Hard1 markMultiple Choice
Area II: SecurityHIPAARegulations

CPA · Question 25 · Area II: Security

A company is subject to HIPAA. An employee loses a company laptop containing unencrypted ePHI (electronic Protected Health Information). Under the HIPAA Breach Notification Rule, what is the immediate requirement if the breach affects more than 500 individuals?

Answer options:

A.

Notify the individuals within 60 days; notify HHS annually.

B.

Notify the individuals, the Secretary of HHS, and prominent media outlets without unreasonable delay (no later than 60 days).

C.

Notify the individuals only.

D.

Pay a fine immediately.

How to approach this question

Recall the '500 rule' for HIPAA notifications.

Full Answer

B.Notify the individuals, the Secretary of HHS, and prominent media outlets without unreasonable delay (no later than 60 days).✓ Correct
B
For breaches affecting 500 or more individuals, HIPAA requires notification to the affected individuals, the Secretary of HHS, and prominent media outlets in the state or jurisdiction. This must happen without unreasonable delay and no later than 60 days after discovery.

Common mistakes

Thinking HHS notification can wait until the end of the year (only true for <500).

Practice the full CPA ISC Practice Exam 3

82 questions · hints · full answers · grading

More questions from this exam