Health Insurance Portability and Accountability Act
Comprehensive Certification Examination
Total Questions 100 Multiple-Choice
Time Allowed 3 Hours
Passing Score 70% (70 of 100 correct)
Exam Sections 8 Sections
Exam Year 2026
Candidate Name: _______________________________________________________
Date: _______________________________________________________
Organization: _______________________________________________________
Candidate ID: _______________________________________________________
Exam Sections Overview
Section 1: HIPAA Overview & History Questions 1–10 (10 questions)
,HIPAA Final Exam 2026 Confidential — For Authorized Use Only
Section 2: Protected Health Information (PHI) Questions 11–20 (10 questions)
Section 3: The Privacy Rule Questions 21–35 (15 questions)
Section 4: The Security Rule Questions 36–50 (15 questions)
Section 5: The Breach Notification Rule Questions 51–65 (15 questions)
Section 6: Enforcement & Penalties Questions 66–80 (15 questions)
Section 7: Business Associates & Agreements Questions 81–90 (10 questions)
Section 8: Patient Rights & Special Situations Questions 91–100 (10 questions)
Page 2
, HIPAA Final Exam 2026 Confidential — For Authorized Use Only
EXAM INSTRUCTIONS
General Instructions
• This exam consists of 100 multiple-choice questions covering all major aspects of HIPAA, including
the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and the HITECH Act
amendments.
• You have 3 hours to complete the exam. Manage your time accordingly.
• Each question has four answer choices (A, B, C, D). Select the one best answer for each question.
• A passing score of 70% (70 correct answers out of 100) is required for certification.
• Mark your answers clearly on the answer sheet or as directed by the exam administrator.
• There is no penalty for guessing. It is to your advantage to answer every question.
Topics Covered
• HIPAA Overview & History — The foundations, purpose, and structure of HIPAA legislation.
• Protected Health Information (PHI) — Definitions, identifiers, de-identification, and limited data sets.
• The Privacy Rule — Patient rights, authorizations, permitted disclosures, minimum necessary standard,
and the Notice of Privacy Practices.
• The Security Rule — Administrative, physical, and technical safeguards for ePHI, risk analysis, and
implementation specifications.
• The Breach Notification Rule — Breach definitions, notification timelines, safe harbor provisions, and the
risk assessment process.
• Enforcement & Penalties — Civil and criminal penalties, the four-tier penalty structure, OCR
enforcement, and complaint procedures.
• Business Associates & Agreements — Definitions, BAA requirements, subcontractor obligations, and
liability.
• Patient Rights & Special Situations — Confidential communications, minors, deceased individuals,
research, and preemption analysis.
Exam Policies
• Do not open the exam booklet until instructed to do so.
• All electronic devices must be turned off and stored during the exam.
• No reference materials, notes, or external resources are permitted.
• If you have a question during the exam, raise your hand and an administrator will assist you.
• Upon completion, submit your answer sheet to the exam administrator.
Page 3