HIPAA Compliance Certification Exam โ Questions and Answers
Question 1: Which HIPAA concept describes a patient's right to receive a list of certain disclosures of their PHI made by a covered entity?
- Notice of privacy practices
- Accounting of disclosures (Correct answer)
- Right of access
- Minimum necessary standard
Correct answer: Accounting of disclosures
The accounting of disclosures provision gives patients the right to receive a list of certain disclosures of their PHI made without their authorization, covering the prior six years.
Question 2: A hospital employee snoops through a celebrity patient's records out of curiosity and shares them with friends. Which criminal tier most likely applies?
- No criminal liability โ only civil penalties apply
- Tier 2: up to 5 years in prison (Correct answer)
- Tier 3: up to 10 years in prison
- Tier 1: up to 1 year in prison
Correct answer: Tier 2: up to 5 years in prison
Knowingly obtaining or disclosing PHI under false pretenses (beyond simple curiosity, for personal benefit/sharing) typically falls under Tier 2, carrying up to 5 years imprisonment.
Question 3: According to the HIPAA Privacy Rule's 'Minimum Necessary' standard, a covered entity must make reasonable efforts to limit the use and disclosure of PHI. In which of the following scenarios does the Minimum Necessary standard NOT apply?
- A disclosure to a business associate for billing operations.
- A request for PHI from another covered entity for payment purposes.
- A disclosure from one healthcare provider to another for treatment purposes. (Correct answer)
- A use of PHI for internal quality assessment activities.
Correct answer: A disclosure from one healthcare provider to another for treatment purposes.
The HIPAA Privacy Rule explicitly exempts disclosures of PHI for treatment purposes between healthcare providers from the Minimum Necessary standard. This allows providers to freely share information necessary to provide quality care. However, the Minimum Necessary standard does apply to disclosures for payment and healthcare operations, such as billing or quality assessment.
Question 4: Which of the following best describes a patient's right to request confidential communications from a healthcare provider under HIPAA?
- The patient must provide a detailed reason, such as a threat of danger, for the provider to accommodate the request.
- The provider can charge an administrative fee for setting up an alternative method of communication.
- The provider must accommodate reasonable requests to communicate via alternative means or at alternative locations. (Correct answer)
- The provider must agree to any requested communication method, including unencrypted email, if the patient insists.
Correct answer: The provider must accommodate reasonable requests to communicate via alternative means or at alternative locations.
Under 45 CFR ยง 164.522(b), a healthcare provider must permit individuals to request and must accommodate *reasonable* requests to receive communications of PHI by alternative means (e.g., cell phone vs. home phone) or at alternative locations (e.g., P.O. Box vs. home address). The provider cannot require the patient to explain the reason for the request.
Question 5: A covered entity that discovers a breach of unsecured PHI must notify affected individuals within:
- 60 calendar days of discovery (Correct answer)
- 24 hours of discovery
- 72 hours, following GDPR standards
- 30 business days of discovery
Correct answer: 60 calendar days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.
Question 6: A hospital billing department needs to send a list of patient accounts to a third-party collection agency. According to the HIPAA Privacy Rule's 'minimum necessary' standard, which of the following actions is most appropriate?
- Refuse to disclose any information without a court order for each individual patient.
- Provide the patient's name and total amount due, but no contact information.
- Send the entire medical record for each patient to provide complete context.
- Disclose only the demographic and financial information necessary for collection purposes. (Correct answer)
Correct answer: Disclose only the demographic and financial information necessary for collection purposes.
The 'minimum necessary' standard requires covered entities to make reasonable efforts to limit the use or disclosure of Protected Health Information (PHI) to the minimum necessary to accomplish the intended purpose. For debt collection, this includes demographic information to identify and locate the individual and financial information about the debt, but not their entire clinical history.
Question 7: A hospital shares a patient's treatment records with a business associate for billing purposes. Under HIPAA, this disclosure is:
- Requires a court order
- Prohibited without explicit written patient consent
- Permitted as part of Treatment, Payment, or Operations (TPO) (Correct answer)
- Allowed only if the patient is deceased
Correct answer: Permitted as part of Treatment, Payment, or Operations (TPO)
HIPAA permits covered entities to disclose PHI to business associates for Treatment, Payment, and Healthcare Operations (TPO) without additional patient authorization.
Question 8: Under the HITECH Act, what percentage of collected HIPAA civil monetary penalties must be used for affected individuals?
- 50%
- 25%
- A percentage determined by the HHS Secretary (Correct answer)
- 10%
Correct answer: A percentage determined by the HHS Secretary
The HITECH Act authorizes HHS to distribute a percentage of CMPs to harmed individuals, with the exact percentage determined by the HHS Secretary.
Question 9: A research organization conducts a study and previously collected PHI under a valid HIPAA authorization. Under the Omnibus Rule, can the same authorization cover future research?
- No, each new research study always requires a fresh authorization
- Yes, authorizations can cover future research studies if sufficiently described (Correct answer)
- Only if the future research is unrelated to the original purpose
- Only if the research is conducted by a different covered entity
Correct answer: Yes, authorizations can cover future research studies if sufficiently described
The Omnibus Rule clarified that a single authorization can cover future research studies as long as the future purposes are adequately described in the authorization.
Question 10: Which of the following is NOT considered one of the 18 HIPAA identifiers that make health information PHI?
- Account numbers
- Blood type alone (Correct answer)
- Social Security numbers
- Device identifiers and serial numbers
Correct answer: Blood type alone
Blood type alone is not one of the 18 identifiers listed under HIPAA; it only becomes PHI when combined with an identifier that links it to a specific individual.
Question 11: Under HIPAA, what must a covered entity do if an authorized law enforcement officer presents at a mental health facility to speak with a patient who is currently in treatment?
- All law enforcement requests at mental health facilities must be refused
- Mental health patients automatically lose privacy rights when law enforcement is involved
- The covered entity may decline to confirm the patient is a patient or disclose information beyond what is specifically required by law, using professional and legal judgment (Correct answer)
- The facility must immediately facilitate the law enforcement contact with the patient
Correct answer: The covered entity may decline to confirm the patient is a patient or disclose information beyond what is specifically required by law, using professional and legal judgment
Mental health facilities have significant discretion in how they respond to law enforcement inquiries and may protect patient privacy beyond what law enforcement requests, except where legally compelled.
Question 12: A covered entity discovers that a business associate's EHR integration has been exposing ePHI for 60 days. What is the first required action?
- Conduct a risk assessment to determine breach scope (Correct answer)
- Terminate the BAA immediately
- Notify HHS within 24 hours
- Notify all affected patients within 24 hours
Correct answer: Conduct a risk assessment to determine breach scope
The first step after discovering a potential breach is conducting a risk assessment to determine whether a reportable breach occurred.
Question 13: A cloud storage vendor holds ePHI on behalf of a covered hospital. Under the HIPAA Security Rule, this vendor is best classified as a:
- Hybrid entity
- Workforce member
- Business associate (Correct answer)
- Covered entity
Correct answer: Business associate
A vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate subject to the Security Rule.
Question 14: Under the Omnibus Rule, when is a Notice of Privacy Practices (NPP) update required to be distributed to existing patients?
- Whenever any minor change is made to the NPP
- Every time a business associate relationship changes
- Only at the beginning of each calendar year regardless of changes
- Only when the change involves new uses or disclosures of PHI not previously described (Correct answer)
Correct answer: Only when the change involves new uses or disclosures of PHI not previously described
Under the Omnibus Rule, covered entities must redistribute the NPP to existing patients only when material changes involve new uses or disclosures not previously described.
Question 15: A hospital refuses to provide a patient's records because the patient owes an outstanding balance. Is this permissible under HIPAA?
- No, unless a court authorizes the withholding
- Yes, providers may condition access on payment of outstanding bills
- No, the right to access PHI cannot be conditioned on payment of outstanding balances (Correct answer)
- Yes, but only if the balance exceeds $100
Correct answer: No, the right to access PHI cannot be conditioned on payment of outstanding balances
HIPAA does not permit covered entities to withhold PHI access simply because a patient has an unpaid balance.
Question 16: A deceased patient's executor requests access to the patient's PHI. Under HIPAA, the executor is considered:
- An individual who must obtain a court order to access records
- A business associate of the covered entity
- An unauthorized third party with no rights to PHI
- A personal representative with the same access rights as the patient had (Correct answer)
Correct answer: A personal representative with the same access rights as the patient had
HIPAA allows personal representatives of deceased individuals, such as executors, the same PHI access rights the patient had.
Question 17: A covered entity's dataset contains dates of service but not patient names or identifiers. Under HIPAA Safe Harbor, what must be done with these dates?
- Service dates may be retained as they are not personal identifiers
- All dates related to an individual must be removed except year, including service dates, admission dates, and discharge dates (Correct answer)
- Dates may be retained if they are more than 3 years old
- Only birth dates must be removed; service dates may be retained
Correct answer: All dates related to an individual must be removed except year, including service dates, admission dates, and discharge dates
Safe Harbor requires removal of all dates (except year) directly related to an individual, including dates of service, admission, discharge, and procedures.
Question 18: A patient requests access to their own PHI. Under HIPAA, the covered entity must generally provide access within:
- 10 business days
- 30 calendar days, with one possible 30-day extension (Correct answer)
- 7 calendar days
- 60 calendar days
Correct answer: 30 calendar days, with one possible 30-day extension
HIPAA requires covered entities to provide patients access to their PHI within 30 calendar days, with one permissible 30-day extension if the entity notifies the patient of the delay.
Question 19: Under HIPAA's Safe Harbor de-identification method, geographic data must be limited to:
- City level or smaller
- ZIP code level or larger
- County level or larger
- State level or larger (Correct answer)
Correct answer: State level or larger
The Safe Harbor method requires geographic subdivisions to be no smaller than a state, except that the first three digits of a ZIP code may be retained if the geographic unit contains more than 20,000 people.
Question 20: How does the Minimum Necessary Standard apply to a covered entity's own workforce members who use PHI in their daily work?
- Access must be limited based on each member's role and what they need to do their job (Correct answer)
- Workforce access policies are set solely by the entity's Human Resources department
- Only licensed clinical staff are subject to the Minimum Necessary Standard
- All workforce members must have access to all PHI to function effectively
Correct answer: Access must be limited based on each member's role and what they need to do their job
Covered entities must implement policies and procedures limiting PHI access for workforce members to the minimum necessary for their specific job functions.
