CERTIFICATION EXAM REVIEW | HIGH-YIELD PRIVACY &
COMPLIANCE QUESTIONS | VERIFIED Q&A | COMPLETE EXAM
PREPARATION | UPDATED VERSION
1. What is required of business associates under HIPAA when working with
covered entities?
Conduct regular audits
Enter into a business associate agreement
Submit annual compliance reports
Provide training to employees
2. Which of the following would MOST likely be defined as a Covered Entity?
Medical Lab Courier
Clearinghouse
Medical IT Vendor
Insurance Agency
3. Describe the conditions under which research use/disclosure of PHI can be
combined with other authorizations according to HIPAA.
Research use/disclosure cannot be combined under any
circumstances.
Research use/disclosure can be combined if it benefits the
organization financially.
Research use/disclosure can be combined only if the patient is
informed verbally.
Research use/disclosure can be combined if treatment is
conditioned on the provision of one of the authorizations.
,4. Describe the significance of identifying an organization as a 'Covered Entity'
under HIPAA regulations.
Identifying an organization as a 'Covered Entity' determines its
obligations to protect PHI and comply with HIPAA regulations.
It allows organizations to share PHI without restrictions.
It exempts organizations from all privacy laws.
It categorizes organizations based on their size and revenue.
5. If a healthcare provider hires an independent medical transcriptionist to
handle patient records, what must they ensure regarding HIPAA compliance?
They must hire a full-time employee instead of a contractor.
They must establish a Business Associate contract with the
transcriptionist.
They should only inform the transcriptionist about HIPAA regulations.
They can proceed without any formal agreement.
6. Which of the follow is true regarding a Business Associate Contract?
Defines the obligations of a Business Associate.
Is written assurance that a Business Associate will appropriately
safeguard PHI that they use or have disclosed to them from a covered
entity.
Is required between a covered entity and business associate if
Protected Health Information (PHI) will be shared between the two.
All of the above.
,7. If a Business Associate fails to comply with HIPAA regulations after HITECH,
what potential consequences could they face?
They could only be required to improve their compliance training.
They would be protected by liability waivers from covered entities.
They would not face any consequences as they are exempt from
HIPAA.
They could face legal penalties and fines for non-compliance.
8. What is the title of the Code of Federal Regulations (CFR) where HIPAA is
located?
Title 50
Title 42
Title 21
Title 45
9. What does SORN stand for in the context of the Privacy Act of 1974?
System of Records Notice
Systematic Overview of Records Notification
Summary of Records Notice
Standard of Records Notification
10. HIPAA provide standards for the access, disclosure, transmission, and
retention of PHI, and created a national baseline for health information
Privacy and Security. At the state level, they can also develop health
information statutes but only adding higher or more restrictive standards
than the Federal HIPAA rules. This is referred as:
, HIPAA state law
HIPAA status
HIPAA preemption
HIPAA assurance
11. Describe the criteria used to identify whether an organization falls under
HIPAA regulations.
An organization is subject to HIPAA if it provides healthcare services
only.
An organization is subject to HIPAA if it has more than 50 employees.
An organization is subject to HIPAA if it is a government entity.
An organization is subject to HIPAA if it is a covered entity or a
business associate that handles protected health information.
12. If a healthcare facility is found to be non-compliant with Part 2 regulations
while treating a patient for both Substance Use Disorder and Mental Health
issues, what could be a potential consequence?
Improved patient satisfaction
No consequences as HIPAA overrides Part 2 regulations
Legal penalties and loss of funding
Increased patient enrollment
13. HIPAA's main purpose is to:
Control the price of medications.
Standardize healthcare education across the U.S.
Ensure privacy and security of patient health information.