nerdexam
(ISC)2

HCISPP · Question #157

Breach notification exceptions are provided to all, EXCEPT:

The correct answer is C. If the information impacted less than 500 people within a single demographic area. Option C is correct because the number of individuals affected has no bearing on whether breach notification is required under HIPAA - there is no "under 500 people" exemption. The 500-person threshold determines the type of notification required (breaches affecting 500+ in a…

Regulatory and Standards Environment

Question

Breach notification exceptions are provided to all, EXCEPT:

Options

  • ABusiness associates who access information by good faith, unintentional means and do not further
  • BUnintentional, good faith access by employees of covered entities if the information was not further
  • CIf the information impacted less than 500 people within a single demographic area
  • DInadvertent disclosure made individual to individual within a covered entity who is authorized to

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    4% (2)
  • C
    76% (38)
  • D
    8% (4)

Explanation

Option C is correct because the number of individuals affected has no bearing on whether breach notification is required under HIPAA - there is no "under 500 people" exemption. The 500-person threshold determines the type of notification required (breaches affecting 500+ in a jurisdiction require media notification), but it does not waive the obligation to notify affected individuals regardless of how small the breach is.

Options A, B, and D are all legitimate HIPAA breach notification exceptions: A covers business associates who access PHI in good faith without intent and do not further disclose it; B mirrors that protection for employees of covered entities under the same conditions; D covers inadvertent disclosures between authorized personnel within the same covered entity where the information is not further used or disclosed. All three exceptions share a common theme - unintentional access that goes no further.

Memory tip: Think of the three valid exceptions as "accidental and contained" - they all involve someone who shouldn't have seen the data but stumbled upon it and kept it to themselves. Option C is the trap because it sounds like a threshold rule (which does exist elsewhere in HIPAA), but no breach gets a free pass based on headcount.

Topics

#HIPAA breach notification#Breach notification exceptions#Covered entities#Low probability of compromise

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice