Breach Notification Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Breach Notification Rule flashcards as text
Under the Breach Notification Rule, what is the deadline for notifying the HHS Secretary about a breach affecting 500 or more individuals?
Answer: Within 60 days of discovery
Covered entities must notify HHS within 60 days of discovering a breach affecting 500 or more individuals.
A hospital's laptop containing unencrypted PHI is stolen. Which factor is NOT part of the four-factor risk assessment used to determine if a breach occurred?
Answer: The financial cost of the breach to the covered entity
The four-factor risk assessment does not include financial cost; it focuses on nature of PHI, the unauthorized person, whether PHI was accessed, and extent of risk mitigation.
Which of the following is an exception to the Breach Notification Rule that does NOT require notification?
Answer: An unintentional acquisition of PHI by a workforce member acting in good faith
Unintentional acquisition, access, or use of PHI by a workforce member acting in good faith and within scope of authority is an exception to breach notification.
If a breach affects fewer than 500 individuals in a state, when must the covered entity notify HHS?
Answer: Within 60 days after the end of the calendar year
For breaches affecting fewer than 500 individuals, covered entities must maintain a log and report to HHS annually within 60 days after the end of each calendar year.
A business associate discovers a breach of PHI. What is the business associate's primary notification obligation?
Answer: Notify the covered entity without unreasonable delay and within 60 days of discovery
Business associates must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovering the breach.
Which of the following breach notification methods is required when a covered entity cannot locate contact information for 10 or more affected individuals?
Answer: Posting a notice on the covered entity's website for 90 days
When contact information is insufficient for 10 or more individuals, covered entities must post a conspicuous notice on their website for at least 90 days.
What type of information is NOT required to be included in a breach notification to affected individuals?
Answer: The names and addresses of all other individuals affected by the breach
Breach notifications must include a description of the breach, types of PHI involved, steps to protect against harm, and contact information, but NOT the names of other affected individuals.