HIPAA Compliance Certification Exam — Questions and Answers
Question 1: A hospital billing department outsources its coding to a third-party company. The coding company requires access to patient charts to perform its function. Under HIPAA, what is the most critical step the hospital must take before granting this access?
- Ensure the coding company has general liability insurance.
- De-identify all patient data before sending it to the coding company.
- Execute a Business Associate Agreement (BAA) with the coding company. (Correct answer)
- Obtain individual patient authorization for each record shared.
Correct answer: Execute a Business Associate Agreement (BAA) with the coding company.
When a covered entity (the hospital) hires a person or entity (the coding company) to perform functions involving the use or disclosure of PHI, that entity is considered a Business Associate. HIPAA requires a formal, written Business Associate Agreement (BAA) to be in place before any PHI is shared. This contract legally requires the business associate to maintain the same level of protection for the PHI as the covered entity.
Question 2: Under HIPAA, a covered entity discovers its business associate experienced a security incident that did not result in acquisition or viewing of PHI. What is the covered entity's obligation?
- No further action is required because no PHI was accessed
- Automatically terminate the BAA
- Issue breach notifications to all potentially affected individuals immediately
- Determine whether the incident constitutes a reportable breach using the four-factor risk assessment (Correct answer)
Correct answer: Determine whether the incident constitutes a reportable breach using the four-factor risk assessment
Even when PHI access appears unlikely, the covered entity must conduct the four-factor risk assessment to determine if a reportable breach occurred.
Question 3: What is 'k-anonymity' in the context of healthcare data de-identification?
- A technique ensuring each individual's record cannot be distinguished from at least k-1 other individuals in a dataset (Correct answer)
- The minimum number of identifiers that must be removed under Safe Harbor
- A federal standard for data encryption key management
- A HIPAA-required certification for de-identification specialists
Correct answer: A technique ensuring each individual's record cannot be distinguished from at least k-1 other individuals in a dataset
k-anonymity is a privacy model ensuring that each record in a dataset is indistinguishable from at least k-1 other records based on quasi-identifiers, reducing re-identification risk.
Question 4: A covered entity discovers that a business associate has experienced a breach of PHI. Who is primarily responsible for notifying affected individuals?
- The state attorney general handles all breach notifications
- The business associate must notify all affected individuals directly
- The covered entity is responsible for notifying affected individuals (Correct answer)
- HHS notifies affected individuals on behalf of both parties
Correct answer: The covered entity is responsible for notifying affected individuals
Under the HIPAA Breach Notification Rule, the covered entity bears primary responsibility for notifying affected individuals, even when the breach occurred at a business associate.
Question 5: A substance abuse treatment program receives a subpoena for a patient's records. Under 42 CFR Part 2, what is the program's proper response?
- Provide a redacted version within 48 hours
- Notify the patient and resist disclosure without a court order and patient consent (Correct answer)
- Comply with the subpoena immediately
- Release records only to the court clerk
Correct answer: Notify the patient and resist disclosure without a court order and patient consent
Under 42 CFR Part 2, a subpoena alone is insufficient — the program must resist disclosure unless there is both a court order and patient consent, or another specific exception applies.
Question 6: Under the Omnibus Rule, individuals have a right to request restrictions on disclosures of PHI to health plans when the individual pays out-of-pocket in full. What must a covered entity do in this situation?
- Restrict the disclosure only if approved by the covered entity's privacy officer
- Deny the request if the health plan requires the information for claims processing
- Comply with the restriction request if it relates to the specific item or service paid for out-of-pocket (Correct answer)
- Notify the health plan within 30 days and then restrict the disclosure
Correct answer: Comply with the restriction request if it relates to the specific item or service paid for out-of-pocket
The Omnibus Rule requires covered entities to honor a patient's restriction request when the patient pays out-of-pocket in full for a specific item or service.
Question 7: A covered entity's EHR is hosted by a SaaS vendor that stores data in multiple international data centers. What HIPAA implication does this create?
- International storage is prohibited under HIPAA
- The BAA must address data stored internationally, as HIPAA applies regardless of where PHI is stored (Correct answer)
- International data storage is automatically HIPAA-compliant
- Only data stored in EU-compliant data centers requires a BAA
Correct answer: The BAA must address data stored internationally, as HIPAA applies regardless of where PHI is stored
HIPAA applies to covered entities and business associates regardless of where PHI is stored; the BAA must address international storage and ensure equivalent protections.
Question 8: Under HIPAA, a covered entity may disclose PHI about a deceased individual to a medical examiner or coroner to:
- Support a civil lawsuit filed by the deceased's surviving family members
- Identify a deceased individual or determine the cause of death (Correct answer)
- Comply with insurance claims processing requirements from the deceased's health plan
- Help the covered entity reduce liability exposure related to the death
Correct answer: Identify a deceased individual or determine the cause of death
The HIPAA Privacy Rule explicitly permits disclosure of PHI to medical examiners and coroners for purposes of identifying a deceased person or determining the cause of death. This exception recognizes the public interest in proper death investigation. It does not extend to litigation support or liability management.
Question 9: What does the 'duty to warn' or 'Tarasoff doctrine' mean in the context of HIPAA and mental health?
