CIPP-US - Limits on Private-Sector Collection and Use of Data - Section 2.2

Explain HIPAA's Privacy Rule and Security Rule requirements, permissible uses and disclosures, and the HITECH Act's breach notification obligations.

Describe the HIPAA Privacy Rule's framework for permissible uses and disclosures of protected health information (PHI) by covered entities and business associates, and the Security Rule's administrative, physical, and technical safeguards for electronic PHI. Apply HITECH breach notification requirements to determine when and to whom a covered entity must report an impermissible disclosure.

HIPAA Privacy RulePHICovered entityHITECH breach notification

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datahard

A compliance officer at a covered clinic is structuring the clinic's protections for electronic protected health information so that they map cleanly onto the categories of safeguards the HIPAA Security Rule requires. Which three categories of safeguards does the Security Rule require the clinic to implement for electronic PHI? (Select THREE.)

  • AAdministrative safeguards, such as a security management process, workforce training, and assignment of a security official. Correct
  • BPhysical safeguards, such as facility access controls and rules for workstation use and device and media disposal. Correct
  • CTechnical safeguards, such as access controls, audit controls, integrity controls, and transmission security. Correct
  • DFinancial safeguards, such as cyber-insurance coverage and a funded reserve sized to the cost of a notifiable breach.
  • EContractual safeguards, such as business associate agreements that by themselves satisfy the Rule's safeguard obligations for the clinic.
The HIPAA Security Rule organises protection of electronic PHI into three required categories: administrative, physical, and technical safeguards. The Security Rule structures its standards into administrative, physical, and technical safeguards, each addressing a distinct layer of protection for electronic PHI; financial and contractual safeguards are not categories the Rule defines, so options invoking insurance reserves or treating a business associate agreement as a standalone safeguard misstate the framework.

Why A is correct: Administrative safeguards are one of the three required categories and cover the policies, risk management, and personnel measures that govern security.

Why B is correct: Physical safeguards are a required category covering protection of facilities, workstations, and the devices and media that hold electronic PHI.

Why C is correct: Technical safeguards are a required category governing the technology that controls and monitors access to electronic PHI.

Why D is wrong: The Security Rule defines administrative, physical, and technical safeguards; it does not establish a financial safeguards category or mandate insurance reserves.

Why E is wrong: Business associate agreements are required where applicable but are not one of the Security Rule's three safeguard categories and do not discharge the clinic's own safeguard duties.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Limits on Private-Sector Collection and Use of Data objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.