1 | Page
HIPAA/PA REFRESHER TEST
2026/2027 ACTUAL QUESTIONS
WITH VERIFIED ANSWERS.
Under HIPAA, a covered entity (CE) is defined as: - ANSWER-
All of the above
Under HIPAA, a CE is a health plan, a health care
clearinghouse, or a health care provider engaged in standard
electronic transactions covered by HIPAA.
The minimum necessary standard: - ANSWER-All of the above
The minimum necessary standard limits uses, disclosures, and
requests for PHI to the minimum necessary amount of PHI
needed to carry out the intended purposes of the use or
disclosure. The minimum necessary standard does not apply to
disclosures to, or requests by, a health care provider for
treatment purposes. It also does not apply to uses or
disclosures made to the individual or pursuant to the
individual's authorization.
, 2 | Page
Which of the following would be considered PHI? - ANSWER-
An individual's first and last name and the medical diagnosis in
a physician's progress report
The HIPAA Privacy Rule applies to which of the following? -
ANSWER-All of the above
The HIPAA Privacy Rule applies to PHI that is transmitted or
maintained by a covered entity or a business associate in any
form or medium.
Which of the following statements about the HIPAA Security
Rule are true? - ANSWER-All of the above
The HIPAA Security Rule: Established a national set of
standards for the protection of PHI that is created, received,
maintained, or transmitted in electronic media by a HIPAA CE
or BA; protects ePHI; and addresses three types of safeguards
- administrative, technical and physical - that must be in place
to secure individuals' ePHI.
The HIPAA Security Rule applies to which of the following: -
ANSWER-PHI transmitted electronically
HIPAA/PA REFRESHER TEST
2026/2027 ACTUAL QUESTIONS
WITH VERIFIED ANSWERS.
Under HIPAA, a covered entity (CE) is defined as: - ANSWER-
All of the above
Under HIPAA, a CE is a health plan, a health care
clearinghouse, or a health care provider engaged in standard
electronic transactions covered by HIPAA.
The minimum necessary standard: - ANSWER-All of the above
The minimum necessary standard limits uses, disclosures, and
requests for PHI to the minimum necessary amount of PHI
needed to carry out the intended purposes of the use or
disclosure. The minimum necessary standard does not apply to
disclosures to, or requests by, a health care provider for
treatment purposes. It also does not apply to uses or
disclosures made to the individual or pursuant to the
individual's authorization.
, 2 | Page
Which of the following would be considered PHI? - ANSWER-
An individual's first and last name and the medical diagnosis in
a physician's progress report
The HIPAA Privacy Rule applies to which of the following? -
ANSWER-All of the above
The HIPAA Privacy Rule applies to PHI that is transmitted or
maintained by a covered entity or a business associate in any
form or medium.
Which of the following statements about the HIPAA Security
Rule are true? - ANSWER-All of the above
The HIPAA Security Rule: Established a national set of
standards for the protection of PHI that is created, received,
maintained, or transmitted in electronic media by a HIPAA CE
or BA; protects ePHI; and addresses three types of safeguards
- administrative, technical and physical - that must be in place
to secure individuals' ePHI.
The HIPAA Security Rule applies to which of the following: -
ANSWER-PHI transmitted electronically