CRIS TEST ACTUAL 2026/2027 QUESTIONS AND
100% CORRECT ANSWERS
A covered entity is training its workforce on the HIPAA Privacy Rule. It has scheduled all of its paid
employees to attend training sessions. This covered entity has scheduled everyone that needs to receive
training. CORRECT ANSWER: False
A covered entity may deny an amendment request if it determines that the information in question is not
part of the DRS. CORRECT ANSWER: True
A covered entity must consider, but is never required to accommodate, a restriction request. CORRECT
ANSWER: False
A hospital employee's pre-employment physical examination is in his personnel file in Human Resources;
this report is protected by HIPAA. CORRECT ANSWER: False
A limited data set does not receive HIPAA Privacy Rule protection. CORRECT ANSWER: False
A limited data set may be used or disclosed without authorization for research, public health, or healthcare
operations purposes. CORRECT ANSWER: True
By definition, a designated record set includes billing records. CORRECT ANSWER: True
Covered entities consist only of healthcare providers, health plans, and healthcare clearinghouses.
CORRECT ANSWER: True
Deleting a file sufficiently eliminates the existence of electronic PHI. CORRECT ANSWER: False
Drug and alcohol abuse treatment records received protection under federal law prior to the HIPAA Privacy
Rule. CORRECT ANSWER: True
HITECH gives state attorneys general the power to bring civil actions in federal district court on behalf of
residents negatively affected by a HIPAA violation. CORRECT ANSWER: True
If a workcomp subpoena is received that states 'any and all records' without an authorization, it should
automatically be rejected as workcomp applies only to injury. CORRECT ANSWER: False
If an request from a physician office asks for records from 2019, it is ok to assume that they really want
2019 to current and send all years accordingly. CORRECT ANSWER: False
One of the 12 public interest and benefit exceptions to the authorization requirements is disclosure to organ
procurement agencies. CORRECT ANSWER: True
One of the greatest risks to electronic PHI is the lack of control over portable devices. CORRECT
ANSWER: True
Per HIPAA, breach notification is one method by which an organization can mitigate a breach. CORRECT
ANSWER: True
Preemption requires compliance with state law when a federal law and state law conflict with one another
CORRECT ANSWER: False
The HIPAA consent explains an individual's rights and the covered entity's legal duties with respect to PHI.
CORRECT ANSWER: False
100% CORRECT ANSWERS
A covered entity is training its workforce on the HIPAA Privacy Rule. It has scheduled all of its paid
employees to attend training sessions. This covered entity has scheduled everyone that needs to receive
training. CORRECT ANSWER: False
A covered entity may deny an amendment request if it determines that the information in question is not
part of the DRS. CORRECT ANSWER: True
A covered entity must consider, but is never required to accommodate, a restriction request. CORRECT
ANSWER: False
A hospital employee's pre-employment physical examination is in his personnel file in Human Resources;
this report is protected by HIPAA. CORRECT ANSWER: False
A limited data set does not receive HIPAA Privacy Rule protection. CORRECT ANSWER: False
A limited data set may be used or disclosed without authorization for research, public health, or healthcare
operations purposes. CORRECT ANSWER: True
By definition, a designated record set includes billing records. CORRECT ANSWER: True
Covered entities consist only of healthcare providers, health plans, and healthcare clearinghouses.
CORRECT ANSWER: True
Deleting a file sufficiently eliminates the existence of electronic PHI. CORRECT ANSWER: False
Drug and alcohol abuse treatment records received protection under federal law prior to the HIPAA Privacy
Rule. CORRECT ANSWER: True
HITECH gives state attorneys general the power to bring civil actions in federal district court on behalf of
residents negatively affected by a HIPAA violation. CORRECT ANSWER: True
If a workcomp subpoena is received that states 'any and all records' without an authorization, it should
automatically be rejected as workcomp applies only to injury. CORRECT ANSWER: False
If an request from a physician office asks for records from 2019, it is ok to assume that they really want
2019 to current and send all years accordingly. CORRECT ANSWER: False
One of the 12 public interest and benefit exceptions to the authorization requirements is disclosure to organ
procurement agencies. CORRECT ANSWER: True
One of the greatest risks to electronic PHI is the lack of control over portable devices. CORRECT
ANSWER: True
Per HIPAA, breach notification is one method by which an organization can mitigate a breach. CORRECT
ANSWER: True
Preemption requires compliance with state law when a federal law and state law conflict with one another
CORRECT ANSWER: False
The HIPAA consent explains an individual's rights and the covered entity's legal duties with respect to PHI.
CORRECT ANSWER: False