Independent learning · P3 Pharmacy Law
HIPAA for the Pharmacist
Learn to protect information without putting unnecessary barriers in the way of patient care.
Read each explanation, work through the examples, and answer the practice cases before checking the reasoning. There is no required score, login, or completion gate. You can revisit any lesson and retry every question. The learning targets will be tested on a course exam; material marked “Background” is context only.
Before you begin
This refreshes the HIPAA foundation from Pharmacy Informatics. You need a current browser and basic ability to select answers, follow links, and print or save a page. No specialist software is needed.
How to learn
Follow the numbered lessons first, then try the Pharmacy Practice Cases without consulting the text. Feedback explains every option. Finish with the printable review and identify questions for class.
Learning objectives (41)
Original numbers are retained for traceability. Background topics are marked in the lessons and are not exam targets.
- Define HIPAA and describe its original intent and expanded scope.
- Distinguish the Privacy, Security, and Breach Notification Rules and their roles in pharmacy practice.
- Identify the three safeguard categories under the Security Rule: administrative, physical, and technical.
- Describe examples of each safeguard type in a pharmacy setting.
- Evaluate whether a pharmacy’s security measures are “reasonable and appropriate” under HIPAA.
- Define Protected Health Information (PHI) and list examples relevant to pharmacy practice.
- Identify types of identifiers that make health information individually identifiable.
- Explain and apply Safe Harbor de-identification to pharmacy information.
- Distinguish between covered entities and business associates under HIPAA.
- Identify examples of business associates in pharmacy operations.
- List and describe the rights patients have under HIPAA (access, amend, accounting, restrict, confidential communication).
- Apply procedures for responding to patient requests regarding their PHI.
- Determine when a personal representative may access PHI and when an agent may not.
- Identify treatment, payment, and health care operations (TPO) as important permitted uses and disclosures without authorization.
- Apply the TPO framework to pharmacy scenarios.
- Determine when written authorization is required for PHI disclosure.
- Explain the Minimum Necessary Standard and its exceptions.
- Evaluate whether a PHI disclosure meets the Minimum Necessary Standard.
- Define incidental disclosures and assess whether they are HIPAA violations.
- Describe the distribution and posting requirements for the NPP.
- Explain the acknowledgment of receipt process and documentation requirements.
- Apply HIPAA rules to situations involving refusal to sign the acknowledgment.
- Define a designated record set and its relevance to patient access.
- Describe the format and fee requirements for providing PHI to patients.
- Apply professional judgment in disclosing PHI to agents.
- List the required elements of an accounting of disclosures.
- Identify disclosures excluded from the accounting requirement.
- Define a breach under HIPAA and list the exceptions.
- Apply breach-notification recipients, thresholds, and deadlines for individuals, HHS, and media.
- Explain the concept and use of substitute notice.
- Describe HIPAA’s expectations for PHI disposal.
- Identify common violations and enforcement actions related to disposal.
- List recommended disposal methods for different PHI formats.
- Apply disposal best practices to pharmacy operations.
- Identify enforcement authorities under HIPAA and their roles.
- Describe the tiered civil penalty structure and apply it to pharmacy violations.
- List criminal offenses under HIPAA and their associated penalties.
- Apply criminal penalty categories to intentional misconduct scenarios.
- Explain the legal implications of HIPAA violations in state courts.
- Apply patient access and amendment response deadlines and permitted extensions.
- Apply accounting request deadlines, extensions, lookback periods, and fee rules.
Objective 16 covers treatment, payment, and health care operations; these are not the only permitted disclosure pathways. Objectives 43–44 make patient-request deadlines explicit.
Your route through the module
- 1What HIPAA covers
About 10 minutes - 2Recognizing and protecting information
About 13 minutes - 3Deciding whether information may be shared
About 15 minutes - 4Patients, representatives, and others
About 18 minutes - 5Notices and acknowledgment
About 9 minutes - 6Accounting for disclosures
About 8 minutes - 7Incidents, notification, and disposal
About 17 minutes - 8Enforcement and consequences
About 10 minutes
The lesson estimates total about 100 minutes; allow another 10–20 for Pharmacy Practice Cases and review. Reading pace and retries will vary.
A green checkmark appears after you reach a lesson’s end and submit every practice question; answers need not all be correct. Checkmarks stay on this browser and are not sent to the instructor. Resetting progress does not remove already submitted anonymous answers.
Help and class follow-up
Write down confusing cases or rules and bring questions to class on Monday, November 2. We will review the content that proved most problematic. For technical or accessibility barriers, use the Samford technology and accommodation resources linked in your Canvas course. If a page fails, try another current browser or the downloadable HTML. Essential instruction is available as text; no audio or video is required.
Anonymous question reporting
The module sends your first submitted choice for each practice question to anonymous class totals. The instructor can see which questions and distractors caused difficulty. Anonymous reporting does not send names, email addresses, student IDs, grades, completion records, or an identifier linking your answers across questions.
More about anonymous reporting
A separate random receipt for each question prevents repeat network submissions. This browser remembers first answers so retries do not alter totals. Clearing storage or using a new device may cause another first answer to count; these are instructional signals, not unique-student measures. Hosting infrastructure may process ordinary connection information, such as IP addresses, to deliver the site; the application does not add it to answer records.
Lesson 1 of 8 · About 10 minutes
What HIPAA covers
Start with the purpose of the law, the organizations it regulates, and the work each rule does.
Learning objectives for this lesson
- Define HIPAA and describe its original intent and expanded scope.
- Distinguish the Privacy, Security, and Breach Notification Rules and their roles in pharmacy practice.
- Distinguish between covered entities and business associates under HIPAA.
- Identify examples of business associates in pharmacy operations.
A statute and its implementing rules
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal statute: a law enacted by Congress. Its original purposes included helping people keep health insurance, combating fraud and abuse, and simplifying health care administration. HHS issues regulations that put the law into practice. Later legislation, including HITECH, strengthened safeguards, business-associate responsibilities, and breach notification.
Four components relevant to pharmacy practice
- Privacy Rule
- Protects protected health information (PHI) whether it is spoken, printed, or electronic. It addresses who may use or receive information, why, and under what conditions, as well as patient rights.
- Security Rule
- Requires administrative, physical, and technical safeguards to protect electronic PHI.
The Breach Notification Rule adds requirements for responding to breaches. This four-component framework is a teaching aid, not a claim that HIPAA has only four provisions.
Who is regulated?
include health plans, health care clearinghouses, and health care providers that send health information electronically in connection with HIPAA-standard transactions. A billing service can send the transactions on the provider's behalf. Most dispensing pharmacies qualify through electronic claims. Email use or interstate shipping alone does not establish covered-entity status.
A handles PHI to perform specified functions or services for a covered entity, outside its workforce. Examples include a software provider managing identifiable refill reminders or maintaining patient databases. A business associate agreement (BAA) sets permitted handling and safeguards; it does not make an otherwise prohibited disclosure permissible.
A contractor that does not handle PHI is not automatically a business associate. Another provider receiving information to treat a shared patient does not become the pharmacy's business associate merely because of that disclosure. Business associates have their own HIPAA duties, but those duties are not identical to every covered-entity duty. Classify a company by what it does, rather than its name.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
HIPAA is:
Reasoning for every choice
A. A state statute
HIPAA is a federal law enacted by Congress, not a state statute. State privacy laws can also affect pharmacy practice.
B. A federal regulation
HHS regulations implement HIPAA, but HIPAA itself is the statute enacted by Congress.
C. A federal statute · Best answer
HIPAA is the Health Insurance Portability and Accountability Act of 1996, enacted by Congress. HHS regulations put its requirements into practice.
Refill service
Reasoning for every choice
A. A treating provider coordinating the patient’s medication care.
A reminder vendor is not automatically a treating provider. The described role is a service for the pharmacy.
