RHIT Compliance, Privacy, and Security EXAM 2026/2027 ACTUAL
QUESTIONS AND 100% CORRECT ANSWERS WITH RATIONS
1. What is the primary purpose of a healthcare privacy program?
A. Increase reimbursement
B. Protect individuals' health information and establish appropriate
uses and disclosures
C. Eliminate all electronic records
D. Reduce staffing
Answer: B
Rationale: Privacy programs establish safeguards and rules governing
the appropriate use and disclosure of protected health information.
2. Which term describes information that identifies an individual and
relates to the individual's health or healthcare?
A. PHI
B. Metadata only
C. Public information
D. Aggregate information
Answer: A
Rationale: Protected health information (PHI) is individually identifiable
health information maintained or transmitted by a covered entity or
business associate.
3. Which principle requires access to information only when needed
to perform assigned duties?
A. Minimum necessary
B. Maximum disclosure
C. Open access
D. Universal access
,Answer: A
Rationale: The minimum-necessary principle limits use, disclosure, and
requests for PHI to what is reasonably necessary for the intended
purpose, subject to applicable exceptions.
4. Which is an example of a direct identifier?
A. Patient name
B. Average length of stay
C. Hospital occupancy rate
D. Disease prevalence
Answer: A
Rationale: A patient's name directly identifies the individual.
5. Which information is generally considered de-identified rather than
PHI when properly processed under applicable requirements?
A. Data from which specified identifiers have been appropriately
removed
B. A patient's full name and diagnosis
C. A medical record number with no safeguards
D. A complete identifiable billing record
Answer: A
Rationale: Proper de-identification reduces the ability to associate the
information with a particular individual.
6. What is the primary purpose of an authorization?
A. Permit specified uses or disclosures of PHI that require the
individual's authorization
B. Replace all privacy policies
C. Grant every employee access
D. Eliminate security controls
,Answer: A
Rationale: An authorization gives an individual permission for specified
uses or disclosures when authorization is required.
7. Which document commonly describes how an organization may use
and disclose an individual's PHI?
A. Notice of Privacy Practices
B. Employee time sheet
C. Disaster-recovery plan
D. Coding worksheet
Answer: A
Rationale: The Notice of Privacy Practices explains permitted uses and
disclosures and describes individual privacy rights.
8. What is a business associate?
A. A person or organization that performs certain functions or services
involving PHI on behalf of a covered entity
B. Any hospital employee
C. Every patient
D. Any insurance beneficiary
Answer: A
Rationale: Business associates perform specified services or functions
for covered entities involving protected health information.
9. What agreement generally establishes permitted PHI handling
responsibilities between a covered entity and business associate?
A. Business Associate Agreement
B. Employment contract
C. Lease agreement
D. Purchase order only
, Answer: A
Rationale: A business associate agreement establishes required privacy
and security responsibilities.
10. Which is an example of a covered entity?
A. Healthcare provider conducting covered electronic transactions
B. Any individual patient
C. Every retail business
D. Any social-media company
Answer: A
Rationale: Covered entities include certain healthcare providers, health
plans, and healthcare clearinghouses subject to HIPAA.
11. Which HIPAA component addresses permitted uses and
disclosures of PHI?
A. Privacy Rule
B. Security Rule only
C. Accounting Rule only
D. Coding Rule
Answer: A
Rationale: The Privacy Rule establishes standards for uses and
disclosures of PHI and individual rights.
12. Which HIPAA component specifically addresses electronic PHI
security?
A. Security Rule
B. Privacy Rule only
C. Coding Rule
D. Reimbursement Rule
QUESTIONS AND 100% CORRECT ANSWERS WITH RATIONS
1. What is the primary purpose of a healthcare privacy program?
A. Increase reimbursement
B. Protect individuals' health information and establish appropriate
uses and disclosures
C. Eliminate all electronic records
D. Reduce staffing
Answer: B
Rationale: Privacy programs establish safeguards and rules governing
the appropriate use and disclosure of protected health information.
2. Which term describes information that identifies an individual and
relates to the individual's health or healthcare?
A. PHI
B. Metadata only
C. Public information
D. Aggregate information
Answer: A
Rationale: Protected health information (PHI) is individually identifiable
health information maintained or transmitted by a covered entity or
business associate.
3. Which principle requires access to information only when needed
to perform assigned duties?
A. Minimum necessary
B. Maximum disclosure
C. Open access
D. Universal access
,Answer: A
Rationale: The minimum-necessary principle limits use, disclosure, and
requests for PHI to what is reasonably necessary for the intended
purpose, subject to applicable exceptions.
4. Which is an example of a direct identifier?
A. Patient name
B. Average length of stay
C. Hospital occupancy rate
D. Disease prevalence
Answer: A
Rationale: A patient's name directly identifies the individual.
5. Which information is generally considered de-identified rather than
PHI when properly processed under applicable requirements?
A. Data from which specified identifiers have been appropriately
removed
B. A patient's full name and diagnosis
C. A medical record number with no safeguards
D. A complete identifiable billing record
Answer: A
Rationale: Proper de-identification reduces the ability to associate the
information with a particular individual.
6. What is the primary purpose of an authorization?
A. Permit specified uses or disclosures of PHI that require the
individual's authorization
B. Replace all privacy policies
C. Grant every employee access
D. Eliminate security controls
,Answer: A
Rationale: An authorization gives an individual permission for specified
uses or disclosures when authorization is required.
7. Which document commonly describes how an organization may use
and disclose an individual's PHI?
A. Notice of Privacy Practices
B. Employee time sheet
C. Disaster-recovery plan
D. Coding worksheet
Answer: A
Rationale: The Notice of Privacy Practices explains permitted uses and
disclosures and describes individual privacy rights.
8. What is a business associate?
A. A person or organization that performs certain functions or services
involving PHI on behalf of a covered entity
B. Any hospital employee
C. Every patient
D. Any insurance beneficiary
Answer: A
Rationale: Business associates perform specified services or functions
for covered entities involving protected health information.
9. What agreement generally establishes permitted PHI handling
responsibilities between a covered entity and business associate?
A. Business Associate Agreement
B. Employment contract
C. Lease agreement
D. Purchase order only
, Answer: A
Rationale: A business associate agreement establishes required privacy
and security responsibilities.
10. Which is an example of a covered entity?
A. Healthcare provider conducting covered electronic transactions
B. Any individual patient
C. Every retail business
D. Any social-media company
Answer: A
Rationale: Covered entities include certain healthcare providers, health
plans, and healthcare clearinghouses subject to HIPAA.
11. Which HIPAA component addresses permitted uses and
disclosures of PHI?
A. Privacy Rule
B. Security Rule only
C. Accounting Rule only
D. Coding Rule
Answer: A
Rationale: The Privacy Rule establishes standards for uses and
disclosures of PHI and individual rights.
12. Which HIPAA component specifically addresses electronic PHI
security?
A. Security Rule
B. Privacy Rule only
C. Coding Rule
D. Reimbursement Rule