Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 73 pages
Exam (elaborations)

HIPAA & Patient Confidentiality Compliance Practice Exam | Updated 2026 Complete Study Guide | Verified Questions with Detailed Rationales on HIPAA Privacy & Security Rules, Protected Health Information (PHI) Handling, Patient Rights & Authorization, Brea

Document preview thumbnail
Preview 4 out of 73 pages

This HIPAA & Patient Confidentiality Compliance Practice Exam and Complete Study Guide Updated 2026 is designed to provide a clear, structured, and exam-focused review of essential privacy and security standards in healthcare. It includes verified questions with detailed rationales covering high-yield topics such as HIPAA Privacy and Security Rules, proper handling of protected health information (PHI), patient rights and authorization processes, breach notification requirements, administrative, physical, and technical safeguards, the minimum necessary standard, and documentation practices for compliance and audit readiness. Built to strengthen legal awareness, data protection practices, and confidence in handling sensitive information, this resource supports effective exam preparation while reinforcing real-world compliance responsibilities. Ideal for healthcare students and professionals seeking a reliable and up-to-date study tool aligned with current regulations and expectations. More exam prep materials available — follow profile

Content preview

HIPAA & Patient Confidentiality Compliance Practice Exam | Updated 2026
Complete Study Guide | Verified Questions with Detailed Rationales on
HIPAA Privacy & Security Rules, Protected Health Information (PHI)
Handling, Patient Rights & Authorization, Breach Notification
Requirements, Administrative, Physical & Technical Safeguards, Minimum
Necessary Standard, Documentation & Audit Readiness, and Legal
Responsibilities for Healthcare Certification Success
Question 1: Which of the following best defines Protected Health Information (PHI)
under HIPAA?
A. Any health information stored electronically
B. Any individually identifiable health information held or transmitted by a covered entity
or business associate
C. Only mental health records and substance abuse treatment documentation
D. Health information that has been de-identified according to HIPAA standards
CORRECT ANSWER: B. Any individually identifiable health information held or
transmitted by a covered entity or business associate
RATIONALE: PHI is defined by HIPAA as any individually identifiable health information,
in any form (electronic, paper, or oral), that is created, received, maintained, or
transmitted by a covered entity or business associate. De-identified information is not
PHI, and PHI is not limited to electronic formats or specific health categories.
Question 2: A nurse receives a phone call from a patient's spouse requesting
information about the patient's recent surgery. The patient has not provided
authorization for disclosure. What is the most appropriate action?
A. Provide general information about the procedure but not specific outcomes
B. Disclose information if the spouse can verify the patient's date of birth
C. Refuse to disclose any information without patient authorization or applicable
exception
D. Share information because family members are automatically entitled to patient
records
CORRECT ANSWER: C. Refuse to disclose any information without patient
authorization or applicable exception
RATIONALE: Under the HIPAA Privacy Rule, covered entities may not disclose PHI to
family members without the patient's authorization unless an exception applies (e.g.,
patient is incapacitated and disclosure is in best interest, or patient has opportunity to
agree/object and does not). Verification of identity alone does not permit disclosure
without authorization or applicable exception.
Question 3: Which scenario represents a permissible use of PHI without patient
authorization under HIPAA?

,A. Sharing patient lab results with a pharmaceutical company for marketing purposes
B. Disclosing PHI to a public health authority for disease surveillance
C. Providing patient contact information to a fundraising organization without opt-out
notice
D. Releasing mental health records to an employer for fitness-for-duty evaluation
CORRECT ANSWER: B. Disclosing PHI to a public health authority for disease
surveillance
RATIONALE: HIPAA permits disclosure of PHI to public health authorities for purposes
such as disease reporting, surveillance, and interventions without patient authorization.
Marketing disclosures, fundraising without proper notice/opt-out, and employment-
related disclosures generally require explicit authorization.
Question 4: What is the primary purpose of the HIPAA Security Rule?
A. To establish national standards for protecting electronic protected health information
(ePHI)
B. To regulate the disclosure of PHI to law enforcement agencies
C. To define patient rights to access and amend their health records
D. To standardize medical coding and billing procedures across healthcare entities
CORRECT ANSWER: A. To establish national standards for protecting electronic
protected health information (ePHI)
RATIONALE: The HIPAA Security Rule specifically addresses safeguards for ePHI,
requiring administrative, physical, and technical protections to ensure confidentiality,
integrity, and availability of electronic health information. Other options relate to the
Privacy Rule, enforcement provisions, or unrelated regulatory frameworks.
Question 5: Under the HIPAA Minimum Necessary Standard, workforce members
should:
A. Access all patient records to ensure comprehensive care coordination
B. Request and use only the minimum amount of PHI needed to accomplish the
intended purpose
C. Share PHI with any healthcare provider involved in the patient's care without
limitation
D. Document every instance of PHI access regardless of job function
CORRECT ANSWER: B. Request and use only the minimum amount of PHI needed
to accomplish the intended purpose
RATIONALE: The Minimum Necessary Standard requires covered entities to make
reasonable efforts to limit access to and use of PHI to the minimum necessary to
achieve the intended purpose. This principle applies to uses, disclosures, and requests
for PHI, with specific exceptions for treatment purposes.

,Question 6: A healthcare organization experiences a breach involving unencrypted
laptops containing ePHI of 600 patients. Within what timeframe must affected
individuals be notified under the HIPAA Breach Notification Rule?
A. Within 30 days of discovery
B. Within 60 calendar days of discovery
C. Within 90 days of discovery
D. Notification is only required if law enforcement confirms criminal activity
CORRECT ANSWER: B. Within 60 calendar days of discovery
RATIONALE: The HIPAA Breach Notification Rule requires covered entities to notify
affected individuals of a breach of unsecured PHI without unreasonable delay and no
later than 60 calendar days after discovery of the breach. Additional notifications to
HHS and media may be required depending on breach size.
Question 7: Which of the following is NOT a required element of a valid HIPAA
authorization for use or disclosure of PHI?
A. A description of the information to be used or disclosed
B. The name of the person or class of persons authorized to make the disclosure
C. The patient's Social Security Number for verification purposes
D. An expiration date or event related to the individual or the purpose of the
use/disclosure
CORRECT ANSWER: C. The patient's Social Security Number for verification
purposes
RATIONALE: HIPAA specifies core elements for valid authorization including description
of information, authorized parties, purpose, expiration, and patient signature/right to
revoke. Social Security Number is not a required element and should generally not be
used as a primary identifier due to privacy risks.
Question 8: What is the role of a Business Associate under HIPAA?
A. A covered entity that provides direct patient care services
B. A person or entity that performs functions or activities involving PHI on behalf of a
covered entity
C. A patient's legally authorized representative for healthcare decisions
D. A government agency responsible for HIPAA enforcement
CORRECT ANSWER: B. A person or entity that performs functions or activities
involving PHI on behalf of a covered entity
RATIONALE: A Business Associate is defined as a person or entity that creates,
receives, maintains, or transmits PHI on behalf of a covered entity for functions such as
billing, legal services, IT support, or data analysis. Business Associates must comply
with HIPAA through a written Business Associate Agreement.

, Question 9: Which safeguard category under the HIPAA Security Rule includes
policies, procedures, and workforce training?
A. Technical safeguards
B. Physical safeguards
C. Administrative safeguards
D. Organizational safeguards
CORRECT ANSWER: C. Administrative safeguards
RATIONALE: Administrative safeguards are administrative actions, policies, and
procedures to manage security measures, including security management processes,
workforce training, contingency planning, and evaluation. Technical safeguards involve
technology controls; physical safeguards address facility and device access.
Question 10: A patient requests an amendment to their medical record, stating that
a diagnosis documented by their physician is incorrect. The covered entity
disagrees with the patient's request. What is the entity's obligation?
A. Automatically amend the record as requested by the patient
B. Deny the request without explanation to maintain record integrity
C. Provide a written denial with reasons and inform the patient of their right to submit a
statement of disagreement
D. Forward the request to the Office for Civil Rights for resolution
CORRECT ANSWER: C. Provide a written denial with reasons and inform the patient
of their right to submit a statement of disagreement
RATIONALE: Under HIPAA, if a covered entity denies an amendment request, it must
provide a written denial stating the basis for denial and inform the patient of their right
to file a statement of disagreement, which must be included in future disclosures of the
relevant PHI.
Question 11: Which of the following activities is expressly prohibited under HIPAA
without explicit patient authorization?
A. Disclosing PHI to another covered entity for treatment purposes
B. Using PHI for internal quality improvement activities
C. Selling PHI to a third party for marketing purposes
D. Reporting communicable diseases to public health authorities
CORRECT ANSWER: C. Selling PHI to a third party for marketing purposes
RATIONALE: HIPAA prohibits the sale of PHI without explicit patient authorization, with
limited exceptions. Treatment disclosures, quality improvement (as part of healthcare
operations), and public health reporting are generally permitted without authorization
under specific provisions.
Question 12: What does the HIPAA Privacy Rule permit regarding patient access to
their own PHI?

Document information

Uploaded on
April 2, 2026
Number of pages
73
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BrightVarsity
3.5
(48)
Sold
1059
Followers
15
Items
3623
Last sold
9 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions