MPJE: MULTISTATE PHARMACY JURISPRUDENCE EXAMINATION • PHARMACY AND PHARMACIST PRACTICE

PHI Safeguards — Determine required safeguards and breach-response actions for PHI incidents

Understanding the legal framework that protects patient health information and dictates pharmacy responses to data breaches.

Historical Context & Motivation

Before the digital revolution transformed pharmacy practice, patient records existed primarily as handwritten prescription files stored in locked cabinets. Privacy protections were largely governed by professional ethics codes and scattered state statutes, creating a patchwork of inconsistent standards across jurisdictions. As electronic health records, computerized prescription processing, and networked pharmacy systems became ubiquitous in the 1990s, the vulnerability of protected health information (PHI) to unauthorized access, theft, and inadvertent disclosure grew exponentially. Congress recognized that the healthcare industry needed a unified federal framework to safeguard patient data while still allowing the flow of information necessary for treatment, payment, and healthcare operations.

1996
HIPAA Enacted
The Health Insurance Portability and Accountability Act (HIPAA) was signed into law, mandating the development of national standards for electronic healthcare transactions and establishing the statutory foundation for privacy and security protections.
2003
Privacy Rule Effective
The HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) took full effect, establishing national standards for the protection of individually identifiable health information held by covered entities, including pharmacies.
2005
Security Rule Effective
The HIPAA Security Rule became enforceable, requiring covered entities to implement administrative, physical, and technical safeguards specifically for electronic PHI (ePHI), bringing technological rigor to data protection.
2009
HITECH Act Enacted
The Health Information Technology for Economic and Clinical Health (HITECH) Act introduced the Breach Notification Rule, significantly increased civil monetary penalties, and extended HIPAA requirements directly to business associates of covered entities.
2013
Omnibus Rule Finalized
The HIPAA Omnibus Rule implemented HITECH provisions, modified the breach notification standard to a presumption of breach, strengthened patient rights, and imposed direct liability on business associates for HIPAA compliance.

This legislative evolution raises a central question for pharmacy professionals preparing for the MPJE: what specific safeguards must a pharmacy implement to protect PHI, and when a breach occurs, what actions are legally mandated? Answering this question requires understanding both the regulatory architecture and the practical steps a pharmacist must take in real-world scenarios involving compromised patient data.

Core Principles & Definitions

The HIPAA regulatory framework rests on several foundational concepts that pharmacy professionals must internalize. Protected Health Information (PHI) encompasses any individually identifiable health information transmitted or maintained in any form—electronic, paper, or oral—by a covered entity or its business associates. A pharmacy qualifies as a covered entity under HIPAA because it conducts standard electronic transactions such as claims submission. The scope of PHI is broad, including prescription records, insurance information, patient addresses, dates of birth, and any data that could identify an individual in connection with their health condition or treatment.

1

Administrative Safeguards

Policies, procedures, and workforce training that govern the selection, development, implementation, and maintenance of security measures. Examples include designating a Privacy Officer, conducting risk assessments, and implementing workforce sanctions for violations.
2

Physical Safeguards

Measures that protect electronic information systems, equipment, and buildings from natural and environmental hazards and unauthorized intrusion. In pharmacies, this includes locked prescription filing areas, workstation positioning to prevent screen visibility, and controlled access to server rooms.
3

Technical Safeguards

Technology-based protections and associated policies governing access to ePHI. These include access controls (unique user IDs, passwords), audit controls that track system activity, integrity controls to prevent data alteration, and transmission security such as encryption.
4

Minimum Necessary Standard

Covered entities must make reasonable efforts to limit PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose. This standard does not apply to disclosures for treatment purposes, to the individual, or as required by law.
5

Breach Notification Rule

Requires covered entities to notify affected individuals, HHS, and in certain cases the media, following the discovery of a breach of unsecured PHI. The post-Omnibus Rule standard presumes any impermissible acquisition, access, use, or disclosure is a breach unless a risk assessment demonstrates low probability of compromise.
KEY TAKEAWAY
Think of PHI safeguards like the concentric security rings around a research laboratory. Administrative safeguards are the institutional policies determining who is authorized to enter and under what conditions. Physical safeguards are the locked doors, badge readers, and surveillance cameras. Technical safeguards are the biometric scanners and encrypted keycards. A breach in any single ring can compromise the entire facility—just as a failure in any safeguard category can expose patient data.

Visual Explanation — The Three Safeguard Categories

The concentric ellipses illustrate how the three safeguard categories form layered defenses around ePHI. Administrative safeguards (outermost) establish governance; physical safeguards (middle) protect hardware and facilities; technical safeguards (innermost) directly control electronic access. A failure at any layer exposes the data within.

As the diagram illustrates, administrative safeguards form the broadest protective layer because they encompass the organizational policies, risk assessments, workforce training programs, and business associate agreements that define the entire security posture of the pharmacy. Within that layer, physical safeguards address tangible protections such as facility access controls, workstation positioning to prevent unauthorized screen viewing, and proper device and media disposal procedures. At the core, technical safeguards directly interface with the electronic systems storing ePHI, implementing access controls through unique user identification, automatic logoff, encryption, audit trails that log system activity, and integrity mechanisms that detect unauthorized data alteration. Each category contains both required implementation specifications (mandatory) and addressable implementation specifications (which must be implemented or documented as to why an equivalent alternative measure was adopted).

Breach Determination & Response Mechanism

Under the HITECH Act and the 2013 Omnibus Rule, a breach is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI. The Omnibus Rule shifted the standard from a "significant risk of harm" test to a presumption that any impermissible use or disclosure constitutes a breach unless the covered entity can demonstrate, through a four-factor risk assessment, that there is a low probability that the PHI has been compromised. This risk assessment must be documented regardless of its outcome.

The Four-Factor Risk Assessment

When an impermissible use or disclosure of PHI occurs, the covered entity must evaluate four factors to determine whether breach notification is required. These factors are codified at 45 CFR § 164.402 and provide a structured analytical framework.

1

Nature & Extent of PHI

What types of identifiers and clinical information were involved? PHI containing Social Security numbers, financial data, or detailed clinical diagnoses presents higher risk than limited demographic data alone.
2

Unauthorized Person

Who received or accessed the PHI? A disclosure to another covered entity bound by HIPAA carries lower risk than exposure to a completely unrelated party without any obligation to protect health information.
3

Actual Acquisition or Viewing

Was the PHI actually acquired or viewed, or was there merely an opportunity for access? A misdirected fax retrieved and returned unopened poses lower risk than a stolen laptop with unencrypted patient files.
4

Extent of Risk Mitigation

What steps were taken to mitigate the risk? Obtaining assurances of data destruction or return from the unauthorized recipient can reduce the probability of compromise and may support a low-risk determination.

Three Exceptions to the Breach Definition

  1. Unintentional acquisition by workforce member: An employee acting in good faith and within the scope of authority who inadvertently accesses PHI, provided no further impermissible use or disclosure occurs (e.g., a pharmacy technician accidentally opens the wrong patient profile).
  2. Inadvertent disclosure between authorized persons: A person authorized to access PHI at a covered entity or business associate inadvertently discloses it to another similarly authorized person at the same or an affiliated entity, and the information is not further used or disclosed impermissibly.
  3. Good faith belief of non-retention: The covered entity has a good faith belief that the unauthorized recipient would not reasonably be able to retain the information (e.g., a verbal disclosure of limited data during a brief phone call).
⚠️ MPJE Exam Tip
The MPJE frequently tests whether a scenario constitutes a reportable breach. Remember: the default presumption is that any impermissible disclosure IS a breach. The burden falls on the covered entity to demonstrate low probability of compromise through the documented four-factor risk assessment. If you cannot apply an exception or demonstrate low risk, notification is required.

Breach Notification Requirements & Timelines

Once a breach of unsecured PHI is confirmed—meaning the four-factor risk assessment does not support a low-probability-of-compromise conclusion—the covered entity must initiate the notification process without unreasonable delay. The Breach Notification Rule at 45 CFR §§ 164.404–164.408 specifies distinct obligations depending on the scale and nature of the breach. The term unsecured PHI refers to PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption or destruction meeting HHS-specified standards. If the PHI was properly encrypted or destroyed at the time of the incident, breach notification is not required.

This flowchart traces the decision path from an impermissible use or disclosure through exception analysis, four-factor risk assessment, and breach confirmation to the divergent notification requirements for standard breaches (fewer than 500 individuals) versus large-scale breaches (500 or more individuals).
Comparison of Breach Notification Obligations Based on Scale
Notification Requirement< 500 Individuals Affected≥ 500 Individuals Affected
Individual NotificationWritten notice by first-class mail (or e-mail if individual consented) within 60 days of breach discoveryWritten notice by first-class mail (or e-mail if individual consented) within 60 days of breach discovery
HHS NotificationAnnual log submitted to HHS within 60 days after end of the calendar year in which breaches were discoveredNotify HHS contemporaneously with individual notification (within 60 days of discovery)
Media NotificationNot requiredMust notify prominent media outlets serving the state or jurisdiction within 60 days of discovery
Substitute NoticeIf <10 individuals with insufficient contact info: telephone, written, or other means. If ≥10: conspicuous posting on website (90 days) or major media outlet.Same substitute notice rules apply when contact information is insufficient; toll-free number required for 90 days
Content of Individual NoticeDescription of breach; types of PHI involved; steps individuals should take; what entity is doing; contact informationSame content requirements as standard breach notification

Worked Example — Pharmacy Breach Scenario

Consider the following scenario: A community pharmacy discovers that a laptop containing an unencrypted spreadsheet of 1,200 patients' prescription records—including names, dates of birth, medication lists, and insurance identification numbers—was stolen from a pharmacist's vehicle. The theft occurred on March 1, and the pharmacy discovered it on March 5. Walk through the required breach-response actions.

