CITI HIPAA TRAINING
PRACTICE TEST 60
QUESTIONS
Question 1: What is the primary purpose of the HIPAA Privacy Rule?
Choices:
1) To standardize hospital stang ratios 2) To establish national standards for protecting individuals' medical information while allowing appropriate information ow 3) To require every health record to be stored electronically 4) To prohibit all disclosures of patient information Correct Answer: To establish national standards for protecting individuals' medical information while allowing appropriate information ow Explanation: The HIPAA Privacy Rule establishes national standards for protecting protected health information while permitting uses and disclosures needed for care and other lawful purposes.Page 1
Question 2: Which federal oce is primarily responsible for administering and enforcing the HIPAA Privacy, Security, and Breach Notication Rules?
Choices:
1) Centers for Disease Control and Prevention 2) Oce of Inspector General 3) HHS Oce for Civil Rights 4) Federal Trade Commission
Correct Answer: HHS Oce for Civil Rights
Explanation: The U.S. Department of Health and Human Services Oce for Civil Rights administers and enforces the HIPAA Privacy, Security, and Breach Notication Rules.
Question 3: Which statement best describes protected health information under
HIPAA?
Choices:
1) Any health-related fact found anywhere on the internet 2) Individually identiable health information held or transmitted by a covered entity or business associate in a covered form 3) Only a physician's written diagnosis 4) Only electronic billing records Correct Answer: Individually identiable health information held or transmitted by a covered entity or business associate in a covered form Explanation: PHI is individually identiable health information created, received, maintained, or transmitted by covered entities or business associates, subject to HIPAA's scope and exclusions.Page 2
Question 4: Which information is protected by the HIPAA Security Rule?
Choices:
1) All paper medical records 2) Only verbal conversations about patients 3) Electronic protected health information 4) De-identied health statistics only
Correct Answer: Electronic protected health information
Explanation: The Security Rule specically protects electronic protected health information, or ePHI, through administrative, physical, and technical safeguards.Question 5: A clinic learns that state law gives patients stronger privacy protection than HIPAA for a particular type of record. What should the clinic generally do?
Choices:
1) Ignore state law because HIPAA always preempts it 2) Follow the more stringent state privacy protection when applicable 3) Apply whichever rule is easier for sta 4) Disclose the record whenever HIPAA would permit it Correct Answer: Follow the more stringent state privacy protection when applicable Explanation: HIPAA generally creates a federal oor of privacy protection. More stringent state privacy laws can remain applicable and must be followed.Page 3