HIPAA AND PRIVACY ACT TRAINING EXAM
SCRIPT 2026 TEST PAPER QUESTIONS AND
SOLUTIONS GRADED A+
◉ Which of the following are breach prevention best practices?
Answer: >All of the above (correct)
Access only the minimum amount of PHI/personally identifiable
information (PII) necessary
Logoff or lock your workstation when it is unattended
Promptly retrieve documents containing PHI/PHI from the printer
◉ A breach as defined by the DoD is broader than a HIPAA breach
(or breach defined by HHS). Answer: True (correct)
◉ A Privacy Impact Assessment (PIA) is an analysis of how
information is handled: Answer: >All of the above (correct)
To ensure handling conforms to applicable legal, regulatory, and
policy requirements regarding privacy
, To determine the risks and effects of collecting, maintaining and
disseminating information in identifiable form in an electronic
information system
To examine and evaluate protections and alternative processes for
handling information to mitigate potential privacy risks
◉ A Systems of Records Notice (SORN) serves as a notice to the
public about a system of records and must: Answer: >All of the
above (correct)
Specify routine uses (how the information will be used)
Be republished if a new routine use is created
Be provided to Office of Management and Budget (OMB) and
Congress and published in the Federal Register before the system is
operational
◉ Which of the following are examples of personally identifiable
information (PII)? Answer: >All of the above (correct)
Social Security number
SCRIPT 2026 TEST PAPER QUESTIONS AND
SOLUTIONS GRADED A+
◉ Which of the following are breach prevention best practices?
Answer: >All of the above (correct)
Access only the minimum amount of PHI/personally identifiable
information (PII) necessary
Logoff or lock your workstation when it is unattended
Promptly retrieve documents containing PHI/PHI from the printer
◉ A breach as defined by the DoD is broader than a HIPAA breach
(or breach defined by HHS). Answer: True (correct)
◉ A Privacy Impact Assessment (PIA) is an analysis of how
information is handled: Answer: >All of the above (correct)
To ensure handling conforms to applicable legal, regulatory, and
policy requirements regarding privacy
, To determine the risks and effects of collecting, maintaining and
disseminating information in identifiable form in an electronic
information system
To examine and evaluate protections and alternative processes for
handling information to mitigate potential privacy risks
◉ A Systems of Records Notice (SORN) serves as a notice to the
public about a system of records and must: Answer: >All of the
above (correct)
Specify routine uses (how the information will be used)
Be republished if a new routine use is created
Be provided to Office of Management and Budget (OMB) and
Congress and published in the Federal Register before the system is
operational
◉ Which of the following are examples of personally identifiable
information (PII)? Answer: >All of the above (correct)
Social Security number