Stolen Laptop with Unencrypted ePHI
1
Step 1 — Identify Whether PHI Was InvolvedThe spreadsheet contained patient names, dates of birth, medication lists, and insurance IDs. These are individually identifiable health information relating to past or present health conditions or provision of health care. This is clearly PHI, and because it was stored electronically, it qualifies as ePHI.
Confirmed: PHI/ePHI is involved.
2
Step 2 — Determine Whether PHI Was UnsecuredHHS specifies that PHI is considered "secured" only if it has been encrypted using an algorithm consistent with NIST guidelines or physically destroyed. The spreadsheet was stored on an unencrypted laptop. Because no encryption or equivalent protection was in place, this constitutes unsecured PHI.
PHI was unsecured — breach notification may be required.
3
Step 3 — Apply the Three ExceptionsException 1 (unintentional workforce acquisition) does not apply—the laptop was stolen by an unknown external party, not accessed by an employee in good faith. Exception 2 (inadvertent disclosure between authorized persons) does not apply for the same reason. Exception 3 (good faith belief of non-retention) does not apply—a thief who stole a physical laptop likely retains access to its contents.
No exception applies.
4
Step 4 — Conduct the Four-Factor Risk AssessmentFactor 1: The PHI included highly sensitive identifiers—names, DOBs, insurance IDs, and medication lists (high risk). Factor 2: The unauthorized person is unknown (high risk). Factor 3: Physical possession of the laptop means the data was almost certainly acquired or viewable (high risk). Factor 4: No mitigation has been achieved—the laptop has not been recovered, and the thief has not been identified (no risk reduction). The combined analysis does not support a "low probability of compromise" finding.
Breach confirmed — notification is required.
5
Step 5 — Execute Notification ObligationsThe breach affects 1,200 individuals, which exceeds the 500-person threshold for a large-scale breach. The pharmacy discovered the breach on March 5, so all notifications must occur no later than May 4 (60 days). The pharmacy must: (1) send written notification to all 1,200 affected individuals by first-class mail, including a description of the breach, the types of PHI involved, recommended protective steps (e.g., monitoring insurance statements), what the pharmacy is doing in response, and contact information for questions; (2) notify HHS contemporaneously via the HHS breach notification portal; (3) notify prominent media outlets in the state(s) where affected individuals reside. The pharmacy must also document the breach, its investigation, risk assessment, and all remedial actions in its records, which must be retained for at least six years.
Deadline: May 4. Required: individual notice, HHS notice, and media notice.

Safeguard Implementation — Required vs. Addressable

The HIPAA Security Rule distinguishes between required and addressable implementation specifications. Required specifications must be implemented as written—there is no flexibility. Addressable specifications require the covered entity to assess whether each specification is a reasonable and appropriate safeguard in its environment; if not, the entity must document why and implement an equivalent alternative measure. "Addressable" does not mean "optional." This distinction frequently appears on the MPJE and is a common source of exam errors.

Required vs. Addressable Implementation Specifications Under the HIPAA Security Rule
Safeguard CategoryRequired Implementation SpecificationsAddressable Implementation Specifications
AdministrativeRisk analysis; risk management; sanction policy; information system activity reviewSecurity reminders; login monitoring; password management; testing of contingency plan
PhysicalDisposal procedures; media re-use proceduresContingency operations; facility security plan; access control and validation procedures; accountability for hardware movements
TechnicalUnique user identification; emergency access procedure; audit controls; authenticationAutomatic logoff; encryption and decryption; mechanism to authenticate ePHI; encryption of ePHI in transmission
KEY TAKEAWAY
Think of "addressable" like a building code that requires fire protection. The code mandates the outcome—fire protection—but allows you to choose between a sprinkler system and a suppression gas system based on your building's characteristics. You must document why your chosen method provides equivalent protection. You cannot simply decide to have no fire protection at all. Similarly, addressable specifications demand an informed, documented decision—never inaction.

Penalties, Enforcement, and Advanced Considerations

The HITECH Act dramatically expanded the enforcement landscape for HIPAA violations, establishing a tiered civil monetary penalty structure based on the level of culpability. Understanding these tiers is essential for MPJE preparation because the exam tests whether candidates can identify the severity of a violation and its potential consequences. Additionally, state attorneys general were empowered under HITECH to bring civil actions on behalf of state residents for HIPAA violations, adding a second enforcement pathway beyond the HHS Office for Civil Rights (OCR).

HITECH Act Tiered Civil Monetary Penalty Structure (as adjusted for inflation)
TierCulpability LevelPenalty Per ViolationAnnual Maximum
Tier 1Did not know and would not have known (reasonable diligence)$100 − $50,000$25,000
Tier 2Reasonable cause (not willful neglect)$1,000 − $50,000$100,000
Tier 3Willful neglect — corrected within 30 days$10,000 − $50,000$250,000
Tier 4Willful neglect — NOT corrected within 30 days$50,000 minimum$1,500,000

Beyond civil penalties, the MPJE candidate should be aware that criminal penalties also apply under HIPAA. Knowingly obtaining or disclosing PHI can result in fines up to $50,000 and one year of imprisonment. If the offense involves false pretenses, penalties increase to $100,000 and up to five years. If the offense involves the intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm, the maximum penalty escalates to $250,000 and up to ten years of imprisonment. The Department of Justice (DOJ), rather than OCR, handles criminal enforcement.

📋 State Law Interaction
HIPAA establishes a federal floor, not a ceiling. State laws that provide greater privacy protections than HIPAA are not preempted and remain enforceable. On the MPJE, you must apply the more stringent standard—whether federal or state—in any given scenario. Some states impose their own breach notification requirements with shorter timelines or broader definitions of personal information.

Practice Problems

PROBLEM 1CONCEPTUAL
A pharmacy technician accidentally opens the electronic profile of a patient with the same last name as the patient she intended to look up. She immediately recognizes the error and closes the profile without reading or recording any information. Does this constitute a reportable breach under HIPAA? Explain your reasoning.
PROBLEM 2BASIC CALCULATION
A pharmacy discovers on June 15 that a breach affecting 200 patients occurred on June 1. By what date must the pharmacy notify affected individuals? Must the pharmacy notify HHS at the same time, or may it wait?
PROBLEM 3INTERMEDIATE
A mail-order pharmacy sends a package containing a filled prescription and a prescription label (showing the patient's name, address, medication, prescriber, and Rx number) to the wrong address. The package is returned to the pharmacy unopened four days later. The pharmacy conducts a four-factor risk assessment. Analyze each factor and determine whether breach notification is required.
PROBLEM 4APPLIED
A hospital pharmacy's server is targeted by a ransomware attack that encrypts all ePHI. The pharmacy determines that the attackers exfiltrated approximately 3,500 patient records before encrypting the system. The records include names, SSNs, diagnoses, and medication histories. The pharmacy's backup system allows it to restore operations within 12 hours. Describe the complete breach-response protocol, including all parties that must be notified and applicable timelines.
PROBLEM 5CRITICAL THINKING
A community pharmacy has implemented all required Security Rule specifications but has documented that encryption of ePHI at rest is "not reasonable and appropriate" for its environment because of legacy system limitations. Instead, it implemented an alternative measure: strict physical access controls to the server room and automatic logoff after 2 minutes of inactivity. Three years later, a burglar breaks into the pharmacy, bypasses the physical controls, and steals the server. OCR investigates. Evaluate whether the pharmacy's handling of the addressable encryption specification was legally compliant, and discuss how the burglary changes the analysis.

Lesson Summary

Pharmacies, as HIPAA-covered entities, must implement three categories of safeguards to protect protected health information (PHI): administrative safeguards (policies, risk assessments, workforce training, sanction policies, Privacy Officer designation), physical safeguards (facility access controls, workstation security, device and media disposal), and technical safeguards (unique user IDs, audit controls, encryption, transmission security). Implementation specifications under the Security Rule are classified as either required (mandatory as written) or addressable (requiring documented assessment and equivalent alternatives if not implemented as written—never optional). The minimum necessary standard requires limiting PHI use and disclosure to the minimum amount needed to accomplish the intended purpose.

When an impermissible use or disclosure of unsecured PHI occurs, the Breach Notification Rule presumes a breach has occurred unless one of three statutory exceptions applies or the documented four-factor risk assessment demonstrates low probability of compromise. Confirmed breaches require notification to affected individuals within 60 days of discovery. Breaches affecting 500 or more individuals additionally require contemporaneous HHS notification and prominent media notification. Civil penalties follow a four-tiered structure based on culpability, with maximum penalties reaching $1.5 million per violation category per year, and criminal penalties can include imprisonment of up to ten years for offenses involving intent to sell or misuse PHI.

Varsity Tutors • MPJE: Multistate Pharmacy Jurisprudence Examination • PHI Safeguards — Determine required safeguards and breach-response actions for PHI incidents