Free HIPAA Practice Test
Free HIPAA practice test with answers and explanations.
Check your HIPAA knowledge in a few minutes. This free practice test covers the Privacy Rule, Security Rule, breach notification, business associates, and the everyday workplace situations that trip people up. You see whether each answer is right as you go, then unlock your scored results, full explanations, and a study plan at the end.
Free practice test
Start your HIPAA practice test
20 multiple-choice questions across the Privacy Rule, Security Rule, breach notification, business associates, and real workplace scenarios. You see whether each answer is right as you go. At the end you unlock your scored results, full explanations, and a short study plan.
This practice test helps you study. It is not a substitute for completing the HIPAA course, passing its graded assessment, and earning a dated certificate.
Sample questions
HIPAA quiz questions and answers from this practice test
PHI Basics
Which of the following is protected health information (PHI) under HIPAA?
- A patient's first name stored next to their appointment diagnosis
- A hospital's published main phone number
- A fully de-identified research dataset with no identifiers
- A generic brochure about flu season
Show answer
Correct answer: A patient's first name stored next to their appointment diagnosis
PHI is individually identifiable health information transmitted or maintained by a covered entity or business associate, subject to the exclusions in 45 CFR 160.103. A name tied to a diagnosis identifies the person and reveals health information, so it qualifies.
Privacy Rule
What does the minimum necessary standard require?
- Sharing complete records whenever a coworker asks
- Using, disclosing, or requesting only the PHI reasonably needed for the task
- Limiting PHI access only to physicians
- Applying only to paper records, never electronic ones
Show answer
Correct answer: Using, disclosing, or requesting only the PHI reasonably needed for the task
The minimum necessary standard limits PHI to what is reasonably needed to accomplish a specific purpose. It applies broadly, though treatment disclosures between providers are a notable exception.
Security Rule
The HIPAA Security Rule requires three categories of safeguards for electronic PHI. What are they?
- Financial, legal, and clinical
- Administrative, physical, and technical
- Federal, state, and local
- Marketing, billing, and scheduling
Show answer
Correct answer: Administrative, physical, and technical
The Security Rule organizes protections for electronic PHI into administrative safeguards, physical safeguards, and technical safeguards.
Breach Notification
Under the Breach Notification Rule, when must affected individuals generally be notified after a breach of unsecured PHI is discovered?
- Within 24 hours
- Without unreasonable delay and no later than 60 days
- Within one year
- Only if the patient asks
Show answer
Correct answer: Without unreasonable delay and no later than 60 days
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI.
Business Associates
A cloud vendor will store patient appointment data for your practice. What is the key HIPAA question?
- Whether the vendor offers a nicer dashboard
- Whether the vendor is cheaper than your current tool
- Whether the vendor is a business associate that needs a signed BAA
- Whether the vendor is headquartered in your state
Show answer
Correct answer: Whether the vendor is a business associate that needs a signed BAA
A vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and generally requires a business associate agreement (BAA) before handling PHI.
Common Scenarios
A friend asks you to look up whether a mutual acquaintance was treated at your hospital. What should you do?
- Quickly check and share only a little information
- Decline, because accessing records without a work-related need violates HIPAA
- Check the record but do not tell anyone you looked
- Ask a coworker to look it up instead
Show answer
Correct answer: Decline, because accessing records without a work-related need violates HIPAA
Accessing PHI without a legitimate, work-related reason is prohibited, even out of curiosity and even if nothing is shared.
Want all 40 questions with scoring, explanations, and a study plan? Take the full practice test above, free.
Built for your role
Take the HIPAA practice test written for your job
Nurses
9 role-specific questions plus the core pool.
Medical Assistants
9 role-specific questions plus the core pool.
Dental Offices
9 role-specific questions plus the core pool.
Mental Health Professionals
9 role-specific questions plus the core pool.
Medical Billing and Coding
9 role-specific questions plus the core pool.
Front Desk Staff
9 role-specific questions plus the core pool.
Healthcare IT and Security
9 role-specific questions plus the core pool.
Business Associates and Vendors
9 role-specific questions plus the core pool.
Home Health and Hospice
9 role-specific questions plus the core pool.
Telehealth and Remote Workers
9 role-specific questions plus the core pool.
Pharmacy Teams
9 role-specific questions plus the core pool.
EMTs and First Responders
9 role-specific questions plus the core pool.
What it covers
Six core HIPAA domains covered in this practice test
Privacy Rule
PHI, minimum necessary, and patient rights
Identify protected health information, apply the minimum necessary standard, and answer questions about access, amendment, and accounting of disclosures.
Security Rule
Administrative, physical, and technical safeguards
Tell the three safeguard categories apart, recognize access controls and encryption decisions, and connect risk analysis to real safeguards.
Breach Notification
Timelines, thresholds, and incident response
Know the 60-day federal outer limit, the separate HHS and media thresholds, and the first reporting step when PHI reaches the wrong person.
Business Associates
When a vendor needs a BAA
Decide when a vendor is a business associate, what a business associate agreement does, and where covered-entity responsibility still applies.
Enforcement
OCR, penalty tiers, and willful neglect
Understand who enforces HIPAA, how civil penalty tiers map to culpability, and why curiosity-driven record access can violate policy and the HIPAA Rules.
Workplace Scenarios
Hallway conversations, email, and snooping
Work through everyday situations where reasonable safeguards, incidental disclosure rules, and the right of access decide the correct answer.
Study guide
How to read each HIPAA topic before you answer
HIPAA basics: who is covered and what counts as PHI
HIPAA, the Health Insurance Portability and Accountability Act, sets national rules for how protected health information is used and disclosed. The rules apply to covered entities, which are health plans, healthcare clearinghouses, and healthcare providers that conduct covered standard transactions electronically. A person or organization can be a business associate when it performs a defined function or service for a covered entity that involves PHI, subject to the exceptions in 45 CFR 160.103. Health data outside those relationships may still be governed by other federal or state laws.
Protected health information, or PHI, is individually identifiable health information transmitted or maintained by a covered entity or business associate, subject to the exclusions in 45 CFR 160.103. A name next to a diagnosis and a medical record number tied to a visit are common examples. Removing the 18 Safe Harbor identifier categories is one de-identification method, but it works only when the covered entity also has no actual knowledge that the remaining information could identify the individual.
The Privacy Rule and the minimum necessary standard
The Privacy Rule controls how PHI may be used and shared. The most important idea to carry into the exam is the minimum necessary standard: you use, disclose, or request only the PHI that is reasonably needed for the task in front of you. A billing clerk filing a claim needs the procedure code, not the full clinical note. A scheduler needs an appointment time, not a complete history. The clearest violations on a test involve someone reaching for far more information than the job requires.
There is one large exception worth memorizing. Minimum necessary does not restrict disclosures for treatment among providers, because clinicians need a complete picture to care for a patient safely. The Privacy Rule also permits use and disclosure for treatment, payment, and healthcare operations, often shortened to TPO, without a separate patient authorization. The rule permits other defined uses and disclosures as well. Uses that meet the Privacy Rule definition of marketing and sales of PHI generally require written authorization unless a regulatory exception applies.
Patient rights you will be tested on
Patients hold several rights under the Privacy Rule, and questions love to probe the edges of them. The right of access lets a patient inspect and obtain a copy of their records, generally within 30 days, for no more than a reasonable cost-based fee. Patients can request an amendment when they believe a record is wrong, request an accounting of certain disclosures, and request restrictions on how their information is used. What patients cannot do is force a provider to permanently delete a lawful medical record on demand, and HIPAA does not control what a person voluntarily shares about their own health on social media.
The Security Rule: three kinds of safeguards
The Security Rule protects electronic PHI through three safeguard categories, and you should be able to sort any example into the right bucket. Administrative safeguards are the policies and people side: workforce training, risk analysis, access management, and sanction policies. Physical safeguards control physical access to systems and devices, such as locking server rooms, securing workstations, and controlling the disposal of media. Technical safeguards live in the technology itself: unique user IDs, authentication, access control, audit logs, and encryption.
Two details show up often. First, the risk analysis is foundational. It identifies risks to the confidentiality, integrity, and availability of electronic PHI so the organization can put reasonable and appropriate safeguards in place. Second, encryption is an addressable specification, not a flat mandate. Addressable does not mean optional. It means you assess whether encryption is reasonable and appropriate, implement it when it is, and document your reasoning and any equivalent alternative when it is not.
Breach notification: timelines and thresholds
When unsecured PHI is breached, the clock starts. Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. If a breach affects 500 or more individuals, the covered entity must notify HHS on the large-breach timeline. Media notice has a different test: it applies when more than 500 residents of one State or jurisdiction are affected. Breaches affecting fewer than 500 individuals must be maintained in a log and reported to HHS no later than 60 days after the end of the calendar year. Individual notice still has its own 60-day outer limit.
A practice question may use a simple mistake, such as emailing PHI to the wrong recipient. The right first move is to report it promptly through the organization's incident process so the responsible team can preserve facts, contain further disclosure, assess the event, and document the decision.
Business associates and BAAs
Business-associate status depends on the function or service performed and whether it involves PHI, with exceptions for workforce members, certain treatment disclosures, conduits, and other relationships described in 45 CFR 160.103. When an outside party meets that definition, the covered entity and business associate need the written assurances required by 45 CFR 164.502(e) and 164.504(e). Each party retains the duties that apply to its role.
Enforcement and penalties
The Department of Health and Human Services, Office for Civil Rights, known as OCR, is the primary enforcer of the Privacy, Security, and Breach Notification Rules. Civil monetary penalties follow a tiered structure based on culpability, ranging from cases where the entity did not know and could not reasonably have known, up to willful neglect that was never corrected. The dollar amounts and annual caps are adjusted over time, so a good test answer focuses on the tiered, culpability-based structure rather than memorizing a specific number. Accessing records out of curiosity with no work-related reason can violate the HIPAA Rules and the organization's access policy even if nothing is shared.
De-identification and the two HIPAA methods
Questions often hinge on whether data is still PHI. HIPAA recognizes two ways to de-identify information so it falls outside the Privacy Rule. The first is Safe Harbor, which removes 18 specific categories of identifiers, including names, all geographic detail smaller than a state with a narrow exception for the first three ZIP code digits, all date elements more specific than a year, phone and fax numbers, email addresses, account and record numbers, biometric identifiers, and full-face photos. The second is the expert determination method, where a qualified statistician documents that the risk of re-identification is very small. Once data is properly de-identified, it is no longer PHI and can be used more freely. The trap on a test is assuming that simply deleting a name is enough, because a date of service paired with a small town can still identify someone.
Notice of Privacy Practices and authorizations
Covered entities subject to 45 CFR 164.520 must provide a Notice of Privacy Practices that explains covered uses and disclosures, legal duties, and individual rights. The distribution and posting rules vary by entity and direct-treatment relationship. The notice is not a permission slip. A separate authorization may be required for uses such as defined marketing or a sale of PHI, while the Privacy Rule permits many other uses and disclosures without one.
Incidental disclosures versus impermissible disclosures
Not every overheard detail is a violation. The Privacy Rule tolerates incidental disclosures, the limited and unavoidable byproducts of an otherwise permitted use, as long as the entity applies reasonable safeguards and follows the minimum necessary standard. A visitor catching a fragment of a clinical conversation in a treatment area can be acceptable. An impermissible disclosure is different: sharing PHI with someone who has no legitimate reason to receive it, or sharing far more than the situation requires. The exam-friendly distinction is whether reasonable safeguards were in place and whether the underlying use was permitted. Lowering your voice, using private rooms when practical, and positioning screens away from public view are the safeguards that turn a risky moment into an acceptable incidental one.
Workforce sanctions and a culture of compliance
The Security Rule and the Privacy Rule both expect organizations to apply sanctions against workforce members who violate policies and procedures. The organization applies its sanction policy to the facts and maintains required documentation. Training, clear policies, role-based access, audit log review, and consistent enforcement work together as a program rather than as isolated rules. On a test, the sound answer in a workforce scenario combines reporting the issue, applying the policy, and documenting the outcome rather than handling it quietly or making an undocumented exception.
HITECH, the Omnibus Rule, and direct liability for vendors
The original 1996 law was strengthened by the HITECH Act in 2009 and the Omnibus Rule in 2013. Two changes matter most for a test. First, business associates became directly liable for many HIPAA requirements, so a vendor can now be investigated and penalized by OCR on its own, not only through the covered entity that hired it. Second, the breach standard shifted toward a presumption that an impermissible use or disclosure of unsecured PHI is a breach unless a documented four-factor risk assessment shows a low probability that the information was compromised. The four factors look at the nature of the PHI, who received or used it, whether it was actually viewed or acquired, and the extent to which the risk has been mitigated. If a question asks who can be held responsible for a vendor mishandling PHI, the modern answer often includes both the covered entity and the business associate.
State laws, the floor rule, and where HIPAA stops
HIPAA sets a federal floor, not a ceiling. When a state privacy law is more protective of the individual or grants greater rights, the stricter state requirement generally applies on top of HIPAA. This is why organizations in states with their own health privacy statutes follow both. It also helps to remember what HIPAA does not cover. HIPAA does not regulate every entity that touches health data, so many consumer apps, wearables, and direct-to-consumer services sit outside it, even though other laws such as state privacy statutes or Federal Trade Commission rules may still apply. HIPAA also does not restrict what individuals choose to share about their own health. Knowing the edges of the law is as useful on a test as knowing the core rules, because several questions are designed to see whether you can recognize when HIPAA simply does not apply.
Common mistakes that cost points
Watch for answers that assume encryption is always mandatory when it is an addressable specification that still must be addressed and documented. They assume a signed BAA moves all liability to the vendor when the covered entity keeps its own duties. They confuse the 30-day right of access timeline with the 60-day breach notification deadline. They treat the Notice of Privacy Practices as consent. They forget that minimum necessary does not apply to treatment disclosures between providers. And they pick the quiet option in an incident scenario when the rules require prompt reporting and documentation. Slowing down to ask which rule the question is testing, and what that rule actually requires, can prevent avoidable mistakes.
How to use your practice score
After you finish, the summary breaks your result down by topic so you can see exactly where to study. If business associates or breach notification came back weak, open the matching guides below and run the practice test again. Aim for 90 percent or higher before you sit for a graded assessment. That margin shows you understand the reasoning, which matters more than memorizing an answer key, because real situations rarely look exactly like a sample question.
Keep studying
Guides that match each practice test topic
Free tool
HIPAA software compliance checklist
For engineering, DevOps, product, and support teams: generate a prioritized Security Rule checklist tailored to the PHI your software handles and where it runs.
Build your checklistPrivacy Rule
HIPAA training requirements
See who needs training, how often, and what regulators expect you to document.
Read the requirementsSecurity Rule
HIPAA Security Rule explained
Walk through administrative, physical, and technical safeguards in plain English.
Study safeguardsBreach
HIPAA breach notification
Learn the notification timelines, thresholds, and documentation a breach triggers.
Review breach rulesVendors
Business associate agreements
Understand the functional business-associate test, its exceptions, and what a required agreement must cover.
Open BAA guideChecklist
Free HIPAA compliance checklist
Run a clean first pass through training, vendors, risk analysis, and proof.
Get the checklistCertification
How to get HIPAA certified
See the full path from training to a dated, verifiable certificate.
See the stepsFree tool
HIPAA violation penalty calculator
Compare a hypothetical civil penalty range by selected culpability tier and violation count.
Estimate penaltiesFree tool
Free HIPAA BAA generator
Build a business associate agreement for a vendor from the HHS sample provisions, then copy or download it.
Generate a BAAFree tool
Notice of privacy practices generator
Draft a notice based on 45 CFR 164.520 and review which covered-entity and direct-treatment requirements apply.
Generate your NPPPractice test FAQ
Common questions about the HIPAA practice test
Is this HIPAA practice test really free?
Yes. The practice test is free and needs no account to start. You answer the questions, then enter your email at the end to unlock your full results, answer explanations, and study plan on the page. We also email your score, focus areas, and a link for later study. It is a study aid that helps you check your knowledge before you complete a course with a graded assessment and earn a dated, verifiable certificate.
Does passing this practice test make me HIPAA certified?
No. A practice test cannot certify you. With USA HIPAA, certification requires completing the course and earning at least 80 percent on its graded assessment. The resulting dated certificate has an online verification code. A receiving employer or school sets its own requirements. The practice test only organizes topics for further study.
What score should I aim for?
USA HIPAA requires 80 percent on its graded final assessment. HIPAA itself does not set a universal passing score for private training courses. You can use 90 percent as a personal study target on this practice test, but it is not a regulatory or certification threshold. Review the explanation for every missed topic.
How many questions are on the practice test?
Each run draws 20 questions from a pool of 40, and the order changes between attempts, so you can retake it several times and see different combinations. Every question includes an explanation so you learn the reasoning, not just the answer key.
Who should take a HIPAA practice test?
Anyone whose work touches protected health information benefits: nurses, medical assistants, front-desk and billing staff, IT and security teams, remote and telehealth workers, and business associate employees at vendors that handle PHI for healthcare clients.
How long is a HIPAA certificate valid?
USA HIPAA certificates carry a one-year term, but HIPAA does not set a universal expiration date for private training. For covered entities, the Privacy Rule requires training for new workforce members and retraining when a material policy or procedure change affects their work. Covered entities and business associates subject to the Security Rule must maintain a security awareness and training program. Your employer may add its own refresh cadence, so check its rules and keep a dated certificate for the training record.
Ready to turn study time into proof? See the HIPAA certification courses or compare team pricing for employer-scheduled refreshes.
Source note: HIPAA sets workforce training and documentation duties, but it does not establish a private-course accreditor or universal exam score. See HHS guidance on private certification claims and 45 CFR 164.530(b).
From practice to proof