Compliance & RegulatoryQuestion 97 of 100
A breach of unsecured protected health information under HIPAA generally requires the covered entity to:
a.Ignore it if fewer than 100 records are involved
b.Notify affected individuals, and in some cases HHS and the media, within required timeframes
c.Immediately delete all patient records
d.Charge the affected patients a fee
Explanation
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, and depending on the breach's size, HHS and sometimes the media, within specified timeframes after discovering a breach of unsecured PHI. Business associates must notify the covered entity of breaches. Timely, proper notification is a legal obligation, not optional.
Law Reference: HIPAAPractice all 100 questions free — no signup required.
Related questions on this topic
- Accurate and complete medical record documentation is important for billing because:
- If a billing staff member accesses a patient's record out of curiosity, with no job-related reason, this is:
- A compliance program in a medical practice is designed to:
- Medical record retention requirements are generally set by:
- Obtaining a patient's signed authorization is generally required before a provider may:
- A Notice of Privacy Practices (NPP) is a document that a covered entity must:
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against NHA Certified Billing & Coding Specialist (CBCS) Exam · How we review