HIPAA AND PRIVACY ACT TRAINING –
1.5 HRS – PRE-TEST ANSWERS – 2026 –
STUDY AND COMPLIANCE GUIDE
Core Domains
HIPAA Privacy Rule Fundamentals
HIPAA Security Rule and Safeguards
Privacy Act of 1974
Breach Prevention and Response
Enforcement, Penalties, and Compliance
Introduction
The HIPAA and Privacy Act Training Pre-Test assesses the
workforce member's foundational knowledge of federal privacy
laws governing protected health information and personally
identifiable information. This 1.5-hour course evaluates
understanding of the HIPAA Privacy and Security Rules, the
Privacy Act of 1974, breach notification requirements, and
compliance obligations within healthcare and federal agency
settings. Questions incorporate multiple-choice and select-all-
that-apply formats requiring application of regulatory standards
to real-world scenarios. Emphasis is placed on identifying
permissible uses and disclosures, recognizing breach causes,
implementing safeguards, and understanding enforcement
mechanisms. Successful completion demonstrates readiness to
protect sensitive information in compliance with federal law.
SECTION ONE: QUESTIONS 1–40
Question 1
,In which of the following circumstances must an individual be
given the opportunity to agree or object to the use and disclosure
of their PHI?
A. Before PHI directly relevant to a person's involvement with the
individual's care or payment of health care is shared with that
person
B. Before their information is included in a facility directory
C. Before treatment is provided in an emergency room
D. Before research data is de-identified
🟢 A and B
🔴 RATIONALE: HIPAA requires patient agreement or objection in
two specific circumstances: (1) when sharing PHI with family or
friends involved in the individual's care or payment, and (2) when
including patient information in a facility directory . Emergency
treatment and de-identified research data do not require such
consent because different privacy protections apply.
Question 2
Which of the following statements about the HIPAA Security Rule
are true?
A. It requires safeguards to ensure the confidentiality, integrity,
and availability of ePHI
B. It requires entities to protect against reasonably anticipated
threats or hazards
C. It requires protection against uses or disclosures not permitted
by the Privacy Rule
D. It requires workforce compliance through training and policies
🟢 All of the above
, 🔴 RATIONALE: The Security Rule establishes a national set of
standards for protecting electronic PHI and addresses three types
of safeguards: administrative, technical, and physical. All listed
statements are integral components of compliance under the
Security Rule .
Question 3
Administrative safeguards are:
A. Firewalls and encryption policies
B. Administrative actions, and policies and procedures to manage
the selection, development, implementation, and maintenance of
security measures for ePHI
C. Physical locks and alarm systems
D. IT software access controls
🟢 B. Administrative actions, and policies and procedures to
manage the selection, development, implementation, and
maintenance of security measures for ePHI
🔴 RATIONALE: Administrative safeguards focus on policy,
workforce training, risk analysis, and ongoing oversight to protect
ePHI. Physical and technical protections fall into separate
categories .
Question 4
Physical safeguards are:
A. Password authentication systems
B. Physical measures, including policies and procedures to protect
electronic systems, equipment, and facilities from hazards and
unauthorized intrusion
C. Role-based access permissions
D. Audit trails of ePHI access
1.5 HRS – PRE-TEST ANSWERS – 2026 –
STUDY AND COMPLIANCE GUIDE
Core Domains
HIPAA Privacy Rule Fundamentals
HIPAA Security Rule and Safeguards
Privacy Act of 1974
Breach Prevention and Response
Enforcement, Penalties, and Compliance
Introduction
The HIPAA and Privacy Act Training Pre-Test assesses the
workforce member's foundational knowledge of federal privacy
laws governing protected health information and personally
identifiable information. This 1.5-hour course evaluates
understanding of the HIPAA Privacy and Security Rules, the
Privacy Act of 1974, breach notification requirements, and
compliance obligations within healthcare and federal agency
settings. Questions incorporate multiple-choice and select-all-
that-apply formats requiring application of regulatory standards
to real-world scenarios. Emphasis is placed on identifying
permissible uses and disclosures, recognizing breach causes,
implementing safeguards, and understanding enforcement
mechanisms. Successful completion demonstrates readiness to
protect sensitive information in compliance with federal law.
SECTION ONE: QUESTIONS 1–40
Question 1
,In which of the following circumstances must an individual be
given the opportunity to agree or object to the use and disclosure
of their PHI?
A. Before PHI directly relevant to a person's involvement with the
individual's care or payment of health care is shared with that
person
B. Before their information is included in a facility directory
C. Before treatment is provided in an emergency room
D. Before research data is de-identified
🟢 A and B
🔴 RATIONALE: HIPAA requires patient agreement or objection in
two specific circumstances: (1) when sharing PHI with family or
friends involved in the individual's care or payment, and (2) when
including patient information in a facility directory . Emergency
treatment and de-identified research data do not require such
consent because different privacy protections apply.
Question 2
Which of the following statements about the HIPAA Security Rule
are true?
A. It requires safeguards to ensure the confidentiality, integrity,
and availability of ePHI
B. It requires entities to protect against reasonably anticipated
threats or hazards
C. It requires protection against uses or disclosures not permitted
by the Privacy Rule
D. It requires workforce compliance through training and policies
🟢 All of the above
, 🔴 RATIONALE: The Security Rule establishes a national set of
standards for protecting electronic PHI and addresses three types
of safeguards: administrative, technical, and physical. All listed
statements are integral components of compliance under the
Security Rule .
Question 3
Administrative safeguards are:
A. Firewalls and encryption policies
B. Administrative actions, and policies and procedures to manage
the selection, development, implementation, and maintenance of
security measures for ePHI
C. Physical locks and alarm systems
D. IT software access controls
🟢 B. Administrative actions, and policies and procedures to
manage the selection, development, implementation, and
maintenance of security measures for ePHI
🔴 RATIONALE: Administrative safeguards focus on policy,
workforce training, risk analysis, and ongoing oversight to protect
ePHI. Physical and technical protections fall into separate
categories .
Question 4
Physical safeguards are:
A. Password authentication systems
B. Physical measures, including policies and procedures to protect
electronic systems, equipment, and facilities from hazards and
unauthorized intrusion
C. Role-based access permissions
D. Audit trails of ePHI access