Practice questions › Healthcare Information and Systems Management › Privacy and Security
The presumption of a breach, rebutted by a low probability of compromise
A practice question in the style of the CPHIMS® exam, from the free questions of HealthITPrep. The question is in English, as in the exam.
An employee accidentally emails a spreadsheet containing patients' PHI to the wrong outside recipient. Under the HIPAA Breach Notification Rule, when can the organization conclude that this incident is NOT a reportable breach?
Choose an answer, or open the explanation below.
Show the answer and the explanation
The correct answer: B. When a documented risk assessment demonstrates a low probability that the PHI was compromised
✅ Why this answer
The rule of the reversed presumption: any improper use or disclosure of PHI is presumed to be a breach automatically, and the burden of proof is on the organization; it rebuts the presumption with a documented risk assessment showing “a low probability that the information has been compromised”, using its four factors:
- The nature and extent of the information involved.
- The unauthorized person who used or received it.
- Whether the information was actually viewed or acquired.
- The extent to which the risk has been mitigated (was the message recalled? was it deleted, with confirmation?).
❌ Why the other options are wrong
- Showing that no patient was harmed (A): the deadly historical trap; the “no harm” standard is the old, repealed standard that allowed evasion (“nobody was harmed!”), and it was deliberately replaced with a stricter, more objective one. The question tests whether your knowledge is up to date.
- The employee apologizing to the recipient (C): has no legal value in the assessment.
- The incident happening outside business hours (D): timing is unrelated to the classification.
💡 Key concept
Beyond the rebuttal rule there are limited exits. Data encrypted to an approved standard are not “unsecured” in the first place, so no notification is due for them (a related question in the full bank). There are three narrow exceptions: unintentional access by a workforce member acting in good faith and within their authority; an inadvertent disclosure between two authorized persons in the same organization (in both of these, provided the information is not then used or disclosed improperly); and a disclosure to a recipient who could not reasonably have retained the information. But the general rule is the “low probability that the information has been compromised” formula.
In the exam: any use or disclosure that is not permitted is presumed to be a breach, and the organization must show otherwise with a documented risk assessment. “Nobody was harmed” is the old, repealed standard, so an option that relies on it is wrong.
🔗 Related facts and questions
- The four factors of the assessment: the nature and extent of the information, who received or used it without authorization, whether it was actually viewed or acquired, and how far the risk was mitigated after the event.
Practice question: a fax with protected health information was sent by mistake to a clinic of another hospital, which is itself bound by HIPAA. The clinic confirmed in writing that it destroyed the fax without using it. Which way does the assessment lean? → Toward a low probability: the recipient is itself obliged to protect the information, and the destruction is confirmed. - Encryption takes the event out of the rule:
Practice question: a laptop holding patient information encrypted to an approved standard is stolen, and the encryption key was not stolen with it. Is notification required? → No. The information is secured, and the notification rule concerns unsecured information. - The notification deadlines: individuals are notified without unreasonable delay, and no later than 60 days after the breach is discovered. When 500 or more individuals are affected, the Department of Health and Human Services (HHS) is notified within the same period (a related question in the full bank). When fewer than 500 are affected, the department is notified once a year, within 60 days of the end of the calendar year in which the breach was discovered.
Practice question: a breach affected 120 patients. When is the department notified? → In the annual report, within 60 days of the end of the calendar year. The patients are notified within 60 days of discovery. - What the notice says, and who else is told: the notice states briefly what happened, when, and when it was discovered, the types of information involved, what individuals can do to protect themselves, what the organization is doing to investigate, limit the harm and prevent a repeat, and how to contact it. When the breach involves more than 500 residents of one state, prominent media outlets there are notified too.
Practice question: a breach involved 700 patients who live in one state. Who is notified besides the patients and the department? → Prominent media outlets in that state. - Documentation is the evidence: the burden of proof is on the organization. So the risk assessment is written and kept, whether it ends in notification or not.
- The business associate: if the breach happens at a business associate, it must inform the covered entity, which is the one that notifies the individuals.
40 questions like this one, free
A timed 20-question trial exam with this kind of explanation for every option and a score per domain, drawn from 40 free questions. No payment details needed.
Start the trial examAll 30 free practice questions · CPHIMS guide
Practice questions written for study; they are not the questions of the real exam. An independent site, not affiliated with or endorsed by HIMSS. CPHIMS® is a registered trademark of HIMSS.