B. A business associate performing a PHI service for the pharmacy. · Best answer
Its PHI-related function on behalf of the pharmacy makes this a business-associate role, normally requiring a BAA and applicable safeguards.
C. An ordinary contractor outside HIPAA because it does not dispense.
Dispensing is not the test for business-associate status. Handling PHI for a covered entity can trigger obligations.
Covered entity
Reasoning for every choice
A. It submits standard electronic prescription claims to payers. · Best answer
Electronic health information in a HIPAA-standard transaction satisfies the qualifying electronic-transaction requirement.
B. It ships prescription medicines across a state boundary.
Interstate shipping alone is not the HIPAA covered-entity test.
C. It routinely exchanges health-related email messages with staff.
Email alone is not enough; the electronic transmission must be connected to a standard transaction.
A pharmacy’s covered-entity status depends on its qualifying electronic transactions. A business associate handles PHI for the pharmacy in a specified service role; another provider receiving information for treatment does not become its business associate merely because of that disclosure.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 2 of 8 · About 13 minutes
Recognizing and protecting information
Recognize PHI before choosing safeguards. Privacy applies beyond the computer screen.
Learning objectives for this lesson
- Distinguish the Privacy, Security, and Breach Notification Rules and their roles in pharmacy practice.
- Identify the three safeguard categories under the Security Rule: administrative, physical, and technical.
- Describe examples of each safeguard type in a pharmacy setting.
- Evaluate whether a pharmacy’s security measures are “reasonable and appropriate” under HIPAA.
- Define Protected Health Information (PHI) and list examples relevant to pharmacy practice.
- Identify types of identifiers that make health information individually identifiable.
- Explain and apply Safe Harbor de-identification to pharmacy information.
PHI is information in context
is information about a person’s health, care, or payment for care that identifies the person or could reasonably identify them. HIPAA protects it when held or transmitted by a covered entity or business associate, subject to the rule’s exclusions. A prescription record, billing entry, patient profile, or conversation about an identifiable patient’s medication can be PHI.
A name alone is not necessarily PHI. It becomes PHI when linked to information about that person’s health, care, or payment for care. Removing a name is not enough if other details—such as a prescription number—still identify the patient.
Find the identifiers on this fictional prescription label
Hover, tap, or use Tab and Enter to inspect the outlined components.
Select an outlined component to see its explanation.
Check every Safe Harbor identifier category—not just the fields highlighted here—and consider whether the remaining information could identify the patient.
Two recognized methods of de-identification
HIPAA recognizes two methods for de-identifying health information: Safe Harbor and expert determination. Properly de-identified information is no longer PHI.
Method 1: Safe Harbor
requires removing the specified 18 categories of identifiers about the patient and their relatives, household members, and employers, and having no actual knowledge that the remaining information could identify the patient.
| Category | Category |
|---|---|
| 1. Names | 10. Account numbers |
| 2. Geographic details below the state level | 11. Certificate or license numbers |
| 3. Dates related to a person, except year; ages over 89 | 12. Vehicle identifiers and serial numbers, including license plates |
| 4. Telephone numbers | 13. Device identifiers and serial numbers |
| 5. Fax numbers | 14. Web URLs |
| 6. Email addresses | 15. IP addresses |
| 7. Social Security numbers | 16. Biometric identifiers, including fingerprints and voiceprints |
| 8. Medical record numbers | 17. Full-face photographs and comparable images |
| 9. Health-plan beneficiary numbers | 18. Other unique identifying numbers, characteristics, or codes |
Geographic information has a limited three-digit ZIP-code exception. Remove date elements other than year; ages over 89 and associated date elements must be grouped as age 90 or older. A specially permitted re-identification code has separate conditions. The pharmacy must also consider whether the remaining details could identify the person.
Method 2: Expert Determination
A qualified expert applies accepted statistical or scientific methods, determines that the risk of identifying a person is very small, and documents the methods and results. This is not an informal judgment by pharmacy staff that a record “looks anonymous.”
Both are recognized methods. In this module, you will practice applying Safe Harbor rather than performing an expert determination.
Protect confidentiality, integrity, and availability
Three goals explain what effective protection accomplishes:
Confidentiality: only authorized people can see it
Keep patient information from people who have no authorized reason to see it. Position a pharmacy screen so customers cannot read other patients’ profiles.
Integrity: information stays accurate
Protect information from improper changes or destruction. A dispensing record must not be altered by someone without permission.
Availability: staff can obtain it when needed
Authorized staff need access for patient care. Backups and a tested recovery plan help restore access after a system failure.
| Category | What it protects and examples |
|---|---|
| Administrative | People and processes: training, risk analysis, access policies, incident procedures, and backup/recovery planning. |
| Physical | Places and equipment: screen positioning, locked storage areas, device control, and secure disposal. |
| Technical | Electronic access and activity: unique logins, authentication, audit controls, and protected transmissions. |
Safeguards must be reasonable and appropriate for the pharmacy’s size, resources, systems, costs, and risks. Small size is not an exemption from required standards.
Being able to open a patient’s record does not mean you are permitted to do so. Access it only for an authorized work purpose. The pharmacy should limit access according to job duties and review records of system activity.
Privacy or security?
Select each example to check the distinction.
May the pharmacist tell a patient’s spouse about an unrelated medication?
The Privacy Rule governs whether sharing is permitted.
How does the pharmacy prevent unauthorized electronic profile access?
The Security Rule addresses safeguards for electronic PHI, such as access controls.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
An oral disclosure
Reasoning for every choice
A. This information is not PHI because it was provided orally instead of in writing.
HIPAA protects PHI whether it is spoken, printed, or electronic. Oral format does not remove protection.
B. The combination of information identifying a specific patient and information relating to health care for that patient is PHI. · Best answer
Tom Smith is identified and linked to medication use. That combination is identifiable health information in this pharmacy setting.
C. This information is not PHI because the speaker is a pharmacy employee rather than the patient.
Who speaks does not determine whether the information is PHI. Staff can disclose PHI through conversation.
A teaching screenshot
Reasoning for every choice
A. Yes; the classroom use establishes the necessary de-identification.
Education can have its own permission analysis; it does not change identifiable records into de-identified data.
B. No; specified identifiers remain in the screenshot. · Best answer
Dates and identifying numbers can remain identifying. Safe Harbor has specified categories and a no-actual-knowledge condition.
C. Yes; removal of the name eliminates the identifying connection.
The method is not based solely on the audience’s familiarity. Removing the name is insufficient.
Safeguards
Reasoning for every choice
Training staff to respond to privacy incidents: Administrative
Correct. Training and procedures are administrative safeguards.
Positioning a workstation so customers cannot read its screen: Physical
Correct. Screen positioning is a physical safeguard.
Requiring each staff member to use a unique system login: Technical
Correct. Unique user identification is a technical safeguard.
Just removing a name does not make information de-identified. Protect patient information whether it is spoken, printed, or electronic. Use administrative, physical, and technical safeguards together.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 3 of 8 · About 15 minutes
Deciding whether information may be shared
Permission to disclose and how much to disclose are separate questions.
Learning objectives for this lesson
- Identify treatment, payment, and health care operations (TPO) as important permitted uses and disclosures without authorization.
- Apply the TPO framework to pharmacy scenarios.
- Determine when written authorization is required for PHI disclosure.
- Explain the Minimum Necessary Standard and its exceptions.
- Evaluate whether a PHI disclosure meets the Minimum Necessary Standard.
- Define incidental disclosures and assess whether they are HIPAA violations.
Start with a permitted purpose
Treatment, payment, and health care operations (TPO) are three important reasons HIPAA permits information use or sharing without a written authorization. They are not the only permitted reasons.
- Providing, coordinating, or managing care, including consultation between providers.
- Claims, eligibility checks, billing, reimbursement, and related activities.
- Specified activities supporting the pharmacy’s work, such as quality improvement, staff evaluation or training, and compliance.
