Breach Notification & Legal Enforcement Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Breach Notification & Legal Enforcement flashcards as text
A covered entity discovers that a business associate improperly disclosed PHI for 520 individuals. Who must notify the affected individuals?
Answer: The covered entity
The covered entity retains responsibility for notifying affected individuals even when the breach is caused by a business associate.
Under HIPAA, what is the maximum penalty tier for violations due to willful neglect that are not corrected within the required timeframe?
Answer: $50,000 per violation
Willful neglect not corrected carries a minimum of $10,000 and maximum of $50,000 per identical violation category per year.
A hospital's laptop containing unencrypted PHI is stolen. The hospital determines 480 individuals are affected. What is the correct breach notification sequence?
Answer: Notify individuals within 60 days and HHS within 60 days
For breaches affecting fewer than 500 individuals, covered entities must notify individuals and HHS within 60 days of discovery.
Which of the following constitutes a 'breach' under the HIPAA Breach Notification Rule?
Answer: Impermissible use or disclosure of PHI that compromises its security or privacy
A breach is defined as an impermissible use or disclosure of PHI that poses a significant risk of financial, reputational, or other harm to the individual.
A covered entity believes a breach occurred but cannot demonstrate a low probability that PHI was compromised. Under HIPAA, what must it do?
Answer: Treat the incident as a breach and provide required notifications
If the covered entity cannot demonstrate a low probability of compromise using the four-factor risk assessment, it must treat the event as a breach and notify.
What is the role of the HHS Office for Civil Rights (OCR) in HIPAA enforcement?
Answer: Investigating complaints and enforcing the Privacy and Security Rules
OCR investigates complaints, conducts compliance reviews, and enforces the HIPAA Privacy, Security, and Breach Notification Rules.
A nurse accidentally emails PHI for 3 patients to the wrong physician. The information is returned unread and deleted. After a risk assessment, the entity documents a low probability of compromise. What should the covered entity do?
Answer: Document the assessment findings and treat it as a non-breach
If all four risk assessment factors support a low probability of compromise, the entity may document its conclusion and forego notification.