2026 | PRACTICE EXAM QUESTIONS &
VERIFIED ANSWERS | PATIENT PRIVACY, PHI
& HEALTHCARE COMPLIANCE STUDY GUIDE
HIPAA COMPLIANCE TRAINING POST-TEST 2026 | PRACTICE EXAM QUESTIONS
& VERIFIED ANSWERS | PATIENT PRIVACY, PHI & HEALTHCARE COMPLIANCE
STUDY GUIDE
• 200 comprehensive questions covering all major HIPAA Privacy, Security, and
Breach Notification Rules with detailed verified answers
• Study systematically through all sections: use this guide to identify weak areas,
review EXPERT RATIONALE thoroughly, and reinforce compliance knowledge
before taking official assessments
1. What does PHI stand for in HIPAA compliance?
A) Public Health Information
B) Protected Health Information
C) Private Hospital Information
D) Patient Health Identification
E) Protective Healthcare Initiative
CORRECT ANSWER: B) Protected Health Information
EXPERT RATIONALE: Protected Health Information (PHI) is the specific term used in
HIPAA to describe health information that can be linked to an individual. PHI
includes medical records, billing information, and any health information held or
transmitted by covered entities or business associates. Understanding this
definition is fundamental to all HIPAA compliance obligations.
2. Which of the following is NOT considered PHI under HIPAA?
,A) Patient's medical record number
B) Patient's date of birth
C) Patient's social security number
D) Anonymous health statistics about disease prevalence
E) Patient's diagnosis codes
CORRECT ANSWER: D) Anonymous health statistics about disease prevalence
EXPERT RATIONALE: De-identified health information that cannot be linked to a
specific individual is not considered PHI. Anonymous statistics about disease
patterns do not identify any particular person. In contrast, medical record numbers,
dates of birth, social security numbers, and diagnosis codes can all be linked to
individual patients and therefore constitute PHI.
3. What is the primary purpose of the HIPAA Privacy Rule?
A) To establish penalties for healthcare fraud
B) To set standards for protecting patient privacy and controlling the use and
disclosure of PHI
C) To require electronic health record systems in all medical facilities
D) To establish billing procedures for healthcare services
E) To regulate pharmaceutical pricing
CORRECT ANSWER: B) To set standards for protecting patient privacy and
controlling the use and disclosure of PHI
EXPERT RATIONALE: The HIPAA Privacy Rule is specifically designed to establish
national standards that protect patient privacy by limiting how health information
can be used and disclosed by covered entities and business associates. This rule
gives patients rights over their health information and sets limits on how that
information can be used.
,4. Which of the following entities is covered by HIPAA regulations?
A) Life insurance companies that do not handle health information
B) Employers that sponsor health plans
C) Healthcare providers, health plans, and healthcare clearinghouses
D) Retail stores that collect customer contact information
E) Schools that maintain student records
CORRECT ANSWER: C) Healthcare providers, health plans, and healthcare
clearinghouses
EXPERT RATIONALE: HIPAA defines covered entities as healthcare providers
(doctors, hospitals, clinics), health plans (insurance companies, HMOs), and
healthcare clearinghouses (entities that process health information). Life insurance
companies, employers (unless self-insured), retail stores, and schools are generally
not covered entities unless they also operate as health plans or providers.
5. What is a Business Associate under HIPAA?
A) Any employee of a healthcare facility
B) A company or individual that performs services for a covered entity and has
access to PHI
C) A patient advocate or medical consultant
D) A third-party insurance company that does not access PHI
E) Any vendor hired by a covered entity regardless of function
CORRECT ANSWER: B) A company or individual that performs services for a
covered entity and has access to PHI
EXPERT RATIONALE: A Business Associate is specifically defined as an individual or
organization that performs services or functions for a covered entity and, in the
course of performing those services, has access to or creates, receives, maintains,
or transmits PHI. Examples include billing services, IT vendors, transcription
, services, and legal consultants. Business Associates must sign Business Associate
Agreements and have equivalent compliance obligations.
6. What document must be signed between a covered entity and a Business
Associate?
A) Service Agreement
B) Confidentiality Statement
C) Business Associate Agreement (BAA)
D) Purchase Order
E) Terms of Service Contract
CORRECT ANSWER: C) Business Associate Agreement (BAA)
EXPERT RATIONALE: A Business Associate Agreement is a required legally binding
contract between covered entities and their business associates. The BAA
establishes the permitted and required uses and disclosures of PHI, requires
appropriate safeguards, permits termination if there is material breach, and defines
responsibilities for each party regarding HIPAA compliance.
7. Under the HIPAA Privacy Rule, when must a patient have the opportunity
to request restrictions on uses and disclosures of their PHI?
A) Only upon admission to a hospital
B) At the first contact with the healthcare provider
C) At any time during their relationship with the covered entity
D) Only if they file a formal complaint
E) Only if they are participating in research
CORRECT ANSWER: C) At any time during their relationship with the covered
entity