Updated Questions & Answers with Detailed Rationales |
Healthcare Compliance Certification Johns Hopkins University
This study resource is built for healthcare professionals, compliance officers, and
students preparing for HIPAA and Privacy Act training exams. It mirrors the style,
difficulty, and topic coverage of university and hospital compliance training
programs, covering the HIPAA Privacy Rule, Security Rule, Breach Notification
Rule, patient rights, minimum necessary standard, business associate
agreements, enforcement penalties, and the Privacy Act of 1974. The 300 unique
MCQs include verified updated answers and detailed rationales
1. Which of the following best defines Protected Health Information (PHI)
under HIPAA?
A) Any health-related information stored electronically
B) Individually identifiable health information held or transmitted by a
covered entity or business associate
C) Any medical record created after 1996
D) Information about a patient's insurance coverage only
Explanation: PHI is defined by HIPAA as individually identifiable health information
that is created, received, maintained, or transmitted by a covered entity or
business associate, in any form or medium (electronic, paper, or oral). It includes
demographic data and relates to past, present, or future physical/mental health,
provision of health care, or payment for health care.
,2. Under the HIPAA Privacy Rule, which entity is NOT considered a "covered
entity"?
A) A hospital that bills Medicare
B) A health insurance company
C) A software developer creating a fitness tracking app not contracted by a
health plan
D) A university health center that conducts electronic transactions covered by
HIPAA
Explanation: Covered entities under HIPAA include health plans, health care
clearinghouses, and health care providers who transmit health information
electronically in connection with standard transactions. A standalone app
developer not acting on behalf of a covered entity is not a covered entity unless
they qualify as a business associate through a formal agreement.
3. What is the primary purpose of the HIPAA Security Rule?
A) To regulate the pricing of health insurance premiums
B) To establish national standards for protecting electronic protected health
information (ePHI)
C) To mandate patient access to all medical records within 24 hours
D) To prohibit all disclosures of PHI without written authorization
Explanation: The HIPAA Security Rule specifically addresses the protection of
ePHI by requiring covered entities and business associates to implement
administrative, physical, and technical safeguards to ensure the confidentiality,
integrity, and availability of ePHI.
,4. A patient requests a copy of their medical records. Under HIPAA, what is
the maximum time frame a covered entity has to respond to this request?
A) 15 calendar days
B) 30 calendar days
C) 45 calendar days
D) 60 calendar days
Explanation: HIPAA requires covered entities to provide individuals with access to
their PHI within 30 calendar days of receiving a request. One 30-day extension is
permitted if the entity provides a written statement of the reasons for the delay
and the date by which it will provide the records.
5. Which of the following disclosures of PHI is permitted under HIPAA
without patient authorization?
A) Sharing a patient's diagnosis with their employer for workplace
accommodations
B) Disclosing PHI to a family member involved in the patient's care when the
patient does not object
C) Posting a patient's before-and-after treatment photos on social media for
marketing
D) Disclosing PHI to a journalist for a news story about the hospital
Explanation: HIPAA permits covered entities to disclose PHI to family members or
friends involved in the patient's care, provided the patient does not object.
Disclosures for marketing or to employers generally require authorization.
, 6. A hospital employee receives a subpoena for patient records. What is the
appropriate first step under HIPAA?
A) Immediately provide the records to comply with the law
B) Ignore the subpoena as a violation of patient privacy
C) Verify the subpoena is valid and seek a qualified protective order or
attempt to quash it
D) Contact the patient's family for permission
Explanation: A valid court order or subpoena is not a blanket authorization. The
proper action is to verify its validity and attempt to negotiate a protective order
that limits the disclosure to the minimum necessary, or to quash the subpoena to
protect PHI.
7. Which of the following is NOT an example of a physical safeguard required
by the HIPAA Security Rule?
A) Facility access controls
B) Workstation security
C) Encryption of data at rest
D) Security incident procedures
Explanation: Security incident procedures are a type of administrative safeguard,
as they involve policies and procedures for responding to security breaches.
Physical safeguards include facility access controls, workstation security, and
device and media controls.