Treatment: see a pharmacy example
A physician requests a shared patient’s fill history to adjust treatment. The pharmacy generally may share it for treatment without a HIPAA authorization.
Payment: see a pharmacy example
The pharmacy submits prescription information to the patient’s insurer for reimbursement. This is payment.
Operations: see a pharmacy example
A pharmacist reviews dispensing errors to improve the pharmacy’s checking process. This is quality improvement, a health care operation. Treating an affected patient after the error is treatment.
Other rules permit sharing with the patient, people involved in care, and public-health authorities under specified conditions. A requester’s job title or interest in the information does not, by itself, authorize disclosure.
When authorization is needed
If no permitted or required reason applies, obtain a valid written before sharing the information. Many marketing uses and sales of PHI require authorization, subject to exceptions. A routine reminder about a currently prescribed medication is not automatically marketing.
An authorization must say what information can be shared, who may share it, who may receive it, why, and when permission expires. It must include a signature, date, and required statements about withdrawal and other consequences. It must be understandable, complete, and still valid. See the fictional form below.
A patient’s verbal agreement to involve a caregiver is a different permission rule. Signing an acknowledgment of receiving the Notice of Privacy Practices is not an authorization.
Explore a completed authorization
This fictional form illustrates a patient authorizing a pharmacy to send a specified medication history to an attorney. Select highlighted sections to examine required elements. It is a teaching example, not a form for clinical use.
The authorization must use plain language. Give the patient a copy of the signed authorization when the pharmacy seeks it. Some uses, such as certain marketing or sales, require additional statements.
Share only what the purpose needs
The requires reasonable steps to limit information to what is needed for the purpose. Staff access should reflect their roles and duties. Sharing only one medication does not make an unauthorized disclosure permissible.
The standard does not apply to disclosures to, or requests by, health care providers for treatment. Other exceptions include sharing with the patient, uses or disclosures under a valid authorization, disclosures required by law, required disclosures to HHS for enforcement, and required HIPAA administrative-simplification compliance.
Internal access still follows job duties
- Appropriate: a pharmacist opens the patient’s profile to check interactions before dispensing.
- Inappropriate: a technician opens a neighbor’s profile out of curiosity.
- Important distinction: the provider-treatment disclosure/request exception does not give every employee unrestricted access to every record. Internal uses remain subject to role-based, minimum-necessary policies.
Incidental is not a synonym for accidental
An is a limited secondary use or sharing of information that happens during an otherwise permitted activity. It can be permitted when reasonable safeguards are used and minimum necessary is satisfied where applicable. For example, someone may briefly overhear quiet counseling despite reasonable separation. Safeguards need not eliminate every possibility of overhearing.
Shouting a diagnosis across a waiting line is different. Giving a prescription bag directly to the wrong patient is an unauthorized primary disclosure; calling it “accidental” does not make it an incidental disclosure.
If someone requests patient information for a legal proceeding, refer the request to the pharmacy’s privacy officer.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
Treatment, payment, or operations?
Reasoning for every choice
A. Operations: the stated purpose is process improvement. · Best answer
Quality improvement is an operations activity. Purpose and facts determine the category.
B. Payment: the review addresses financial exposure from errors.
Potential expense does not make every activity payment. The scenario specifies quality improvement.
C. Treatment: reviewing a health record is a clinical care activity.
Treating the harmed patient would be treatment. This review is explicitly retrospective process improvement.
Prescriber request
Reasoning for every choice
A. Treatment permits it; the provider-treatment exception applies. · Best answer
The lawful purpose is treatment. The exception concerns disclosures to/requests by providers for treatment; other safeguards still matter.
B. Authorization is needed because records leave the original provider.
HIPAA allows qualifying treatment disclosures without a separate written authorization.
C. A fill date is minimal enough to supply the disclosure permission.
Small quantity does not create authority. Establish the treatment pathway before addressing scope.
Employer interest
Reasoning for every choice
A. Withhold pending a valid permission pathway or authorization. · Best answer
The employer’s interest is not a HIPAA permission pathway. A valid authorization or other applicable legal basis must be established.
B. Disclose the result alone to satisfy the minimum-necessary rule.
Minimum necessary limits an otherwise permitted disclosure; it does not authorize this disclosure.
C. Disclose under operations because promotion affects employment.
The employer’s personnel decision is not the pharmacy’s health care operations.
Quiet counseling
Reasoning for every choice
A. The overhearing must be handled as a reportable breach.
HIPAA does not require elimination of every possibility of overhearing when reasonable safeguards are used.
B. This is a permitted incidental disclosure. · Best answer
The counseling is permitted, reasonable safeguards are used, and information is limited appropriately. Brief secondary overhearing under these facts can be permitted; this does not excuse every overheard conversation.
C. The accidental nature of the overhearing supplies permission.
Accidental primary disclosures can be unauthorized. The safeguards and otherwise lawful activity matter.
Identify why the information is needed before sharing it. Treatment, payment, and health care operations can permit sharing, but each request still needs the appropriate scope and safeguards. An accidental disclosure is not automatically a permitted incidental disclosure.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 4 of 8 · About 18 minutes
Patients, representatives, and others
Do not confuse a person helping with care with a person legally authorized to act for the patient.
Learning objectives for this lesson
- List and describe the rights patients have under HIPAA (access, amend, accounting, restrict, confidential communication).
- Apply procedures for responding to patient requests regarding their PHI.
- Determine when a personal representative may access PHI and when an agent may not.
- Define a designated record set and its relevance to patient access.
- Describe the format and fee requirements for providing PHI to patients.
- Apply professional judgment in disclosing PHI to agents.
- Apply patient access and amendment response deadlines and permitted extensions.
Personal representatives and people involved in care
A has legal authority to act for the patient in relevant health care decisions. HIPAA generally treats that person as the patient within that authority’s scope. Verify both the authority and its limits. A financial power of attorney does not necessarily authorize health care decisions.
Parents often represent minors, but state law and HIPAA exceptions can limit parental access. Abuse, neglect, or danger to the patient can also affect representative access. Being a relative alone does not establish representative status.
A friend, spouse, or caregiver may receive information directly relevant to involvement in care or payment. When a patient can make decisions and is present, use their agreement, an opportunity to object, or a reasonable inference that they do not object. If the patient is absent or unable to decide, professional judgment can support limited sharing in the patient’s best interest. Waiting for the patient’s input may be appropriate.
A telephone request from a spouse
Choose each response. Feedback explains your choice; continue after selecting the appropriate response. This exploration does not send statistics.
A caller says: “I’m the patient’s spouse. I’m collecting his lisinopril. Tell me every medication he takes.” What should you do first?
The patient has asked the spouse to collect lisinopril. No authority or permission for a full history is established. What can you ordinarily share, using professional judgment?
The spouse next asks whether the patient takes an antidepressant. What should you do?
Keep sharing connected to the person’s role. Relevant pickup counseling is different from a full history. A relationship alone does not establish representative authority.
Picking up a prescription for someone else
A person, e.g., a friend or neighbor, sent to pick up a specific prescription for a patient may ordinarily receive the prescription and information relevant to its use. The pharmacist should use professional judgment and knowledge of the circumstances in determining what information to share. This does not authorize the pharmacist to provide information unrelated to the prescription being picked up. Knowing the patient’s date of birth alone does not authorize a full history.
After death, HIPAA generally protects PHI for 50 years. An executor, administrator, or another legally authorized person can be a personal representative. Separately, relevant information may be shared with someone involved in care or payment before death unless it conflicts with the patient’s known expressed wishes.
Responding to a patient’s request for records
A includes medical and billing records and records used to make decisions about individuals. A pharmacy’s dispensing history and relevant billing records generally qualify; not every internal document does.
- Confirm who is requesting the records. Reasonably verify identity and, if applicable, authority to act for the patient. Do not create unreasonable barriers.
- Identify the records requested. Clarify the request and locate existing information in the designated record set, including records held for the pharmacy. New analyses or reconstructed conversations are not required.
