and Answers Latest Updated 2025/2026
(Graded A+)
1. Within HIPAA how does Security differ from Privacy?
• Correct Answer — Security defines safeguards for ePHI versus Privacy
which defines safeguards for PHI
Rationale:
HIPAA Privacy Rule covers the rights and permissible uses of all Protected Health
Information (PHI) whether oral, paper, or electronic, while the Security Rule
focuses specifically on electronic PHI (ePHI) and sets administrative, physical, and
technical safeguards to protect it. This distinction ensures both broad patient
confidentiality and targeted data protection in electronic systems.
2. Covered Entities may also use or disclose PHI without authorization in the
following circumstances EXCEPT:
A. Emergencies involving imminent threat to health or safety (to the
individual or the public)
B. Where required by law
C. Law enforcement
D. Medical research with information that identifies the individual
E. Public health activities
F. Workers' compensation
, • Correct Answer — D. Medical research with information that identifies the
individual
Rationale:
HIPAA permits PHI disclosures without authorization for public health, law
enforcement, legal requirements, emergencies, and workers’ compensation.
However, research that identifies individuals requires specific patient
authorization or an IRB waiver. This ensures that patient rights are not bypassed
in research contexts.
3. Authorization is required for which of the following?
A. Minimum necessary disclosures of PHI
B. Non-routine disclosures of PHI
C. Referrals
D. Treatment
• Correct Answer — B. Non-routine disclosures of PHI
Rationale:
Routine uses like treatment, payment, or healthcare operations do not require
patient authorization. HIPAA does require authorization for non-routine or non-
standard disclosures, such as sharing PHI for purposes beyond core health
operations, to ensure patient consent in non-traditional data use.
4. Penalties for non-compliance can be which of the following types?
A. Civil and Accidental
B. Criminal and Incidental
C. Accidental and Purposeful
D. Civil and Criminal
• Correct Answer — D. Civil and Criminal
Rationale:
HIPAA violations can trigger civil monetary penalties (for negligence or lack of due
,diligence) and criminal penalties (for intentional misuse, such as selling PHI). This
dual system enforces accountability across varying levels of severity.
5. Which of the following is NOT an example of physical security?
A. Lock file cabinets
B. Lock office doors
C. Locked media storage cases
D. Data encryption
• Correct Answer — D. Data encryption
Rationale:
Physical security measures involve tangible barriers (locks, secured rooms,
restricted access areas). Data encryption, while vital, is a technical safeguard, not
physical. HIPAA requires layered protection, combining physical, administrative,
and technical strategies.
6. What is a key to success for HIPAA compliance?
A. Managerial expertise
B. Education
C. Organizational structure
D. Apathy
• Correct Answer — B. Education
Rationale:
Training ensures that all workforce members understand policies, patient rights,
and security requirements. Without education, even robust technical safeguards
fail due to human error. Continuous education is central to sustaining HIPAA
compliance.
, 7. Which of the following are examples of health care plans?
A. An HMO
B. The Medicaid program
C. Employer group health plans
D. All of the above
• Correct Answer — D. All of the above
Rationale:
HIPAA applies to a broad range of health plans: HMOs, government-funded
programs (Medicaid/Medicare), and employer-sponsored group health plans.
Recognizing this scope is vital because HIPAA protects PHI across all these
contexts, not just within hospitals or clinics.
8. The Security Rule's requirements are organized into which of the following
three categories:
A. Administrative, Non-Administrative, and Technical safeguards
B. Physical, Technical, and Non-Technical safeguards
C. Administrative, Physical, and Technical safeguards
D. Privacy, Security, and Electronic Transactions
• Correct Answer — C. Administrative, Physical, and Technical safeguards
Rationale:
The HIPAA Security Rule mandates three safeguard categories. Administrative
safeguards are policies and procedures; Physical safeguards protect equipment,
facilities, and access points; Technical safeguards secure ePHI via IT systems.
Together, they ensure layered protection of electronic health data.
9. Incidental Use and Disclosures refers to disclosures that are incidental to an
otherwise permitted use or disclosure.