Study Guide, Practice Exam Questions and Answers, Exam Prep Test Bank, Patient
Privacy and Confidentiality Standards, Protected Health Information (PHI) Rules,
HIPAA Privacy and Security Regulations, Breach Notification Procedures,
Healthcare Data Protection, and Detailed Revision Material for Certification
Success
Question 1: Under HIPAA, which of the following is considered a covered entity?
A. A cloud storage provider that stores patient data for a hospital
B. A health insurance company that processes claims
C. An external IT consultant who repairs a clinic's network
D. A medical transcriptionist working from home
CORRECT ANSWER: B. A health insurance company that processes claims
Rationale: Covered entities under HIPAA include health plans, health care
clearinghouses, and health care providers who transmit health information
electronically. A health insurance company is a health plan and therefore a covered
entity. Business associates, such as cloud providers, consultants, and transcriptionists,
are not covered entities but are bound by HIPAA through Business Associate
Agreements.
Question 2: Which of the following is NOT a permissible use or disclosure of
Protected Health Information (PHI) without patient authorization?
A. Treatment purposes
B. Payment activities
C. Marketing communications for a new pharmaceutical product
D. Health care operations
CORRECT ANSWER: C. Marketing communications for a new pharmaceutical
product
Rationale: HIPAA permits the use and disclosure of PHI without patient authorization
for treatment, payment, and health care operations (TPO). Marketing for a third-party
product or service generally requires explicit patient authorization unless it is a face-to-
face communication or a promotional gift of nominal value.
Question 3: What is the maximum civil penalty per violation for a covered entity
that willfully neglected HIPAA rules and did not correct the issue within 30 days?
A. $1,000
B. $50,000
C. $25,000
D. $1.5 million
CORRECT ANSWER: D. $1.5 million
,Rationale: The HIPAA penalty structure includes tiered penalties based on culpability.
The highest tier applies to willful neglect that is not corrected within 30 days, with a
maximum annual penalty of $1.5 million per violation category.
Question 4: A patient requests an electronic copy of their medical records. Under
the HIPAA Privacy Rule, what is the maximum time a covered entity has to provide
the records?
A. 15 days
B. 30 days
C. 60 days
D. 90 days
CORRECT ANSWER: B. 30 days
Rationale: The HIPAA Privacy Rule requires covered entities to act on a patient’s
request for access to PHI within 30 days of receiving the request. An extension of up to
an additional 30 days is permitted if the entity provides a written explanation of the
delay.
Question 5: Which of the following administrative safeguards is a required
implementation specification under the HIPAA Security Rule?
A. Contingency operations
B. Risk analysis
C. Device and media controls
D. Access control
CORRECT ANSWER: B. Risk analysis
Rationale: The HIPAA Security Rule requires covered entities to conduct an accurate
and thorough assessment of potential risks and vulnerabilities to the confidentiality,
integrity, and availability of electronic protected health information (ePHI). This is a
foundational required implementation specification.
Question 6: A nurse discusses a patient's lab results with a colleague at the
hospital cafeteria. Which principle of HIPAA has been violated?
A. Minimum Necessary Standard
B. Notice of Privacy Practices
C. Patient's Right to Amend
D. Administrative Simplification
CORRECT ANSWER: A. Minimum Necessary Standard
,Rationale: The Minimum Necessary Standard requires that only the minimum amount
of PHI necessary to accomplish the intended purpose be used or disclosed. Discussing
PHI in a public area like a cafeteria, where unauthorized individuals might overhear,
violates this standard and constitutes a breach of confidentiality.
Question 7: Who is responsible for ensuring that Business Associate Agreements
(BAAs) are in place before PHI is shared with a third party?
A. The Department of Health and Human Services
B. The covered entity
C. The business associate itself
D. The patient
CORRECT ANSWER: B. The covered entity
Rationale: The HIPAA Privacy and Security Rules mandate that a covered entity must
obtain satisfactory assurances from its business associates that they will appropriately
safeguard PHI. This is accomplished through a written Business Associate Agreement,
and the responsibility falls on the covered entity to secure it.
Question 8: Which of the following is an example of a physical safeguard required
by the HIPAA Security Rule?
A. Implementing two-factor authentication for system login
B. Conducting security awareness training for staff
C. Installing surveillance cameras in areas where paper records are stored
D. Encrypting data on laptops
CORRECT ANSWER: C. Installing surveillance cameras in areas where paper
records are stored
Rationale: Physical safeguards are measures to protect the physical premises and
equipment from unauthorized access. Surveillance cameras, locked file rooms, and
secure workstations are examples of physical safeguards. Encryption and two-factor
authentication are technical safeguards, while training is an administrative safeguard.
Question 9: Under HIPAA, a patient has the right to request an amendment to their
medical record. What must the covered entity do if the request is denied?
A. Provide the patient with a written denial and inform them of their right to submit a
statement of disagreement
B. Destroy the medical record and create a new one
C. Inform the patient that they have no right to appeal
D. Amend the record regardless of the entity's assessment
, CORRECT ANSWER: A. Provide the patient with a written denial and inform them of
their right to submit a statement of disagreement
Rationale: If a covered entity denies a patient's request to amend PHI, it must provide a
written denial, including the reason for the denial and the patient’s right to submit a
written statement disagreeing with the denial. The patient also has the right to have the
denial and their statement included in future disclosures.
Question 10: What is the primary purpose of the HIPAA Breach Notification Rule?
A. To ensure patients are informed when their unsecured PHI has been compromised
B. To penalize covered entities for all data breaches
C. To require public disclosure of all security incidents
D. To mandate encryption of all PHI
CORRECT ANSWER: A. To ensure patients are informed when their unsecured PHI
has been compromised
Rationale: The Breach Notification Rule requires covered entities and business
associates to provide notification to affected individuals, the Secretary of HHS, and, in
some cases, the media following the discovery of a breach of unsecured PHI. The
primary purpose is to ensure transparency and allow patients to take steps to protect
themselves.
Question 11: A covered entity has a workforce member who is leaving the
organization. When should the entity terminate the workforce member's electronic
access to PHI?
A. At the end of the pay period
B. Within 30 days of their last day
C. Immediately upon termination
D. The next day after termination
CORRECT ANSWER: C. Immediately upon termination
Rationale: The HIPAA Security Rule requires that covered entities implement
procedures to terminate access to electronic protected health information (ePHI) when
the employment or engagement of a workforce member ends. This is a required
implementation specification to ensure no unauthorized access occurs.
Question 12: Which of the following is NOT a right afforded to individuals under the
HIPAA Privacy Rule?
A. Right to access their PHI
B. Right to request restrictions on certain uses and disclosures