HIPAA Training Quiz & Practice Questions

Take a free practice quiz or point your phone at any HIPAA training question for an instant, explained answer — Privacy Rule, Security Rule, and breach notification, without the guesswork.

Try it freeFree forever · no card required
Cambo
QUESTION
Under HIPAA, what is considered Protected Health Information (PHI)?
Answer — Individually identifiable health information held or transmitted by a covered entity — including medical records, billing information, and any health data linked to a specific patient.
How it works

Three steps, a few seconds each.

01
Snap a photo
Point your phone at the question — on a screen, a printout, anywhere.
02
Get the answer
Cambo reads the question and answers it in a few seconds.
03
See the explanation
Read the reasoning behind the answer so it actually sticks.

Looking for the official training, not practice questions? hhs.gov — HIPAA training materials ↗

Why it works

Built for exactly this kind of question.

HIPAA training questions often ask you to apply the Privacy Rule or Security Rule to a specific scenario — is this disclosure permitted, is this a reportable breach — and the right answer depends on details easy to miss. Cambo reads the exact scenario and explains the reasoning, not just the answer.

Practice quiz

Test yourself with real practice questions.

Under HIPAA, what is considered Protected Health Information (PHI)?

  1. AAny medical information published in a peer-reviewed journal
  2. BOnly paper medical records held in a physician's office
  3. CIndividually identifiable health information held or transmitted by a covered entity, including medical records and billing data
  4. DAggregate health statistics released by a state health department
Tap the card to reveal the answer
Answer
CIndividually identifiable health information held or transmitted by a covered entity, including medical records and billing data
Individually identifiable health information held or transmitted by a covered entity — including medical records, billing information, and any health data linked to a specific patient.

A nurse discusses a patient's diagnosis with a coworker in a public hallway. What HIPAA concern does this raise?

  1. ANo concern — clinical staff may discuss any patient anywhere in the facility
  2. BA potential Privacy Rule violation, since PHI should be discussed on a need-to-know basis in a way that minimizes incidental disclosure
  3. CA concern only if a family member of the patient overhears it
  4. DA Security Rule violation, since the discussion was not encrypted
Tap the card to reveal the answer
Answer
BA potential Privacy Rule violation, since PHI should be discussed on a need-to-know basis in a way that minimizes incidental disclosure
A potential Privacy Rule violation — PHI should only be discussed on a need-to-know basis and in a manner that minimizes the risk of incidental disclosure to others.

A hospital employee accesses the medical record of a celebrity patient out of curiosity, with no job-related reason. What HIPAA issue does this raise?

  1. ANo violation, because the employee did not share the information with anyone
  2. BNo violation, because the employee is an authorized user of the record system
  3. CA violation only if the celebrity later files a complaint
  4. DAn impermissible access — viewing PHI without a treatment, payment, or operations need is a violation even if nothing is shared
Tap the card to reveal the answer
Answer
DAn impermissible access — viewing PHI without a treatment, payment, or operations need is a violation even if nothing is shared
An impermissible access/disclosure — accessing PHI without a legitimate treatment, payment, or operations need is a violation even if the information is never shared further.

What is the "minimum necessary" standard under HIPAA?

  1. AUsing, disclosing, or requesting only the minimum PHI needed to accomplish the intended purpose
  2. BKeeping records for the minimum period required by state law
  3. CLimiting the number of staff who may be granted system access
  4. DCollecting the minimum number of signatures on a consent form
Tap the card to reveal the answer
Answer
AUsing, disclosing, or requesting only the minimum PHI needed to accomplish the intended purpose
The requirement to use, disclose, or request only the minimum amount of PHI needed to accomplish the intended purpose — not the entire record when only part of it is relevant.

Does HIPAA require patient authorization to share PHI for treatment purposes?

  1. AYes — written authorization is required before any disclosure of PHI
  2. BYes — but only when the providers work for different organizations
  3. CNo — the Privacy Rule permits sharing PHI for treatment, payment, and healthcare operations without specific authorization
  4. DNo — HIPAA does not regulate disclosures between healthcare providers at all
Tap the card to reveal the answer
Answer
CNo — the Privacy Rule permits sharing PHI for treatment, payment, and healthcare operations without specific authorization
No — the Privacy Rule permits sharing PHI without specific authorization for treatment, payment, and healthcare operations; authorization is generally required for other purposes, like marketing.

What is the deadline for notifying affected individuals after a HIPAA breach affecting 500 or more people?

  1. AWithin 24 hours of discovery
  2. BWithin 30 days of discovery
  3. CWithin 6 months of discovery
  4. DWithout unreasonable delay and no later than 60 days after discovery
Tap the card to reveal the answer
Answer
DWithout unreasonable delay and no later than 60 days after discovery
Without unreasonable delay, and no later than 60 days after discovery — breaches of this size also require notifying HHS and, in some cases, the media.
1 / 6
2 / 6
3 / 6
4 / 6
5 / 6
6 / 6
FAQ

Questions, answered.

How often is HIPAA training required?

Annually for most healthcare organizations, though HIPAA itself doesn't specify an exact frequency — it requires training that is 'periodic' and covers policy updates.

Who has to complete HIPAA training?

Any workforce member of a covered entity or business associate who may come into contact with Protected Health Information, including clinical and non-clinical staff.

What's the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs how PHI can be used and disclosed. The Security Rule specifically addresses safeguarding electronic PHI (ePHI) through administrative, physical, and technical controls.

Is Cambo affiliated with HHS or any official HIPAA program?

No. Cambo is an independent study tool, not produced or endorsed by the U.S. Department of Health and Human Services.

What counts as a HIPAA breach?

An impermissible use or disclosure of PHI that compromises its security or privacy, unless the covered entity demonstrates a low probability that the information was compromised.

What are the penalties for HIPAA violations?

They range widely based on the level of culpability, from a few hundred dollars per violation for unknowing violations to over a million dollars annually for willful neglect that isn't corrected.
Practice resources

Browse questions for a specific test or training.

Cambo works on any question you can photograph — here are the ones tutors and students search for most.