List of questions
Related questions
Question 109 - CIPP-US discussion
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track information about its patients. Recently, SMH suffered a data breach where a third-party hacker was able to gain access to the SMH internal network.
Because it is a HIPPA-covered entity, SMH made a notification to the Office of Civil Rights at the U.S. Department of Health and Human Services about the breach.
Which statement accurately describes SMH's notification responsibilities?
If SMH is compliant with HIPAA, it will not have to make a separate notification to individuals in the state of New York.
If SMH has more than 500 patients in the state of New York, it will need to make separate notifications to these patients.
If SMH must make a notification in any other state in which it operates, it must also make a notification to individuals in New York.
If SMH makes credit monitoring available to individuals who inquire, it will not have to make a separate notification to individuals in the state of New York.
0 comments
Leave a comment first