RHIT HIPAA Privacy and Security 4 — Questions and Answers
Question 1: Under HIPAA, which of the following is a 'hybrid entity'?
- An organization that is only partially a covered entity but performs both covered and non-covered functions (Correct answer)
- A covered entity with operations in multiple states
- A business associate that also acts as a covered entity
- An entity that uses both paper and electronic records
Correct answer: An organization that is only partially a covered entity but performs both covered and non-covered functions
A hybrid entity is an organization whose covered functions are not its primary business, allowing it to designate specific healthcare components as subject to HIPAA.
Question 2: What is the maximum civil monetary penalty per violation category under HIPAA if the covered entity did not know of the violation?
- $100 per violation, up to $25,000 annually (Correct answer)
- $1,000 per violation, up to $100,000 annually
- $10,000 per violation, up to $250,000 annually
- $50,000 per violation, up to $1.5 million annually
Correct answer: $100 per violation, up to $25,000 annually
For violations where the entity did not know and could not have known, the penalty is $100–$50,000 per violation, with a $25,000 annual cap for identical violations.
Question 3: Which safeguard category under the HIPAA Security Rule includes unique user identification and automatic logoff?
- Administrative safeguards
- Physical safeguards
- Technical safeguards (Correct answer)
- Organizational safeguards
Correct answer: Technical safeguards
Technical safeguards include access controls such as unique user IDs, automatic logoff, and encryption mechanisms to protect ePHI.
Question 4: A covered entity discovers a potential breach. The HIPAA breach notification rule presumes that an impermissible use or disclosure is a breach unless:
- The covered entity reports it to HHS within 24 hours
- A low probability assessment shows the PHI was not compromised (Correct answer)
- The patient was notified within 10 days
- The data was encrypted at rest
Correct answer: A low probability assessment shows the PHI was not compromised
The covered entity can rebut the presumption of breach by demonstrating through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 5: Which of the following must be included in an accounting of disclosures provided to a patient?
- All disclosures for treatment, payment, and operations
- Disclosures for which the patient signed an authorization
- Disclosures made without authorization for purposes other than TPO (Correct answer)
- Internal uses of PHI by healthcare staff
Correct answer: Disclosures made without authorization for purposes other than TPO
Accounting of disclosures covers disclosures made without authorization, excluding those for treatment, payment, and operations.
Question 6: A covered entity receives a subpoena for a patient's medical records. Under HIPAA, the covered entity may disclose the records if:
- Any attorney requests them
- Satisfactory assurances are provided that the patient was notified or a protective order is in place (Correct answer)
- The court case is pending for more than 6 months
- The covered entity's legal counsel approves
Correct answer: Satisfactory assurances are provided that the patient was notified or a protective order is in place
HIPAA allows disclosure pursuant to a subpoena if satisfactory assurances are received that the individual was notified or that a qualified protective order has been issued.
Question 7: Which of the following best describes 'addressable' implementation specifications under the HIPAA Security Rule?
- They are optional and need not be implemented
- They must be implemented exactly as written
- They must be implemented if reasonable and appropriate, or an equivalent alternative used (Correct answer)
- They apply only to large covered entities
Correct answer: They must be implemented if reasonable and appropriate, or an equivalent alternative used
Addressable specifications require covered entities to assess whether the specification is reasonable and appropriate; if not, they must document why and implement an equivalent measure.
Under HIPAA, which of the following is a 'hybrid entity'?