RHIT HIPAA Privacy and Security 3 — Questions and Answers
Question 1: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within:
- 15 days of discovery
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 60 days of the end of the calendar year
Correct answer: 60 days of discovery
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach.
Question 2: A healthcare worker accesses a colleague's medical record out of curiosity without any treatment purpose. This is a violation of which HIPAA concept?
- Minimum necessary standard (Correct answer)
- The right to access
- The authorization requirement
- The accounting of disclosures rule
Correct answer: Minimum necessary standard
Accessing records without a job-related need violates the minimum necessary standard, which prohibits accessing more PHI than required for one's role.
Question 3: Which of the following is a required implementation specification under the HIPAA Security Rule's administrative safeguards?
- Workstation security
- Encryption and decryption
- Security management process (Correct answer)
- Facility access controls
Correct answer: Security management process
Security management process is a required administrative safeguard that includes conducting risk analyses and implementing risk management procedures.
Question 4: A patient asks a covered entity to restrict disclosure of PHI to their health plan for services paid out-of-pocket. The covered entity must:
- Deny the request as it conflicts with billing requirements
- Comply with the restriction (Correct answer)
- Consult with the health plan before deciding
- Comply only if the service cost is under $500
Correct answer: Comply with the restriction
Under the HITECH Act amendment to HIPAA, covered entities must honor a patient's request to restrict disclosure to a health plan when the patient has paid out-of-pocket in full.
Question 5: Which HIPAA provision allows patients to request corrections to their medical records?
- Right to access
- Right to amend (Correct answer)
- Right to accounting of disclosures
- Right to request restrictions
Correct answer: Right to amend
The right to amend allows patients to request corrections to inaccurate or incomplete PHI in a covered entity's designated record set.
Question 6: Which of the following constitutes a permissible disclosure of PHI without patient authorization?
- Sharing records with a patient's employer
- Disclosing PHI to public health authorities for disease reporting (Correct answer)
- Providing records to a life insurance company
- Releasing PHI to a marketing firm
Correct answer: Disclosing PHI to public health authorities for disease reporting
HIPAA permits disclosure to public health authorities for activities such as disease reporting, injury surveillance, and public health investigations.
Question 7: The HIPAA Privacy Rule's 'treatment, payment, and operations' (TPO) provision allows covered entities to:
- Share PHI with any party for any reason
- Use and disclose PHI without patient authorization for TPO purposes (Correct answer)
- Sell PHI to business partners
- Disclose all PHI to other covered entities
Correct answer: Use and disclose PHI without patient authorization for TPO purposes
HIPAA allows covered entities to use and disclose PHI without patient authorization when the purpose is treatment, payment, or healthcare operations.
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within: