CITI Training HFH Exam
Questions and Answers 100%
PASS
Which of the following is likely to be the level of review determined as appropriate by the
IRB?—ANSWER-Exempt as the study presents no greater than minimal risk and does not
collect identifying information.
Would this research be eligible for exemption?—ANSWER-No. The investigator may be able
to identify subjects based on telephone numbers and birth dates, so this should not be
considered exempt.
An investigator has proposed a multi-site study of PSA (Prostate Specific Antigen) test results
among patients with prostate cancer. The research involves only review of medical records at
institutions in several states. The investigator will not collect any identifying information on
the subjects, only their PSA scores and ages (which will be collected in a range format so as
to not have the person's specific age). The investigator may correctly conclude that:—
ANSWER-IRB review, or similar process, may be required since generally investigators are not
able to exempt their own research.
, Decisions about compliance with HIPAA's research provisions may sometimes be made by:—
ANSWER-An organization's IRB, "Privacy Board", "Privacy Officer", or "Security Officer,"
depending on the particular issue and the requirements of the HIPAA regulations.
Under HIPAA, a "disclosure accounting" is required:—ANSWER-for all human subjects
research that uses PHI without an authorization from the data subject, except for limited
data sets.
If you're unsure about the particulars of HIPAA research requirements at your organization
or have questions, you can usually consult with:—ANSWER-An organizational IRB or Privacy
Board, "Privacy Officer", or "Privacy Official," depending on the issue.
The HIPAA "minimum necessary" standard applies—ANSWER-to all human subjects research
that uses PHI without an authorization from the data subject.
HIPAA includes in its definition of "research" the activities related to—ANSWER-
development of generalizable knowledge.
A covered entity may use or disclose PHI without an authorization, or documentation of a
waiver or an alteration of authorization, for all of the following EXCEPT:—ANSWER-Data that
does not cross state lines when disclosed by the covered entity.
HIPAA's protections for health information used for research purposes—ANSWER-
supplement those of the Common Rule and FDA.
Under HIPAA, "retrospective research" (a.k.a., data mining) on collections of PHI generally—
ANSWER-is research, and so requires either an authorization or meeting one of the criteria
for a waiver of authorization.
© 2026 Copyright. All Rights Reserved. This document is
protected by copyright law, Copyrighted By Brittie Donald
Questions and Answers 100%
PASS
Which of the following is likely to be the level of review determined as appropriate by the
IRB?—ANSWER-Exempt as the study presents no greater than minimal risk and does not
collect identifying information.
Would this research be eligible for exemption?—ANSWER-No. The investigator may be able
to identify subjects based on telephone numbers and birth dates, so this should not be
considered exempt.
An investigator has proposed a multi-site study of PSA (Prostate Specific Antigen) test results
among patients with prostate cancer. The research involves only review of medical records at
institutions in several states. The investigator will not collect any identifying information on
the subjects, only their PSA scores and ages (which will be collected in a range format so as
to not have the person's specific age). The investigator may correctly conclude that:—
ANSWER-IRB review, or similar process, may be required since generally investigators are not
able to exempt their own research.
, Decisions about compliance with HIPAA's research provisions may sometimes be made by:—
ANSWER-An organization's IRB, "Privacy Board", "Privacy Officer", or "Security Officer,"
depending on the particular issue and the requirements of the HIPAA regulations.
Under HIPAA, a "disclosure accounting" is required:—ANSWER-for all human subjects
research that uses PHI without an authorization from the data subject, except for limited
data sets.
If you're unsure about the particulars of HIPAA research requirements at your organization
or have questions, you can usually consult with:—ANSWER-An organizational IRB or Privacy
Board, "Privacy Officer", or "Privacy Official," depending on the issue.
The HIPAA "minimum necessary" standard applies—ANSWER-to all human subjects research
that uses PHI without an authorization from the data subject.
HIPAA includes in its definition of "research" the activities related to—ANSWER-
development of generalizable knowledge.
A covered entity may use or disclose PHI without an authorization, or documentation of a
waiver or an alteration of authorization, for all of the following EXCEPT:—ANSWER-Data that
does not cross state lines when disclosed by the covered entity.
HIPAA's protections for health information used for research purposes—ANSWER-
supplement those of the Common Rule and FDA.
Under HIPAA, "retrospective research" (a.k.a., data mining) on collections of PHI generally—
ANSWER-is research, and so requires either an authorization or meeting one of the criteria
for a waiver of authorization.
© 2026 Copyright. All Rights Reserved. This document is
protected by copyright law, Copyrighted By Brittie Donald