- Mental health providers may (and in some states must) disclose information to prevent serious and imminent threats to the safety of identifiable third parties (Correct answer)
- Mental health providers must warn all patients' family members about treatment plans
- Duty to warn only applies to providers treating violent criminals
- HIPAA prohibits disclosure even to prevent violence
Correct answer: Mental health providers may (and in some states must) disclose information to prevent serious and imminent threats to the safety of identifiable third parties
HIPAA's serious threat exception permits mental health providers to disclose PHI to prevent serious and imminent threats — this aligns with state 'duty to warn' laws derived from the Tarasoff case.
Question 10: Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
- Healthcare providers who transmit health information electronically
- Healthcare clearinghouses
- Health plans
- Employers who sponsor self-insured health plans (Correct answer)
Correct answer: Employers who sponsor self-insured health plans
Employers who sponsor self-insured health plans are not themselves covered entities; however, the plan itself may be a covered entity, and employers must separate plan functions from employment functions.
Question 11: Under the HIPAA Omnibus Rule, which party is directly liable for HIPAA compliance failures?
- Both covered entities and business associates are directly liable (Correct answer)
- Only business associates acting as agents of covered entities
- Only covered entities
- Subcontractors only when they sign a BAA with the covered entity
Correct answer: Both covered entities and business associates are directly liable
The 2013 Omnibus Rule made business associates directly liable for HIPAA violations, not just contractually liable through the BAA.
Question 12: A covered entity's workforce member improperly accesses a celebrity patient's records out of curiosity. This is an example of:
- An impermissible use of PHI that violates the Privacy Rule (Correct answer)
- An incidental disclosure permitted by HIPAA
- A minor infraction that does not require documentation
- A permitted use for healthcare operations
Correct answer: An impermissible use of PHI that violates the Privacy Rule
Accessing PHI for personal curiosity without a legitimate purpose is an impermissible use that violates the HIPAA Privacy Rule's minimum necessary and permissible use standards.
Question 13: A health care provider with a direct treatment relationship is giving a new patient their Notice of Privacy Practices (NPP) for the first time. According to HIPAA, when must this occur?
- Within 30 days after the first service is provided.
- At least once every three years.
- Only when the patient makes a written request for the notice.
- No later than the date of the first service delivery. (Correct answer)
Correct answer: No later than the date of the first service delivery.
The HIPAA Privacy Rule requires that a covered health care provider with a direct treatment relationship with an individual must provide the Notice of Privacy Practices (NPP) no later than the date of the first service delivery. The requirement for health plans to notify members every three years is a different standard.
Question 14: An employer contacts a covered behavioral health provider requesting an employee's mental health records. Under HIPAA, the provider may release records:
- Only with the employee's valid written authorization (Correct answer)
- If the employer has a business associate agreement
- If the records are for workers' compensation only
- Immediately upon the employer's written request
Correct answer: Only with the employee's valid written authorization
Mental health records may only be released to an employer with the patient's valid written authorization, as employers are not typically covered entities with treatment relationships.
Question 15: Under HIPAA, which of the following workforce members should have access to a patient's complete medical record?
- Any clinician working at the same facility
- All hospital employees for quality assurance
- Only those whose job functions require that level of access (Correct answer)
- Any employee who requests access for patient care purposes
Correct answer: Only those whose job functions require that level of access
HIPAA's minimum necessary standard requires that access to PHI be limited to workforce members whose specific job duties require that information.
Question 16: A BAA must require the business associate to make its internal practices available to which government agency upon request?
- The Federal Trade Commission (FTC)
- The Social Security Administration (SSA)
- The Department of Health and Human Services (HHS) (Correct answer)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Department of Health and Human Services (HHS)
BAAs must require the business associate to make its books, records, and practices available to HHS for purposes of determining the covered entity's compliance.
Question 17: Which entity is directly required to comply with the HIPAA Security Rule?
- Patients who access their own ePHI
- Any vendor that sells software to hospitals
- Health IT developers funded by CMS
- Covered entities and their business associates (Correct answer)
Correct answer: Covered entities and their business associates
The Security Rule applies directly to covered entities (health plans, providers, clearinghouses) and their business associates.
Question 18: Under HIPAA, what consideration applies when a covered entity receives a request to disclose mental health PHI for a workers' compensation claim?
- Workers' compensation disclosure may be permitted as required by law, but only to the extent necessary for the workers' compensation claim and subject to any state mental health record restrictions (Correct answer)
- Mental health information can never be disclosed for workers' compensation purposes
- The employer may directly request and receive mental health records once a workers' comp claim is filed
- Workers' compensation claims automatically override all HIPAA mental health protections
Correct answer: Workers' compensation disclosure may be permitted as required by law, but only to the extent necessary for the workers' compensation claim and subject to any state mental health record restrictions
Workers' compensation disclosures are permitted as required by law under HIPAA, but are limited to information relevant to the claim and may be further restricted by state mental health confidentiality laws.
Question 19: A researcher wants to use patient data without obtaining individual authorizations. Under HIPAA, this is permissible if:
- The research is funded by a federal agency
- The data involves fewer than 500 patients
- An Institutional Review Board (IRB) waives the authorization requirement (Correct answer)
- The patients are not currently receiving treatment
Correct answer: An Institutional Review Board (IRB) waives the authorization requirement
HIPAA allows use of PHI for research without individual authorization when an IRB or Privacy Board grants a waiver based on criteria protecting patients' privacy interests.
Question 20: A healthcare provider may share a patient's PHI with a family member without patient authorization when:
- The family member is listed as an emergency contact in the record
- The patient is present and does not object, or the provider determines it is in the patient's best interest (Correct answer)
- The family member provides a notarized letter confirming their relationship
- The patient has signed a general consent-to-treatment form
Correct answer: The patient is present and does not object, or the provider determines it is in the patient's best interest
HIPAA permits sharing PHI with family members when the patient is present, given the opportunity to agree or object, and does not object, or when the provider deems it in the patient's best interest.
Question 21: A covered entity may disclose PHI without patient authorization to report a communicable disease to a public health authority. This falls under which HIPAA exception?
- Law enforcement exception
- Healthcare operations exception
- Public health activities exception (Correct answer)
- Emergency circumstances exception
Correct answer: Public health activities exception
HIPAA's public health activities exception permits covered entities to disclose PHI to public health authorities authorized by law to collect data for preventing or controlling disease.
Question 22: Under HIPAA, what rights does a patient have regarding their psychotherapy notes if they request access?
- Patients have the same right to access psychotherapy notes as any other medical record
- Covered entities may deny patients access to psychotherapy notes — this is one of the few exceptions to the general right of access (Correct answer)
- Patients can only access psychotherapy notes through a court order
- Psychotherapy notes must be shared with patients upon request within 30 days
Correct answer: Covered entities may deny patients access to psychotherapy notes — this is one of the few exceptions to the general right of access
HIPAA specifically allows covered entities to deny patients access to psychotherapy notes — this is one of the few exceptions to the general right of access to PHI.
Question 23: What is the difference between a 'threat' and a 'vulnerability' in the context of a HIPAA Security Rule risk analysis?
- Threats relate to technical systems; vulnerabilities relate to people
- Threats are internal; vulnerabilities are external
- There is no meaningful distinction under the Security Rule
- A threat is a potential danger to ePHI; a vulnerability is a weakness that could be exploited by a threat (Correct answer)
Correct answer: A threat is a potential danger to ePHI; a vulnerability is a weakness that could be exploited by a threat
In risk analysis, a threat is a potential occurrence that could negatively impact ePHI, while a vulnerability is a flaw or weakness that increases the likelihood of that threat causing harm.
Question 24: A business associate engages a subcontractor to perform data analytics involving PHI. What must the business associate do?
- Notify all affected patients before sharing their PHI with the subcontractor
- Enter into a BAA with the subcontractor that imposes equivalent PHI protections (Correct answer)
- Obtain written approval from HHS before engaging the subcontractor
- Ensure the subcontractor is a covered entity
Correct answer: Enter into a BAA with the subcontractor that imposes equivalent PHI protections
Business associates must obtain satisfactory assurances from subcontractors through a BAA that imposes the same PHI safeguards required of the business associate.
Question 25: Which of the following is an example of PHI in a non-electronic format covered by the HIPAA Privacy Rule?
- A hospital's aggregate statistics on patient outcomes
- Anonymous survey responses about general health behaviors
- De-identified insurance claims data
- A paper prescription with a patient's name and medication (Correct answer)
Correct answer: A paper prescription with a patient's name and medication
A paper prescription containing a patient's name (an identifier) linked to medication information (health-related data) constitutes PHI subject to the HIPAA Privacy Rule.
Question 26: A hospital's compliance officer discovers that several nurses completed the annual HIPAA training but failed the assessment. What is the most appropriate next step?
- Terminate the nurses immediately
- Document the failure and require retraining before PHI access is restored (Correct answer)
- Allow the nurses to continue working without restriction
- Report the nurses to the state nursing board
Correct answer: Document the failure and require retraining before PHI access is restored
When workforce members fail compliance training, covered entities should document the failure, provide remedial training, and restrict PHI access until competency is demonstrated.
Question 27: What does the HITECH Act require regarding accounting of disclosures for covered entities using EHR systems?
- Disclosures for treatment must be tracked for 3 years
- Accounting requirements are eliminated for EHR users
- Only disclosures for marketing need to be tracked
- Accounting must include treatment, payment, and operations disclosures (Correct answer)
Correct answer: Accounting must include treatment, payment, and operations disclosures
HITECH expanded accounting of disclosures requirements to include treatment, payment, and operations disclosures for covered entities using EHR systems.
Question 28: A law firm provides legal services to a hospital and, in the course of its work, has access to PHI. Under HIPAA, what is the relationship between the law firm and the hospital?
- The law firm is considered part of the hospital's workforce and does not need a BAA.
- The law firm is a 'Business Associate' and must have a signed BAA with the hospital. (Correct answer)
- The law firm is a 'Covered Entity' in this context, operating under its own HIPAA policies.
- The law firm is exempt from HIPAA because legal services are not a core healthcare function.
Correct answer: The law firm is a 'Business Associate' and must have a signed BAA with the hospital.
A business associate is a person or entity that performs certain functions or activities involving the use or disclosure of PHI on behalf of a covered entity. Providing legal services that involve access to PHI is explicitly listed as a business associate function. Therefore, the hospital (covered entity) must have a signed BAA with the law firm (business associate).
Question 29: A researcher wants access to identifiable mental health records from a covered entity without patient authorization. Under HIPAA, this may be allowed if:
- An IRB or Privacy Board waives the authorization requirement and specific conditions are met (Correct answer)
- The researcher is employed at a university
- The research is federally funded
- The researcher agrees to destroy the records after use
Correct answer: An IRB or Privacy Board waives the authorization requirement and specific conditions are met
HIPAA permits covered entities to disclose identifiable PHI for research without authorization only when an IRB or Privacy Board has waived the authorization requirement and specific regulatory conditions are satisfied.
Question 30: Psychotherapy notes receive special protection under HIPAA because:
- They may only be disclosed to law enforcement
- Mental health information is exempt from the minimum necessary standard
- They are not considered PHI
- They require a separate, specific authorization for disclosure beyond standard PHI (Correct answer)
Correct answer: They require a separate, specific authorization for disclosure beyond standard PHI
Psychotherapy notes are treated as a special category of PHI under HIPAA and require a specific authorization for most disclosures, separate from an authorization that covers other PHI.
Question 31: How did HITECH affect the civil money penalty ranges for Business Associates under HIPAA?
- Only criminal penalties, not civil penalties, apply to business associates
- Business associate penalties are capped at one-tenth of covered entity penalties
- Business associates cannot be subject to civil money penalties, only breach notification requirements
- HITECH made business associates directly subject to the same civil money penalty tiers as covered entities (Correct answer)
Correct answer: HITECH made business associates directly subject to the same civil money penalty tiers as covered entities
HITECH subjected business associates to the same four-tier civil money penalty structure as covered entities, enabling OCR to directly fine BAs for HIPAA Security Rule violations.
Question 32: A Business Associate Agreement (BAA) must include a provision that addresses the termination of the agreement. Which of the following is a required element of this termination provision?
- A mandate for the business associate to return or destroy all PHI at the end of the contract. (Correct answer)
- A requirement that the business associate pay a financial penalty to the covered entity upon any termination.
- A provision that all PHI becomes the property of the business associate upon termination.
- A clause stating that the BAA is perpetual and can only be terminated by mutual consent.
Correct answer: A mandate for the business associate to return or destroy all PHI at the end of the contract.
A standard and required component of a BAA is a clause specifying that upon termination of the contract, the business associate must, if feasible, return or destroy all PHI received from, or created or received by the business associate on behalf of, the covered entity. If this is not feasible, protections must be extended to the information, and limits must be placed on further uses and disclosures.
Question 33: The HHS Office for Civil Rights (OCR) determines that a covered entity's violation was due to 'willful neglect,' but the entity corrected the violation within 30 days of discovery. Into which tier of Civil Monetary Penalties does this violation fall?
- Tier 3: Willful Neglect - Corrected (Correct answer)
- Tier 1: No Knowledge
- Tier 2: Reasonable Cause
- Tier 4: Willful Neglect - Not Corrected
Correct answer: Tier 3: Willful Neglect - Corrected
The HIPAA penalty structure is tiered based on the level of culpability. Tier 3 is specifically for violations caused by willful neglect that are corrected within a 30-day period. This tier carries a lower penalty range than Tier 4, which applies when willful neglect is not corrected in a timely manner.
Question 34: Which entity is primarily responsible for enforcing HIPAA's Privacy Rule?
- The Office for Civil Rights (OCR) within HHS (Correct answer)
- The Centers for Medicare & Medicaid Services (CMS)
- The Federal Trade Commission (FTC)
- The Department of Justice (DOJ)
Correct answer: The Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) is the primary enforcement agency for HIPAA's Privacy and Security Rules.
Question 35: Which of the following scenarios describes a valid authorization under the HIPAA Privacy Rule?
- A specific written authorization for releasing records to a life insurance company, signed by the patient with an expiration date (Correct answer)
- A blanket authorization signed at the time of hospital admission covering all future uses
- An oral agreement by the patient to allow their employer to receive their diagnosis
- An authorization obtained under duress to receive treatment
Correct answer: A specific written authorization for releasing records to a life insurance company, signed by the patient with an expiration date
A valid HIPAA authorization must be specific, written, signed, include an expiration date or event, and cannot be conditioned on receiving treatment.
Question 36: What is 'data masking' in the context of HIPAA de-identification?
- A process that encrypts entire PHI files so they cannot be read without a key
- Replacing sensitive data values with realistic but fictitious substitutes to preserve data format and utility (Correct answer)
- A technique that splits a database across multiple servers so no single server holds complete PHI
- Removing all data fields except those approved by the HIPAA Privacy Rule
Correct answer: Replacing sensitive data values with realistic but fictitious substitutes to preserve data format and utility
Data masking substitutes real PHI values with realistic fictional values (e.g., replacing a real name with a fake name) to maintain data structure and utility while eliminating actual identifiers.
Question 37: Electronic Protected Health Information (ePHI) differs from PHI in that it:
- Only applies to information stored in cloud systems
- Does not include information transmitted via email
- Is specifically governed by the HIPAA Security Rule in addition to the Privacy Rule (Correct answer)
- Has fewer HIPAA protections than paper-based PHI
Correct answer: Is specifically governed by the HIPAA Security Rule in addition to the Privacy Rule
ePHI is PHI that is created, stored, transmitted, or received electronically, and it is subject to both the HIPAA Privacy Rule and the additional technical safeguards required by the Security Rule.
Question 38: Under the HITECH Act, what percentage of collected HIPAA civil monetary penalties must be used for affected individuals?
- 25%
- A percentage determined by the HHS Secretary (Correct answer)
- 50%
- 10%
Correct answer: A percentage determined by the HHS Secretary
The HITECH Act authorizes HHS to distribute a percentage of CMPs to harmed individuals, with the exact percentage determined by the HHS Secretary.
Question 39: A practice's policy requires that all laptops used off-site must have full-disk encryption enabled. This addresses which category of HIPAA safeguard?
- Technical Safeguards — Transmission Security
- Physical Safeguards — Device and Media Controls (Correct answer)
- Technical Safeguards — Access Control
- Administrative Safeguards
Correct answer: Physical Safeguards — Device and Media Controls
Full-disk encryption on portable devices is a control under Device and Media Controls, which governs hardware and media that house ePHI.
Question 40: Under HIPAA, which of the following is true about deceased individuals' PHI?
- PHI protections apply for 50 years after death
- PHI of deceased individuals is protected for 50 years after death (Correct answer)
- PHI protections expire immediately upon death
- Deceased individuals' PHI can be freely shared with any family member
Correct answer: PHI of deceased individuals is protected for 50 years after death
HIPAA protects the PHI of deceased individuals for 50 years following the date of death, after which it is no longer considered protected health information.
Question 41: What is the scope of HIPAA's workforce training requirement under Administrative Safeguards?
- Workforce members hired after the compliance date
- Only workforce members who directly handle ePHI
- All workforce members, including volunteers and trainees (Correct answer)
- Only IT staff responsible for ePHI systems
Correct answer: All workforce members, including volunteers and trainees
Security awareness training must be provided to all workforce members, including management, regardless of whether they directly handle ePHI.
Question 42: A patient pays for a cosmetic procedure entirely out-of-pocket and asks the clinic not to share any information about this service with their health insurance plan. Under HIPAA, how must the clinic respond?
- The clinic can agree to the restriction but is not required to do so.
- The clinic must agree to the request to restrict disclosure to the health plan. (Correct answer)
- The clinic must inform the health plan but can ask them to keep it confidential.
- The clinic can deny the request because it conflicts with their billing practices.
Correct answer: The clinic must agree to the request to restrict disclosure to the health plan.
The HIPAA Privacy Rule requires a covered entity to agree to a request to restrict disclosure of PHI to a health plan if the disclosure is for payment or health care operations and the PHI pertains solely to a service for which the individual has paid the covered entity in full out-of-pocket. In this scenario, the provider's compliance is mandatory, not optional.
Question 43: Under the Minimum Necessary Standard, what must a covered entity do when it routinely requests PHI from another covered entity?
- Request the entire medical record to avoid missing relevant information
- Submit requests only through a certified health information exchange
- Establish standard protocols or criteria limiting requests to the minimum needed (Correct answer)
- Obtain a written authorization from the patient each time
Correct answer: Establish standard protocols or criteria limiting requests to the minimum needed
For routine requests, covered entities must establish standard protocols that limit PHI requests to what is reasonably necessary for the identified purpose.
Question 44: A HIPAA-covered entity's security training includes reminders about malicious software. This training element maps to which implementation specification?
- Protection from malicious software (Correct answer)
- Security reminders
- Password management
- Log-in monitoring
Correct answer: Protection from malicious software
Training on malicious software falls under the 'protection from malicious software' addressable specification within the security awareness and training standard.
Question 45: A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon patient request
- Only when PHI is first disclosed to a third party
- Annually regardless of changes
- No later than the date of first service delivery (Correct answer)
Correct answer: No later than the date of first service delivery
Covered entities must provide patients with the NPP no later than the date of first service delivery, and must make a good-faith effort to obtain written acknowledgment of receipt.
Question 46: Under HIPAA, what must a BAA require regarding the business associate's minimum necessary standard when using PHI?
- The business associate must reduce PHI use to zero unless it is a healthcare provider
- The minimum necessary standard only applies to covered entities, not business associates
- The business associate must use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose (Correct answer)
- The business associate may use all PHI it receives as broadly as needed to complete its work
Correct answer: The business associate must use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose
Business associates are bound by the minimum necessary standard and must limit their use and disclosure of PHI to what is needed for the specified purpose.
Question 47: Which HITECH Act provision requires covered entities to provide patients with an electronic copy of their PHI upon request?
- Breach Notification Rule
- Right of Access provision (Correct answer)
- Meaningful Use requirement
- Business Associate expansion
Correct answer: Right of Access provision
HITECH's Right of Access provision requires covered entities using EHRs to provide patients with electronic copies of their PHI when requested.
Question 48: Which statement correctly describes the relationship between HIPAA patient rights and state law?