- Determine the format and delivery method. Provide the requested form and format if readily producible. Otherwise follow the rule’s readable-format and agreement requirements.
- Provide access on time. Act within 30 calendar days of receiving the request. One extension of up to 30 more days is permitted if written reasons and a completion date are provided within the initial period.
- Apply only permitted fees. Explain any allowed copying fee in advance.
- Use the required procedure for a denial. Denial must rest on a permitted ground and include the required written explanation and review rights where applicable.
Details: fees
A reasonable cost-based copying fee can include copying labor, supplies, requested postage, and an agreed summary or explanation. It cannot include searching, retrieving records, or verifying identity. Inspection alone is not copying.
Details: email delivery
A patient can request unencrypted email. Briefly explain the transmission risk, confirm the patient still wants it, verify the destination, and honor the request under the access rules. Do not force the patient to use a portal solely because email is unencrypted.
Details: denial
Some information is excluded, including separately maintained psychotherapy notes and information compiled for litigation. Other denials require specified grounds. Provide a written explanation; include review rights when the denial is reviewable and complaint information.
Amendment, restrictions, and confidential communication
A patient may request an to their records. Act within 60 calendar days of receiving the request. One extension of up to 30 days is permitted with timely written reasons and a completion date. The pharmacy can require a written request and reason if explained in advance.
The pharmacy may deny an amendment on specified grounds, such as an accurate and complete record or a record created elsewhere when its originator remains available. An accepted amendment is added or linked to the affected record and communicated as required; it does not automatically erase history. A written denial explains the reasons, the patient’s right to submit a statement of disagreement, and complaint options.
Patients may request restrictions on sharing, but the pharmacy ordinarily need not agree. It must honor a qualifying restriction on sharing with a health plan for payment or operations when the information relates solely to an item or service paid in full by the patient or someone other than the plan on the patient’s behalf, unless sharing is otherwise required by law. This does not prohibit all treatment disclosures.
The pharmacy must accommodate reasonable requests for confidential communications, such as a different phone number or mailing address, without requiring the patient to explain why. Reasonable conditions may include specifying an alternative contact method and how payment will be handled.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
A spouse’s telephone request
Reasoning for every choice
A. Clarify involvement and scope; consider relevant sharing or wait. · Best answer
The scenario supports clarification and a limited care-involvement analysis, not automatic full disclosure. Waiting can be appropriate.
B. Limit disclosure to situations covered by written authorization.
Some care-involvement disclosures are permitted without written authorization. A blanket rule can obstruct lawful care.
C. Provide the whole history after confirmation of the birth date.
Knowing identifying facts is not authority to receive the full profile. Marriage alone is not unrestricted access.
A neighbor asks about other medicines
Watch the 10-second conversation, or read its transcript below. The patient asked her neighbor to collect her lisinopril prescription. Decide what the pharmacist may share before checking your answer.
English audio; Spanish captions and transcript are available.
Transcript and visual description
Setup: The patient asked her neighbor to collect her lisinopril prescription.
Visual description: At a pharmacy counter, the pharmacist holds a prescription bag while the neighbor speaks. The clip ends before the pharmacist gives an answer or hands over the bag.
Neighbor: “She asked me to pick up her lisinopril. Could you also tell me what other medicines she takes?”
Reasoning for every choice
A. Share pickup-relevant information, not unrelated history. · Best answer
Keep disclosures directly relevant to the role. Counseling relevant to this prescription can be appropriate.
B. Require legal representative authority before any pickup sharing.
HIPAA permits appropriate pickup by friends/family without making them legal representatives. Other dispensing safeguards still apply.
C. Discuss the full profile under the patient’s pickup permission.
The patient’s request supports the pickup, not unrestricted profile access.
Scope of authority
Reasoning for every choice
A. Obtain a confidentiality promise from the requester.
A confidentiality promise does not establish entitlement to the record.
B. Confirm the family relationship through a matching surname.
Relationship or surname does not supply the necessary legal authority.
C. Determine legally conferred authority and scope. · Best answer
Personal-representative status is based on legal authority and scope, not the document’s label alone.
Electronic access
Reasoning for every choice
A. Explain risk; confirm preference/destination and fulfill access. · Best answer
Honor the access request while using reasonable verification and confirming the patient’s informed preference.
B. Send to the supplied address without verifying the caller.
Verification and reasonable destination safeguards matter; the request is not permission to disregard them.
C. Decline email and offer a route secured by the pharmacy.
OCR recognizes the individual’s right to request this transmission route after risk explanation/confirmation.
Access clock
Reasoning for every choice
A. Give timely written notice; use one extension up to 30 days. · Best answer
Timely written notice is required. The initial deadline is 30 calendar days.
B. Start a new 30-day period when the records team begins.
The clock is measured from receipt, not internal assignment.
C. Continue in successive 30-day periods while retrieval is pending.
The rule permits only one qualifying extension, not repeated extensions.
Paid in full
Reasoning for every choice
A. Honor the qualifying restriction in the workflow. · Best answer
The stated conditions fit the mandatory health-plan restriction: solely the paid-in-full item, payment/operations, and no legal requirement to disclose.
B. Apply it as a ban on subsequent treatment disclosures too.
This particular restriction concerns the health plan for payment/operations; it is not a universal treatment-disclosure ban.
C. Handle it under the general discretion to decline restrictions.
The general discretionary rule has this important exception.
Amendment request
Reasoning for every choice
A. Erase the disputed history when the patient requests correction.
The right is subject to the rule’s procedures/grounds. Accepted amendments append/link corrections rather than automatically erasing history.
B. Act within 60 days, using the specified amendment procedures. · Best answer
The amendment timeline is distinct from access. A denial requires the prescribed written response and disagreement/complaint information.
C. Apply the access procedure’s initial 30-day deadline to amendment.
Access starts with 30 days; amendment starts with 60.
Confidential communication
Reasoning for every choice
A. Apply the request as a restriction on all provider disclosures.
Changing the communication route is not the same as restricting every disclosure.
B. Ask the patient to explain why the alternative contact is needed.
Covered-provider rules do not require the patient to explain why. Health-plan requirements differ.
C. Accommodate the reasonable alternative contact request. · Best answer
Covered providers must accommodate reasonable requests, subject to permissible practical conditions.
After death
Reasoning for every choice
A. Restrict all after-death sharing to a court-appointed executor.
Personal-representative access is one route; it is not the only possible disclosure route.
B. Relevant prior-care sharing can be permitted; full access differs. · Best answer
HIPAA permits relevant sharing with people involved before death, subject to known preferences. Other medication-safety/legal issues must still be handled appropriately.
C. Provide the full history based on the established marital relationship.
Spousal status alone does not establish a full-record right.
A pharmacy must act on a patient’s access request within 30 calendar days. One additional 30-day extension is permitted if the pharmacy provides the required written notice within the initial period. A pharmacy must act on an amendment request within 60 calendar days, with one additional 30-day extension permitted under the required notice procedure.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 5 of 8 · About 9 minutes
Notices and acknowledgment
A notice explains practices. An acknowledgment documents receipt. Neither is a general authorization.
Learning objectives for this lesson
- Describe the distribution and posting requirements for the NPP.
- Explain the acknowledgment of receipt process and documentation requirements.
- Apply HIPAA rules to situations involving refusal to sign the acknowledgment.
What the notice does
The explains how the pharmacy uses and shares PHI, patients’ rights, and the pharmacy’s privacy responsibilities. It must be written in plain language and match the pharmacy’s lawful practices.
Provide, post, and document
A pharmacy providing care directly to a patient generally must provide the NPP by the first time it provides care to that patient—for example, when dispensing the patient’s first prescription. For an emergency, provide it as soon as reasonably practicable afterward.
Electronic delivery is possible with the patient’s agreement. The patient can still obtain a paper copy. Make the notice available on request and post it clearly at the pharmacy. If the pharmacy maintains a website describing its services or benefits, prominently post the notice there too. Website posting alone does not ordinarily replace providing the notice to a new patient. Keep the notice current and follow revision/posting requirements when practices change.
Except in emergencies, make a good-faith effort to obtain the patient’s written acknowledgment of receipt. If the patient refuses or acknowledgment cannot be obtained, document the effort and reason. Continue providing service if the patient refuses to sign. A signature is not needed for every prescription, and acknowledging receipt is not an authorization.
Keep required notice and acknowledgment documentation for six years from creation or its last effective date, whichever is later. Someone collecting a prescription is not automatically the patient’s personal representative for signing.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
First service
Reasoning for every choice
A. By the time the pharmacy dispenses her first prescription. · Best answer
Provide the notice by the first service to the patient. Posting it at the pharmacy and on an applicable website supplements that duty.
B. At her next visit, after creating her patient profile.
A first nonemergency service is the deadline; creating a profile does not justify waiting until another visit.
C. Only if she asks for information about the pharmacy’s privacy practices.
The pharmacy must provide the notice even if the patient does not know to ask.
Refusal to sign
Reasoning for every choice
A. Apply refusal as a withdrawal of TPO disclosure permission.
Acknowledgment records receipt; it is not the legal authorization for ordinary TPO.
B. Condition dispensing on the patient’s signed acknowledgment.
A refusal to sign does not justify denial of treatment under this requirement.
C. Continue service; document the effort and refusal. · Best answer
HIPAA requires a good-faith effort and documentation when unsuccessful, not compulsory patient signature as a treatment condition.
Provide the Notice of Privacy Practices and attempt to get the patient’s written acknowledgment of receiving it. If the patient refuses to acknowledge receipt, document the attempt and refusal but continue to provide service to the patient.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 6 of 8 · About 8 minutes
Accounting for disclosures
An accounting is a record of specified disclosures, not a list of every time someone viewed a chart.
Learning objectives for this lesson
- List the required elements of an accounting of disclosures.
- Identify disclosures excluded from the accounting requirement.
- Apply accounting request deadlines, extensions, lookback periods, and fee rules.
What is an accounting of disclosures?
An is a report a patient can request showing certain occasions when the pharmacy shared the patient’s PHI. It does not include every disclosure or every time an employee opened the patient’s record.
The patient can request the six years before the request or a shorter period. Include disclosures involving business associates as required. Certain public-health reports are common examples. Do not confuse an accounting with a medication history or a system access log.
What each entry includes
- Date of disclosure.
- Recipient’s name and address, if known.
- Brief description of the PHI shared.
- Purpose of the disclosure, or a qualifying written request in place of that explanation.
Common exclusions
- Treatment, payment, and health care operations.
- Disclosures to the patient.
- Disclosures made under an authorization.
- Permitted incidental disclosures.
- Permitted sharing with people involved in care or payment, and facility-directory disclosures.
Respond on time and charge correctly
An accounting of disclosures must be provided within 60 calendar days of receiving the request. One extension of up to 30 days is permitted if written reasons and a completion date are provided within the initial period.
The first accounting in any 12-month period is free. Later accountings in that period may have a reasonable cost-based fee, with advance notice and an opportunity to withdraw or change the request. Keep required accounting documentation under the six-year documentation rule.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
Which disclosure belongs?
Reasoning for every choice
A. A treatment disclosure to a physician coordinating care.
TPO disclosures are excluded under the current accounting rule.
B. A disclosure made under the patient’s valid authorization.
Authorization-based disclosures are excluded.
C. A qualifying disclosure to a public-health authority. · Best answer
Public-health disclosures generally are accountable. Being permitted does not make a disclosure excluded.
Accounting contents
Reasoning for every choice
A. All staff logins associated with the record.
An accounting of covered disclosures is not a complete access-log report.
B. A promise of no subsequent redisclosure.
This is not a required accounting element.
C. The recipient’s known address. · Best answer
The accounting includes the recipient’s address if known, in addition to the other listed elements.
Lookback and response
Reasoning for every choice
A. 60-day response; six-year lookback; first in 12 months free. · Best answer
These are the default accounting rules; one qualifying 30-day extension may be available.
B. 30-day response; six-year lookback; first accounting chargeable.
Thirty days is the initial access deadline. The first accounting within 12 months is free.
C. 60-day response; one-year lookback; subsequent requests free.
The lookback is six years unless a shorter period is requested. Subsequent accountings may carry a reasonable cost-based fee with required notice.
A patient may request an accounting covering the previous six years or a shorter period. Provide it within 60 days of receiving the request; one additional 30-day extension is permitted with timely written notice explaining the delay and giving a completion date. The first accounting in any 12-month period is free. A disclosure may be permitted under HIPAA and still need to appear in the accounting.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 7 of 8 · About 17 minutes
Incidents, notification, and disposal
Respond promptly to an incident, then apply the breach rules without assuming that every error is harmless or automatically reportable.
Learning objectives for this lesson
- Define a breach under HIPAA and list the exceptions.
- Apply breach-notification recipients, thresholds, and deadlines for individuals, HHS, and media.
- Explain the concept and use of substitute notice.
- Describe HIPAA’s expectations for PHI disposal.
- Identify common violations and enforcement actions related to disposal.
- List recommended disposal methods for different PHI formats.
- Apply disposal best practices to pharmacy operations.
From incident to breach determination
If PHI is accessed, used, or shared without permission, stop any continuing exposure, address patient-safety risks, and promptly notify the pharmacy’s designated privacy or security official. Preserve the facts and document the response. Do not wait for proof that the patient was harmed.
An unauthorized acquisition, access, use, or disclosure is presumed to be a unless an exception applies or a documented assessment demonstrates a low probability that PHI was compromised. The assessment concerns compromise of the information, not simply whether financial or reputational harm occurred.
Assess at least these four factors:
- What information was involved? Consider its type and amount, identifiers, and how likely it is that someone could identify the patient.
- Who received or used it? Consider the unauthorized person’s role and ability to use or further share the information.
- Was it actually obtained or viewed? Establish whether the information was seen or acquired rather than assuming it was.
- What reduced the exposure? Consider retrieval, deletion, or other steps to limit further use. A promise to destroy the information matters but does not settle the assessment alone.
The pharmacy may provide required notices without performing the low-probability assessment. It must document why notice was not required or that required notices were made.
Three limited exceptions
- Good-faith, unintentional access, acquisition, or use: by a workforce member or someone acting under the organization’s authority, within their authorized work, with no further impermissible use or disclosure.
- Inadvertent disclosure by an authorized person: to another authorized person at the same covered entity or business associate, or a qualifying organized health care arrangement, with no further impermissible use or disclosure.
- Good-faith belief that information could not be retained: the pharmacy reasonably believes the unauthorized recipient could not retain it.
Curiosity access is outside authorized work and does not qualify for the first exception. A wrong patient who reads a prescription label is not automatically within an exception.
Breach-notification requirements apply to —information not protected using an HHS-specified method, such as appropriate encryption or destruction. A password alone does not make PHI secured for this purpose. Other security and incident-response duties can still apply when breach notification is not required.
| Recipient / threshold | Timing |
|---|---|
| Affected individuals | Without unreasonable delay; no later than 60 calendar days after discovery. Generally first-class mail; email if agreed. |
| HHS: 500 or more individuals | Without unreasonable delay; no later than 60 days after discovery, contemporaneously with individual notice. |
| HHS: fewer than 500 | Maintain a log and report no later than 60 days after the end of the calendar year of discovery. Individual notices still have their own deadline. |
| Media: more than 500 residents of a state or jurisdiction | Notify prominent media serving that area without unreasonable delay; no later than 60 days after discovery. |
| Business associate to covered entity | Without unreasonable delay; no later than 60 days after discovery. A BAA may require faster reporting. |
Discovery includes when the entity knew or, with reasonable diligence, should have known. Sixty days is an outer limit, not permission to delay. Specified law-enforcement delay provisions may apply.
Individual notice describes what happened and relevant dates if known, types of PHI, protective steps, the entity's investigation/mitigation/prevention actions, and contact procedures. Media notice has the same content requirements. For insufficient/outdated contact details affecting fewer than 10 people, alternative written notice, telephone, or other means can be used. For 10 or more, use homepage posting for at least 90 days or major print/broadcast media where affected individuals likely reside; include a toll-free number active for at least 90 days. An urgent risk may require additional telephone or other notice. Substitute notice is not a replacement for HHS/media duties when those independently apply.
Protect information through disposal
Use reasonable safeguards, train staff, and follow documented disposal procedures. Keep information secure while waiting for destruction. Follow applicable record-retention requirements before destroying records.
- Paper: shred, pulp, burn, or pulverize so information is unreadable and cannot be reconstructed.
- Labeled prescription bottles: opaque bags in a secure area can hold them for destruction by an appropriate disposal business associate. An opaque bag in a public dumpster is not equivalent.
- Electronic storage: use clearing, purging, or destruction suited to the device. Deleting files alone is not a reliable disposal method. Magnetic degaussing does not solve disposal of nonmagnetic flash storage.
Choose a disposal method
Try one decision for each format. These short explorations give feedback without sending statistics.
Paper records
Labeled prescription bottles
Electronic storage
OCR settlements involving CVS and Cornell Prescription Pharmacy illustrate failures to protect records during disposal, along with policy and training problems. Learn the failure pattern; settlement amounts are not automatic fines.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
Wrong prescription bag
Reasoning for every choice
A. Require evidence of financial harm before an external decision.
The current test concerns low probability of compromise, not proved harm.
B. Treat the mistake as permitted incidental disclosure.
This is an unauthorized primary disclosure, not made permissible by being accidental.
C. Mitigate, escalate, and assess breach/notification duties. · Best answer
Respond immediately internally and assess notification duties using the current breach framework.
Curiosity access
Reasoning for every choice
A. The access is permitted because the technician has a pharmacy-system login.
A login makes access possible; it does not authorize curiosity access. Staff need an authorized work purpose.
B. The access is unauthorized, but no further review is needed unless the technician shares the information.
Unauthorized access itself matters. Report it for assessment even when no further sharing is known.
C. The access is unauthorized and must be reported internally for assessment, even if the technician does not share the information. · Best answer
Report the unauthorized access promptly. The privacy official evaluates the breach rules and notification duties; unauthorized access and required external notification are separate determinations.
Compromise assessment
Reasoning for every choice
A. Whether the patient can substantiate resulting financial harm.
Financial loss is not the governing four-factor compromise standard.
B. Whether the pharmacy intended to protect the patient’s interests.
Intent can matter elsewhere, but good intentions do not replace the documented factors.
C. Actual acquisition/viewing and mitigation of exposure. · Best answer
Actual acquisition/viewing and mitigation are two factors; also assess PHI nature/extent and the unauthorized recipient.
Exactly 500
Reasoning for every choice
A. Individuals and HHS; these facts do not trigger media notice. · Best answer
Individual/HHS timing is without unreasonable delay and no later than 60 days after discovery.
B. Individuals only; the HHS threshold begins at 501.
HHS uses 500 or more.
C. Individuals, HHS, and media in every affected state.
Media uses more than 500 residents of a single state/jurisdiction, not the national HHS threshold.
A smaller breach
Reasoning for every choice
A. Individuals ≤60 days; no HHS report below 500 people.
Below 500 changes the HHS timing, not the existence of its reporting requirement.
B. Individuals ≤60 days; HHS ≤60 days after discovery-year end. · Best answer
Small breaches still require applicable individual notice and HHS reporting, but HHS has the annual-report deadline.
C. Individuals and HHS together with the next annual filing.
The annual HHS pathway does not delay individual notice.
Unreachable individuals
Reasoning for every choice
A. Homepage ≥90 days or qualifying media; toll-free ≥90 days. · Best answer
Twelve meets the 10-or-more threshold. Include the required duration and toll-free contact; other notification duties remain separate.
B. Use telephone-only notice under the fewer-than-10 procedure.
Alternative telephone/other means apply to fewer than 10 with inadequate contact information.
C. Post to social media for a day without a toll-free contact.
This does not meet the 10-or-more substitute-notice framework.
Disposal vendor pickup
Reasoning for every choice
A. Hold bags securely for appropriate vendor destruction. · Best answer
Secure holding plus appropriate vendor destruction follows the safeguard approach. The Cornell/CVS examples illustrate failures of access protection, policies, and training.
B. Remove names and put the remaining labeled bottles in public trash.
Other details may identify the patient. Safe disposal is not merely name removal.
C. Keep the opaque bags beside the public dumpster for pickup.
Opacity does not control access once the public can obtain the bags.
Report unauthorized access or sharing promptly, limit further exposure, and document the facts. Assess whether PHI was compromised, rather than waiting for evidence of harm. HHS’s larger-breach threshold is 500 or more people; the media threshold is more than 500 residents of one state or jurisdiction. Required notices must be made without unreasonable delay and within their applicable deadlines.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Lesson 8 of 8 · About 10 minutes
Enforcement and consequences
Distinguish civil culpability, criminal misconduct, and state-law claims.
Learning objectives for this lesson
- Identify enforcement authorities under HIPAA and their roles.
- Describe the tiered civil penalty structure and apply it to pharmacy violations.
- List criminal offenses under HIPAA and their associated penalties.
- Apply criminal penalty categories to intentional misconduct scenarios.
- Explain the legal implications of HIPAA violations in state courts.
Who enforces what?
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces the Privacy, Security, and Breach Notification Rules through complaints, compliance reviews, investigations, resolution agreements, corrective action plans, and civil money penalties. The U.S. Department of Justice (DOJ) prosecutes criminal HIPAA violations. State attorneys general can bring authorized HIPAA civil actions in federal court on behalf of affected residents. The Centers for Medicare & Medicaid Services (CMS) has administrative-simplification responsibilities outside OCR's privacy, security, and breach-notification role. 'Which agency enforces HIPAA?' is too broad unless the question identifies the provision or enforcement type.
| Tier | Culpability |
|---|---|
| 1 | The entity did not know and, with reasonable diligence, would not have known of the violation. |
| 2 | Reasonable cause; not willful neglect. |
| 3 | Willful neglect, corrected within the required period. |
| 4 | Willful neglect, not corrected within the required period. |
The pharmacy knew—or should have known through reasonable care—that its conduct violated HIPAA, but it did not consciously fail to comply or recklessly disregard its duties.
The pharmacy consciously failed to comply or showed reckless disregard for its obligations.
Compare responses to the same problem
In both examples, a replacement record-storage cabinet does not secure patient paperwork as required.
Response A: investigates and corrects
Management should have identified the faulty cabinet through reasonable review. The pharmacy investigates, secures the records, repairs the cabinet, and improves its checks. If the evidence shows a violation it should have known about but no conscious failure or reckless disregard, reasonable cause may apply.
Response B: knowingly ignores the problem
Management receives repeated warnings that the cabinet leaves patient records exposed but refuses to act because correcting the problem is inconvenient. These facts point toward willful neglect. Whether correction occurs within the required period affects which willful-neglect tier applies.
The correction period for the corrected willful-neglect tier is generally 30 days from when the pharmacy knew, or through reasonable diligence should have known, of the violation, subject to applicable rules. An ordinary mistake is not automatically Tier 1, and a serious outcome alone does not establish willful neglect. Actual classification depends on all relevant facts.
Civil dollar amounts change with inflation and enforcement policy. For this course, understand and apply the tiers; do not memorize dollar ranges.
Criminal categories
42 U.S.C. 1320d-6 addresses knowing violations involving identifiers or individually identifiable health information, including unauthorized obtaining/disclosure by individuals. The basic statutory category allows up to one year imprisonment; false pretenses allows up to five years; intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm allows up to ten years. Statutory fines can also apply. These are maxima and categories, not automatic sentences. Knowingly snooping is different from an inadvertent authorized-work mistake; selling records adds a specified aggravated purpose.
State-court consequences
Patients cannot sue directly under HIPAA. That does not eliminate state-law claims such as negligence, breach of confidentiality, or invasion of privacy where the state's law supports them. HIPAA may inform the duties at issue, but the legal claim and available remedies depend on the applicable state’s law.
In Walgreen Co. v. Hinchy, 21 N.E.3d 99 (Ind. Ct. App. 2014), a pharmacist accessed and disclosed a patient's information for personal reasons. The Indiana appellate court upheld the challenged judgment, including employer responsibility for the employee’s conduct and the damages award. Use it as an Indiana state-law example, not a direct HIPAA lawsuit or an automatic rule of Alabama liability. This module makes no claim that Indiana's doctrines govern Alabama.
Practice the reasoning
Choose an answer before reading feedback. Retry freely; only the first submitted answer is eligible for anonymous reporting.
Enforcement roles
Reasoning for every choice
A. HHS Office for Civil Rights handles private patient damages claims in state court.
OCR complaints are not private HIPAA lawsuits. State-law claims need an independent basis.
B. HHS Office for Civil Rights handles civil enforcement; the U.S. Department of Justice prosecutes criminal violations. · Best answer
OCR civil enforcement and DOJ prosecution are distinct. State attorneys general also have authorized federal civil enforcement powers.
C. Centers for Medicare & Medicaid Services prosecutes criminal violations; HHS Office for Civil Rights licenses pharmacies.
These are not the described roles. Pharmacy licensure is a separate state function.
Known problem, no correction
Reasoning for every choice
A. Tier 1: a violation unknown despite reasonable diligence.
The facts show awareness/indifference, not a problem unknowable with diligence.
B. Tier 4: willful neglect not corrected in the required period. · Best answer
The stated conscious disregard and lack of timely correction support the uncorrected willful-neglect tier.
C. Tier 3: willful neglect corrected within the required period.
Tier 3 requires correction within the applicable period; that fact is absent here.
Selling profiles
Reasoning for every choice
A. Specified gain/sale-purpose category: up to ten years. · Best answer
These facts fit the aggravated-purpose category. A statutory maximum is not an automatic sentence; fines can also apply.
B. False-pretenses category: up to five years.
False pretenses is a distinct category. The facts expressly describe sale for personal gain.
C. Basic knowing-violation category: up to one year.
The specified aggravated purpose can change the category.
State-law claims
Reasoning for every choice
A. OCR enforcement excludes other legal consequences of disclosure.
DOJ, authorized state enforcement, and independently supported state-law litigation are distinct possible routes.
B. A direct HIPAA damages action is available in federal court.
HIPAA does not create that private right.
C. Independent state-law claims may exist; no private HIPAA action. · Best answer
Negligence/confidentiality/privacy claims depend on the state’s law. The Indiana Hinchy example does not establish an automatic Alabama result.
Civil penalty tiers depend on what the pharmacy knew or should have known, whether it took reasonable care to comply, and whether it corrected the violation within the required period. OCR handles civil enforcement of HIPAA’s privacy, security, and breach-notification requirements; DOJ prosecutes criminal violations. Patients cannot sue directly under HIPAA, but the same conduct may support a separate claim under state law.
Sources and rule references
Reach this point and submit every practice question to mark this lesson complete on this browser.
Transfer & apply · About 10–15 minutes
Pharmacy Practice Cases
Decide the relevant rule from the facts. Try these without the lesson text, then use feedback to identify what needs another look.
New analytics contract
Reasoning for every choice
A. Confirm that the sharing is permitted, put a business associate agreement in place, and establish appropriate safeguards. · Best answer
The company performs a PHI-related function for the pharmacy. Establish the permitted purpose, business associate agreement, and safeguards before sharing.
B. Share the records without a business associate agreement because quality improvement is a pharmacy activity.
Operations permission does not remove business-associate requirements for a company handling PHI on the pharmacy’s behalf.
C. Remove patient names and assume the remaining records are de-identified.
Other identifiers can remain. Name removal alone does not establish de-identification.
Queue exposure
Reasoning for every choice
A. Prevent patients from viewing the information; calling the exposure “incidental” does not excuse inadequate safeguards. · Best answer
The visible identifiable prescription information and ongoing exposure undermine the proposed rationale.
B. Treat prescription-only information as outside PHI protection.
Names linked to medicines are health information even without diagnoses.
C. Permit the viewing as an accidental secondary disclosure.
Incidental permission depends on reasonable safeguards and otherwise permitted activity.
A copying invoice
Reasoning for every choice
A. Retain both charges because an older record required searching.
Age does not turn search/retrieval labor into a permissible patient-access fee.
B. Remove both charges because all patient access is free.
Certain copying/supply/postage or agreed-summary costs can be permitted. Inspection itself is different.
C. Exclude retrieval; assess permitted copying costs. · Best answer
The access fee rule excludes search/retrieval and verification. Explain permitted fees in advance.
Caregiver limits
Reasoning for every choice
A. Postpone discussion pending a formal written authorization.
Care-involvement permission can operate through patient agreement without a formal written authorization.
B. Discuss the full profile under the daughter’s involvement in care.
Involvement in one part of care does not override an expressed objection or confer full access.
C. Discuss the inhaler within the patient’s stated limit. · Best answer
Patient agreement supports relevant inhaler discussion. The known objection to other information limits disclosure.
Three requests
Reasoning for every choice
A. Access 30 / amendment 60 / accounting 60 days. · Best answer
Keep separate clocks: access 30; amendment 60; accounting 60. Each has a single qualifying extension of up to 30 days.
B. Access 60 / amendment 30 / accounting 60 days.
This reverses the access and amendment initial periods.
C. Access 30 / amendment 30 / accounting 30 days.
Only access has the 30-day initial period.
Brief misdirected view
Reasoning for every choice
A. Assess all factors; destruction mitigates but does not exempt. · Best answer
Recipient, PHI nature/extent, actual viewing, and mitigation all matter. Notification may follow assessment or be made without it.
B. Assess notification only if the patient demonstrates actual harm.
The current presumption/low-probability test does not require proof of harm.
C. Treat destruction as making the original disclosure permitted.
Mitigation affects the assessment; it does not rewrite the original disclosure’s permission.
Regional breach
Reasoning for every choice
A. HHS only; media notice replaces notices to affected individuals.
Applicable notices are cumulative, not substitutes for each other.
B. Affected individuals, HHS, and prominent media serving both Alabama and Georgia.
The media trigger is more than 500 residents within a state/jurisdiction, not national total.
C. Affected individuals, HHS, and prominent media serving Alabama. · Best answer
Alabama exceeds the resident media threshold; total affected exceeds the HHS threshold. Without unreasonable delay/no later than 60 days applies.
Retiring a drive
Reasoning for every choice
A. Degauss the flash drive, then dispose of it in ordinary waste.
Flash storage is not sanitized simply by a magnetic method suitable for some magnetic media.
B. Delete the files, then dispose of the drive in ordinary waste.
Deleted data can remain recoverable.
C. Use appropriate controlled sanitization or destruction. · Best answer
Choose a method appropriate to the device and risks, with safeguards and applicable retention obligations.
A record for teaching
Reasoning for every choice
A. Remove the remaining Safe Harbor identifiers and confirm there is no actual knowledge that the remaining information could identify the patient. · Best answer
The prescription number is an identifying code, and the full fill date includes date elements other than year. Apply all Safe Harbor requirements, including the remaining-information condition.
B. Present the case because removing the name satisfies Safe Harbor.
Names are only one identifier category. Prescription numbers and full dates can still identify the patient.
C. Present the case because an educational purpose allows all identifiers to remain.
Educational value does not remove privacy obligations. In this scenario, the pharmacist has chosen Safe Harbor and must satisfy it.
PHAR 516 · Pharmacy Law
HIPAA: Review & Apply
Use this as a retrieval checklist after the lessons. Explain the reasoning before checking the rule.
Five questions before sharing information
- Is this identifiable information about health, care, or payment for care?
- Who is requesting it, and what identity or authority should be verified?
- What permits or requires this use or disclosure?
- Does minimum necessary apply, and what information is needed?
- What safeguards, patient preferences, and documentation apply?
Core distinctions
- HIPAA is a federal statute. HHS regulations put its requirements into practice.
- Covered entity vs. business associate: most dispensing pharmacies qualify through electronic claims. A business associate handles PHI for the pharmacy outside its workforce. A prescriber receiving information for treatment does not become its business associate merely because of that disclosure.
- Privacy vs. security: the Privacy Rule protects spoken, printed, and electronic PHI. The Security Rule requires safeguards for electronic PHI.
- De-identification: removing a name alone is insufficient. Safe Harbor requires removal of specified identifiers and no actual knowledge that remaining information could identify the patient.
- Safeguards: administrative safeguards manage people and processes; physical safeguards protect places and equipment; technical safeguards control electronic access and activity.
- Security goals: confidentiality protects who can see information; integrity protects its accuracy; availability lets authorized staff obtain it when needed.
Permission and scope
Treatment, payment, and health care operations (TPO) are important permitted purposes. They are not the only reasons HIPAA permits sharing. If no permitted or required reason applies, obtain a valid written authorization before sharing. An acknowledgment of receiving a privacy notice is not an authorization.
Minimum necessary: take reasonable steps to limit information to the purpose when the standard applies. Exceptions include disclosures to or requests by providers for treatment, disclosures to the patient, valid authorizations, required HHS enforcement disclosures, disclosures required by law, and required HIPAA administrative-simplification compliance. The treatment disclosure/request exception does not allow unrestricted internal browsing.
Incidental use or disclosure: limited secondary exposure during an otherwise permitted activity, with reasonable safeguards and minimum necessary where applicable. Giving a prescription bag to the wrong patient is not permitted merely because it was accidental.
If someone requests information for a legal proceeding, refer the request to the pharmacy’s privacy officer.
Patients and people helping them
- A personal representative has legal authority to act for the patient in relevant health care decisions. Verify that authority and its limits. Being a spouse or neighbor does not automatically authorize a full history.
- Share information directly relevant to a caregiver’s involvement. Use patient agreement or non-objection when applicable; professional judgment can support best-interest sharing when the patient is absent or unable to decide.
- A neighbor collecting lisinopril may receive relevant counseling. The errand does not authorize unrelated medication information.
- PHI generally remains protected for 50 years after death. Representative access and limited sharing with people previously involved in care are different rules.
Patient requests: follow the steps
For access, confirm identity and authority; identify requested records in the designated record set; determine format and delivery; respond on time; apply only permitted fees; and follow required denial procedures. Dispensing histories and relevant billing records generally belong in the record set.
Allowed copying fees do not include searching, retrieving, or verifying identity. A patient’s requested unencrypted email can be honored after explaining risk, confirming the preference, and verifying the destination.
| Request | Initial limit | Extension |
|---|---|---|
| Access | 30 calendar days after receipt. | One extension of up to 30 days. |
| Amendment | 60 calendar days after receipt. | One extension of up to 30 days. |
| Accounting | 60 calendar days after receipt. | One extension of up to 30 days. |
For each extension, provide written reasons and a completion date within the initial period. Amendment follows required acceptance or denial procedures; an accepted correction does not automatically erase history.
Honor qualifying paid-in-full restrictions on health-plan payment/operations disclosures unless sharing is legally required. Accommodate reasonable confidential-communication requests without requiring the patient to explain why.
Accounting and privacy notices
An accounting of disclosures reports specified sharing, not every record access. It can cover the previous six years or a shorter period. Each entry includes date, recipient name and address if known, a description of PHI, and purpose or a qualifying written request. Common exclusions include TPO, sharing with the patient, authorizations, permitted incidental disclosures, and permitted involvement-in-care disclosures. The first accounting in any 12-month period is free.
Provide the Notice of Privacy Practices (NPP) by the first time the pharmacy provides care to a patient, with the emergency exception. Electronic delivery is possible with the patient’s agreement; a paper copy remains available. Meet posting duties too. Attempt written acknowledgment; document the attempt and refusal if unsuccessful, and continue service.
Incident response and notification
For unauthorized access, use, or sharing, stop continuing exposure, address patient safety, promptly report internally, and document facts. A breach is presumed unless an exception applies or a documented assessment demonstrates low probability that PHI was compromised.
Assess information involved; unauthorized recipient; actual acquisition or viewing; and steps reducing exposure. Do not wait for financial or reputational harm. Exceptions require their full conditions: good-faith unintentional authorized-work access/use; specified inadvertent authorized-to-authorized sharing; or a good-faith belief that the recipient could not retain the information.
Notification rules apply to unsecured PHI, meaning information not protected using an HHS-specified method such as appropriate encryption or destruction. A password alone does not establish that protection.
| Recipient | Requirement |
|---|---|
| Affected individuals | Without unreasonable delay; no later than 60 calendar days after discovery. |
| HHS: 500 or more people | Without unreasonable delay; no later than 60 days after discovery, with individual notices. |
| HHS: fewer than 500 people | Log and report no later than 60 days after the discovery calendar year ends. |
| Prominent media | More than 500 affected residents in one state or jurisdiction; without unreasonable delay, no later than 60 days after discovery. |
| Business associate to pharmacy | Without unreasonable delay; no later than 60 days after discovery. The agreement may require faster reporting. |
Sixty days is an outer limit, not permission to wait. Individual notice explains what happened, PHI involved, protective steps, the pharmacy’s response, and contact information. For insufficient contact information: fewer than 10 people permits alternative written, telephone, or other notice; 10 or more requires homepage posting for at least 90 days or qualifying major media, plus a toll-free number for at least 90 days.
Disposal and consequences
Keep information secure through disposal and observe retention duties. Paper must become unreadable and not reconstructable. Labeled bottles may be held in opaque bags in a secure area for appropriate destruction; public trash is different. Electronic storage needs a method suited to the device; deleting files alone is insufficient.
Civil tiers: (1) did not know and would not have known through reasonable diligence; (2) reasonable cause without willful neglect; (3) willful neglect corrected within the required period; (4) willful neglect not corrected. Reasonable cause means knew or should have known, without conscious failure or reckless disregard. Willful neglect means conscious failure or reckless disregard. Learn the tiers, not dollar amounts.
Criminal maximum imprisonment: basic knowing violation, one year; false pretenses, five years; specified commercial advantage, personal gain, or malicious harm, ten years. Fines can also apply. OCR handles civil privacy/security/breach enforcement; DOJ prosecutes criminal violations. No direct patient lawsuit under HIPAA, but separate state-law claims may exist.
Background only: transactions/code sets, NPI, expert determination, NPP-content groups, and specialized accounting rules provide context. Bring unresolved questions to class Monday, November 2. Full linked sources appear in the module.
Return to an explanation
- What HIPAA covers
- Recognizing and protecting information
- Deciding whether information may be shared
- Patients, representatives, and others
- Notices and acknowledgment
- Accounting for disclosures
- Incidents, notification, and disposal
- Enforcement and consequences
Sources
Sources and rule references
Sources and rule references
Sources and rule references
Sources and rule references
Sources and rule references
Sources and rule references
Sources and rule references
Sources and rule references
Faculty instructional-design review guide and alignment map
Content reviewed for legal accuracy October 7, 2026.
Clears lesson checkmarks on this browser; anonymous totals remain unchanged.