RHIT HIPAA Privacy and Security 5 — Questions and Answers
Question 1: Which of the following scenarios represents a valid use of the HIPAA 'limited data set'?
- Providing PHI to a marketing company for advertising
- Sharing data with a researcher under a data use agreement with 16 identifiers removed (Correct answer)
- Giving full PHI to a business associate without a BAA
- Disclosing records to an employer for hiring decisions
Correct answer: Sharing data with a researcher under a data use agreement with 16 identifiers removed
A limited data set excludes most direct identifiers but may include dates and geographic data; it can be shared for research, public health, or healthcare operations under a data use agreement.
Question 2: Under the HITECH Act, which entities became directly liable for HIPAA compliance?
- Health plans only
- Business associates as well as covered entities (Correct answer)
- Only covered entities with more than 50 employees
- Federal healthcare agencies
Correct answer: Business associates as well as covered entities
The HITECH Act extended direct HIPAA liability to business associates, meaning they are subject to HIPAA Security Rule requirements and civil and criminal penalties.
Question 3: A hospital posts a notice on its website and in patient areas about its privacy practices. This document is known as the:
- Business associate agreement
- Notice of Privacy Practices (NPP) (Correct answer)
- Authorization form
- Security risk assessment
Correct answer: Notice of Privacy Practices (NPP)
The Notice of Privacy Practices (NPP) informs patients how their PHI may be used and disclosed and outlines their rights under HIPAA.
Question 4: Which of the following is true regarding HIPAA and deceased individuals' PHI?
- HIPAA protections end immediately upon death
- PHI of deceased individuals is protected for 50 years after death (Correct answer)
- HIPAA protections apply for 5 years after death
- Deceased individuals have no HIPAA rights
Correct answer: PHI of deceased individuals is protected for 50 years after death
HIPAA extends privacy protections to the PHI of deceased individuals for 50 years following their death.
Question 5: An HIM professional sends a fax containing PHI to the wrong recipient. Under HIPAA, this is considered:
- An authorized disclosure requiring no action
- A potential breach requiring a risk assessment (Correct answer)
- Automatically a reportable breach
- A de minimis event with no consequences
Correct answer: A potential breach requiring a risk assessment
A misdirected fax is an impermissible disclosure that triggers the four-factor risk assessment to determine if it constitutes a reportable breach.
Question 6: Which of the following best describes the HIPAA 'right to request confidential communications'?
- Patients can demand all records be encrypted
- Patients can request that communications be made through alternative means or locations (Correct answer)
- Patients can require providers to never contact them
- Patients can block all disclosures to family members
Correct answer: Patients can request that communications be made through alternative means or locations
Patients may request that covered entities communicate with them in a specific way or at a specific location, such as calling a work number instead of a home number.
Question 7: Which office is responsible for enforcing HIPAA Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Food and Drug Administration (FDA)
- Office of Inspector General (OIG)
Correct answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) is the primary federal agency responsible for enforcing HIPAA Privacy and Security Rules.
Which of the following scenarios represents a valid use of the HIPAA 'limited data set'?