- State laws that are less protective than HIPAA are allowed because of federalism
- HIPAA and state law are completely independent with no interaction
- State laws that provide greater privacy protections than HIPAA generally prevail (Correct answer)
- HIPAA preempts all state laws regarding patient access to records
Correct answer: State laws that provide greater privacy protections than HIPAA generally prevail
HIPAA sets a federal floor; state laws that are more protective of patient privacy are not preempted.
Question 49: Under the CARES Act of 2020, 42 CFR Part 2 was amended to allow SUD records to be used for which purpose without patient consent?
- Marketing pharmaceutical products
- Life insurance underwriting
- Payment and healthcare operations by entities that received consent at admission (Correct answer)
- Employment background checks
Correct answer: Payment and healthcare operations by entities that received consent at admission
The CARES Act allowed Part 2 programs to use SUD records for payment and healthcare operations purposes — similar to HIPAA — when a general consent was obtained at the time of admission.
Question 50: Under HIPAA, which workforce members are required to receive privacy and security training?
- Only full-time employees with system access
- All workforce members, including volunteers and trainees (Correct answer)
- Only employees hired after April 2003
- Only clinical staff who access patient records
Correct answer: All workforce members, including volunteers and trainees
HIPAA requires that ALL workforce members—including volunteers, trainees, and part-time staff—receive appropriate privacy and security training.
Question 51: Under the Omnibus Rule, a covered entity discovers an impermissible disclosure of PHI by a workforce member acting with willful neglect that is not corrected. What penalty tier applies?
- $50,000–$1,500,000 per violation (willful neglect — not corrected tier) (Correct answer)
- $1,000–$50,000 per violation (reasonable cause tier)
- $100–$50,000 per violation (unknowing violation tier)
- $10,000–$50,000 per violation (willful neglect — corrected tier)
Correct answer: $50,000–$1,500,000 per violation (willful neglect — not corrected tier)
Willful neglect violations that are not corrected within 30 days carry the highest penalty tier of $50,000 to $1,500,000 per violation per calendar year.
Question 52: Under HIPAA, when may a covered entity disclose a minor patient's mental health records to their parents over the minor's objection?
- Disclosure to parents over the minor's objection is generally governed by state law; if the minor consented to treatment under state law, disclosure to parents may be restricted (Correct answer)
- Minors have no privacy rights until age 18 under HIPAA
- Mental health records of minors under 16 can never be shared with parents under HIPAA
- Parents always override minor patient objections to disclosure
Correct answer: Disclosure to parents over the minor's objection is generally governed by state law; if the minor consented to treatment under state law, disclosure to parents may be restricted
State law determines when minors can consent to treatment independently; when they do, disclosure to parents may be restricted, and HIPAA defers to state law on this balance.
Question 53: A business associate agrees to provide data analytics but later expands its services to include direct patient communications without amending the BAA. What HIPAA issue does this create?
- The business associate must notify patients but does not need to amend the BAA
- This is permitted as long as the covered entity gives verbal approval
- No issue, because the original BAA covers all services the business associate performs
- The business associate's new activities may exceed the permitted uses of PHI under the existing BAA, creating a violation (Correct answer)
Correct answer: The business associate's new activities may exceed the permitted uses of PHI under the existing BAA, creating a violation
Using PHI for purposes beyond those specified in the BAA violates HIPAA; the BAA must be amended to authorize new activities involving PHI.
Question 54: Which of the following scenarios BEST illustrates the right to confidential communications?
- A patient demands to see who entered information into their chart
- A patient requests that their records be destroyed after treatment
- A patient asks that their diagnosis never be shared with anyone
- A patient asks the provider to call them at their work number rather than home (Correct answer)
Correct answer: A patient asks the provider to call them at their work number rather than home
Requesting an alternative contact number is a classic example of exercising the right to confidential communications.
Question 55: Under the HIPAA Privacy Rule, a covered entity may use or disclose PHI for research without individual authorization when:
- The researcher is employed full-time by the covered entity
- The research will be published in a peer-reviewed journal within 12 months
- The research is funded entirely by a federal agency such as the NIH
- An Institutional Review Board (IRB) or Privacy Board has approved a waiver of authorization (Correct answer)
Correct answer: An Institutional Review Board (IRB) or Privacy Board has approved a waiver of authorization
HIPAA permits use or disclosure of PHI for research without individual authorization if an IRB or Privacy Board has approved a waiver, finding that the research meets specific criteria (e.g., minimal privacy risk, impracticable to conduct otherwise). Employment status and funding source are not the determining factors.
Question 56: Which of the following is a required element in every Business Associate Agreement?
- A prohibition on the business associate using or disclosing PHI beyond what is permitted by the agreement (Correct answer)
- A requirement to store PHI only in the covered entity's data center
- An annual audit conducted by the covered entity
- A fixed pricing schedule for services rendered
Correct answer: A prohibition on the business associate using or disclosing PHI beyond what is permitted by the agreement
BAAs must prohibit the business associate from using or disclosing PHI in any manner not permitted or required by the agreement.
Question 57: How does HIPAA treat mental health records differently in the context of a parent's access to their minor child's mental health records?
