Confidentiality Quiz
Questions: 16 · 10 minutes
1. A colleague who is not assigned to a case asks to see its file because they are curious about the outcome. What should you do?
Decline and direct the colleague to the proper authorization or access process.
Show only sections that do not appear especially sensitive.
Allow access if the colleague works in the same department.
Share a verbal summary but not the written file.
2. Which statement best defines confidentiality?
Information is confidential only when it is protected by encryption or a password.
All information about a person must remain secret in every circumstance.
People may decide for themselves which personal details deserve protection.
Information entrusted to someone is used or disclosed only for authorized purposes and to authorized people.
3. What does the “minimum necessary” principle generally require?
Keeping every record for the shortest technically possible period.
Accessing or sharing only the information needed for an authorized task.
Giving all team members equal access so work is not delayed.
Removing names from information before every internal use.
4. Which statement about exceptions to confidentiality is most accurate?
Confidentiality has no exceptions once information has been received in confidence.
Any concern about another person's behavior permits complete disclosure.
Defined laws or policies may allow or require disclosure, usually with information limited to what is necessary.
Exceptions apply only when the person concerned gives written consent.
5. While working remotely, you notice that people passing behind you can see confidential information on your screen. What should you do?
Lower the screen brightness while continuing to work in the same position.
Continue if the people nearby are unlikely to understand the information.
Lock or shield the screen and move to a setting where viewing is restricted to authorized people.
Minimize documents whenever someone walks past, then reopen them afterward.
6. How does pseudonymized information differ from fully anonymized information?
Pseudonymized information replaces identifiers but can still be linked back using additional information.
Pseudonymized information can be published freely because direct names are absent.
Pseudonymized information contains no data relating to individuals.
Pseudonymized information is simply confidential information stored without encryption.
7. What is the best way to dispose of printed documents containing confidential information?
Keep the documents indefinitely so disposal cannot create a disclosure risk.
Tear each document into several pieces before placing it in ordinary recycling.
Place the documents face down in an office waste bin.
Use the organization's approved secure-disposal process, such as a protected shredding container.
8. For consent to disclose confidential information to be meaningful, what should the person generally understand?
That consent permanently transfers control of the information to the recipient.
Only the name of the organization receiving the information.
What will be shared, with whom, for what purpose, and any relevant limits or choices.
That agreeing is normally required to continue receiving any service.
9. You receive a legal-looking demand for confidential records. What is the most appropriate response?
Send the records promptly because formal-looking requests are automatically valid.
Send a summary instead of the records so formal review is unnecessary.
Ignore it unless the requester contacts you a second time.
Preserve the request and refer it to the authorized legal, privacy, or records function for validation before disclosure.
10. Someone calls claiming to be the parent of an adult client and asks whether the client attended an appointment. No authorization is visible. What is the best response?
Confirm attendance because close family members normally have an implied right to know.
Ask the caller to provide the adult client's date of birth before answering.
Confirm only whether an appointment existed, not what happened during it.
Avoid confirming any personal information and follow the applicable identity and authorization procedure.
11. A friend asks whether someone they know receives services from your organization. You have no authorization to discuss the person. What should you do?
Confirm it but avoid sharing details about the services.
Say you cannot discuss current cases, which indirectly confirms the person is involved.
Do not confirm or deny the person's involvement, and provide only general public information if useful.
Ask why the friend wants to know before deciding whether to answer.
12. You accidentally email a confidential attachment to the wrong internal recipient. What is the best immediate response?
Wait to see whether the recipient opens it before treating it as an incident.
Use any available recall feature and promptly follow the organization's incident-reporting procedure.
Ask the recipient to delete it, then report it only if they do not respond.
Decide whether the information seems sensitive enough before involving anyone else.
13. What usually happens to confidentiality responsibilities when an employee leaves an organization?
They may continue under law, professional duties, or agreements, and information must be returned or handled as instructed.
They end on the final working day unless the information was marked secret.
They continue only for information the former employee still remembers word for word.
They end once the former employee loses access to organizational systems.
14. You are preparing confidential case notes for discussion at a team meeting. Which approach best protects confidentiality?
Include only relevant information, restrict attendance to authorized participants, and secure the notes afterward.
Include the complete history so no participant needs to ask follow-up questions.
Remove the person's name, then invite any employee who may have useful ideas.
Circulate the notes in advance to the whole department to improve preparation.
15. A research dataset has names removed, but rare details could still allow individuals to be recognized. What is the correct conclusion?
The dataset is fully anonymous because direct names are absent.
Re-identification may still be possible, so disclosure controls and risk assessment remain important.
The dataset is no longer confidential if it is used for research.
Only the rare details need protection; the rest can be released without review.
16. During a professional conversation, a person describes a specific and imminent threat of serious harm. What is the soundest general response?
Promise that the information will remain confidential before asking for more details.
Follow the applicable urgent-safety and escalation procedure, sharing necessary information only with appropriate responders.
Record the concern but wait for harm to occur before escalating it.
Warn everyone who knows the person so they can monitor the situation.