HIPAA Enforcement and Penalties 2 — Questions and Answers
Question 1: Which federal agency is primarily responsible for enforcing HIPAA's Privacy and Security Rules?
- The Federal Trade Commission (FTC)
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Department of Justice (DOJ)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing HIPAA's Privacy and Security Rules.
Question 2: Under HIPAA's tiered civil penalty structure, what is the minimum penalty per violation for the tier where the covered entity did not know of the violation?
- $100 (Correct answer)
- $1,000
- $10,000
- $50,000
Correct answer: $100
The lowest tier (unknowing violation) carries a minimum penalty of $100 per violation.
Question 3: A covered entity that discovers a potential HIPAA violation and corrects it within 30 days of discovery may avoid civil monetary penalties under which provision?
- Safe harbor for good faith reliance
- Affirmative defense of correction (Correct answer)
- Willful neglect correction exception
- Reasonable cause exemption
Correct answer: Affirmative defense of correction
HIPAA provides an affirmative defense (correction within 30 days) that can shield a covered entity from civil monetary penalties if it corrects the violation promptly.
Question 4: Criminal HIPAA penalties involving 'wrongful disclosure for commercial advantage, personal gain, or malicious harm' carry a maximum imprisonment term of:
- 1 year
- 5 years
- 10 years (Correct answer)
- 20 years
Correct answer: 10 years
The most severe criminal tier under HIPAA provides for up to 10 years in prison when the offense involves commercial advantage, personal gain, or malicious harm.
Question 5: State attorneys general were granted authority to bring civil actions for HIPAA violations under which federal legislation?
- HITECH Act of 2009 (Correct answer)
- Affordable Care Act of 2010
- GINA of 2008
- Medicare Modernization Act of 2003
Correct answer: HITECH Act of 2009
The HITECH Act of 2009 granted state attorneys general the right to bring civil actions on behalf of state residents for HIPAA violations.
Question 6: OCR's resolution agreements typically require a covered entity to pay a monetary settlement AND:
- Terminate all business associate agreements
- Implement a corrective action plan (CAP) (Correct answer)
- Notify every affected patient individually
- Submit to annual third-party audits indefinitely
Correct answer: Implement a corrective action plan (CAP)
Resolution agreements include both a financial settlement and a corrective action plan (CAP) outlining the steps the entity must take to achieve compliance.
Question 7: Which of the following best describes 'reasonable cause' in HIPAA's civil penalty tiers?
- The entity knew of the violation but chose not to act
- The entity should have known of the violation through ordinary business care (Correct answer)
- The entity was completely unaware of the violation
- The entity corrected the violation within 30 days
Correct answer: The entity should have known of the violation through ordinary business care
Reasonable cause means the covered entity knew or should have known of the violation through ordinary diligence, but it did not constitute willful neglect.
Which federal agency is primarily responsible for enforcing HIPAA's Privacy and Security Rules?