Correct Verified Answers/ Latest Update 2026/ Rated
A+
1. HIPAA rules apply to "business associates" in addition to
health plans and providers. Which of the following are included
under "business associates"?
A) Only employees of the health plan
B) Employees and subcontractors such as contracted sales agents
and brokers
C) Only healthcare providers
D) Only members and beneficiaries
Answer: B
Rationale: Under HIPAA, business associates include employees
and subcontractors such as contracted sales agents and brokers
who handle protected health information (PHI) on behalf of the
1
,health plan . This expands the scope of HIPAA compliance
beyond just health plans and providers.
2. Brandon, a sales agent, completed the review of Cigna
policies and procedures and signed the attestation to comply last
year. Will Brandon be required to complete the review and
attestation again this year?
A) No, the attestation is valid for 3 years
B) Yes, all sales agents are contractually obligated to review
and abide by policies and sign an attestation yearly
C) Only if there are major policy changes
D) Only if requested by the compliance department
Answer: B
Rationale: All sales agents of Cigna are contractually obligated
to review and abide by the policies and procedures and sign an
attestation yearly . This ensures agents remain current with
evolving compliance requirements and company policies.
2
,3. Which of the following is a reason why the Compliance
Department conducts internal and external audits?
A) To identify areas of risk and compliance with Federal and
State regulatory guidelines
B) To evaluate sales performance
C) To determine salary increases
D) To assess marketing effectiveness
Answer: A
Rationale: The Compliance Department conducts internal and
external audits to identify areas of risk and ensure compliance
with Federal and State regulatory guidelines . This proactive
approach helps prevent violations and protect both the company
and its customers.
4. Which of the following statements is true of the HITECH Act?
3
, A) It only applies to healthcare providers
B) It made business associates of covered entities directly liable
for compliance with certain HIPAA Security and Privacy Rules
C) It eliminated all HIPAA requirements
D) It only applies to government agencies
Answer: B
Rationale: The HITECH Act made business associates of covered
entities directly liable for compliance with certain HIPAA Security
and Privacy Rules . This significantly expanded the scope of
HIPAA compliance obligations.
5. Which of the following best describes the auditing and
monitoring programs of the Sales Development Action Program
(SDAP)?
A) Sales Integrity monitors data pertaining to the sale of Cigna
products and potential violations of state, federal, or Cigna
policy
4