The Omnibus Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 The Omnibus Rule flashcards as text
Under the Omnibus Rule, which of the following uses of PHI by a covered entity requires an individual's written authorization?
Answer: Selling PHI to a third party for remuneration
The Omnibus Rule requires written authorization for the sale of PHI, prohibiting covered entities from receiving remuneration for PHI without patient authorization.
The Omnibus Rule addressed the use of genetic information for underwriting purposes. What did it establish?
Answer: Health plans are prohibited from using genetic information for underwriting purposes
The Omnibus Rule implemented GINA provisions by prohibiting health plans from using or disclosing genetic information for underwriting purposes.
Under the Omnibus Rule, a business associate may use PHI for its own purposes if:
Answer: The use is permitted by the Privacy Rule and the BAA
Business associates may only use PHI in ways that are permitted by the HIPAA Privacy Rule and specifically authorized in the business associate agreement.
A research organization conducts a study and previously collected PHI under a valid HIPAA authorization. Under the Omnibus Rule, can the same authorization cover future research?
Answer: Yes, authorizations can cover future research studies if sufficiently described
The Omnibus Rule clarified that a single authorization can cover future research studies as long as the future purposes are adequately described in the authorization.
Which of the following is an example of a 'hybrid entity' under HIPAA as clarified by the Omnibus Rule?
Answer: An organization that performs both covered and non-covered healthcare functions
A hybrid entity is one that performs both covered healthcare-related functions and non-covered functions, and it must designate its healthcare component for HIPAA compliance purposes.
Under the Omnibus Rule's four-factor test to determine whether a breach occurred, which factor is NOT part of the assessment?
Answer: The number of individuals who were affected by the breach
The four-factor test assesses the nature and extent of PHI, the unauthorized person involved, whether PHI was acquired or viewed, and the extent to which risk was mitigated — not the number of individuals affected.
Under the Omnibus Rule, if a covered entity discovers that its business associate has been in violation of the BAA, what is the covered entity's obligation?
Answer: Take reasonable steps to cure the breach or end the violation, and terminate the BAA if unsuccessful
When a covered entity becomes aware of a BAA violation, it must take reasonable steps to cure the breach or end the violation, and if not resolved, terminate the BAA.