Practice Questions with Verified Answers and
Detailed Rationales | Patient Privacy and
Confidentiality, HIPAA Rules and Regulations,
Protected Health Information (PHI), Security
and Data Protection Standards, Healthcare
Compliance Requirements, Breach Notification
and Legal Responsibilities
Question 1: Which federal law established national standards to protect individuals' medical
records and other personal health information?
A. The Affordable Care Act
B. The Health Information Technology for Economic and Clinical Health Act
C. The Health Insurance Portability and Accountability Act
D. The Patient Safety and Quality Improvement Act
CORRECT ANSWER: C. The Health Insurance Portability and Accountability Act
Rationale: HIPAA, enacted in 1996, established the first national standards to protect
individuals' medical records and personal health information. The Privacy Rule, Security Rule,
and Breach Notification Rule all derive their authority from HIPAA legislation.
Question 2: Under HIPAA, which of the following is NOT considered a Covered Entity?
A. A hospital that submits electronic insurance claims
B. A health insurance company
C. A healthcare clearinghouse
D. A fitness app that tracks user steps without receiving PHI from a Covered Entity
CORRECT ANSWER: D. A fitness app that tracks user steps without receiving PHI from a
Covered Entity
Rationale: Covered Entities under HIPAA include health plans, healthcare clearinghouses, and
healthcare providers who transmit health information electronically in connection with certain
transactions. A standalone fitness app not acting on behalf of a Covered Entity and not
receiving PHI is not a Covered Entity.
Question 3: What does the acronym "PHI" stand for under HIPAA regulations?
A. Personal Health Identifier
B. Protected Health Information
,C. Private Health Indicator
D. Public Health Inventory
CORRECT ANSWER: B. Protected Health Information
Rationale: PHI stands for Protected Health Information, which refers to any information in a
medical record or designated record set that can be used to identify an individual and that was
created, used, or disclosed in the course of providing a health care service, such as a diagnosis
or treatment.
Question 4: Which HIPAA Rule specifically addresses the use and disclosure of Protected
Health Information?
A. Security Rule
B. Breach Notification Rule
C. Privacy Rule
D. Enforcement Rule
CORRECT ANSWER: C. Privacy Rule
Rationale: The HIPAA Privacy Rule establishes national standards for the protection of PHI,
including when and how Covered Entities may use or disclose PHI, and grants patients rights
regarding their health information.
Question 5: A healthcare provider may disclose PHI without patient authorization for which
of the following purposes?
A. Marketing the provider's new wellness program
B. Selling patient contact lists to a pharmaceutical company
C. Treatment, payment, and healthcare operations
D. Sharing with an employer for hiring decisions
CORRECT ANSWER: C. Treatment, payment, and healthcare operations
Rationale: HIPAA permits Covered Entities to use and disclose PHI for treatment, payment, and
healthcare operations (TPO) without obtaining patient authorization. All other uses generally
require explicit authorization unless another specific exception applies.
Question 6: Which of the following is an example of a "minimum necessary" standard
application under HIPAA?
A. Sharing a patient's entire medical history with a specialist consulting on one specific
condition
B. Providing a billing clerk access only to diagnosis and procedure codes needed for claims
processing
,C. Allowing all hospital staff to view any patient record for educational purposes
D. Disclosing full psychiatric records to a patient's family member without consent
CORRECT ANSWER: B. Providing a billing clerk access only to diagnosis and procedure codes
needed for claims processing
Rationale: The minimum necessary standard requires Covered Entities to make reasonable
efforts to limit PHI use, disclosure, and requests to the minimum amount necessary to
accomplish the intended purpose. Limiting billing staff access to only necessary codes
exemplifies this principle.
Question 7: Under HIPAA, when must a Covered Entity provide a patient with an accounting
of disclosures of their PHI?
A. Upon any verbal request by the patient
B. Only if the disclosure was for marketing purposes
C. Within 60 days of a written request, covering disclosures made in the past six years (with
some exceptions)
D. Only for disclosures that resulted in a breach
CORRECT ANSWER: C. Within 60 days of a written request, covering disclosures made in the
past six years (with some exceptions)
Rationale: Patients have the right to receive an accounting of certain disclosures of their PHI
made by a Covered Entity in the six years prior to the request. The Covered Entity must respond
within 60 days (with one 30-day extension allowed) and may charge a reasonable, cost-based
fee for subsequent requests within a 12-month period.
Question 8: Which of the following actions would constitute a HIPAA breach?
A. A nurse discusses a patient's condition with another nurse directly involved in the patient's
care
B. An unencrypted laptop containing unsecured PHI is stolen from a healthcare worker's car
C. A doctor shares de-identified health data for research purposes
D. A hospital sends a prescription reminder via secure patient portal
CORRECT ANSWER: B. An unencrypted laptop containing unsecured PHI is stolen from a
healthcare worker's car
Rationale: A breach is the acquisition, access, use, or disclosure of PHI in a manner not
permitted under the Privacy Rule that compromises the security or privacy of the PHI. The theft
of an unencrypted device containing unsecured PHI is presumed a breach unless a risk
assessment demonstrates a low probability of compromise.
Question 9: What is the maximum time frame a Covered Entity has to notify affected
individuals following discovery of a breach of unsecured PHI?
, A. 24 hours
B. 7 calendar days
C. 30 calendar days
D. 60 calendar days
CORRECT ANSWER: D. 60 calendar days
Rationale: Under the HIPAA Breach Notification Rule, Covered Entities must notify affected
individuals without unreasonable delay and no later than 60 calendar days after discovery of a
breach of unsecured PHI.
Question 10: Which safeguard category under the HIPAA Security Rule includes policies and
procedures for workforce training and management?
A. Technical Safeguards
B. Physical Safeguards
C. Administrative Safeguards
D. Organizational Safeguards
CORRECT ANSWER: C. Administrative Safeguards
Rationale: Administrative Safeguards are administrative actions, policies, and procedures to
manage the selection, development, implementation, and maintenance of security measures.
This includes workforce training, security management processes, and assigned security
responsibility.
Question 11: A Business Associate Agreement (BAA) is required when a Covered Entity
engages which of the following?
A. A janitorial service that never accesses PHI
B. A cloud storage provider that hosts encrypted PHI on behalf of the Covered Entity
C. A patient who requests their own records
D. A researcher using fully de-identified data
CORRECT ANSWER: B. A cloud storage provider that hosts encrypted PHI on behalf of the
Covered Entity
Rationale: A Business Associate is a person or entity that performs functions or activities on
behalf of a Covered Entity that involve the use or disclosure of PHI. Cloud storage providers
handling PHI are Business Associates and require a signed BAA before PHI is shared.
Question 12: Which of the following is NOT a patient right under the HIPAA Privacy Rule?
A. Right to access and obtain a copy of their PHI
B. Right to request amendment of their PHI