HIPAA Quiz
Questions: 16 · 10 minutes
1. Which example is protected health information, or PHI, when maintained by a HIPAA covered entity?
A public report containing only anonymous county-level health totals
A school education record governed by FERPA
An employer’s personnel record about an employee’s sick leave
A clinic appointment record connected to a patient’s name
2. When a breach of unsecured PHI requires notice to affected individuals, what is HIPAA’s general federal timing rule?
Notice must be provided without unreasonable delay and no later than 60 calendar days after discovery
Notice may wait until the organization’s next annual privacy report
Notice must be provided within 90 days after the calendar year ends
Notice must be provided within five business days in every case
3. Which group is composed entirely of HIPAA covered entities?
Health plans, health care clearinghouses, and health care providers that conduct covered transactions electronically
All employers, insurance brokers, and health-related mobile apps
Every health care provider, regardless of whether it conducts covered electronic transactions
Medical device manufacturers, pharmaceutical companies, and life insurers
4. Which two HIPAA methods can be used to de-identify health information?
Expert Determination and Safe Harbor
Minimum Necessary and Role-Based Access
Encryption and Password Protection
Patient Authorization and Notice of Privacy Practices
5. A receptionist calls a patient’s name in a waiting room, and another visitor hears it. Reasonable privacy precautions are in place. How is this generally treated under HIPAA?
It is always a reportable breach because another person heard the name
It is prohibited unless the patient signed a written authorization
It may be a permissible incidental disclosure when tied to an allowed activity and reasonable safeguards are used
It is permitted only if the waiting room contains no more than two patients
6. A hospital wants to place an identifiable patient photograph in a public advertising campaign. What does HIPAA generally require before this use?
A verbal agreement witnessed by any hospital employee
An acknowledgment that the patient received the Notice of Privacy Practices
A valid written authorization from the patient
Approval from the patient’s health plan instead of the patient
7. A workforce member steps away from a shared-area computer displaying electronic PHI. What is the most appropriate immediate action?
Turn the monitor slightly so people passing by are less likely to read it
Lock or log off the workstation according to the organization’s security procedures
Leave the screen open because other authorized staff may need the computer
Minimize the record window but leave the active session available
8. Which disclosure is generally excluded from a standard HIPAA accounting of disclosures?
A disclosure to another provider for the patient’s treatment
A report of specified information to a public health authority
A disclosure made for a qualifying law-enforcement purpose
A disclosure made in response to a qualifying court order
9. An employee receives an unexpected email asking for a password to prevent immediate loss of medical-record access. What is the best HIPAA-aware response?
Reply to confirm whether the sender knows the employee’s username
Open the link but leave the password field blank
Forward the message to coworkers so they can determine whether it looks genuine
Avoid the link and report the suspected phishing attempt through the organization’s security process
10. A hospital encrypts electronic PHI stored on employees’ laptops. Under the Security Rule, encryption is primarily what type of safeguard?
An administrative safeguard
A patient access safeguard
A physical safeguard
A technical safeguard
11. A billing employee needs records to answer a health plan’s payment question. What best follows HIPAA’s minimum necessary standard?
Send the entire medical record because the health plan already knows the patient
Access and disclose only the information reasonably needed to resolve the payment question
Ask the patient to authorize every payment-related disclosure
Refuse to share any information unless the request comes from a treating physician
12. A patient asks a clinic for a copy of records in a designated record set. Under the HIPAA federal rule, what is the usual response deadline?
Ten business days, with no extension allowed
Thirty calendar days, with one possible 30-day extension if the patient receives a written explanation and completion date
Sixty calendar days after the request
Forty-five calendar days, with an automatic extension
13. An unencrypted laptop containing PHI is lost. Which statement best reflects HIPAA’s breach analysis?
It cannot be a breach unless someone admits opening a patient file
It is automatically a breach in every case, so no assessment is permitted
The incident is presumed to be a breach unless a documented risk assessment demonstrates a low probability that the PHI was compromised
It matters only if the laptop contains records for at least 500 people
14. A medical practice hires a cloud company to store electronic PHI on its behalf. What is generally required by HIPAA?
No agreement if the vendor does not routinely open the files
Only a standard nondisclosure agreement between the two companies
Patient authorization for every record placed in cloud storage
A business associate agreement establishing permitted uses and required safeguards
15. A patient asks a covered entity to amend information in a designated record set. Which statement is accurate?
The covered entity must accept every requested change exactly as written
The covered entity may deny the request on permitted grounds but must provide a written denial explaining applicable rights
The patient has no HIPAA right to request an amendment
The covered entity may silently reject the request if a clinician disagrees
16. Which federal office is primarily responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules?
The Centers for Disease Control and Prevention
The Federal Communications Commission
The HHS Office for Civil Rights
The Social Security Administration