Question 21: Psychotherapy notes receive special protection under HIPAA because:
- They may only be disclosed to law enforcement
- Mental health information is exempt from the minimum necessary standard
- They are not considered PHI
- They require a separate, specific authorization for disclosure beyond standard PHI (Correct answer)
Correct answer: They require a separate, specific authorization for disclosure beyond standard PHI
Psychotherapy notes are treated as a special category of PHI under HIPAA and require a specific authorization for most disclosures, separate from an authorization that covers other PHI.
Question 22: A patient pays for a cosmetic procedure entirely out-of-pocket and asks the clinic not to share any information about this service with their health insurance plan. Under HIPAA, how must the clinic respond?
- The clinic must inform the health plan but can ask them to keep it confidential.
- The clinic can agree to the restriction but is not required to do so.
- The clinic can deny the request because it conflicts with their billing practices.
- The clinic must agree to the request to restrict disclosure to the health plan. (Correct answer)
Correct answer: The clinic must agree to the request to restrict disclosure to the health plan.
The HIPAA Privacy Rule requires a covered entity to agree to a request to restrict disclosure of PHI to a health plan if the disclosure is for payment or health care operations and the PHI pertains solely to a service for which the individual has paid the covered entity in full out-of-pocket. In this scenario, the provider's compliance is mandatory, not optional.
Question 23: A business associate discovers a breach on March 1 and notifies the covered entity on April 20. Is this compliant with HITECH?
- Yes, as long as the covered entity notifies patients within 60 days
- No, BAs must notify within 30 days of discovery
- No, BAs must notify within 24 hours of discovery
- Yes, notification within 60 days of discovery is compliant (Correct answer)
Correct answer: Yes, notification within 60 days of discovery is compliant
April 20 is 50 days after March 1, which falls within the 60-day window business associates have to notify covered entities under HITECH.
Question 24: OCR's HIPAA Audit Program, established under HITECH, is designed to:
- Limit enforcement to only the largest health systems
- Proactively assess covered entity and business associate compliance (Correct answer)
- Issue automatic penalties to all audited organizations
- Replace complaint-based investigations entirely
Correct answer: Proactively assess covered entity and business associate compliance
The HIPAA Audit Program proactively evaluates whether covered entities and business associates comply with HIPAA requirements, independent of complaints.
Question 25: What happens to a BAA when the underlying service contract between a covered entity and a business associate expires?
- The BAA remains in force indefinitely until formally terminated
- The BAA automatically converts to a subcontractor agreement
- The BAA obligations typically terminate along with the service contract unless PHI return/destruction obligations remain (Correct answer)
- The business associate must retain PHI for an additional 10 years
Correct answer: The BAA obligations typically terminate along with the service contract unless PHI return/destruction obligations remain
BAA obligations generally end when the contract ends, but the BAA must address return or destruction of PHI at termination.
Question 26: Under the Breach Notification Rule, what is the deadline for notifying the HHS Secretary about a breach affecting 500 or more individuals?
- Within 60 days after the end of the calendar year in which the breach occurred
- Within 90 days of the end of the calendar year
- Within 60 days of discovery (Correct answer)
- Within 30 days of discovery
Correct answer: Within 60 days of discovery
Covered entities must notify HHS within 60 days of discovering a breach affecting 500 or more individuals.
Question 27: What is the HIPAA significance of a 'behavioral health record' when it is maintained separately from the general medical record at a hospital?
- Behavioral health records maintained separately require a separate NPP
- Separately maintained behavioral health records are still PHI subject to full HIPAA protections; the separate maintenance may trigger state mental health privacy law requirements (Correct answer)
- Separate maintenance means the records are automatically psychotherapy notes with heightened protection
- Separately maintained behavioral health records are subject to no HIPAA requirements
Correct answer: Separately maintained behavioral health records are still PHI subject to full HIPAA protections; the separate maintenance may trigger state mental health privacy law requirements
Behavioral health records maintained separately are still PHI subject to HIPAA; the separate maintenance may indicate state mental health law applies and may mean some records qualify as psychotherapy notes.
Question 28: A business associate agreement (BAA) under HIPAA is required when a covered entity shares PHI with a vendor who:
- Is a government agency with its own HIPAA obligations
- Only accesses aggregated, statistical health data
- Only handles de-identified data
- Creates, receives, maintains, or transmits PHI on behalf of the covered entity (Correct answer)
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of the covered entity
A BAA is legally required whenever a covered entity engages a business associate that will create, receive, maintain, or transmit PHI while performing services on the covered entity's behalf.
Question 29: Which of the following is a direct liability for a Business Associate under the HIPAA Omnibus Rule?
- Charging an unreasonable, cost-based fee for providing an individual with access to their PHI.
- Failing to provide a Notice of Privacy Practices to patients.
- Failure to comply with the HIPAA Security Rule. (Correct answer)
- Designating a new Privacy Official without notifying the covered entity.
Correct answer: Failure to comply with the HIPAA Security Rule.
The HIPAA Omnibus Rule and HITECH Act made Business Associates directly liable for compliance with the HIPAA Security Rule. This includes implementing administrative, physical, and technical safeguards. Other duties, like providing a Notice of Privacy Practices or liability for charging unreasonable fees for records access, generally remain the direct responsibility of the Covered Entity.
Question 30: Under HIPAA, an individual's right to an accounting of disclosures applies to disclosures made for which of the following purposes?
- Disclosures required by law, for public health purposes, and other non-TPO disclosures (Correct answer)
- Treatment, payment, and health care operations made after January 1, 2011
- Only disclosures made to law enforcement agencies
- All disclosures regardless of purpose, going back 10 years
Correct answer: Disclosures required by law, for public health purposes, and other non-TPO disclosures
The right to an accounting covers disclosures other than those for TPO, to the individual themselves, or pursuant to an authorization, for the 6 years prior to the request.
Question 31: What are 'psychotherapy notes' under HIPAA, and how do they differ from other mental health records?
- Psychotherapy notes are subject to the same rules as billing records
- Any note created by a mental health professional constitutes a psychotherapy note
- Psychotherapy notes can be freely shared with other treatment providers without authorization
- Psychotherapy notes are notes from a therapist's private files capturing mental impressions during therapy, separate from formal treatment records, and requiring specific authorization for disclosure (Correct answer)
Correct answer: Psychotherapy notes are notes from a therapist's private files capturing mental impressions during therapy, separate from formal treatment records, and requiring specific authorization for disclosure
Psychotherapy notes are mental impressions and analysis captured in a therapist's private files โ distinct from treatment records โ and require specific authorization for most disclosures.
Question 32: A hospital's legal counsel argues that emails exchanged with the hospital's outside law firm are exempt from HIPAA if they contain PHI. Is this correct?
- No, but a BAA is only required if the law firm bills the hospital separately for HIPAA work
- Yes, law firms are expressly excluded from the definition of business associate
- No, law firms that receive PHI on behalf of a covered entity are business associates and need a BAA (Correct answer)
- Yes, attorney-client privilege supersedes HIPAA requirements
Correct answer: No, law firms that receive PHI on behalf of a covered entity are business associates and need a BAA
Law firms that receive PHI while providing legal services to a covered entity are business associates and must sign a BAA.
Question 33: A covered entity may disclose PHI without patient authorization for which of the following purposes?
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Selling PHI to a data analytics company
- Marketing a new drug treatment to the patient
- Sharing PHI with an employer for workplace wellness incentives
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosure of PHI without authorization when required by law, such as mandatory reporting of gunshot wounds to law enforcement.
Question 34: If a breach affects fewer than 500 individuals in a state, when must the covered entity notify HHS?
- Within 60 days after the end of the calendar year (Correct answer)
- Within 30 days of discovery
- Within 90 days after the end of the calendar year
- Within 60 days of discovery
Correct answer: Within 60 days after the end of the calendar year
For breaches affecting fewer than 500 individuals, covered entities must maintain a log and report to HHS annually within 60 days after the end of each calendar year.
Question 35: When a BAA is required but never executed, which party bears the greatest regulatory risk if PHI is misused?
- The business associate alone, because it holds the PHI
- Both parties share equal liability with no distinction
- HHS, for failing to enforce the requirement proactively
- The covered entity, because it is responsible for ensuring BAAs are in place before sharing PHI (Correct answer)
Correct answer: The covered entity, because it is responsible for ensuring BAAs are in place before sharing PHI
Covered entities are responsible for obtaining signed BAAs before sharing PHI; failing to do so exposes the covered entity to HIPAA penalties.
Question 36: Under 42 CFR Part 2, what is unique about the prohibition on 're-disclosure' that differs from standard HIPAA?
- Re-disclosure is governed only by state law, not federal regulation
- 42 CFR Part 2 has no re-disclosure prohibition
- 42 CFR Part 2 explicitly prohibits recipients of substance use disorder records from further disclosing the information without new patient consent, even for treatment purposes (Correct answer)
- HIPAA prohibits re-disclosure while Part 2 allows it for treatment purposes
Correct answer: 42 CFR Part 2 explicitly prohibits recipients of substance use disorder records from further disclosing the information without new patient consent, even for treatment purposes
42 CFR Part 2 uniquely prohibits re-disclosure of substance use disorder records without new consent โ recipients cannot pass the information along even to other treatment providers without the patient's specific consent.
Question 37: Which of the following scenarios would NOT require a Business Associate Agreement?
- An IT firm that remotely accesses servers storing PHI to provide maintenance
- A billing company submitting insurance claims on behalf of a physician practice
- A janitorial company whose staff may incidentally view PHI on a whiteboard (Correct answer)
- A transcription service that converts physician voice recordings into clinical notes
Correct answer: A janitorial company whose staff may incidentally view PHI on a whiteboard
Incidental exposure by a janitorial company does not make it a business associate; BAAs apply to those who handle PHI as a function of their service.
Question 38: Which standard specifies the encryption requirements for PHI at rest that satisfy HITECH's breach notification safe harbor?
- AES-128 minimum
- SSL/TLS 1.2
- ISO 27001
- FIPS 140-2 (Correct answer)
Correct answer: FIPS 140-2
NIST guidance specifying FIPS 140-2 validated encryption processes is referenced as the standard for PHI at rest to qualify for HITECH's safe harbor.
Question 39: A patient's name combined with their appointment date at a mental health clinic is considered PHI because:
- Names are always PHI regardless of context
- It links an identifier to information that reveals health status or treatment (Correct answer)
- Appointment dates are always PHI regardless of context
- Mental health information has special protections under HIPAA
Correct answer: It links an identifier to information that reveals health status or treatment
PHI is created when an identifier (like a name) is combined with information that relates to a person's health condition, treatment, or payment for healthcare.
Question 40: Which of the following best describes 'incidental disclosures' of PHI under HIPAA?
- Accidental emailing of PHI to the wrong patient
- Verbal disclosures made during emergency treatment
- Deliberate sharing of PHI with unauthorized parties
- Secondary disclosures that occur as a byproduct of permitted disclosures (Correct answer)
Correct answer: Secondary disclosures that occur as a byproduct of permitted disclosures
Incidental disclosures are unintended secondary disclosures that occur as a result of a permitted disclosure, and they do not violate HIPAA if the covered entity has implemented reasonable safeguards.
Question 41: A covered entity is preparing a breach notification letter for affected individuals. Which of the following elements is explicitly required to be included in the notice according to the Breach Notification Rule?
- A detailed technical report of the forensic investigation.
- An offer of complimentary credit monitoring services for one year.
- A brief description of what the entity is doing to investigate the breach and prevent future breaches. (Correct answer)
- The names of the employees responsible for the breach.
Correct answer: A brief description of what the entity is doing to investigate the breach and prevent future breaches.
The HIPAA Breach Notification Rule specifies several required elements for individual notifications. These include a brief description of the breach, the types of information involved, steps individuals should take to protect themselves, what the entity is doing to investigate, mitigate harm, and prevent future breaches, and contact information.
Question 42: A practice can refuse to amend the record:
- Under NO cirumstances
- Under specific circumstances (Correct answer)
- Only if it doesnt affect insurance coverage
- If you do not find it necessary for patient care
Correct answer: Under specific circumstances
The correct answer is "Under specific circumstances". This means that a practice has the right to refuse to amend a medical record, but only in certain situations. <br>It suggests that there are specific criteria or conditions that need to be met for the practice to exercise this right. <br>The answer implies that there are limitations to the practice's ability to refuse amending the record, and it is not a blanket refusal under any circumstance.
Question 43: A covered entity removes all 18 Safe Harbor identifiers but retains free-text clinical notes. Is the resulting data de-identified under HIPAA?
- No, because de-identification always requires Expert Determination for datasets with clinical notes
- No, because free-text notes may contain incidental identifiers and the entity must verify no such information remains (Correct answer)
- Yes, because free-text clinical notes are not PHI under HIPAA
- Yes, because all 18 required identifiers have been removed
Correct answer: No, because free-text notes may contain incidental identifiers and the entity must verify no such information remains
Safe Harbor also requires that the covered entity have no actual knowledge that the remaining information could identify an individual, which unredacted free-text notes often violate.
Question 44: Under HIPAA, what must a covered entity provide to patients at first service delivery?
- A copy of the entire HIPAA Privacy Rule
- A Notice of Privacy Practices describing how the covered entity uses and discloses PHI (Correct answer)
- A list of all workforce members with access to their PHI
- Written authorization forms for all potential future uses of their PHI
Correct answer: A Notice of Privacy Practices describing how the covered entity uses and discloses PHI
HIPAA requires covered entities to provide patients with a Notice of Privacy Practices (NPP) at first service delivery, explaining how their PHI will be used and protected.
Question 45: A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data. Under HIPAA, does this vendor require a BAA?
- Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity (Correct answer)
- Only if the covered entity has more than 500 patients
- No, because it cannot decrypt the PHI
- Only if the vendor is based in the United States
Correct answer: Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity
A vendor that maintains PHI on behalf of a covered entity is a business associate regardless of whether it can access or decrypt the data.
Question 46: Under HIPAA, are mental health records treated differently from other medical records regarding privacy protections?
- Mental health records are protected by HIPAA but may receive additional state-law protections; psychotherapy notes have heightened protection under federal law (Correct answer)
- Mental health records require separate patient authorization for all uses and disclosures
- Mental health records have fewer protections than general medical records
- Mental health records are completely exempt from HIPAA
Correct answer: Mental health records are protected by HIPAA but may receive additional state-law protections; psychotherapy notes have heightened protection under federal law
Mental health PHI receives HIPAA's standard protections, and psychotherapy notes specifically receive heightened protection; many states also provide stronger protections for mental health records.
Question 47: A mid-level manager instructs a subordinate to access a celebrity patient's records 'just to check' on their status, out of personal interest. What should the subordinate do?
- Refuse, as accessing PHI without a job-related need is a HIPAA violation regardless of who asks (Correct answer)
- Access the records because a supervisor requested it
- Ask the patient's permission before complying
- Access the records but report it afterward
Correct answer: Refuse, as accessing PHI without a job-related need is a HIPAA violation regardless of who asks
Workforce members must refuse instructions that violate HIPAA; accessing PHI without a legitimate job-related purpose is a violation regardless of whether a manager directed it.
Question 48: A BAA is in place, but the business associate experiences a ransomware attack that encrypts PHI. Under HIPAA, is this presumed to be a breach?
- No, ransomware is a cybersecurity event, not a HIPAA breach
- Yes, ransomware is presumed to be a breach unless the covered entity can demonstrate a low probability of PHI compromise (Correct answer)
- No, if the PHI is recovered within 72 hours
- Only if the attackers publicly release the data
Correct answer: Yes, ransomware is presumed to be a breach unless the covered entity can demonstrate a low probability of PHI compromise
HHS guidance states that ransomware attacks are presumed breaches because the attacker gained unauthorized access or control over PHI, unless the risk assessment shows low probability of compromise.
Question 49: Which of the following is NOT considered Protected Health Information (PHI) under the HIPAA Privacy Rule?
- A patient's diagnosis recorded in their medical chart
- De-identified health information with all 18 identifiers removed (Correct answer)
- Health information transmitted electronically to an insurer
- A patient's prescription history linked to their name
Correct answer: De-identified health information with all 18 identifiers removed
Once all 18 identifiers are removed using an approved de-identification method, the information is no longer PHI and is not subject to HIPAA Privacy Rule protections.
Question 50: A covered entity wants to share a de-identified dataset with a vendor. Is a BAA required?
- No, unless the dataset contains more than 500 records
- No, because de-identified data is not PHI and BAA requirements do not apply (Correct answer)
- Yes, all vendor relationships require a BAA regardless of data type
- Yes, but only if the vendor will re-identify the data
Correct answer: No, because de-identified data is not PHI and BAA requirements do not apply
De-identified data is not PHI under HIPAA, so sharing it with a vendor does not trigger the BAA requirement.
Question 51: Under HIPAA Administrative Safeguards, 'log-in monitoring' is classified as:
- An addressable implementation specification under security awareness and training (Correct answer)
- A required implementation specification under access control
- An addressable standard under security management process
- A required standard
Correct answer: An addressable implementation specification under security awareness and training
Log-in monitoring is an addressable implementation specification under the security awareness and training standard, focusing on training staff to monitor login attempts.
Question 52: Under HIPAA, which of the following is a primary requirement for electronic health record systems handling Protected Health Information (PHI)?
- Storing all records on local servers only
- Printing all records daily as a backup
- Sharing EHR login credentials among staff for efficiency
- Implementing access controls that limit PHI access to authorized users (Correct answer)
Correct answer: Implementing access controls that limit PHI access to authorized users
HIPAA's Security Rule requires covered entities to implement technical access controls ensuring only authorized individuals can access PHI in electronic form.
Question 53: Which HIPAA implementation specification supports emergency access to ePHI when normal access controls are unavailable?
- Automatic Logoff
- Emergency Access Procedure (Correct answer)
- Unique User Identification
- Contingency Operations
Correct answer: Emergency Access Procedure
Emergency Access Procedure is a required implementation specification under the Access Control standard that establishes how to access ePHI during emergency situations.
Question 54: Under HIPAA, what is a 'covered entity's' obligation when it receives a request from a public health authority to share PHI about a potential disease outbreak?
- Only hospitals, not physician practices, may respond to public health authority requests
- The covered entity must obtain patient authorization before sharing with public health authorities
- Public health disclosures require a court order or subpoena
- The covered entity may share the minimum necessary PHI to assist in public health activities without patient authorization (Correct answer)
Correct answer: The covered entity may share the minimum necessary PHI to assist in public health activities without patient authorization
HIPAA explicitly permits disclosures to public health authorities authorized by law to collect information for public health activities without individual authorization.
Question 55: A research institution wants to use a large dataset of patient information for a study. To avoid HIPAA constraints, they decide to de-identify the data using the Safe Harbor method. Which of the following must be removed from the dataset?
- The state of residence for all patients.
- The patient's year of birth.
- All patient ages over 89, aggregated into a single category of '90 or older'.
- The first three digits of a zip code if the area has fewer than 20,000 people. (Correct answer)
Correct answer: The first three digits of a zip code if the area has fewer than 20,000 people.
The Safe Harbor method requires the removal of 18 specific identifiers. For geographic subdivisions smaller than a state, zip codes must be handled carefully. The initial three digits of a zip code must be removed (or changed to 000) if the geographic unit contains 20,000 or fewer people. The state of residence and year of birth (for those under 90) are generally permissible, and aggregating ages over 89 is a requirement, not a removal of a valid data point.
Question 56: A covered entity's workforce member improperly accesses a celebrity patient's records out of curiosity. This is an example of:
- A minor infraction that does not require documentation
- An impermissible use of PHI that violates the Privacy Rule (Correct answer)
- A permitted use for healthcare operations
- An incidental disclosure permitted by HIPAA
Correct answer: An impermissible use of PHI that violates the Privacy Rule
Accessing PHI for personal curiosity without a legitimate purpose is an impermissible use that violates the HIPAA Privacy Rule's minimum necessary and permissible use standards.
Question 57: Under HIPAA, what is required before a healthcare provider can share a patient's substance use disorder diagnosis with their primary care physician for integrated care?
- No special requirements apply โ treatment disclosures to other providers are always permitted
- Only the patient's health insurance needs to be notified
- If the records are from a 42 CFR Part 2-covered program, specific written consent is required even for treatment disclosures to other providers (Correct answer)
- A BAA between the substance use disorder program and the primary care physician
Correct answer: If the records are from a 42 CFR Part 2-covered program, specific written consent is required even for treatment disclosures to other providers
If the substance use disorder records are governed by 42 CFR Part 2, they cannot be shared with other treatment providers without specific patient consent โ the standard HIPAA treatment exception does not apply to Part 2 records.
Question 58: A hospital system acquires a smaller clinic. The clinic has an existing BAA with a billing vendor. What should the hospital do regarding this BAA?
- Terminate all existing BAAs and start fresh after 90 days
- Assume the existing BAA transfers automatically with no changes needed
- File the existing BAA with HHS for approval
- Review and update the BAA to reflect the new covered entity relationship and ensure it meets current HIPAA standards (Correct answer)
Correct answer: Review and update the BAA to reflect the new covered entity relationship and ensure it meets current HIPAA standards
After an acquisition, the new covered entity should review existing BAAs to confirm they are adequate and properly reflect the new organizational structure.
Question 59: A researcher wants to use patient data without obtaining individual authorizations. Under HIPAA, this is permissible if:
- The data involves fewer than 500 patients
- An Institutional Review Board (IRB) waives the authorization requirement (Correct answer)
- The patients are not currently receiving treatment
- The research is funded by a federal agency
Correct answer: An Institutional Review Board (IRB) waives the authorization requirement
HIPAA allows use of PHI for research without individual authorization when an IRB or Privacy Board grants a waiver based on criteria protecting patients' privacy interests.
Question 60: A health plan mails an Explanation of Benefits to a member's former address, revealing PHI to an unknown person. How is this classified under the Breach Notification Rule?
- Not a breach because it was a mailing error, not an intentional disclosure
- A breach requiring full risk assessment to determine if notification is needed (Correct answer)
- Not a breach because EOBs are required by law to be mailed
- Always exempt from notification because it involves mailing errors
Correct answer: A breach requiring full risk assessment to determine if notification is needed
Misdirected EOBs involving PHI disclosure to unauthorized individuals require a four-factor risk assessment to determine whether breach notification is required.
Question 61: A hospital discovers that a server containing the electronic protected health information (ePHI) of 350 patients was improperly decommissioned and sold. The data was not encrypted. According to the HIPAA Breach Notification Rule, what is the hospital's deadline for notifying the Secretary of Health and Human Services (HHS)?
- Within 30 days of notifying the affected individuals.
- No later than 60 days after the end of the calendar year in which the breach was discovered. (Correct answer)
- Immediately upon discovery, via the HHS online portal.
- Without unreasonable delay, and in no case later than 60 days after the discovery of the breach.
Correct answer: No later than 60 days after the end of the calendar year in which the breach was discovered.
For breaches affecting fewer than 500 individuals, a covered entity must notify the Secretary of HHS by submitting a report no later than 60 days after the end of the calendar year in which the breach was discovered. The 60-day deadline from the date of discovery applies to notifying individuals and to notifying the Secretary for breaches affecting 500 or more individuals.
Question 62: Under the Omnibus Rule, what must a business associate agreement (BAA) include regarding subcontractors?
- A prohibition on the business associate using any subcontractors who handle PHI
- A requirement that subcontractors be certified by HHS before handling PHI
- A provision requiring the business associate to enter into BAAs with its subcontractors (Correct answer)
- A list of all approved subcontractors the business associate may use
Correct answer: A provision requiring the business associate to enter into BAAs with its subcontractors
The Omnibus Rule requires that BAAs include a provision obligating business associates to enter into compliant BAAs with any subcontractors who create, receive, maintain, or transmit PHI.
Question 63: The X12 835 transaction under HIPAA is used for which purpose?
- Enrolling or disenrolling members in health plans
- Verifying patient eligibility before a visit
- Healthcare claim payment and remittance advice (Correct answer)
- Submitting professional claims to health plans
Correct answer: Healthcare claim payment and remittance advice
The X12 835 transaction is the Health Care Claim Payment/Advice, used by payers to communicate payment details and explanations back to providers. Eligibility verification uses X12 270/271, enrollment uses X12 834, and claim submission uses X12 837.
Question 64: When a breach involves PHI of individuals from multiple states, which state's media outlets must receive notification?
- The media outlets in each state where more than 500 residents were affected (Correct answer)
- Only the state where the covered entity is headquartered
- Only the state where the most individuals were affected
- All 50 states must receive media notification regardless of how many individuals are affected in each
Correct answer: The media outlets in each state where more than 500 residents were affected
Media notification is required in each state or jurisdiction where more than 500 of its residents were affected by the breach.
Question 65: A patient discovers an error in their medical record and submits a formal written request to their provider to have it corrected. Under the HIPAA Privacy Rule, what right is the patient exercising?
- The Right to Restrict Disclosures
- The Right to Amend PHI (Correct answer)
- The Right of Access
- The Right to an Accounting of Disclosures
Correct answer: The Right to Amend PHI
The HIPAA Privacy Rule provides patients with the right to request an amendment of their PHI in a designated record set if they believe the information is inaccurate or incomplete. The covered entity must then review the request and either make the amendment or provide a written denial to the patient.
Question 66: A covered entity learns that its business associate has a pattern of non-compliance that constitutes a material breach of the Business Associate Agreement (BAA). If the business associate fails to cure the breach, what is the covered entity's primary obligation under HIPAA?
- Publish a notice of the business associate's non-compliance in a major newspaper.
- Immediately pay any fines on behalf of the business associate.
- Terminate the BAA with the business associate, if feasible. (Correct answer)
- Report the business associate to the local law enforcement agency.
Correct answer: Terminate the BAA with the business associate, if feasible.
