HCISPP · Question #157
Breach notification exceptions are provided to all, EXCEPT:
The correct answer is C. If the information impacted less than 500 people within a single demographic area. Option C is correct because the number of individuals affected has no bearing on whether breach notification is required under HIPAA - there is no "under 500 people" exemption. The 500-person threshold determines the type of notification required (breaches affecting 500+ in a…
Question
Breach notification exceptions are provided to all, EXCEPT:
Options
- ABusiness associates who access information by good faith, unintentional means and do not further
- BUnintentional, good faith access by employees of covered entities if the information was not further
- CIf the information impacted less than 500 people within a single demographic area
- DInadvertent disclosure made individual to individual within a covered entity who is authorized to
How the community answered
(50 responses)- A12% (6)
- B4% (2)
- C76% (38)
- D8% (4)
Explanation
Option C is correct because the number of individuals affected has no bearing on whether breach notification is required under HIPAA - there is no "under 500 people" exemption. The 500-person threshold determines the type of notification required (breaches affecting 500+ in a jurisdiction require media notification), but it does not waive the obligation to notify affected individuals regardless of how small the breach is.
Options A, B, and D are all legitimate HIPAA breach notification exceptions: A covers business associates who access PHI in good faith without intent and do not further disclose it; B mirrors that protection for employees of covered entities under the same conditions; D covers inadvertent disclosures between authorized personnel within the same covered entity where the information is not further used or disclosed. All three exceptions share a common theme - unintentional access that goes no further.
Memory tip: Think of the three valid exceptions as "accidental and contained" - they all involve someone who shouldn't have seen the data but stumbled upon it and kept it to themselves. Option C is the trap because it sounds like a threshold rule (which does exist elsewhere in HIPAA), but no breach gets a free pass based on headcount.
Topics
Community Discussion
No community discussion yet for this question.