HIPAA Practice Question: If ePHI is encrypted using approved methods and is acquired by an... | CyberCertPrep
HHSHIPAABreach NotificationEASYFree question
If ePHI is encrypted using approved methods and is acquired by an unauthorized person, is it a reportable breach?
A.No, properly encrypted ePHI is considered unusable and not a breach requiring notification
B.Yes, always
C.Only if the encryption key is also compromised
D.Only if more than 500 records are involved
Why A is correct
If ePHI is encrypted per HHS guidance and the encryption key is not compromised, the data is considered unusable and the incident is not a reportable breach.
Know someone studying for HIPAA? Send them this one.
Where this fits in the HIPAA exam
Breach Notification
Covers breach notification concepts and practices within HIPAA.
This question belongs to the "Breach Notification & Enforcement" domain, which makes up about 10% of the HIPAA exam.
CyberCertPrep gives you 20 free HIPAA questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
HIPAA and HHS are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by HHS or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Another method that renders PHI 'secured' under the safe harbor is: