1|Page
RHIA CERTIFICATION MOCK EXAMINATION
2026 ACTUAL QUESTIONS AND CORRECT
DETAILED ANSWERS WITH RATIONALES
ALREADY A GRADED WITH EXPERT
FEEDBACK |2 CURRENTLY TESTING
VERSIONS|NEW AND REVISED
Credential: Registered Health Information Administrator (RHIA)
Governing Body: American Health Information Management Association
Format: Multiple Choice (Single Best Answer)
Total Questions: 400 | (Full Exam Target): 180
Section 1: Questions 1–30
(Answers bolded with detailed rationales in italics)
This mock exam mirrors the RHIA blueprint used by the American Health Information
Management Association, assessing core competencies in health data governance,
privacy/security, coding & classification, revenue cycle, informatics, compliance, analytics, and
leadership. The exam emphasizes application, decision-making, regulatory knowledge, and real-
world scenarios expected of competent Registered Health Information Administrators. Useful for
self-study and targeted remediation.
1. Which regulation provides the primary federal framework for protecting patients’
individually identifiable health information in the United States?
A. HITECH Act
B. FERPA
C. HIPAA Privacy Rule
D. Sarbanes-Oxley Act
Rationale: The HIPAA Privacy Rule establishes national standards for protecting
individually identifiable health information. The HITECH Act expanded HIPAA
enforcement and breach notification but HIPAA is the primary privacy framework.
2. Under HIPAA, which of the following is considered a valid authorization for disclosure
of PHI?
A. Verbal permission from a family member only
B. Implied consent through treatment without documentation
C. A written and signed authorization that specifies recipient, purpose, and an
expiration date
D. A blanket authorization signed at time of employment for all future uses
Rationale: HIPAA requires a valid written authorization with specific elements
(recipient, purpose, expiration, signature) for most disclosures not otherwise permitted.
3. A hospital intends to repurpose patient data for a secondary research project without
individual authorizations. Which action best supports compliance?
A. Publish identifiable records online for peer reviewers
,2|Page
B. De-identify data per the Safe Harbor or expert determination method
C. Sell data to researchers without a DUA
D. Use social security numbers to link additional data
Rationale: Use of de-identified data (or obtaining IRB approval and a waiver) supports
secondary research without patient authorizations; identifiable data requires
authorization or an approved waiver and appropriate data use agreements.
4. Who owns the physical medical record in most U.S. health care organizations?
A. The patient
B. The health care provider / organization that created and maintains the record
C. The payer who reimbursed services
D. The state health department
Rationale: Typically the provider or facility owns the physical record; however, patients
have rights to access and obtain copies of their health information.
5. Which HIPAA right allows a patient to request changes to incorrect data in their health
record?
A. Right to accounting of disclosures
B. Right to restrict disclosures
C. Right to request amendment
D. Right to confidential communications
Rationale: Patients may request amendments (corrections) to protected health
information; the covered entity must evaluate and respond per HIPAA timelines.
6. A release of information (ROI) request asks for complete mental health psychotherapy
notes. Under HIPAA, how should these be treated?
A. Released with any medical record request automatically
B. Never released under any circumstance
C. Psychotherapy notes are afforded special protections and require specific
authorization for most disclosures
D. Treated as radiology reports
Rationale: Psychotherapy notes (separate from medical record progress notes) have
stricter protections and generally require specific patient authorization.
7. Which of the following is a core component of an effective data governance program?
A. Purchasing more storage capacity
B. Defined policies, assigned stewardship roles, and data quality metrics
C. Eliminating all legacy data
D. Allowing informal ad hoc data requests only
Rationale: Data governance requires policies, stewardship, accountability, and quality
metrics to ensure data reliability and usability.
8. A health system is implementing master patient index (MPI) improvements. Which
activity most directly reduces duplicate records?
A. Increasing chart access privileges uniformly
B. Storing multiple SSNs per record
C. Applying enterprise-wide patient matching algorithms and standardized
demographic capture
D. Deleting older records older than 1 year
Rationale: Matching algorithms and standardized demographic data entry reduce
duplicate records and improve patient identity management.
,3|Page
9. Under ICD-10-CM coding conventions, which guideline applies when a condition is
described as “due to” another condition?
A. Code the symptom first, then the underlying cause
B. Always code only the symptom
C. Code the underlying cause first (if documented as causal) and the manifesting
condition second
D. Use symptom codes exclusively when cause is listed
Rationale: When a condition is due to another (manifestation), code the underlying
cause first, then the manifestation according to ICD-10-CM sequencing rules.
10. Which code set is primarily used for reporting inpatient procedures in the United States?
A. ICD-10-CM
B. ICD-10-PCS
C. CPT®
D. HCPCS Level II
Rationale: ICD-10-PCS is the U.S. system for coding inpatient procedures; CPT is
commonly used for outpatient and professional services.
11. A facility is validating a new encoder/Coding Assist tool. Which activity best ensures
clinical accuracy?
A. Turning the tool on for everyone without testing
B. Conducting parallel coding and clinician audits before full implementation
C. Deleting all previous coding policies
D. Allowing automated code assignment without human review permanently
Rationale: Parallel testing and audits detect discrepancies and ensure tool accuracy
before full adoption; human oversight is necessary.
12. Under the Notice of Privacy Practices, covered entities must:
A. Obtain signature for release in every encounter
B. Publish all PHI online
C. Provide patients a clear NPP explaining uses, disclosures, and patients’ rights
D. Ignore patient requests for privacy preferences
Rationale: Covered entities must provide a Notice of Privacy Practices that describes
uses of PHI and the patient’s HIPAA rights.
13. Which security control is an example of administrative safeguards under the HIPAA
Security Rule?
A. Encryption of data at rest
B. Workforce training and security policies
C. Firewall configuration
D. Physical door locks
Rationale: Administrative safeguards include policies, procedures, workforce training,
risk analysis, and assigned responsibilities. Technical and physical safeguards cover
encryption and door locks respectively.
14. A health information manager performing a chart review notes that a provider has not
documented a significant procedure in the medical record. The best immediate step is to:
A. Change the record to include the procedure yourself
B. Query the provider for clarification or additional documentation using a
compliant provider query process
C. Ignore the omission
, 4|Page
D. Bill the procedure regardless of documentation
Rationale: Use formal, compliant query processes to obtain clinical clarification; HIM
staff should not alter provider documentation.
15. Which of the following is a permissible use of PHI without patient authorization?
A. Sale of PHI to a marketing company
B. Posting PHI on social media for fundraising
C. Treatment, payment, and health care operations (TPO) consistent with HIPAA
rules
D. Public posting of medical histories for non-health research
Rationale: TPO activities are permitted disclosures under HIPAA without signed
authorization; other uses generally require patient authorization.
16. A facility experiences a breach affecting 700 patients’ e-mail addresses and appointment
details. What is the HIPAA breach notification requirement?
A. No notification needed under any circumstances
B. Notify only leadership internally
C. Notify affected individuals and, if >500 residents of a state or jurisdiction, notify
the HHS Secretary and local media
D. Only notify law enforcement
Rationale: Breaches affecting >500 individuals in a state trigger HHS and media
notification; individual notifications are required in all breaches unless a low
probability of compromise is demonstrated.
17. Which documentation element is necessary to support a medical necessity determination
for inpatient admission?
A. Nursing notes only
B. Patient financial history
C. Attending physician’s admission assessment and justification of inpatient level of
care
D. Staff schedule
Rationale: Medical necessity is supported by physician documentation that explains
why inpatient care (as opposed to outpatient/observation) is required.
18. In revenue cycle management, what is the primary purpose of pre-authorization?
A. To verify clinical diagnoses for research
B. To confirm payer will cover the service and reduce claim denials
C. To obtain patient social media consent
D. To assist in credentialing providers
Rationale: Pre-authorization verifies coverage and helps prevent payer denials for
services that require prior approval.
19. Which governance document defines roles, responsibilities, and accountability for health
data stewardship?
A. Privacy notice
B. Data governance charter
C. Job descriptions only
D. Data retention schedule only
Rationale: A data governance charter articulates structure, roles, responsibilities, and
oversight for data stewardship.
RHIA CERTIFICATION MOCK EXAMINATION
2026 ACTUAL QUESTIONS AND CORRECT
DETAILED ANSWERS WITH RATIONALES
ALREADY A GRADED WITH EXPERT
FEEDBACK |2 CURRENTLY TESTING
VERSIONS|NEW AND REVISED
Credential: Registered Health Information Administrator (RHIA)
Governing Body: American Health Information Management Association
Format: Multiple Choice (Single Best Answer)
Total Questions: 400 | (Full Exam Target): 180
Section 1: Questions 1–30
(Answers bolded with detailed rationales in italics)
This mock exam mirrors the RHIA blueprint used by the American Health Information
Management Association, assessing core competencies in health data governance,
privacy/security, coding & classification, revenue cycle, informatics, compliance, analytics, and
leadership. The exam emphasizes application, decision-making, regulatory knowledge, and real-
world scenarios expected of competent Registered Health Information Administrators. Useful for
self-study and targeted remediation.
1. Which regulation provides the primary federal framework for protecting patients’
individually identifiable health information in the United States?
A. HITECH Act
B. FERPA
C. HIPAA Privacy Rule
D. Sarbanes-Oxley Act
Rationale: The HIPAA Privacy Rule establishes national standards for protecting
individually identifiable health information. The HITECH Act expanded HIPAA
enforcement and breach notification but HIPAA is the primary privacy framework.
2. Under HIPAA, which of the following is considered a valid authorization for disclosure
of PHI?
A. Verbal permission from a family member only
B. Implied consent through treatment without documentation
C. A written and signed authorization that specifies recipient, purpose, and an
expiration date
D. A blanket authorization signed at time of employment for all future uses
Rationale: HIPAA requires a valid written authorization with specific elements
(recipient, purpose, expiration, signature) for most disclosures not otherwise permitted.
3. A hospital intends to repurpose patient data for a secondary research project without
individual authorizations. Which action best supports compliance?
A. Publish identifiable records online for peer reviewers
,2|Page
B. De-identify data per the Safe Harbor or expert determination method
C. Sell data to researchers without a DUA
D. Use social security numbers to link additional data
Rationale: Use of de-identified data (or obtaining IRB approval and a waiver) supports
secondary research without patient authorizations; identifiable data requires
authorization or an approved waiver and appropriate data use agreements.
4. Who owns the physical medical record in most U.S. health care organizations?
A. The patient
B. The health care provider / organization that created and maintains the record
C. The payer who reimbursed services
D. The state health department
Rationale: Typically the provider or facility owns the physical record; however, patients
have rights to access and obtain copies of their health information.
5. Which HIPAA right allows a patient to request changes to incorrect data in their health
record?
A. Right to accounting of disclosures
B. Right to restrict disclosures
C. Right to request amendment
D. Right to confidential communications
Rationale: Patients may request amendments (corrections) to protected health
information; the covered entity must evaluate and respond per HIPAA timelines.
6. A release of information (ROI) request asks for complete mental health psychotherapy
notes. Under HIPAA, how should these be treated?
A. Released with any medical record request automatically
B. Never released under any circumstance
C. Psychotherapy notes are afforded special protections and require specific
authorization for most disclosures
D. Treated as radiology reports
Rationale: Psychotherapy notes (separate from medical record progress notes) have
stricter protections and generally require specific patient authorization.
7. Which of the following is a core component of an effective data governance program?
A. Purchasing more storage capacity
B. Defined policies, assigned stewardship roles, and data quality metrics
C. Eliminating all legacy data
D. Allowing informal ad hoc data requests only
Rationale: Data governance requires policies, stewardship, accountability, and quality
metrics to ensure data reliability and usability.
8. A health system is implementing master patient index (MPI) improvements. Which
activity most directly reduces duplicate records?
A. Increasing chart access privileges uniformly
B. Storing multiple SSNs per record
C. Applying enterprise-wide patient matching algorithms and standardized
demographic capture
D. Deleting older records older than 1 year
Rationale: Matching algorithms and standardized demographic data entry reduce
duplicate records and improve patient identity management.
,3|Page
9. Under ICD-10-CM coding conventions, which guideline applies when a condition is
described as “due to” another condition?
A. Code the symptom first, then the underlying cause
B. Always code only the symptom
C. Code the underlying cause first (if documented as causal) and the manifesting
condition second
D. Use symptom codes exclusively when cause is listed
Rationale: When a condition is due to another (manifestation), code the underlying
cause first, then the manifestation according to ICD-10-CM sequencing rules.
10. Which code set is primarily used for reporting inpatient procedures in the United States?
A. ICD-10-CM
B. ICD-10-PCS
C. CPT®
D. HCPCS Level II
Rationale: ICD-10-PCS is the U.S. system for coding inpatient procedures; CPT is
commonly used for outpatient and professional services.
11. A facility is validating a new encoder/Coding Assist tool. Which activity best ensures
clinical accuracy?
A. Turning the tool on for everyone without testing
B. Conducting parallel coding and clinician audits before full implementation
C. Deleting all previous coding policies
D. Allowing automated code assignment without human review permanently
Rationale: Parallel testing and audits detect discrepancies and ensure tool accuracy
before full adoption; human oversight is necessary.
12. Under the Notice of Privacy Practices, covered entities must:
A. Obtain signature for release in every encounter
B. Publish all PHI online
C. Provide patients a clear NPP explaining uses, disclosures, and patients’ rights
D. Ignore patient requests for privacy preferences
Rationale: Covered entities must provide a Notice of Privacy Practices that describes
uses of PHI and the patient’s HIPAA rights.
13. Which security control is an example of administrative safeguards under the HIPAA
Security Rule?
A. Encryption of data at rest
B. Workforce training and security policies
C. Firewall configuration
D. Physical door locks
Rationale: Administrative safeguards include policies, procedures, workforce training,
risk analysis, and assigned responsibilities. Technical and physical safeguards cover
encryption and door locks respectively.
14. A health information manager performing a chart review notes that a provider has not
documented a significant procedure in the medical record. The best immediate step is to:
A. Change the record to include the procedure yourself
B. Query the provider for clarification or additional documentation using a
compliant provider query process
C. Ignore the omission
, 4|Page
D. Bill the procedure regardless of documentation
Rationale: Use formal, compliant query processes to obtain clinical clarification; HIM
staff should not alter provider documentation.
15. Which of the following is a permissible use of PHI without patient authorization?
A. Sale of PHI to a marketing company
B. Posting PHI on social media for fundraising
C. Treatment, payment, and health care operations (TPO) consistent with HIPAA
rules
D. Public posting of medical histories for non-health research
Rationale: TPO activities are permitted disclosures under HIPAA without signed
authorization; other uses generally require patient authorization.
16. A facility experiences a breach affecting 700 patients’ e-mail addresses and appointment
details. What is the HIPAA breach notification requirement?
A. No notification needed under any circumstances
B. Notify only leadership internally
C. Notify affected individuals and, if >500 residents of a state or jurisdiction, notify
the HHS Secretary and local media
D. Only notify law enforcement
Rationale: Breaches affecting >500 individuals in a state trigger HHS and media
notification; individual notifications are required in all breaches unless a low
probability of compromise is demonstrated.
17. Which documentation element is necessary to support a medical necessity determination
for inpatient admission?
A. Nursing notes only
B. Patient financial history
C. Attending physician’s admission assessment and justification of inpatient level of
care
D. Staff schedule
Rationale: Medical necessity is supported by physician documentation that explains
why inpatient care (as opposed to outpatient/observation) is required.
18. In revenue cycle management, what is the primary purpose of pre-authorization?
A. To verify clinical diagnoses for research
B. To confirm payer will cover the service and reduce claim denials
C. To obtain patient social media consent
D. To assist in credentialing providers
Rationale: Pre-authorization verifies coverage and helps prevent payer denials for
services that require prior approval.
19. Which governance document defines roles, responsibilities, and accountability for health
data stewardship?
A. Privacy notice
B. Data governance charter
C. Job descriptions only
D. Data retention schedule only
Rationale: A data governance charter articulates structure, roles, responsibilities, and
oversight for data stewardship.