HIPAA - HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT FINAL
EXAM 2026/2027 EXAM READY - VERIFIED QUESTIONS AND ANSWERS VERIFIED BY
EXPERTS - COMPREHENSIVE LATEST VERSION
Q1. What does HIPAA stand for?
ANS: Health Insurance Portability and Accountability Act.
Q2. In what year was HIPAA enacted?
ANS: 1996.
Q3. What are the two main titles of HIPAA?
ANS: Title I covers health insurance reform (portability); Title II covers
administrative simplification, including privacy and security rules.
Q4. What is the primary purpose of HIPAA?
ANS: To protect the privacy and security of individuals' health
information, ensure health insurance portability, and reduce
healthcare fraud and administrative costs.
Q5. Which federal agency enforces HIPAA?
ANS: The Office for Civil Rights (OCR) within the U.S. Department of
Health and Human Services (HHS).
Q6. What is a Covered Entity under HIPAA?
ANS: A health plan, healthcare clearinghouse, or healthcare provider
that transmits health information electronically in connection with a
HIPAA-covered transaction.
,Q7. What is a Business Associate under HIPAA?
ANS: A person or entity that performs services on behalf of a covered
entity and, in doing so, creates, receives, maintains, or transmits
protected health information (PHI).
Q8. What is PHI?
ANS: Protected Health Information — any individually identifiable health
information held or transmitted by a covered entity or business
associate in any form (electronic, paper, or oral).
Q9. What is ePHI?
ANS: Electronic Protected Health Information — PHI that is created,
stored, transmitted, or received in electronic form.
Q10. Name the four main HIPAA Rules.
ANS: The Privacy Rule, the Security Rule, the Breach Notification Rule,
and the Omnibus Rule.
Q11. What does the HIPAA Privacy Rule govern?
ANS: The use and disclosure of PHI by covered entities and business
associates, and patients' rights over their health information.
Q12. What does the HIPAA Security Rule govern?
ANS: The safeguards that covered entities and business associates
must implement to protect ePHI — administrative, physical, and
technical safeguards.
Q13. What is the HITECH Act?
ANS: The Health Information Technology for Economic and Clinical
Health Act (2009), which strengthened HIPAA privacy and security
provisions and increased penalties for violations.
,Q14. What year was the HIPAA Omnibus Rule finalized?
ANS: 2013.
Q15. What major change did the Omnibus Rule make regarding
Business Associates?
ANS: It made Business Associates directly liable for HIPAA compliance
and required them to comply with the Security Rule and certain
Privacy Rule provisions.
Q16. Are verbal communications of PHI covered under HIPAA?
ANS: Yes. PHI includes oral communications, not just written or
electronic forms.
Q17. Which of the following is NOT a covered entity: hospital,
health insurance company, employer, or healthcare
clearinghouse?
ANS: An employer (in its role as an employer) is generally not a covered
entity.
Q18. What is a healthcare clearinghouse under HIPAA?
ANS: An entity that processes nonstandard health information it
receives from another entity into a standard format, or vice versa.
Q19. Does HIPAA apply to all medical records in the United
States?
ANS: No. HIPAA applies only to covered entities and their business
associates. Records held by entities outside HIPAA's scope (e.g.,
certain employers) may not be covered.
Q20. What is the minimum necessary standard?
ANS: The requirement that covered entities make reasonable efforts to
limit the use, disclosure, and requests for PHI to the minimum
necessary to accomplish the intended purpose.
, Q21. What is a Notice of Privacy Practices (NPP)?
ANS: A document that covered entities must provide to patients
describing how PHI may be used and disclosed and what rights
patients have over their information.
Q22. How often must a covered entity update its Notice of Privacy
Practices?
ANS: Whenever a material change is made to privacy practices; the
revised notice must be promptly available and posted.
Q23. What is an Authorization under HIPAA?
ANS: A signed document giving the covered entity permission to use or
disclose PHI for purposes beyond treatment, payment, and
healthcare operations.
Q24. Name three elements required in a valid HIPAA Authorization.
ANS: A description of the PHI to be used/disclosed, the name of the
person/entity authorized to make the disclosure, the purpose of
the disclosure, an expiration date or event, the patient's signature
and date, and a statement that the patient may revoke
authorization.
Q25. Can a covered entity condition treatment on the patient
signing an Authorization?
ANS: Generally no, with limited exceptions (e.g., research-related
treatment, certain health plan enrollment).
Q26. What is the difference between 'use' and 'disclosure' of PHI
under HIPAA?
ANS: 'Use' refers to sharing PHI within the covered entity. 'Disclosure'
refers to sharing PHI with parties outside the covered entity.
EXAM 2026/2027 EXAM READY - VERIFIED QUESTIONS AND ANSWERS VERIFIED BY
EXPERTS - COMPREHENSIVE LATEST VERSION
Q1. What does HIPAA stand for?
ANS: Health Insurance Portability and Accountability Act.
Q2. In what year was HIPAA enacted?
ANS: 1996.
Q3. What are the two main titles of HIPAA?
ANS: Title I covers health insurance reform (portability); Title II covers
administrative simplification, including privacy and security rules.
Q4. What is the primary purpose of HIPAA?
ANS: To protect the privacy and security of individuals' health
information, ensure health insurance portability, and reduce
healthcare fraud and administrative costs.
Q5. Which federal agency enforces HIPAA?
ANS: The Office for Civil Rights (OCR) within the U.S. Department of
Health and Human Services (HHS).
Q6. What is a Covered Entity under HIPAA?
ANS: A health plan, healthcare clearinghouse, or healthcare provider
that transmits health information electronically in connection with a
HIPAA-covered transaction.
,Q7. What is a Business Associate under HIPAA?
ANS: A person or entity that performs services on behalf of a covered
entity and, in doing so, creates, receives, maintains, or transmits
protected health information (PHI).
Q8. What is PHI?
ANS: Protected Health Information — any individually identifiable health
information held or transmitted by a covered entity or business
associate in any form (electronic, paper, or oral).
Q9. What is ePHI?
ANS: Electronic Protected Health Information — PHI that is created,
stored, transmitted, or received in electronic form.
Q10. Name the four main HIPAA Rules.
ANS: The Privacy Rule, the Security Rule, the Breach Notification Rule,
and the Omnibus Rule.
Q11. What does the HIPAA Privacy Rule govern?
ANS: The use and disclosure of PHI by covered entities and business
associates, and patients' rights over their health information.
Q12. What does the HIPAA Security Rule govern?
ANS: The safeguards that covered entities and business associates
must implement to protect ePHI — administrative, physical, and
technical safeguards.
Q13. What is the HITECH Act?
ANS: The Health Information Technology for Economic and Clinical
Health Act (2009), which strengthened HIPAA privacy and security
provisions and increased penalties for violations.
,Q14. What year was the HIPAA Omnibus Rule finalized?
ANS: 2013.
Q15. What major change did the Omnibus Rule make regarding
Business Associates?
ANS: It made Business Associates directly liable for HIPAA compliance
and required them to comply with the Security Rule and certain
Privacy Rule provisions.
Q16. Are verbal communications of PHI covered under HIPAA?
ANS: Yes. PHI includes oral communications, not just written or
electronic forms.
Q17. Which of the following is NOT a covered entity: hospital,
health insurance company, employer, or healthcare
clearinghouse?
ANS: An employer (in its role as an employer) is generally not a covered
entity.
Q18. What is a healthcare clearinghouse under HIPAA?
ANS: An entity that processes nonstandard health information it
receives from another entity into a standard format, or vice versa.
Q19. Does HIPAA apply to all medical records in the United
States?
ANS: No. HIPAA applies only to covered entities and their business
associates. Records held by entities outside HIPAA's scope (e.g.,
certain employers) may not be covered.
Q20. What is the minimum necessary standard?
ANS: The requirement that covered entities make reasonable efforts to
limit the use, disclosure, and requests for PHI to the minimum
necessary to accomplish the intended purpose.
, Q21. What is a Notice of Privacy Practices (NPP)?
ANS: A document that covered entities must provide to patients
describing how PHI may be used and disclosed and what rights
patients have over their information.
Q22. How often must a covered entity update its Notice of Privacy
Practices?
ANS: Whenever a material change is made to privacy practices; the
revised notice must be promptly available and posted.
Q23. What is an Authorization under HIPAA?
ANS: A signed document giving the covered entity permission to use or
disclose PHI for purposes beyond treatment, payment, and
healthcare operations.
Q24. Name three elements required in a valid HIPAA Authorization.
ANS: A description of the PHI to be used/disclosed, the name of the
person/entity authorized to make the disclosure, the purpose of
the disclosure, an expiration date or event, the patient's signature
and date, and a statement that the patient may revoke
authorization.
Q25. Can a covered entity condition treatment on the patient
signing an Authorization?
ANS: Generally no, with limited exceptions (e.g., research-related
treatment, certain health plan enrollment).
Q26. What is the difference between 'use' and 'disclosure' of PHI
under HIPAA?
ANS: 'Use' refers to sharing PHI within the covered entity. 'Disclosure'
refers to sharing PHI with parties outside the covered entity.