← Back to CBT Library

HIPAA & Privacy Act

Health information privacy and the Privacy Act of 1974 — JKO DHA-US001

58 questions and answers — updated 2025/2026
01

What two laws does the DHA-US001 training cover?

02

What is Protected Health Information (PHI)?

03

Which formats are considered electronic PHI (ePHI)?

04

What does the HIPAA Privacy Rule establish?

05

What does the HIPAA Security Rule require?

06

What are the three types of safeguards required by the HIPAA Security Rule?

07

What is the 'minimum necessary' standard?

08

Does the minimum necessary standard apply to disclosures for treatment?

09

What is the Privacy Act of 1974?

10

What does PII stand for and what does it include?

11

What is a System of Records Notice (SORN)?

12

What is a Privacy Impact Assessment (PIA)?

13

Under what circumstances must an individual be given the opportunity to agree or object to the use and disclosure of their PHI?

14

Who is a 'covered entity' under HIPAA?

15

Is the Military Health System (MHS) a covered entity?

16

What is a Business Associate?

17

What is required before sharing PHI with a Business Associate?

18

What are the permitted uses and disclosures of PHI without individual authorization?

19

What uses of PHI ALWAYS require written authorization from the individual?

20

What is the HIPAA Breach Notification Rule?

21

What is considered a 'breach' under HIPAA?

22

Within what timeframe must individuals be notified of a PHI breach?

23

When is media notification required for a breach?

24

What DoD regulation implements the HIPAA Privacy Rule for the Military Health System?

25

What rights do individuals have under the HIPAA Privacy Rule?

26

What is the Notice of Privacy Practices (NPP)?

27

What should you do if you discover or suspect a breach of PHI?

28

What is the penalty for wrongful disclosure of individually identifiable health information?

29

What are the 18 HIPAA identifiers that make health information 'individually identifiable'?

30

What is 'de-identified' health information?

31

What two methods can be used to de-identify PHI?

32

Can a service member's commander access their full medical record?

33

What is the role of the Privacy Officer?

34

What is the role of the Security Officer?

35

What training is required under HIPAA?

36

How often must DoD personnel complete HIPAA and Privacy Act training?

37

What does HIPAA Title I cover?

38

What does HIPAA Title II cover?

39

What are administrative safeguards?

40

What are physical safeguards?

41

What are technical safeguards?

42

What is the 'accounting of disclosures' right?

43

What is a 'designated record set'?

44

Under what circumstances can a covered entity deny a request to amend PHI?

45

What is a Privacy Act 'routine use'?

46

What should you do before emailing PHI?

47

What is the difference between 'use' and 'disclosure' of PHI?

48

Can PHI be disclosed for law enforcement purposes?

49

What is the HITECH Act and how did it affect HIPAA?

50

What should you do if you receive a misdirected fax or email containing PHI?

51

What is 'protected health information' in the context of the Military Health System?

52

Who can file a HIPAA complaint?

53

How long must HIPAA-related documentation be retained?

54

What is 'unsecured PHI'?

55

What are the four factors in a breach risk assessment?

56

Can PHI be used for research without individual authorization?

57

What is the relationship between the Privacy Act and HIPAA in the DoD?

58

What are consequences for DoD personnel who violate HIPAA or the Privacy Act?

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Want to study these as flashcards?

Create a free study set with spaced repetition, multiple choice tests, and AI explanations.

Create Study Set