- Mental health records of minors are completely sealed and inaccessible to parents under HIPAA
- Parents always have full access to minor children's mental health records
- State law governs whether parents can access minor mental health records, and in some states minors may consent to mental health treatment independently, limiting parental access (Correct answer)
- HIPAA grants parents unrestricted access to all minor children's PHI regardless of age
Correct answer: State law governs whether parents can access minor mental health records, and in some states minors may consent to mental health treatment independently, limiting parental access
HIPAA defers to state law on minors' rights in mental health treatment — in many states, minors can consent to mental health treatment without parental consent, limiting parental access under HIPAA.
Question 58: An employee accidentally emails PHI to a wrong recipient who is also a healthcare employee and does not open or read it. Under which exception might this NOT be classified as a reportable breach?
- The inadvertent disclosure exception where the recipient could not reasonably retain the information (Correct answer)
- The small breach exception for fewer than 10 individuals
- The de minimis harm exception
- The workforce member good faith exception
Correct answer: The inadvertent disclosure exception where the recipient could not reasonably retain the information
Inadvertent disclosure of PHI between authorized persons where the recipient could not reasonably have retained the information is an exception to the definition of breach.
Question 59: A covered entity sends breach notifications by first-class mail. The affected individual has moved and does not receive the letter. What does HIPAA require the covered entity to do?
- Provide substitute notification if the covered entity knows the notice was not received
- No additional action is required; mailing first-class mail satisfies the obligation (Correct answer)
- Resend the notification via certified mail immediately
- Attempt email notification as a follow-up
Correct answer: No additional action is required; mailing first-class mail satisfies the obligation
Sending breach notifications via first-class mail to the last known address satisfies HIPAA's notification requirement, even if the individual has moved.
Question 60: Under the HIPAA Privacy Rule, which of the following entities is considered a 'covered entity'?
- A janitorial service that cleans a hospital
- A software company that builds hospital management tools
- A law firm that occasionally reviews medical records
- A health plan that pays for medical care (Correct answer)
Correct answer: A health plan that pays for medical care
Health plans are one of the three categories of covered entities under HIPAA, along with healthcare providers and healthcare clearinghouses.
Question 61: Which HIPAA provision allows a covered entity to disclose PHI to prevent a serious and imminent threat to the health or safety of a person or the public?
- The serious threat exception (Correct answer)
- The law enforcement exception
- The public interest exception
- The healthcare operations exception
Correct answer: The serious threat exception
HIPAA's serious threat exception permits covered entities to disclose PHI to law enforcement or others who can prevent or lessen a serious and imminent threat to the health or safety of a person or the public.
Question 62: What is the primary purpose of the 'termination for cause' provision typically included in a BAA?
- To enable the business associate to end the contract if the covered entity changes its EHR system
- To permit the covered entity to terminate the BAA if the business associate materially breaches its PHI obligations (Correct answer)
- To set automatic renewal terms for the BAA
- To allow either party to exit the contract without penalty for financial reasons
Correct answer: To permit the covered entity to terminate the BAA if the business associate materially breaches its PHI obligations
The termination for cause provision allows the covered entity to end the relationship if the business associate violates the BAA's PHI protection requirements.
Question 63: OCR's resolution agreements typically require a covered entity to pay a monetary settlement AND:
- Submit to annual third-party audits indefinitely
- Implement a corrective action plan (CAP) (Correct answer)
- Terminate all business associate agreements
- Notify every affected patient individually
Correct answer: Implement a corrective action plan (CAP)
Resolution agreements include both a financial settlement and a corrective action plan (CAP) outlining the steps the entity must take to achieve compliance.
Question 64: A clinic is notified by the HHS Office for Civil Rights (OCR) of a potential HIPAA violation. The investigation reveals the violation was due to reasonable cause and not willful neglect. The clinic immediately takes corrective action. Which of the following is an affirmative defense that could prevent OCR from imposing a civil monetary penalty?
- The violation was corrected within 30 days of when the clinic knew or should have known about it. (Correct answer)
- The clinic has a history of excellent patient care.
- The financial cost of the penalty would be excessive for the clinic.
- The violation was a first-time offense for the clinic.
Correct answer: The violation was corrected within 30 days of when the clinic knew or should have known about it.
Under 45 CFR § 160.410, an affirmative defense exists if the violation was due to reasonable cause (and not willful neglect) and was corrected within 30 days. If these conditions are met, HHS is prohibited from imposing a civil monetary penalty. While other factors might mitigate the amount, timely correction of a 'reasonable cause' violation is a specific affirmative defense.
Question 65: Which of the following is NOT a required element of the contact information a covered entity must provide in a breach notification letter?
- A toll-free phone number active for at least 90 days
- An email address for individuals to ask questions
- A website address where individuals can get more information
- The name and title of the privacy officer who authorized the notification (Correct answer)
Correct answer: The name and title of the privacy officer who authorized the notification
Breach notifications must include a toll-free number, email address, or website for questions, but HIPAA does not require the name and title of the privacy officer who authorized the notification.
Question 66: Which of the following is an exception to the Breach Notification Rule that does NOT require notification?
- An unintentional acquisition of PHI by a workforce member acting in good faith (Correct answer)
- A ransomware attack that encrypts PHI
- An email containing PHI sent to the wrong patient
- A stolen laptop with unencrypted PHI
Correct answer: An unintentional acquisition of PHI by a workforce member acting in good faith
Unintentional acquisition, access, or use of PHI by a workforce member acting in good faith and within scope of authority is an exception to breach notification.
