Study Guide, Practice Exam Questions and Answers, Exam Prep Test
Bank, Patient Privacy and Confidentiality Rules, Protected Health
Information (PHI) Standards, Healthcare Data Security Regulations,
Breach Notification Procedures, HIPAA Privacy and Security Rules, and
Detailed Revision Material for Certification Success
Question 1: Under the HIPAA Privacy Rule, which of the following is considered a
permitted use or disclosure of Protected Health Information (PHI) without an
individual's authorization?
A. Disclosure to a life insurance company for underwriting purposes
B. Disclosure to a employer for work performance evaluations
C. Disclosure to a public health authority for the purpose of preventing or controlling
disease
D. Disclosure to a marketing firm for a promotional campaign
CORRECT ANSWER: C. Disclosure to a public health authority for the purpose of
preventing or controlling disease
Rationale: The HIPAA Privacy Rule permits covered entities to disclose PHI without
authorization for specific public interest and benefit activities, including disclosures to
public health authorities authorized by law to collect or receive such information for the
purpose of preventing or controlling disease, injury, or disability. Disclosures for
employment evaluations, life insurance underwriting, and marketing generally require
specific patient authorization or are otherwise restricted.
Question 2: According to the HIPAA Security Rule, which of the following is an
example of a physical safeguard?
A. Implementing password management policies
B. Encrypting data at rest and in transit
C. Installing surveillance cameras and controlling access to server rooms
D. Conducting regular security awareness training for staff
CORRECT ANSWER: C. Installing surveillance cameras and controlling access to
server rooms
Rationale: Physical safeguards are measures to protect a covered entity's electronic
information systems and related buildings and equipment from natural and
environmental hazards, and unauthorized intrusion. This includes facility access
controls such as security cameras, locked doors, and badge entry systems. Password
management and encryption are technical safeguards, while training is an
administrative safeguard.
,Question 3: The HIPAA Breach Notification Rule requires covered entities to notify
affected individuals of a breach of unsecured PHI. What is the maximum time
frame for providing this notification?
A. Within 30 calendar days of the breach discovery
B. Within 60 calendar days of the breach discovery
C. Without unreasonable delay, but no later than 60 days from discovery
D. Within 10 business days of the breach discovery
CORRECT ANSWER: C. Without unreasonable delay, but no later than 60 days from
discovery
Rationale: The HIPAA Breach Notification Rule requires that covered entities notify
affected individuals without unreasonable delay and in no case later than 60 calendar
days after discovery of a breach. This standard ensures timely awareness while allowing
for investigation and mitigation.
Question 4: A covered entity may disclose PHI to law enforcement without a
warrant or court order in which of the following scenarios?
A. To identify a suspect who is already in custody
B. To report a crime that occurred on the covered entity's premises
C. To provide information about a patient's medical history during a routine traffic stop
D. To assist in a civil lawsuit investigation
CORRECT ANSWER: B. To report a crime that occurred on the covered entity's
premises
Rationale: The Privacy Rule permits a covered entity to disclose PHI to law enforcement
officials for the purpose of reporting a crime that occurred on the premises of the
covered entity. This disclosure is permissible without a warrant or court order, provided
certain conditions are met. The other options generally require a warrant, court order, or
specific authorization.
Question 5: What is the minimum necessary standard under the HIPAA Privacy
Rule?
A. A requirement that all PHI be encrypted regardless of its use
B. A requirement that covered entities limit the use, disclosure, and request of PHI to
the minimum amount needed to accomplish the intended purpose
C. A requirement that all employees have the same level of access to PHI
D. A requirement that PHI be destroyed after 6 years
CORRECT ANSWER: B. A requirement that covered entities limit the use,
disclosure, and request of PHI to the minimum amount needed to accomplish the
intended purpose
,Rationale: The Minimum Necessary Standard is a key principle of the HIPAA Privacy
Rule. It requires covered entities to make reasonable efforts to limit the use, disclosure,
and requests for PHI to the minimum necessary to accomplish the intended purpose. It
applies to routine and non-routine disclosures, but does not apply to disclosures for
treatment purposes.
Question 6: Which of the following is considered a Business Associate (BA) under
HIPAA?
A. A hospital's employed physician
B. A claims processing company that handles PHI on behalf of a health plan
C. A patient's family member who picks up their prescription
D. A cleaning service that has no access to PHI
CORRECT ANSWER: B. A claims processing company that handles PHI on behalf of
a health plan
Rationale: A Business Associate is a person or entity that performs functions or
activities on behalf of a covered entity that involve the use or disclosure of PHI, such as
claims processing, data analysis, or billing. Employees of the covered entity are not
BAs; they are part of the workforce. A family member or a cleaning service without
access to PHI does not qualify as a BA.
Question 7: In the event of a breach of unsecured PHI affecting 500 or more
individuals, a covered entity must notify the Secretary of Health and Human
Services (HHS) within what time frame?
A. Within 60 calendar days of the end of the calendar year
B. Within 30 calendar days of the breach discovery
C. Immediately, regardless of the number affected
D. Within 30 calendar days of the end of the calendar year
CORRECT ANSWER: A. Within 60 calendar days of the end of the calendar year
Rationale: For breaches affecting 500 or more individuals, covered entities must notify
the Secretary of HHS no later than 60 calendar days from the discovery of the breach.
For breaches affecting fewer than 500 individuals, the notification must be provided
within 60 days of the end of the calendar year in which the breach was discovered.
Question 8: An individual's right to request an amendment to their PHI under HIPAA
is subject to which of the following exceptions?
A. The information was created by a third party and is not maintained by the covered
entity
, B. The individual disagrees with a physician's clinical judgment
C. The information is part of a legal proceeding
D. The covered entity believes the amendment is unnecessary
CORRECT ANSWER: A. The information was created by a third party and is not
maintained by the covered entity
Rationale: HIPAA grants individuals the right to request an amendment to their PHI, but
this right is not absolute. A covered entity may deny the request if it determines the
information was not created by the covered entity, is not part of the designated record
set, or is accurate and complete. Disagreement with clinical judgment alone does not
constitute grounds for denial, but the covered entity can deny it if they believe the
information is accurate.
Question 9: Which of the following is a required element of a valid HIPAA
authorization for the use of PHI?
A. A statement that the authorization expires in 5 years
B. A description of the specific information to be used or disclosed
C. The individual's social security number
D. A witness signature
CORRECT ANSWER: B. A description of the specific information to be used or
disclosed
Rationale: A valid HIPAA authorization must contain a specific and meaningful
description of the information to be used or disclosed. It must also include the name of
the person or entity authorized to make the disclosure, the name of the recipient, a
description of the purpose, an expiration date or event, and the individual's signature.
Question 10: The HIPAA Security Rule's "Addressable" implementation
specifications differ from "Required" specifications in that addressable
specifications:
A. Must be ignored if they are too costly
B. Must be implemented if they are reasonable and appropriate, or an equivalent
alternative measure must be implemented
C. Are optional and do not need to be considered
D. Must be implemented immediately without any analysis
CORRECT ANSWER: B. Must be implemented if they are reasonable and
appropriate, or an equivalent alternative measure must be implemented
Rationale: The Security Rule distinguishes between Required and Addressable
implementation specifications. Required specifications must be implemented as
stated. For Addressable specifications, the entity must assess whether the