← Back

22 Privacy, Confidentiality & Systems Practice Questions & Answers

Every Privacy, Confidentiality & Systems practice question from the AHIMA CCA Practice Test, with the correct answer and a short explanation.

Start practice test
  1. 1. A coder emails a colleague a spreadsheet of patients' admission dates, five-digit ZIP codes, and full dates of birth, with names and record numbers removed. Under the HIPAA Privacy Rule, how is this file best characterized?

    • A.De-identified data, because the names and medical record numbers were stripped out first
    • B.A limited data set that staff may circulate internally without any further safeguards
    • C.De-identified data, because no one outside the coding unit could match a date to a patient
    • D.Protected health information, since dates and geography are identifiers in themselvesAnswer

    Safe harbor de-identification requires removing 18 identifiers, which include all date elements related to an individual and geographic subdivisions smaller than a state. Admission dates, birth dates, and ZIP codes remain here, so the file is still PHI and must be safeguarded.

    Source: 45 CFR 164.514(b)(2) — safe harbor de-identification, 18 identifiersReport a problem with this question

  2. 2. A coder is assigned an outpatient encounter for a diabetic foot ulcer. In the EHR she can also see notes from the patient's psychiatric admission two years ago. Applying the minimum necessary standard, what should she do?

    • A.Read the whole longitudinal record, because more history always yields more specific codes
    • B.Review the psychiatric admission as well, since coder accounts carry full-chart access rights
    • C.Request written approval from the privacy officer before opening any note in this encounter
    • D.Limit her review to the documentation of the current encounter that supports code assignmentAnswer

    Minimum necessary obliges a covered entity to limit workforce access to the PHI needed for the job at hand. Coding this outpatient encounter does not require the earlier psychiatric admission, and having technical access to a record is not the same as having a work reason to open it.

    Source: 45 CFR 164.502(b) and 164.514(d) — minimum necessary standardReport a problem with this question

  3. 3. A hospital sends a patient's coded diagnoses and operative report to her health plan to support the claim, and separately uses the same record internally for a coding quality review. Which statement about authorization is correct?

    • A.The internal quality review requires a signed authorization; the claim submission does not
    • B.Both uses require a signed authorization, because an operative report is being disclosed
    • C.The claim submission requires a signed authorization; the internal quality review does not
    • D.Neither use requires an authorization, since they are payment and health care operationsAnswer

    The Privacy Rule permits use and disclosure of PHI for treatment, payment, and health care operations without patient authorization. Billing the plan is payment, and coding quality review is a health care operations activity, which is why coding work sits under operations.

    Source: 45 CFR 164.506(c) — uses and disclosures for TPO; 164.501 definition of health care operationsReport a problem with this question

  4. 4. A law firm submits an authorization signed by the patient that names the records sought and the firm as recipient, but the expiration date and expiration event are both left blank. What should the HIM department do?

    • A.Return the authorization, but release the billing portion, which needs no expiration
    • B.Release the records, since a signature and a description of the records are sufficient
    • C.Return the authorization and request one that states an expiration date or eventAnswer
    • D.Release the records and document that an undated authorization defaults to one year

    A valid authorization must contain every core element, including an expiration date or an expiration event tied to the stated purpose. An authorization missing a required element is defective and may not be acted upon, and no default expiration period exists.

    Source: 45 CFR 164.508(b)(2) and (c)(1) — defective authorizations and core elementsReport a problem with this question

  5. 5. At the end of her shift a coder has printed face sheets on her desk, and her supervisor asks for her EHR password so the night coder can finish her work queue. What is the correct action?

    • A.Leave the account signed in for the night coder and place the printouts in recycling
    • B.Write the password down for the night coder and lock the printouts in her desk drawer
    • C.Lock the workstation, put the printouts in the shred bin, and refuse to share itAnswer
    • D.Give the supervisor the password, since a supervisor may authorize temporary sharing

    The Security Rule requires unique user identification so that every action in the system traces to one person, which sharing a password defeats no matter who asks. Printed PHI must be destroyed by shredding or another approved method rather than left in ordinary waste or recycling.

    Source: 45 CFR 164.312(a)(2)(i) unique user identification; 164.530(c) safeguards; HHS PHI disposal guidanceReport a problem with this question

  6. 6. A patient requests a copy of her designated record set. The facility must act within 30 days but cannot compile the record in that time. What does the Privacy Rule permit?

    • A.An indefinite delay while any part of the record is still with the coding unit
    • B.Two successive 15-day extensions, each confirmed by a telephone call to the patient
    • C.A 60-day extension whenever the request covers an inpatient stay of any length
    • D.One 30-day extension, with written notice of the reason and the expected dateAnswer

    Section 164.524 gives a covered entity 30 days to act on an access request and allows a single extension of no more than 30 days, provided the individual receives a written statement of the reason for the delay and the date by which the entity will act.

    Source: 45 CFR 164.524(b)(2) — timely action on access requestsReport a problem with this question

  7. 7. A patient asks for an accounting of disclosures covering the past six years. Which of the following must appear on it?

    • A.The report of a suspected communicable disease made to the state health agencyAnswer
    • B.The claim with coded diagnoses sent to her health plan for payment of her stay
    • C.The copy of her record that was mailed to her at her own written request
    • D.The records sent to a specialist who is treating her for the same condition

    The accounting reaches six years back but expressly excludes disclosures for treatment, payment, and health care operations, disclosures to the individual, and several other categories. A mandatory public health report is none of those, so it must be tracked and accounted for.

    Source: 45 CFR 164.528(a) — accounting of disclosures and its exclusionsReport a problem with this question

  8. 8. A patient pays a clinic in full out of pocket for a visit and asks that nothing about it go to her health plan. No law requires the clinic to report the service. How must the clinic respond?

    • A.It may decline unless the patient also asks for confidential communications by mail
    • B.It must agree, because the request concerns a service paid for in full out of pocketAnswer
    • C.It may decline, since a covered entity never has to accept a requested restriction
    • D.It must agree only after the health plan approves the restriction in writing first

    A covered entity may generally refuse a requested restriction, but agreement is mandatory when the disclosure would go to a health plan for payment or operations, is not otherwise required by law, and the item or service was paid in full by the individual.

    Source: 45 CFR 164.522(a)(1)(vi) — mandatory restriction after out-of-pocket paymentReport a problem with this question

  9. 9. A hospital contracts with an outside coding company whose employees log into the hospital EHR from home to assign codes. Which statement is correct?

    • A.The company is a business associate, needs a written agreement, and is directly liableAnswer
    • B.The company is a covered entity, because it handles PHI in order to prepare claims
    • C.The company needs a written agreement but can be pursued only for breach of contract
    • D.The company is part of the hospital workforce, so no written agreement is needed

    A business associate creates, receives, maintains, or transmits PHI to perform a function on the covered entity's behalf, and coding is such a function. Since the 2013 Omnibus Rule, business associates are directly liable to OCR for the Security Rule and specified Privacy Rule duties, and a written agreement is required.

    Source: 45 CFR 160.103 business associate definition; 164.502(e) and 164.308(b) — BAA and direct liabilityReport a problem with this question

  10. 10. State law where a hospital operates requires specific written consent before HIV test results are released, while HIPAA would permit the release for treatment. Which requirement governs?

    • A.HIPAA, because federal privacy law preempts state health privacy law in every case
    • B.Whichever rule the requesting provider names in the written request for the records
    • C.HIPAA, because disclosures made for treatment are exempt from state consent statutes
    • D.The state law, because HIPAA sets a floor and the more stringent rule prevails hereAnswer

    HIPAA generally preempts contrary state law, but not where the state provision is more stringent, meaning more protective of the individual's privacy rights. The durable, tested duty is to check the applicable state or special-category rule rather than treat the federal standard as a ceiling.

    Source: 45 CFR 160.203(b) and 160.202 — preemption and the definition of 'more stringent'Report a problem with this question

  11. 11. A coder emails a spreadsheet with 40 patients' names and diagnoses to an outside address by mistake. The privacy officer must decide whether notification is owed. What is the correct starting position?

    • A.It is a breach only if the officer can show the recipient opened and read the file
    • B.It is presumed a breach unless a four-factor assessment shows low compromise riskAnswer
    • C.It is a breach only when the impermissible disclosure affects 500 or more people
    • D.It is not a breach, because a single recipient received it and no harm is evident

    Subpart D presumes that an impermissible use or disclosure of unsecured PHI is a breach unless the entity demonstrates a low probability of compromise using a risk assessment that weighs the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the mitigation achieved.

    Source: 45 CFR 164.402 — definition of breach and the four-factor risk assessmentReport a problem with this question

  12. 12. A laptop holding a coding worklist is stolen from an employee's car. The drive was encrypted to HHS-specified standards and the decryption key was stored elsewhere. What follows?

    • A.Notification is required, although encryption lowers the culpability tier applied
    • B.Notification is excused, since encryption to HHS standards leaves the PHI securedAnswer
    • C.Notification is required within 30 calendar days because a device left the facility
    • D.Notification is excused only if the laptop is recovered and examined within 60 days

    The Breach Notification Rule applies only to unsecured PHI. Information encrypted according to the HHS-specified guidance is 'secured,' so a lost or stolen encrypted device falls outside the rule altogether rather than merely reducing the consequence.

    Source: 45 CFR 164.402 'unsecured protected health information'; HHS guidance under HITECH sec. 13402(h)(2)Report a problem with this question

  13. 13. A coder notices a colleague opening the record of a well-known local athlete who is not on that colleague's work list. What should the coder do?

    • A.Report the access to the privacy officer through the organization's incident channelAnswer
    • B.Pull the audit log herself to verify the access before deciding whether to act on it
    • C.Ask the colleague why the record was opened and drop it if the answer sounds fine
    • D.Take no action, since merely viewing a record without telling anyone is no violation

    Workforce members are expected to recognize and report privacy issues and violations, and the organization must maintain a channel for doing so. Opening a record without a work-related reason is itself an impermissible use, and investigating or confronting the coworker is not the reporter's role.

    Source: 45 CFR 164.530(d) complaint process and 164.502(b); AHIMA CCA Domain 6 task 3 (recognize and report)Report a problem with this question

  14. 14. Under the information blocking regulations implementing the 21st Century Cures Act, which of the following is an 'actor' subject to the rules?

    • A.A health plan that receives claims and clinical data from network hospitals monthly
    • B.An employer that keeps occupational health records about its own employees on file
    • C.A malpractice insurer that stores claim files containing copies of clinical records
    • D.A physician practice that maintains electronic health information about its patientsAnswer

    Part 171 recognizes three categories of actor: health care providers, developers of certified health IT, and health information exchanges or networks. Health plans, liability insurers, and employers are not actors, even when they hold clinical information.

    Source: 45 CFR 171.102 — definition of actor (health care provider, certified health IT developer, HIE/HIN)Report a problem with this question

  15. 15. A clinic sets its portal to hold every lab result for three days so a clinician can review it first, applying the delay to all results with no individual determination. How is this best characterized?

    • A.Conduct covered by the Privacy exception, since the patient did not ask for results
    • B.Conduct covered by the Health IT Performance exception, since review is system work
    • C.Conduct covered by no exception, so a blanket delay is information blockingAnswer
    • D.Conduct covered by the Preventing Harm exception, since results can alarm patients

    Information blocking is a practice by an actor likely to interfere with access, exchange, or use of EHI unless required by law or covered by an exception. The Preventing Harm exception demands an individualized determination that the practice substantially reduces a risk of harm, so an across-the-board portal delay does not qualify.

    Source: 45 CFR 171.103 information blocking; 171.201 Preventing Harm exceptionReport a problem with this question

  16. 16. For purposes of the information blocking rules, what does 'electronic health information' (EHI) mean?

    • A.Only the data classes and elements named in the interoperability standard for exchange
    • B.Any clinical data a provider stores, including psychotherapy notes and litigation files
    • C.Only information a covered entity keeps inside its certified electronic record system
    • D.Electronic PHI to the extent it would be in a designated record set, whoever holds itAnswer

    Part 171 defines EHI as electronic protected health information to the extent it would be included in a designated record set, regardless of whether the records are held by a HIPAA covered entity, with the same carve-outs for psychotherapy notes and litigation-compilation information.

    Source: 45 CFR 171.102 — definition of electronic health informationReport a problem with this question

  17. 17. After a coder finalizes the codes for an inpatient stay, the abstracting system runs a grouper. What does the grouper do?

    • A.It assigns the case to an MS-DRG using the codes, discharge status, and case dataAnswer
    • B.It compares the codes with payer edits and rewrites any code that would be denied
    • C.It selects the principal diagnosis by scanning the discharge summary for key phrases
    • D.It translates the ICD-10-CM codes into SNOMED CT concepts for the clinical record

    A grouper takes data the coder has already produced — diagnosis and procedure codes plus discharge status, age, sex, and POA indicators — and places the case in a payment group. It does not assign codes, and the coder stays responsible for the code set that drives it.

    Source: AHIMA CCA Domain 5 task 2 — utilize encoding and grouping software; CMS MS-DRG grouper logicReport a problem with this question

  18. 18. A coder uses an encoder that walks her through branching clinical questions about the documented condition instead of displaying index and tabular pages. What kind of tool is this?

    • A.A grouper, because branching questions are how payment groups get determined
    • B.A logic-based encoder, in which the coder still selects and owns the final codeAnswer
    • C.A computer-assisted coding engine, which reads the note and posts codes itself
    • D.An automated codebook encoder, which reproduces the index and tabular screens

    Logic-based, or knowledge-based, encoders prompt the coder with branching questions built on coding rules and guidance, while automated codebook encoders mirror the printed index and tabular list. With either type the credentialed coder makes and is accountable for the final selection.

    Source: AHIMA CCA Domain 5 task 2 — utilize encoding and grouping softwareReport a problem with this question

  19. 19. A computer-assisted coding system reads a dictated operative note with natural language processing and presents a suggested code set. What is the coder's responsibility?

    • A.Route the suggested codes to the physician for approval before the claim is dropped
    • B.Accept the codes and add a note stating that the software generated the assignment
    • C.Review each suggested code against the documentation before the claim is billedAnswer
    • D.Accept the suggested codes, because the software was validated at implementation

    CAC suggests codes from unstructured text; it does not assign them. Validating that output is an explicit Domain 5 task, and the credentialed coder remains accountable for adding, deleting, and confirming every code before the claim goes out.

    Source: AHIMA CCA Domain 5 task 5 — validate the codes assigned by CAC softwareReport a problem with this question

  20. 20. During pre-bill review a coder sees that the CAC system suggested a sepsis code because the note states that sepsis was ruled out. What should she do?

    • A.Refer the chart to the business office to decide whether the code should stand
    • B.Remove the code, because a condition documented as ruled out is not reportable hereAnswer
    • C.Retain the code, because the software read the actual text of the physician's note
    • D.Retain the code and let a post-payment audit decide whether the record supports it

    Natural language processing can match a term without capturing the negation around it. A code the documentation does not support has to be deleted before the claim is submitted, and 'the software suggested it' is not a defense in an audit.

    Source: AHIMA CCA Domain 5 task 5; AHIMA Standards of Ethical Coding — report only codes supported by documentationReport a problem with this question

  21. 21. A clinic is selecting software to handle scheduling, patient registration, insurance eligibility checks, charge entry, and accounts receivable follow-up. Which system does that work?

    • A.A practice management system, which runs registration and the revenue cycle workAnswer
    • B.A clinical data repository, which stores results and reports for the whole enterprise
    • C.A health information management system, which tracks charts and chart deficiencies
    • D.An encoder, which supports code selection and holds the coding edits and guidance

    Practice management systems run the administrative and financial cycle: scheduling, registration, eligibility, charge entry, claims, and accounts receivable. HIM systems handle chart tracking, deficiency management, release of information, and coding workflow, and the two are not interchangeable.

    Source: AHIMA CCA Domain 5 task 3 — utilize practice management and HIM systemsReport a problem with this question

  22. 22. A coder reviewing a progress note finds the assessment copied word for word from the admission note, still listing an acute condition the record shows resolved two days earlier. How should she proceed?

    • A.Assign codes from the admission note, the most complete source in the whole chart
    • B.Assign the acute condition, since it appears in a signed note from this admission
    • C.Assign the acute condition and let the CDI team correct the record after billing
    • D.Assign codes from the documentation reflecting the patient's status this stayAnswer

    Copy-forward text can carry a resolved condition into later notes, which is a data integrity defect rather than evidence the condition persists. Codes must reflect what the documentation actually establishes for the encounter, so carried-forward text contradicted by the rest of the record cannot support reporting it.

    Source: AHIMA CCA Domain 5 — EHR documentation integrity; ICD-10-CM Official Guidelines Section III (additional diagnoses)Report a problem with this question

Practice questions based on the AHIMA Certified Coding Associate (CCA) Exam Content Outline, the ICD-10-CM and ICD-10-PCS Official Guidelines for Coding and Reporting, and the AHIMA Standards of Ethical Coding. This site is not affiliated with or endorsed by AHIMA. Code sets and their official guidelines are revised every year, so no question here keys a specific code value — always assign codes from the current code books, encoder and official guidelines in effect for the date of service, never from a practice test. Confirm current eligibility and exam requirements with AHIMA before you test. About the CCA credential →