20 HIPAA Privacy, Security & Compliance Practice Questions & Answers
Every HIPAA Privacy, Security & Compliance practice question from the CEHRS Electronic Health Records Specialist Practice Test, with the correct answer and a short explanation.
Start practice test →1. A physician at another hospital who is currently treating the patient calls and asks for the patient's complete record. The EHR specialist worries that sending the whole chart breaks the minimum necessary standard. Which statement is correct?
- A.The minimum necessary standard does not apply to disclosures made to a provider for treatment✓ Answer
- B.The minimum necessary standard applies to every disclosure a covered entity chooses to make
- C.The minimum necessary standard applies unless the patient signs an additional authorization form
- D.The minimum necessary standard applies to paper charts but not to electronic health records
The Privacy Rule lists specific situations in which the minimum necessary standard does not apply, and the first of them is a disclosure to, or request by, a health care provider for treatment; the others include disclosures to the individual, disclosures made under a signed authorization, disclosures to HHS for a compliance investigation, and disclosures required by law. Because treatment is exempt, releasing the record the treating physician asks for is permitted.
Source: HIPAA Privacy Rule, 45 CFR 164.502(b) minimum necessary standardReport a problem with this question
2. A practice plans to take part in a federal EHR incentive program and asks the EHR specialist what the requirement is for the software it uses. What must the practice's EHR system be?
- A.Accredited by the state medical society to which the providers belong
- B.Registered with the professional liability carrier that insures the practice
- C.Approved in writing by the largest commercial payer the practice bills
- D.Certified under the federal health information technology certification program✓ Answer
Federal EHR incentive programs have always been built on certified electronic health record technology: the system must be certified under the national health IT certification program, which tests that it can perform the functions the program measures, such as electronic prescribing, information exchange, and giving patients electronic access to their records. Insurers, payers, and professional societies play no role in that certification.
Source: ONC Health IT Certification Program; NHA CEHRS Test Plan, Regulatory ComplianceReport a problem with this question
3. A data set is being de-identified using the Safe Harbor method. One patient in the file is 94 years old. How must that patient's age be handled?
- A.It is reported without change because age is not an identifier
- B.It is reported as a ten-year band covering the patient's decade
- C.It is reported as the exact age once the birth date is removed
- D.It is reported in a single combined category of 90 or older✓ Answer
Under Safe Harbor, ages and any date elements that indicate an age over 89 must be aggregated into a single category of 90 or older, because very old ages are rare enough in a population to point back to one individual. Ages of 89 and below may be kept, and dates other than the year attached to the person must still be removed.
Source: HIPAA Privacy Rule, 45 CFR 164.514(b) Safe Harbor de-identificationReport a problem with this question
4. A researcher asks the EHR specialist for a file of patient records that keeps admission dates and ZIP codes but has direct identifiers such as names and account numbers removed. What is true of this file?
- A.It is de-identified data and may be shared without further conditions
- B.It is a limited data set and may be released for any business purpose
- C.It is a limited data set and requires a signed data use agreement✓ Answer
- D.It is de-identified data because dates and ZIP codes are not identifiers
A limited data set is still protected health information: it removes sixteen direct identifiers but may keep town or city, state, ZIP code, all dates, and ages, which is exactly why it is not considered de-identified. It may be disclosed only for research, public health, or health care operations, and only after the recipient signs a data use agreement limiting use and barring re-identification.
Source: HIPAA Privacy Rule, 45 CFR 164.514(e) limited data set and data use agreementReport a problem with this question
5. An authorization form arrives that names the requester, describes the records wanted, and carries the patient's signature and date, but it has no expiration date or expiration event. What should the EHR specialist do?
- A.Release only the visit summary because the form is partly complete
- B.Return the form and request a completed authorization from the patient✓ Answer
- C.Release the records and file the form with a note about the omission
- D.Write a one-year expiration date on the form and release the records
An expiration date or expiration event is one of the core elements the Privacy Rule requires, alongside a specific description of the information, the person disclosing, the recipient, the purpose, and the individual's signature and date. An authorization missing a core element is invalid on its face, so no disclosure may be made and staff may not fill in the element themselves.
