HIPAA The Omnibus Rule 2 — Questions and Answers
Question 1: Under the Omnibus Rule, which of the following best describes a 'subcontractor' of a business associate?
- A covered entity that shares PHI with a vendor
- A person or entity that creates, receives, maintains, or transmits PHI on behalf of a business associate (Correct answer)
- An employee of a covered entity who accesses PHI
- A government agency that oversees HIPAA compliance
Correct answer: A person or entity that creates, receives, maintains, or transmits PHI on behalf of a business associate
The Omnibus Rule extended the definition of business associate to include subcontractors who handle PHI on behalf of a business associate.
Question 2: The Omnibus Rule changed the definition of 'marketing' under HIPAA. Which of the following is NOT considered marketing under the revised definition?
- Sending promotional materials for a third-party product without authorization
- Communications about treatment alternatives for the individual (Correct answer)
- Subsidized communications about a health-related product where the covered entity receives remuneration
- Targeted advertisements based on an individual's health status
Correct answer: Communications about treatment alternatives for the individual
Treatment communications describing health-related products or services are excluded from the definition of marketing and do not require authorization.
Question 3: Under the Omnibus Rule, when a business associate agreement (BAA) is in place and a subcontractor breaches it, who bears direct liability to HHS?
- Only the covered entity
- Only the business associate
- Both the business associate and the subcontractor (Correct answer)
- Only the subcontractor
Correct answer: Both the business associate and the subcontractor
The Omnibus Rule made subcontractors directly liable under HIPAA, meaning both business associates and their subcontractors can be held liable by HHS.
Question 4: Which of the following correctly describes the Omnibus Rule's approach to the minimum necessary standard for uses and disclosures?
- Covered entities may use or disclose all PHI in a record if any portion is needed
- Covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose (Correct answer)
- The minimum necessary standard applies only to disclosures to third parties, not internal uses
- Business associates are exempt from the minimum necessary standard
Correct answer: Covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities and business associates to make reasonable efforts to limit PHI access and disclosure to what is needed for the intended purpose.
Question 5: Under the Omnibus Rule, what is the maximum penalty per violation category per calendar year?
- $10,000
- $100,000
- $1,000,000
- $1,500,000 (Correct answer)
Correct answer: $1,500,000
The Omnibus Rule set the maximum civil monetary penalty at $1,500,000 per violation category per calendar year.
Question 6: The Omnibus Rule modified the Breach Notification Rule by changing the standard for what constitutes a breach. What is the new presumption?
- Any impermissible use or disclosure is presumed to be a breach unless the covered entity proves low probability of compromise (Correct answer)
- A breach is only confirmed if PHI is actually viewed by an unauthorized person
- Breaches only require notification when more than 500 individuals are affected
- A covered entity's self-assessment that no harm occurred is sufficient to rebut a breach
Correct answer: Any impermissible use or disclosure is presumed to be a breach unless the covered entity proves low probability of compromise
The Omnibus Rule replaced the 'harm' standard with a presumption that any impermissible use or disclosure is a breach unless a low probability of compromise can be demonstrated.
Question 7: Under the Omnibus Rule, individuals have a right to request restrictions on disclosures of PHI to health plans when the individual pays out-of-pocket in full. What must a covered entity do in this situation?
- Notify the health plan within 30 days and then restrict the disclosure
- Comply with the restriction request if it relates to the specific item or service paid for out-of-pocket (Correct answer)
- Deny the request if the health plan requires the information for claims processing
- Restrict the disclosure only if approved by the covered entity's privacy officer
Correct answer: Comply with the restriction request if it relates to the specific item or service paid for out-of-pocket
The Omnibus Rule requires covered entities to honor a patient's restriction request when the patient pays out-of-pocket in full for a specific item or service.
Under the Omnibus Rule, which of the following best describes a 'subcontractor' of a business associate?