QuestionQ51

Federal Privacy Laws

A covered entity experiences a ransomware attack affecting the personal health information (PHI) of more than 500 individuals. Under federal HIPAA law, to which of the following would the covered entity NOT be required to report the breach?

  • A Department of Health and Human Services
  • B The affected individuals
  • C The local media
  • D Medical providers
Explanation

HIPAA requires notification to affected individuals and the Secretary of HHS after a breach of unsecured PHI. When a breach affects more than 500 residents of a State or jurisdiction, the covered entity must also notify prominent media outlets serving that area. HIPAA does not require a separate breach report to medical providers.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!