Source: HIPAA Privacy Rule, 45 CFR 164.508(c) core elements of a valid authorizationReport a problem with this question
6. A patient asks for a copy of everything in her record, and specifically names the psychotherapy notes her counselor keeps. How should the EHR specialist handle the psychotherapy notes?
- A.They are released to the patient only as a summary prepared by staff
- B.They are released to the patient after the counselor countersigns the request
- C.They are released with the rest of the record once the copy fee is paid
- D.They are released without the psychotherapy notes, which fall outside the right of access✓ Answer
The right of access covers the designated record set, but the Privacy Rule carves out two categories entirely: psychotherapy notes, meaning the counselor's separately kept session notes, and information compiled in reasonable anticipation of litigation. The rest of the record must still be provided, and a provider may choose to share the notes only with a valid authorization.
Source: HIPAA Privacy Rule, 45 CFR 164.524 right of accessReport a problem with this question
7. A patient requests an accounting of disclosures of his protected health information. Which of the following disclosures must be included on that accounting?
- A.A copy sent to an employer under an authorization the patient signed
- B.A communicable disease report sent to a public health agency as required by law✓ Answer
- C.A record summary sent to a specialist who is treating the patient
- D.A claim containing clinical detail submitted to the patient's health plan
The accounting covers the six years before the request but expressly excludes disclosures for treatment, payment, and health care operations, disclosures made under a signed authorization, disclosures to the individual, incidental disclosures, and several others. A report required by law to a public health agency fits none of those exclusions, so it is logged with its date, the recipient, a description of the information, and the purpose.
Source: HIPAA Privacy Rule, 45 CFR 164.528 accounting of disclosuresReport a problem with this question
8. A caller states that he is the patient's attorney and asks that the full chart be faxed to his office today. What should the EHR specialist do first?
- A.Transfer the call to the physician who last treated the patient
- B.Verify his identity and his written authority to receive the record✓ Answer
- C.Fax the record to the number he gives and document the call afterward
- D.Fax a visit summary today and mail the remaining record the next day
The Privacy Rule requires a covered entity to verify the identity of a person requesting protected health information and that person's authority to receive it before making a disclosure. For an attorney that means a valid signed authorization or other legal documentation on file, and the release is then limited to the records the authorization actually describes.
Source: HIPAA Privacy Rule, 45 CFR 164.514(h) verification requirementsReport a problem with this question
9. A nurse whose EHR account is locked out asks the specialist to let her chart under the specialist's login so she does not fall behind. What is the appropriate action?
- A.Give her the password and change it at the end of the shift
- B.Log in for her and stay at the workstation while she documents
- C.Enter her documentation into the chart under the specialist's account
- D.Direct her to the help desk so her own account is restored✓ Answer
The Security Rule requires a unique user identifier for every workforce member precisely so that each action in the system can be traced to one identifiable person. Charting under someone else's login destroys that attribution, makes the audit trail false, and leaves the account owner accountable for entries she did not make, so the fix is to restore the nurse's own access.
Source: HIPAA Security Rule, 45 CFR 164.312(a) unique user identificationReport a problem with this question
10. An EHR specialist with system-wide access opens her adult brother's recent visit record because she is worried about him, and never tells anyone what she read. How is this action viewed?
- A.A violation, because she had no work-related reason to open the record✓ Answer
- B.Acceptable, because she disclosed nothing that she read to anyone else
- C.Acceptable, because immediate family members may view one another's records
- D.A violation only if the visit involved a specially protected type of treatment
Access privileges are granted so a workforce member can do an assigned job, and using them for curiosity or personal concern is unauthorized access even when nothing is copied, printed, or repeated. Being a relative gives no right of entry; the brother would have to request his own record or sign an authorization, and the audit log will show her user ID on the chart.
Source: HIPAA Privacy Rule, 45 CFR 164.502; HIPAA Security Rule, 45 CFR 164.308(a)(4) information access managementReport a problem with this question
11. A user transfers from the billing department to the front registration desk. What should be done with that user's EHR account?
- A.Suspend the account until the user repeats new-employee training
- B.Add the new privileges and keep the former ones for shift coverage
- C.Adjust the privileges to the new role and remove the former ones✓ Answer
- D.Leave the account unchanged until the next annual access review
Information access management requires that privileges be established, reviewed, and modified so they match a user's current role, which is the practical meaning of role-based access and of the minimum necessary standard applied to system rights. Letting old billing privileges accumulate alongside new registration privileges leaves the user able to reach data the current job never needs.
Source: HIPAA Security Rule, 45 CFR 164.308(a)(4) access establishment and modificationReport a problem with this question
12. After a risk analysis, a clinic concludes that encrypting electronic protected health information stored on one server is not reasonable and appropriate in its setting. Under the Security Rule, what must the clinic do?
- A.Document the reasoning and put an equivalent alternative measure in place✓ Answer
- B.Send the decision to the federal enforcement office and await its approval
- C.Record the decision in the risk analysis and take no further action on it
- D.Drop the specification entirely, since addressable measures are optional
An addressable implementation specification is not optional: the entity must assess whether it is a reasonable and appropriate safeguard, and if it is not, document why and implement an equivalent alternative that meets the standard. Encryption of stored electronic protected health information and automatic logoff are addressable, while unique user identification and the emergency access procedure are required outright.
Source: HIPAA Security Rule, 45 CFR 164.306(d) addressable implementation specificationsReport a problem with this question
13. A privacy filter is installed on a monitor at a busy check-in desk so that people standing nearby cannot read the screen. Under the Security Rule, this is an example of which safeguard category?
- A.A physical safeguard✓ Answer
- B.An administrative safeguard
- C.A technical safeguard
- D.An organizational requirement
Physical safeguards protect equipment, media, and the space around them, and workstation security, which covers how a device is placed and shielded from view, sits in that category along with facility access controls and device and media disposal. Technical safeguards are the controls built into the system itself, such as unique logins, audit controls, and automatic logoff, while administrative safeguards are the policies, training, and risk management around them.
Source: HIPAA Security Rule, 45 CFR 164.310 physical safeguardsReport a problem with this question
14. A transcription vendor working under a business associate agreement discovers that a folder of dictation files was exposed to the open internet. Whom must the vendor notify about the incident?
- A.The state agency that issues the covered entity's license
- B.The federal civil rights enforcement office that oversees HIPAA
- C.The covered entity whose patient records were involved✓ Answer
- D.The affected individuals and the local news media outlets
Under the breach notification requirements added by the HITECH Act, a business associate that discovers a breach notifies the covered entity, and the covered entity then carries the duty to notify individuals, the media where applicable, and the federal government. Routing the notice through the covered entity keeps one party responsible for the risk assessment and for proving that required notifications were made.
Source: HITECH Act breach notification; 45 CFR 164.410 notification by a business associateReport a problem with this question
15. A laptop holding electronic protected health information is stolen from an employee's car. Which fact most directly determines whether breach notification is required?
- A.Whether the information on it was encrypted to recognized federal standards✓ Answer
- B.Whether the theft was reported promptly to the local police department
- C.Whether the laptop belonged to the clinic or personally to the employee
- D.Whether the laptop screen was protected by a strong log-in password
Breach notification is triggered only by unsecured protected health information, meaning information that has not been rendered unusable, unreadable, or indecipherable by encryption or destruction that meets federal guidance. A stolen laptop encrypted to that standard generally is not a reportable breach, while an unencrypted one is presumed to be a breach unless a four-factor risk assessment shows a low probability that the information was compromised.
Source: HITECH Act breach notification; 45 CFR 164.402 definition of unsecured protected health informationReport a problem with this question
16. A facility's system faithfully records every access to electronic protected health information, but no one ever examines the logs. How does this practice stand under the Security Rule?
- A.Non-compliant, because records of system activity must be reviewed regularly✓ Answer
- B.Compliant, because the required recording mechanism is in place and working
- C.Non-compliant, because the logs must be printed and filed as paper records
- D.Compliant, because reviewing logs is an addressable rather than required step
Audit controls require mechanisms that record and examine activity in systems containing electronic protected health information, and the separate administrative requirement to review information system activity makes the examination step mandatory rather than optional. Logs that nobody reads cannot detect snooping, cannot support a breach risk assessment, and leave the entity unable to show that it monitored access.
Source: HIPAA Security Rule, 45 CFR 164.312(b) audit controls and 45 CFR 164.308(a)(1) information system activity reviewReport a problem with this question
17. An EHR specialist finds that a set of vital signs was entered into the wrong patient's chart yesterday. How should the erroneous entry be handled in the record?
- A.Delete the wrong entry so that the chart shows only accurate information
- B.Overwrite the values in place and note the change in a separate department log
- C.Ask the system administrator to purge the entry from the underlying database
- D.Enter a dated correction that leaves the original entry visible in the chart✓ Answer
The health record is a legal document, so an error is corrected by adding a dated, timed, attributed entry while the original remains retrievable, which is also how an amendment works when a patient asks for one. Deleting or overwriting an entry breaks the integrity of the record and the audit trail, and it destroys the evidence needed to explain any care that was based on the wrong data.
Source: HIPAA Privacy Rule, 45 CFR 164.526 amendment of protected health information; NHA CEHRS Test Plan, Regulatory ComplianceReport a problem with this question
18. After a two-hour unplanned outage, the paper notes written during downtime are being entered into the EHR. How should those entries be dated and timed?
- A.With the time the note was typed, since that is when the chart changed
- B.With the actual time care was given, recorded as a late entry✓ Answer
- C.With the actual time care was given, so that no delay is apparent
- D.With the time the system came back online, applied to the whole packet
Back-entered downtime documentation must show both truths at once: the entry carries the actual date and time of the care so the clinical sequence is accurate, and it is flagged as a late entry so the record shows when it was actually made. Dating an entry to hide the delay is backdating, which falsifies the legal record even when the clinical facts are right; the paper originals are then scanned in and the reconciled charts audited.
Source: HIPAA Security Rule, 45 CFR 164.308(a)(7) contingency plan; NHA CEHRS Test Plan, Regulatory ComplianceReport a problem with this question
19. Which element of the Security Rule contingency plan is described as creating and maintaining retrievable exact copies of electronic protected health information?
- A.The emergency mode operation plan
- B.The data backup plan✓ Answer
- C.The data criticality analysis
- D.The disaster recovery plan
The contingency plan standard separates three required pieces that candidates often blur: the data backup plan makes retrievable exact copies, the disaster recovery plan restores data that was lost, and the emergency mode operation plan keeps critical business processes running and protected while systems are down. The criticality analysis, which ranks how important each application and data set is, is addressable rather than required.
Source: HIPAA Security Rule, 45 CFR 164.308(a)(7) contingency planReport a problem with this question
20. A provider's free-text medication order in the EHR reads to give ".5 mg" of a drug. Why must this be corrected before the order is carried out?
- A.A dose must always carry a trailing zero after the final decimal digit
- B.A dose smaller than one must be written as a fraction, not a decimal
- C.A dose must be spelled out in words instead of written in numerals
- D.A dose below one must carry a leading zero before the decimal point✓ Answer
A dose written without a leading zero is on the accreditation standard's do-not-use list because a missed decimal point turns .5 mg into 5 mg, a tenfold overdose, so the order must read 0.5 mg. The mirror-image rule bars a trailing zero in a medication dose, since 5.0 mg can be read as 50 mg, and both rules apply to handwritten and free-text electronic orders alike.
Source: The Joint Commission Do Not Use List of abbreviations, acronyms and symbolsReport a problem with this question
Practice questions based on the NHA CEHRS Test Plan, the HIPAA Privacy and Security Rules (45 CFR Part 164), and the HITECH Act. This site is not affiliated with or endorsed by the National Healthcareer Association. Every electronic health record system arranges its own screens and menus, so workflows here are described in general terms — follow your own system's documentation and your facility's policies. Record-retention periods, permissible abbreviations, and many release-of-information details are set by state law and facility policy rather than federally, and penalty amounts are adjusted over time; verify all of these against current sources rather than against a practice test. Confirm current eligibility and exam requirements with NHA before you test. About the CEHRS certification →