HIPAA Practice Question: Encrypted PHI is exempt from breach notification if: | CyberCertPrep
HHSHIPAABreach NotificationEASYFree question
Encrypted PHI is exempt from breach notification if:
A.The entity believes the encryption is adequate
B.Any form of encryption is used
C.The encryption meets NIST standards and the decryption key has not been compromised
D.The encryption was applied after the breach
Why C is correct
PHI encrypted consistent with NIST standards is considered secured, and loss or theft does not trigger notification requirements unless the key is also compromised.
Know someone studying for HIPAA? Send them this one.
Where this fits in the HIPAA exam
Breach Notification
Covers breach notification concepts and practices within HIPAA.
This question belongs to the "Breach Notification & Enforcement" domain, which makes up about 10% of the HIPAA exam.
CyberCertPrep gives you 20 free HIPAA questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
HIPAA and HHS are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by HHS or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
If ePHI is encrypted using approved methods and is acquired by an unauthorized person, is it a reportable breach?