100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CITI - HIPAA Training Questions & Answers 2025/2026 ( A+ GRADED 100% VERIFIED)

Rating
-
Sold
-
Pages
8
Grade
A+
Uploaded on
01-10-2025
Written in
2025/2026

CITI - HIPAA Training Questions & Answers 2025/2026 ( A+ GRADED 100% VERIFIED)










Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
October 1, 2025
Number of pages
8
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

  • citi hipaa training

Content preview

CITI - HIPAA Training


- ANS -

A covered entity may use or disclose PHI without an authorization, or documentation of
a waiver or an alteration of authorization, for all of the following EXCEPT: - ANS - Data
that does not cross state lines when disclosed by the covered entity.

A HIPAA authorization has which of the following characteristics: - ANS - Uses "plain
language" that the data subject can understand, similar to the requirement for an
informed consent document.

Compared to fixed location (desktop) computers, physical security for portable devices
is: - ANS - Generally more necessary, because portable devices tend to be used in
physical environments that are inherently less secure.

Desktop computers are often provided in the workplace by organizations, and laptops
may be as well. However, portable devices (such as tablets and smartphones) may
more commonly be allowed on a BYOD basis. For a BYOD (personally-owned) device: -
ANS - Organizations may have requirements about how BYOD devices may be
configured or used, as a condition of accessing the organization's information
resources.

Desktop computers are often provided in the workplace by organizations, and laptops
may be as well. However, portable devices (such as tablets and smartphones) may
more commonly be allowed on a BYOD basis. For a BYOD (personally-owned) device: -
ANS - Organizations may have requirements about how BYOD devices may be
configured or used, as a condition of accessing the organization's information
resources.

Devices used purely for storage, like USB flash ("thumb") drives and external hard
drives: - ANS - May expose large amounts of data if compromised, so should also use
protections like access passwords or PINs and whole-device data encryption.

Enabling a device login password or PIN, and an inactivity timeout to force (re)login with
that password or PIN after the device is idle for a defined period, is generally
considered: - ANS - Generally considered essential for any portable device.

, Enabling encryption of all data on a desktop or laptop computer is generally considered:
- ANS - Essential for any computer. Only data on computers that are guaranteed to
contain no sensitive information, or where the physical and technical security of the
device is assured, can safely be left unencrypted.

Enabling encryption of all data on a portable device is generally considered: - ANS -
Essential for any portable device.

Ensuring data backups for data stored on a portable device is generally considered: -
ANS - Necessary when the device would otherwise be the only source of
hard-to-replace data, but the backup mechanism must also be secure

External labeling with a physical label, or configuring a device to display the owner's
name and contact information on a login screen, is: - ANS - Generally considered a
good idea, because it allows the device to be returned to its owner when found.
However, always check organizational policies about the practice.

Fines and jail time (occasionally) for information security failures are: - ANS - Generally,
only applied for serious, deliberate misuse, where someone intentionally accesses data
in order to do harm or for personal gain.

For health information privacy and security, are the legal and regulatory requirements
for students different from those for regular members of the healthcare workforce? -
ANS - No, students must meet the same standards as a regular member of the
workforce performing the same tasks.

HIPAA allows health care organizations to control many information decisions. But
where the patient retains control, which of the following is/are true? - ANS - If a person
has a right to make a health care decision, then he/she has a right to control information
associated with that decision.

HIPAA allows healthcare organizations to control many information decisions. However,
where the patient retains control, which of the following is true? - ANS - If a person has
a right to make a healthcare decision, then generally that person has a right to control
information associated with the decision.

HIPAA includes in its definition of "research," activities related to: - ANS - Development
of generalizable knowledge.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
janenurse Chamberlain College Of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
256
Member since
2 year
Number of followers
221
Documents
2462
Last sold
1 month ago

4.1

45 reviews

5
30
4
3
3
5
2
2
1
5

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions