Security Compliance Study Guide & Post-Test Prep
2026/2027 | Protected Health Information (PHI), HIPAA
Privacy Rule, Security Rule, Breach Notification, Patient
Privacy Rights, Minimum Necessary Standard, Permitted
Disclosures, Administrative, Physical & Technical
Safeguards, Confidentiality, Workforce Responsibilities,
Healthcare Data Security, Practice Questions, Answers &
Detailed Rationales
Question 1: Under the HIPAA Privacy Rule, which of the following is
considered a permitted disclosure of Protected Health Information (PHI)
without the individual's authorization?
A. Disclosure to a life insurance company for underwriting purposes
B. Disclosure to a journalist for a news story about the hospital
C. Disclosure to a business associate for the purpose of claims processing
D. Disclosure to a pharmaceutical company for marketing a new drug
CORRECT ANSWER: C. Disclosure to a business associate for the purpose of
claims processing
Rationale: The HIPAA Privacy Rule permits covered entities to disclose PHI to business
associates without individual authorization if the disclosure is for treatment, payment, or
healthcare operations (TPO), provided a valid Business Associate Agreement (BAA) is in
place. Claims processing is a payment activity. The other options require specific
authorizations or are not permitted under TPO.
Question 2: What is the maximum civil monetary penalty per violation tier for
a covered entity that did not know of the HIPAA violation and could not have
avoided it with reasonable diligence?
A. $137 per violation
B. $1,377 per violation
C. $13,785 per violation
D. $137,610 per violation
CORRECT ANSWER: B. $1,377 per violation
Rationale: The HITECH Act established tiered penalties. Tier 1 applies when the
covered entity did not know and could not have reasonably avoided the violation, with a
minimum penalty of $137 per violation and a maximum of $1,377 per violation for the
calendar year. The amounts adjust for inflation.
Question 3: A hospital employee receives a subpoena for patient records. What
is the appropriate first step under HIPAA?
,A. Immediately provide the records to comply with the law
B. Ignore the subpoena as a violation of patient privacy
C. Verify the subpoena is valid and seek a qualified protective order or attempt to quash
it
D. Contact the patient's family for permission
CORRECT ANSWER: C. Verify the subpoena is valid and seek a qualified
protective order or attempt to quash it
Rationale: A valid court order or subpoena is not a blanket authorization. The proper
action is to verify its validity and attempt to negotiate a protective order that limits the
disclosure to the minimum necessary, or to quash the subpoena to protect PHI.
Question 4: Which of the following is NOT an example of a physical safeguard
required by the HIPAA Security Rule?
A. Facility access controls
B. Workstation security
C. Encryption of data at rest
D. Security incident procedures
CORRECT ANSWER: D. Security incident procedures
Rationale: Security incident procedures are a type of administrative safeguard, as they
involve policies and procedures for responding to security breaches. Physical safeguards
include facility access controls, workstation security, and device and media controls.
Question 5: A patient requests an electronic copy of their medical records.
Under HIPAA, how long does the covered entity have to provide the requested
records?
A. 15 calendar days
B. 30 calendar days
C. 60 calendar days
D. 90 calendar days
CORRECT ANSWER: B. 30 calendar days
Rationale: The HIPAA Privacy Rule requires covered entities to act on a patient's
request for access to their PHI no later than 30 calendar days from receiving the request.
One 30-day extension is permitted if the entity provides a written explanation.
Question 6: Which of the following constitutes a "Breach" of unsecured PHI
under HIPAA, requiring notification?
,A. Theft of a paper record that is later recovered unread
B. Inadvertent disclosure of PHI to a colleague in the same department who needs it for
treatment
C. An impermissible use or disclosure under the Privacy Rule that compromises the
security or privacy of the PHI
D. Any disclosure of PHI to a business associate
CORRECT ANSWER: C. An impermissible use or disclosure under the Privacy
Rule that compromises the security or privacy of the PHI
Rationale: Under HIPAA, a breach is defined as the acquisition, access, use, or
disclosure of PHI in a manner not permitted that compromises the security or privacy of
the PHI. The breach must be notified unless the covered entity can demonstrate a low
probability the PHI was compromised.
Question 7: A covered entity uses a cloud service provider to store patient
data. What is required before this arrangement can commence?
A. A Business Associate Agreement (BAA)
B. A Memorandum of Understanding (MOU)
C. A data usage consent form signed by all patients
D. Notification to the Department of Health and Human Services (HHS)
CORRECT ANSWER: A. A Business Associate Agreement (BAA)
Rationale: The HIPAA Privacy and Security Rules require covered entities to obtain
written assurances, typically in the form of a Business Associate Agreement (BAA), from
business associates that create, receive, maintain, or transmit PHI, ensuring they will
safeguard the information.
Question 8: What is the "Minimum Necessary" standard in HIPAA?
A. A covered entity must use the smallest number of employees to treat a patient
B. A covered entity must limit the amount of PHI disclosed to the minimum needed to
achieve the intended purpose
C. A covered entity must store the minimum amount of data required by state law
D. A covered entity must treat the minimum number of patients to stay profitable
CORRECT ANSWER: B. A covered entity must limit the amount of PHI
disclosed to the minimum needed to achieve the intended purpose
Rationale: The Minimum Necessary standard requires covered entities to make
reasonable efforts to limit PHI to the minimum necessary to accomplish the intended
purpose of the use, disclosure, or request. This applies to routine and non-routine
disclosures.
, Question 9: The Privacy Rule's individual right of access does NOT apply to
which of the following?
A. Clinical laboratory results
B. Progress notes created by a mental health professional in psychotherapy sessions
C. Billing records
D. Discharge summaries
CORRECT ANSWER: B. Progress notes created by a mental health professional
in psychotherapy sessions
Rationale: The Privacy Rule specifically excludes psychotherapy notes (notes recorded
by a mental health professional documenting counseling session contents) from the
individual’s right of access. They are protected under a different, more stringent
standard.
Question 10: If a breach of unsecured PHI affects 550 individuals, which of the
following is TRUE regarding notification requirements?
A. Only the affected individuals must be notified
B. Notification must be provided to the affected individuals, the media, and the
Secretary of HHS
C. Only the Secretary of HHS must be notified
D. No notification is required if the breach is recovered within 30 days
CORRECT ANSWER: B. Notification must be provided to the affected
individuals, the media, and the Secretary of HHS
Rationale: The Breach Notification Rule requires that for a breach affecting more than
500 individuals, the covered entity must notify the affected individuals, prominent media
outlets serving the area, and the Secretary of HHS without unreasonable delay but no
later than 60 days.
Question 11: An employee accesses the medical records of a celebrity out of
curiosity, despite having no treatment or billing reason. This is an example of:
A. A permitted use under TPO
B. A violation of the Privacy Rule
C. An acceptable practice as a public figure waives privacy rights
D. A breach that automatically requires state attorney general notification
CORRECT ANSWER: B. A violation of the Privacy Rule
Rationale: Accessing PHI without a valid work-related justification (such as treatment,
payment, or operations) is a violation of the HIPAA Privacy Rule. Curiosity is not a
permitted reason for accessing medical records.