• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 63 pages
Exam (elaborations)

HIPAA Compliance Training Post-Test | HIPAA Privacy & Security Compliance Study Guide & Post-Test Prep 2026/2027 | Protected Health Information (PHI), HIPAA Privacy Rule, Security Rule, Breach Notification, Patient Privacy Rights, Minimum Necessary Standa

Document preview thumbnail
Preview 4 out of 63 pages

Prepare for the HIPAA Compliance Training Post-Test with a comprehensive 2026/2027 healthcare compliance study and post-test preparation resource covering the HIPAA Privacy Rule, Security Rule, Protected Health Information (PHI), patient privacy rights, confidentiality, minimum necessary requirements, permitted uses and disclosures, breach notification, administrative safeguards, physical safeguards, technical safeguards, workforce responsibilities, documentation, data security, and practical healthcare compliance scenarios. HHS states that the HIPAA Privacy Rule requires covered entities to establish privacy procedures, train workforce members on those procedures, designate responsibility for compliance, and safeguard individually identifiable health information. Current Stuvia results show active HIPAA Compliance Training Post-Test resources published throughout 2026, including a 72-page February listing and newer June 2026 listings covering PHI, Privacy and Security Rules, breach notification, confidentiality, and healthcare data security. This independent resource is best positioned with original practice questions, workplace compliance scenarios, answers, and detailed rationales rather than claiming to reproduce proprietary employer-training assessments.

Content preview

HIPAA Compliance Training Post-Test | HIPAA Privacy &
Security Compliance Study Guide & Post-Test Prep
2026/2027 | Protected Health Information (PHI), HIPAA
Privacy Rule, Security Rule, Breach Notification, Patient
Privacy Rights, Minimum Necessary Standard, Permitted
Disclosures, Administrative, Physical & Technical
Safeguards, Confidentiality, Workforce Responsibilities,
Healthcare Data Security, Practice Questions, Answers &
Detailed Rationales
Question 1: Under the HIPAA Privacy Rule, which of the following is
considered a permitted disclosure of Protected Health Information (PHI)
without the individual's authorization?
A. Disclosure to a life insurance company for underwriting purposes
B. Disclosure to a journalist for a news story about the hospital
C. Disclosure to a business associate for the purpose of claims processing
D. Disclosure to a pharmaceutical company for marketing a new drug
CORRECT ANSWER: C. Disclosure to a business associate for the purpose of
claims processing
Rationale: The HIPAA Privacy Rule permits covered entities to disclose PHI to business
associates without individual authorization if the disclosure is for treatment, payment, or
healthcare operations (TPO), provided a valid Business Associate Agreement (BAA) is in
place. Claims processing is a payment activity. The other options require specific
authorizations or are not permitted under TPO.


Question 2: What is the maximum civil monetary penalty per violation tier for
a covered entity that did not know of the HIPAA violation and could not have
avoided it with reasonable diligence?
A. $137 per violation
B. $1,377 per violation
C. $13,785 per violation
D. $137,610 per violation
CORRECT ANSWER: B. $1,377 per violation
Rationale: The HITECH Act established tiered penalties. Tier 1 applies when the
covered entity did not know and could not have reasonably avoided the violation, with a
minimum penalty of $137 per violation and a maximum of $1,377 per violation for the
calendar year. The amounts adjust for inflation.


Question 3: A hospital employee receives a subpoena for patient records. What
is the appropriate first step under HIPAA?

,A. Immediately provide the records to comply with the law
B. Ignore the subpoena as a violation of patient privacy
C. Verify the subpoena is valid and seek a qualified protective order or attempt to quash
it
D. Contact the patient's family for permission
CORRECT ANSWER: C. Verify the subpoena is valid and seek a qualified
protective order or attempt to quash it
Rationale: A valid court order or subpoena is not a blanket authorization. The proper
action is to verify its validity and attempt to negotiate a protective order that limits the
disclosure to the minimum necessary, or to quash the subpoena to protect PHI.


Question 4: Which of the following is NOT an example of a physical safeguard
required by the HIPAA Security Rule?
A. Facility access controls
B. Workstation security
C. Encryption of data at rest
D. Security incident procedures
CORRECT ANSWER: D. Security incident procedures
Rationale: Security incident procedures are a type of administrative safeguard, as they
involve policies and procedures for responding to security breaches. Physical safeguards
include facility access controls, workstation security, and device and media controls.


Question 5: A patient requests an electronic copy of their medical records.
Under HIPAA, how long does the covered entity have to provide the requested
records?
A. 15 calendar days
B. 30 calendar days
C. 60 calendar days
D. 90 calendar days
CORRECT ANSWER: B. 30 calendar days
Rationale: The HIPAA Privacy Rule requires covered entities to act on a patient's
request for access to their PHI no later than 30 calendar days from receiving the request.
One 30-day extension is permitted if the entity provides a written explanation.


Question 6: Which of the following constitutes a "Breach" of unsecured PHI
under HIPAA, requiring notification?

,A. Theft of a paper record that is later recovered unread
B. Inadvertent disclosure of PHI to a colleague in the same department who needs it for
treatment
C. An impermissible use or disclosure under the Privacy Rule that compromises the
security or privacy of the PHI
D. Any disclosure of PHI to a business associate
CORRECT ANSWER: C. An impermissible use or disclosure under the Privacy
Rule that compromises the security or privacy of the PHI
Rationale: Under HIPAA, a breach is defined as the acquisition, access, use, or
disclosure of PHI in a manner not permitted that compromises the security or privacy of
the PHI. The breach must be notified unless the covered entity can demonstrate a low
probability the PHI was compromised.


Question 7: A covered entity uses a cloud service provider to store patient
data. What is required before this arrangement can commence?
A. A Business Associate Agreement (BAA)
B. A Memorandum of Understanding (MOU)
C. A data usage consent form signed by all patients
D. Notification to the Department of Health and Human Services (HHS)
CORRECT ANSWER: A. A Business Associate Agreement (BAA)
Rationale: The HIPAA Privacy and Security Rules require covered entities to obtain
written assurances, typically in the form of a Business Associate Agreement (BAA), from
business associates that create, receive, maintain, or transmit PHI, ensuring they will
safeguard the information.


Question 8: What is the "Minimum Necessary" standard in HIPAA?
A. A covered entity must use the smallest number of employees to treat a patient
B. A covered entity must limit the amount of PHI disclosed to the minimum needed to
achieve the intended purpose
C. A covered entity must store the minimum amount of data required by state law
D. A covered entity must treat the minimum number of patients to stay profitable
CORRECT ANSWER: B. A covered entity must limit the amount of PHI
disclosed to the minimum needed to achieve the intended purpose
Rationale: The Minimum Necessary standard requires covered entities to make
reasonable efforts to limit PHI to the minimum necessary to accomplish the intended
purpose of the use, disclosure, or request. This applies to routine and non-routine
disclosures.

, Question 9: The Privacy Rule's individual right of access does NOT apply to
which of the following?
A. Clinical laboratory results
B. Progress notes created by a mental health professional in psychotherapy sessions
C. Billing records
D. Discharge summaries
CORRECT ANSWER: B. Progress notes created by a mental health professional
in psychotherapy sessions
Rationale: The Privacy Rule specifically excludes psychotherapy notes (notes recorded
by a mental health professional documenting counseling session contents) from the
individual’s right of access. They are protected under a different, more stringent
standard.


Question 10: If a breach of unsecured PHI affects 550 individuals, which of the
following is TRUE regarding notification requirements?
A. Only the affected individuals must be notified
B. Notification must be provided to the affected individuals, the media, and the
Secretary of HHS
C. Only the Secretary of HHS must be notified
D. No notification is required if the breach is recovered within 30 days
CORRECT ANSWER: B. Notification must be provided to the affected
individuals, the media, and the Secretary of HHS
Rationale: The Breach Notification Rule requires that for a breach affecting more than
500 individuals, the covered entity must notify the affected individuals, prominent media
outlets serving the area, and the Secretary of HHS without unreasonable delay but no
later than 60 days.


Question 11: An employee accesses the medical records of a celebrity out of
curiosity, despite having no treatment or billing reason. This is an example of:
A. A permitted use under TPO
B. A violation of the Privacy Rule
C. An acceptable practice as a public figure waives privacy rights
D. A breach that automatically requires state attorney general notification
CORRECT ANSWER: B. A violation of the Privacy Rule
Rationale: Accessing PHI without a valid work-related justification (such as treatment,
payment, or operations) is a violation of the HIPAA Privacy Rule. Curiosity is not a
permitted reason for accessing medical records.

Document information

Uploaded on
September 7, 2026
Number of pages
63
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$14.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
819
Followers
0
Items
311
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions