Compliance & RegulatoryQuestion 97 of 100

A breach of unsecured protected health information under HIPAA generally requires the covered entity to:

a.Ignore it if fewer than 100 records are involved
b.Notify affected individuals, and in some cases HHS and the media, within required timeframes
c.Immediately delete all patient records
d.Charge the affected patients a fee

Explanation

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, and depending on the breach's size, HHS and sometimes the media, within specified timeframes after discovering a breach of unsecured PHI. Business associates must notify the covered entity of breaches. Timely, proper notification is a legal obligation, not optional.

Law Reference: HIPAA

Practice all 100 questions free — no signup required.

Related questions on this topic

Last reviewed: · editorial process

PrepPass Editorial Team · Verified against NHA Certified Billing & Coding Specialist (CBCS) Exam · How we review
Report