If a covered entity knows of a material breach or violation by the business associate, it must take reasonable steps to cure the breach or end the violation. If such steps are unsuccessful, the covered entity is required to terminate the contract or arrangement, if doing so is feasible.
Question 67: What does the HITECH Act require covered entities to include in their Notice of Privacy Practices regarding PHI sale?
- A disclosure of marketing revenue generated from PHI
- The price charged for PHI in recent transactions
- A list of all parties to whom PHI has been sold
- A statement that authorization is required before selling PHI (Correct answer)
Correct answer: A statement that authorization is required before selling PHI
HITECH requires covered entities to state in their Notice of Privacy Practices that patient authorization is required before the entity may sell PHI.
Question 68: A covered entity corrects a HIPAA violation within 30 days of OCR notification. Under which penalty tier does this correction provision NOT eliminate liability?
- Tier 3 โ willful neglect, corrected
- Tier 1 โ unknowing violations
- Tier 2 โ reasonable cause
- Tier 4 โ willful neglect, not corrected (Correct answer)
Correct answer: Tier 4 โ willful neglect, not corrected
The 30-day correction window provides an affirmative defense for Tiers 1โ3, but Tier 4 (willful neglect, not corrected) carries mandatory penalties that cannot be avoided by late correction.
Question 69: What is a 'limited data set' under HIPAA, and how does it relate to the Minimum Necessary Standard?
- A summary of PHI provided to patients upon request
- PHI with most direct identifiers removed, used for research, public health, or healthcare operations under a data use agreement (Correct answer)
- A subset of PHI shared with law enforcement under a court order
- A complete medical record with all identifiers removed, used only for treatment
Correct answer: PHI with most direct identifiers removed, used for research, public health, or healthcare operations under a data use agreement
A limited data set is PHI stripped of most direct identifiers and may be used for research, public health, or operations under a data use agreement, representing one way to apply the Minimum Necessary Standard.
Question 70: What is the HIPAA 'minimum necessary' standard as it applies to PHI?
- Covered entities must use the fewest employees possible to handle PHI
- Only the minimum amount of PHI needed to accomplish a purpose should be used or disclosed (Correct answer)
- PHI must be stored in the smallest possible database
- Patients must provide only minimum information for treatment
Correct answer: Only the minimum amount of PHI needed to accomplish a purpose should be used or disclosed
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the least amount needed to accomplish the intended purpose.
Question 71: A hospital patient asks to inspect their own medical records during their admission. Under HIPAA, what is the hospital's obligation?
- Hospitals are not required to allow inspection during admission for operational reasons
- The hospital must provide access within a reasonable timeframe, though access during admission may be deferred until after discharge (Correct answer)
- Patients have no right to inspect records โ only copies may be requested post-discharge
- The hospital must provide immediate access to all records upon request
Correct answer: The hospital must provide access within a reasonable timeframe, though access during admission may be deferred until after discharge
While HIPAA gives patients the right to access their records, hospitals may use reasonable operational provisions and provide access within 30 days post-request.
Question 72: Under the Omnibus Rule, if a covered entity discovers that its business associate has been in violation of the BAA, what is the covered entity's obligation?
- Report the violation to HHS within 24 hours of discovery
- Immediately terminate the BAA and report to HHS
- Take reasonable steps to cure the breach or end the violation, and terminate the BAA if unsuccessful (Correct answer)
- Notify affected individuals before taking any action against the business associate
Correct answer: Take reasonable steps to cure the breach or end the violation, and terminate the BAA if unsuccessful
When a covered entity becomes aware of a BAA violation, it must take reasonable steps to cure the breach or end the violation, and if not resolved, terminate the BAA.
Question 73: Under the HIPAA Privacy Rule, which of the following is NOT considered Protected Health Information (PHI)?
- An email from a patient to their doctor's office.
- A de-identified health summary used for a statistical study. (Correct answer)
- A photograph of a patient's face stored in their electronic health record.
- A patient's medical record number.
Correct answer: A de-identified health summary used for a statistical study.
Protected Health Information (PHI) is individually identifiable health information. Information that has been de-identified, meaning all 18 specific identifiers (like name, address, dates, etc.) have been removed, is no longer considered PHI and is not subject to the Privacy Rule.
Question 74: A marketing firm offers to analyze patient data and share aggregated results with third parties for profit. A covered entity wants to hire this firm. What HIPAA concern arises?
- The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes (Correct answer)
- The covered entity only needs a data use agreement, not a BAA
- This arrangement is permitted as long as the data is anonymized before sharing
- Marketing firms are exempt from BAA requirements
Correct answer: The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes
A BAA must prohibit business associates from using PHI for their own purposes, including commercial gain, beyond what the agreement permits.
Question 75: Which HHS office is responsible for enforcing the HIPAA Breach Notification Rule?
- Office for Civil Rights (OCR) (Correct answer)
- Office of Inspector General (OIG)
- National Institutes of Health (NIH)
- Centers for Medicare & Medicaid Services (CMS)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Breach Notification Rule.
HIPAA Compliance Certification Exam
The HIPAA Compliance Certification exam tests knowledge of the Health Insurance Portability and Accountability Act, including the Privacy Rule, Security Rule, Breach Notification Rule, PHI handling, patient rights, business associate requirements, and enforcement penalties.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds