Master HIPAA Privacy Rule, breach notification, 42 CFR Part 2, and patient rights for the MPJE. Includes tables, scenarios, and linked practice quiz.
HIPAA (Health Insurance Portability and Accountability Act) governs how pharmacies handle protected health information (PHI). The MPJE tests your understanding of the Privacy Rule, Security Rule, breach notification requirements, and the situations where PHI can and cannot be disclosed.
A pharmacist may disclose PHI without written patient authorization for:
When disclosing PHI, pharmacies must limit information to the minimum necessary to accomplish the purpose. Exception: this standard does NOT apply to treatment disclosures (provider-to-provider communication for patient care).
| Breach Size | Notify Individuals | Notify HHS | Notify Media |
|---|---|---|---|
| < 500 individuals | Within 60 days of discovery | Annual log (within 60 days of year end) | Not required |
| ≥ 500 individuals | Within 60 days of discovery | Within 60 days of discovery | Within 60 days — prominent media outlet |
PharmacyExam.com includes extensive HIPAA scenario-based questions in its MPJE federal law bank.
Explore PharmacyExam →