Enforcement and Penalties Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Enforcement and Penalties flashcards as text
Under the HITECH Act, what percentage of collected HIPAA civil monetary penalties must be used for affected individuals?
Answer: A percentage determined by the HHS Secretary
The HITECH Act authorizes HHS to distribute a percentage of CMPs to harmed individuals, with the exact percentage determined by the HHS Secretary.
Which of the following is NOT a factor OCR considers when determining the amount of a civil monetary penalty?
Answer: The political affiliation of the covered entity's leadership
OCR considers factors such as harm, number of individuals affected, and financial condition, but political affiliation is not a relevant factor.
A hospital employee snoops through a celebrity patient's records out of curiosity and shares them with friends. Which criminal tier most likely applies?
Answer: Tier 2: up to 5 years in prison
Knowingly obtaining or disclosing PHI under false pretenses (beyond simple curiosity, for personal benefit/sharing) typically falls under Tier 2, carrying up to 5 years imprisonment.
The statute of limitations for OCR to impose a civil monetary penalty for a HIPAA violation is:
Answer: 6 years from the date of the violation
OCR must impose civil monetary penalties within 6 years of the date the violation occurred.
Which scenario would most likely result in OCR finding 'willful neglect — not corrected'?
Answer: A practice repeatedly ignores OCR compliance recommendations over two years and makes no changes
Willful neglect uncorrected means the entity consciously and intentionally failed to comply without timely correction, making repeated inaction despite warnings the clearest example.
What is the annual cap on civil monetary penalties for identical violations under a single HIPAA provision?
Answer: $1,919,173 (inflation-adjusted)
The annual cap per identical violation category is $1.5 million, adjusted periodically for inflation (currently approximately $1.919 million).
When a business associate is directly liable for a HIPAA violation, OCR may:
Answer: Fine the business associate directly under HIPAA
Since the HITECH Act, business associates are directly subject to HIPAA civil and criminal penalties and OCR can fine them directly.