after the end of the calendar year
For breaches affecting fewer than 500 individuals, covered entities must maintain a log and report to HHS annually within 60 days after the end of each calendar year.
Question 5: A business associate discovers a breach of PHI. What is the business associate's primary notification obligation?
- Notify affected individuals directly within 60 days
- Notify the covered entity without unreasonable delay and within 60 days of discovery (Correct answer)
- Notify HHS directly within 60 days
- Notify the media within 60 days if over 500 individuals are affected
Correct answer: Notify the covered entity without unreasonable delay and within 60 days of discovery
Business associates must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovering the breach.
Question 6: Which of the following breach notification methods is required when a covered entity cannot locate contact information for 10 or more affected individuals?
- Certified mail to the last known address
- Email notification to an alternative address
- Posting a notice on the covered entity's website for 90 days (Correct answer)
- Publishing a notice in a national newspaper
Correct answer: Posting a notice on the covered entity's website for 90 days
When contact information is insufficient for 10 or more individuals, covered entities must post a conspicuous notice on their website for at least 90 days.
Question 7: What type of information is NOT required to be included in a breach notification to affected individuals?
- A description of what happened, including the date of the breach
- Steps individuals should take to protect themselves from potential harm
- The names and addresses of all other individuals affected by the breach (Correct answer)
- The types of PHI involved in the breach
Correct answer: The names and addresses of all other individuals affected by the breach
Breach notifications must include a description of the breach, types of PHI involved, steps to protect against harm, and contact information, but NOT the names of other affected individuals.
Under the Breach Notification Rule, what is the deadline for notifying the HHS Secretary about a breach affecting 500 or more individuals?