Question 67: What must a covered entity include in its Notice of Privacy Practices (NPP)?
- A complete list of all business associates
- The specific fees charged for releasing medical records
- A description of the types of uses and disclosures the covered entity may make of PHI (Correct answer)
- The names of all employees who have accessed patient records
Correct answer: A description of the types of uses and disclosures the covered entity may make of PHI
The NPP must describe how the covered entity may use and disclose PHI, patient rights, and the covered entity's legal duties regarding PHI.
Question 68: A health plan auditor reviews claims and requests full treatment records. The provider believes a summary of relevant services would suffice. The Minimum Necessary Standard supports:
- Deferring entirely to the health plan's judgment on what records they need
- Refusing any records request until the plan submits a formal legal demand
- Providing only the information that is reasonably necessary to satisfy the auditor's stated purpose (Correct answer)
- Providing full records because health plans have broad access rights for payment purposes
Correct answer: Providing only the information that is reasonably necessary to satisfy the auditor's stated purpose
Even for payment-related disclosures, covered entities must make reasonable efforts to limit disclosure to what is actually necessary for the specific request.
Question 69: Which organization develops and maintains the ASC X12 transaction standards that HIPAA requires for most electronic healthcare transactions?
- The American Medical Association (AMA)
- Accredited Standards Committee X12 (ASC X12) (Correct answer)
- The Office of the National Coordinator for Health IT (ONC)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: Accredited Standards Committee X12 (ASC X12)
ASC X12 is the standards development organization that creates and maintains the X12 electronic data interchange (EDI) standards adopted by HIPAA. CMS enforces HIPAA; the AMA maintains CPT codes; ONC oversees health IT policy but does not develop transaction standards.
Question 70: A covered entity provides breach notification to affected individuals 45 days after discovery. Is this compliant with HIPAA?
- No, notification must occur within 30 days of discovery
- Yes, notification within 60 days of discovery satisfies the requirement (Correct answer)
- No, notification must occur within 10 days of discovery for large breaches
- Yes, but only if fewer than 100 individuals were affected
Correct answer: Yes, notification within 60 days of discovery satisfies the requirement
HIPAA requires individual breach notification without unreasonable delay and within 60 days of discovery, so 45 days is compliant.
Question 71: Under the Security Rule, which standard specifically requires mechanisms to record and examine activity in information systems containing ePHI?
- Access Control
- Audit Controls (Correct answer)
- Integrity
- Transmission Security
Correct answer: Audit Controls
Audit Controls is a required standard under Technical Safeguards that mandates hardware, software, or procedural mechanisms to record and examine access to ePHI systems.
Question 72: A patient discovers an error in their medical record and submits a formal written request to their provider to have it corrected. Under the HIPAA Privacy Rule, what right is the patient exercising?
- The Right to Amend PHI (Correct answer)
- The Right to an Accounting of Disclosures
- The Right of Access
- The Right to Restrict Disclosures
Correct answer: The Right to Amend PHI
The HIPAA Privacy Rule provides patients with the right to request an amendment of their PHI in a designated record set if they believe the information is inaccurate or incomplete. The covered entity must then review the request and either make the amendment or provide a written denial to the patient.
Question 73: A marketing firm offers to analyze patient data and share aggregated results with third parties for profit. A covered entity wants to hire this firm. What HIPAA concern arises?
- The covered entity only needs a data use agreement, not a BAA
- The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes (Correct answer)
- This arrangement is permitted as long as the data is anonymized before sharing
- Marketing firms are exempt from BAA requirements
Correct answer: The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes
A BAA must prohibit business associates from using PHI for their own purposes, including commercial gain, beyond what the agreement permits.
Question 74: A research institution wants to use a large dataset of patient information for a study. To avoid HIPAA constraints, they decide to de-identify the data using the Safe Harbor method. Which of the following must be removed from the dataset?
- The patient's year of birth.
- The state of residence for all patients.
- The first three digits of a zip code if the area has fewer than 20,000 people. (Correct answer)
- All patient ages over 89, aggregated into a single category of '90 or older'.
Correct answer: The first three digits of a zip code if the area has fewer than 20,000 people.
The Safe Harbor method requires the removal of 18 specific identifiers. For geographic subdivisions smaller than a state, zip codes must be handled carefully. The initial three digits of a zip code must be removed (or changed to 000) if the geographic unit contains 20,000 or fewer people. The state of residence and year of birth (for those under 90) are generally permissible, and aggregating ages over 89 is a requirement, not a removal of a valid data point.
Question 75: Under HIPAA, 'de-identification' of PHI can be achieved through which two accepted methods?
- Expert determination and safe harbor (Correct answer)
- Encryption and tokenization
- Anonymization and pseudonymization
- Redaction and aggregation
Correct answer: Expert determination and safe harbor
HIPAA recognizes two official de-identification methods: Expert Determination (statistical verification of re-identification risk) and the Safe Harbor method (removal of all 18 identifiers).
HIPAA Compliance Certification Exam
The HIPAA Compliance Certification exam tests knowledge of the Health Insurance Portability and Accountability Act, including the Privacy Rule, Security Rule, Breach Notification Rule, PHI handling, patient rights, business associate requirements, and enforcement penalties.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds