Relias Hipaa Training
10 community-sourced questions and answers. Free — no login.
Which of the following is NOT an acceptable, permissible, purpose for disclosure of PHI without an authorization?
For entertainment purposes
Tamara is behind on her work as an analyst and decides she needs to do some work at home tonight. She copies the files she has been working on (which contain PHI) to a flash drive and drops the flash drive in her purse for later use. When Tamara gets home, the flash drive is missing. Is this a security breach?
Yes, it is a security breach. The data on the flash drive was not encrypted or otherwise protected and there is no way to undo the potential damage because the flash drive is lost.
True or False: Your company can be fined up to $50,000, per violation, for violating HIPAA even when you disclosed PHI by mistake.
True
Which of the following steps would NOT help to avoid a HIPAA violation?
Asking your friends to promise they wont repeat anything you tell them about work.
True or False: The Safe Harbor method of de-identifying health information requires that 18 types of identifiers of the individual and their relatives, employers, or household members that must be removed.
True
Mark is catching up on progress notes after his shift as a nurse at a long term care community. He remembers a funny incident in which a patient forgot to put on his pants before he went to breakfast. Mark tells the other professionals about the incident who are also catching up on progress notes. Mark laughingly says "Mr. Jones' dementia is really getting the best of him". Is Mark in violation of HIPAA?
Yes, this information is protected by HIPAA.
Under which circumstance can you disclose PHI?
If it is for the purpose of treatment.
Which of the following is not PHI:
A statement about the number of individuals seen by the hospital for treatment of depression in 2014.
Which of the following is not a purpose of HIPAA?
It allows PHI to be unsecured at all times
Raj has been reviewing copies of medical records of patients from his clinic to see if he can identify any opportunities for quality improvement. Company policy requires Raj to shred documents containing PHI and to dispose of the shreds in locked bins for later disposal. But the door to the shredder room is locked and Raj is tired. He decides to throw the copies out in the garbage can without shredding - just this once. Has Raj violated HIPAA?
Yes, Raj did not follow the company's HIPAA P&Ps about proper disposal of PHI. He could have locked them up for later "proper" disposal. So he has violated company policy and HIPAA.
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials