Free HIPAA Practice Test

Free HIPAA practice test with answers and explanations.

Check your HIPAA knowledge in a few minutes. This free practice test covers the Privacy Rule, Security Rule, breach notification, business associates, and the everyday workplace situations that trip people up. You see whether each answer is right as you go, then unlock your scored results, full explanations, and a study plan at the end.

40questions in the pool
12HIPAA topic areas
Freeto take

Free practice test

Start your HIPAA practice test

20 multiple-choice questions across the Privacy Rule, Security Rule, breach notification, business associates, and real workplace scenarios. You see whether each answer is right as you go. At the end you unlock your scored results, full explanations, and a short study plan.

  • 20questions
  • Freeto take
  • Scoredresults plan

This practice test helps you study. It is not a substitute for completing the HIPAA course, passing its graded assessment, and earning a dated certificate.

Sample questions

HIPAA quiz questions and answers from this practice test

Six real questions from the pool, one per core domain, with the correct answer and the reasoning. The full test draws 20 at a time and shuffles both question and answer order.

PHI Basics

Which of the following is protected health information (PHI) under HIPAA?

  • A patient's first name stored next to their appointment diagnosis
  • A hospital's published main phone number
  • A fully de-identified research dataset with no identifiers
  • A generic brochure about flu season
Show answer

Correct answer: A patient's first name stored next to their appointment diagnosis

PHI is individually identifiable health information transmitted or maintained by a covered entity or business associate, subject to the exclusions in 45 CFR 160.103. A name tied to a diagnosis identifies the person and reveals health information, so it qualifies.

Privacy Rule

What does the minimum necessary standard require?

  • Sharing complete records whenever a coworker asks
  • Using, disclosing, or requesting only the PHI reasonably needed for the task
  • Limiting PHI access only to physicians
  • Applying only to paper records, never electronic ones
Show answer

Correct answer: Using, disclosing, or requesting only the PHI reasonably needed for the task

The minimum necessary standard limits PHI to what is reasonably needed to accomplish a specific purpose. It applies broadly, though treatment disclosures between providers are a notable exception.

Security Rule

The HIPAA Security Rule requires three categories of safeguards for electronic PHI. What are they?

  • Financial, legal, and clinical
  • Administrative, physical, and technical
  • Federal, state, and local
  • Marketing, billing, and scheduling
Show answer

Correct answer: Administrative, physical, and technical

The Security Rule organizes protections for electronic PHI into administrative safeguards, physical safeguards, and technical safeguards.

Breach Notification

Under the Breach Notification Rule, when must affected individuals generally be notified after a breach of unsecured PHI is discovered?

  • Within 24 hours
  • Without unreasonable delay and no later than 60 days
  • Within one year
  • Only if the patient asks
Show answer

Correct answer: Without unreasonable delay and no later than 60 days

Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI.

Business Associates

A cloud vendor will store patient appointment data for your practice. What is the key HIPAA question?

  • Whether the vendor offers a nicer dashboard
  • Whether the vendor is cheaper than your current tool
  • Whether the vendor is a business associate that needs a signed BAA
  • Whether the vendor is headquartered in your state
Show answer

Correct answer: Whether the vendor is a business associate that needs a signed BAA

A vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and generally requires a business associate agreement (BAA) before handling PHI.

Common Scenarios

A friend asks you to look up whether a mutual acquaintance was treated at your hospital. What should you do?

  • Quickly check and share only a little information
  • Decline, because accessing records without a work-related need violates HIPAA
  • Check the record but do not tell anyone you looked
  • Ask a coworker to look it up instead
Show answer

Correct answer: Decline, because accessing records without a work-related need violates HIPAA

Accessing PHI without a legitimate, work-related reason is prohibited, even out of curiosity and even if nothing is shared.

Want all 40 questions with scoring, explanations, and a study plan? Take the full practice test above, free.

What it covers

Six core HIPAA domains covered in this practice test

The question pool uses 12 detailed topic labels across these six broader domains, including privacy, security, breaches, vendors, enforcement, and workplace scenarios.

Privacy Rule

PHI, minimum necessary, and patient rights

Identify protected health information, apply the minimum necessary standard, and answer questions about access, amendment, and accounting of disclosures.

Security Rule

Administrative, physical, and technical safeguards

Tell the three safeguard categories apart, recognize access controls and encryption decisions, and connect risk analysis to real safeguards.

Breach Notification

Timelines, thresholds, and incident response

Know the 60-day federal outer limit, the separate HHS and media thresholds, and the first reporting step when PHI reaches the wrong person.

Business Associates

When a vendor needs a BAA

Decide when a vendor is a business associate, what a business associate agreement does, and where covered-entity responsibility still applies.

Enforcement

OCR, penalty tiers, and willful neglect

Understand who enforces HIPAA, how civil penalty tiers map to culpability, and why curiosity-driven record access can violate policy and the HIPAA Rules.

Workplace Scenarios

Hallway conversations, email, and snooping

Work through everyday situations where reasonable safeguards, incidental disclosure rules, and the right of access decide the correct answer.

Study guide

How to read each HIPAA topic before you answer

Short, plain-English refreshers so the practice test teaches you the reasoning, not just the answer key.

HIPAA basics: who is covered and what counts as PHI

HIPAA, the Health Insurance Portability and Accountability Act, sets national rules for how protected health information is used and disclosed. The rules apply to covered entities, which are health plans, healthcare clearinghouses, and healthcare providers that conduct covered standard transactions electronically. A person or organization can be a business associate when it performs a defined function or service for a covered entity that involves PHI, subject to the exceptions in 45 CFR 160.103. Health data outside those relationships may still be governed by other federal or state laws.

Protected health information, or PHI, is individually identifiable health information transmitted or maintained by a covered entity or business associate, subject to the exclusions in 45 CFR 160.103. A name next to a diagnosis and a medical record number tied to a visit are common examples. Removing the 18 Safe Harbor identifier categories is one de-identification method, but it works only when the covered entity also has no actual knowledge that the remaining information could identify the individual.

The Privacy Rule and the minimum necessary standard

The Privacy Rule controls how PHI may be used and shared. The most important idea to carry into the exam is the minimum necessary standard: you use, disclose, or request only the PHI that is reasonably needed for the task in front of you. A billing clerk filing a claim needs the procedure code, not the full clinical note. A scheduler needs an appointment time, not a complete history. The clearest violations on a test involve someone reaching for far more information than the job requires.

There is one large exception worth memorizing. Minimum necessary does not restrict disclosures for treatment among providers, because clinicians need a complete picture to care for a patient safely. The Privacy Rule also permits use and disclosure for treatment, payment, and healthcare operations, often shortened to TPO, without a separate patient authorization. The rule permits other defined uses and disclosures as well. Uses that meet the Privacy Rule definition of marketing and sales of PHI generally require written authorization unless a regulatory exception applies.

Patient rights you will be tested on

Patients hold several rights under the Privacy Rule, and questions love to probe the edges of them. The right of access lets a patient inspect and obtain a copy of their records, generally within 30 days, for no more than a reasonable cost-based fee. Patients can request an amendment when they believe a record is wrong, request an accounting of certain disclosures, and request restrictions on how their information is used. What patients cannot do is force a provider to permanently delete a lawful medical record on demand, and HIPAA does not control what a person voluntarily shares about their own health on social media.

The Security Rule: three kinds of safeguards

The Security Rule protects electronic PHI through three safeguard categories, and you should be able to sort any example into the right bucket. Administrative safeguards are the policies and people side: workforce training, risk analysis, access management, and sanction policies. Physical safeguards control physical access to systems and devices, such as locking server rooms, securing workstations, and controlling the disposal of media. Technical safeguards live in the technology itself: unique user IDs, authentication, access control, audit logs, and encryption.

Two details show up often. First, the risk analysis is foundational. It identifies risks to the confidentiality, integrity, and availability of electronic PHI so the organization can put reasonable and appropriate safeguards in place. Second, encryption is an addressable specification, not a flat mandate. Addressable does not mean optional. It means you assess whether encryption is reasonable and appropriate, implement it when it is, and document your reasoning and any equivalent alternative when it is not.

Breach notification: timelines and thresholds

When unsecured PHI is breached, the clock starts. Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. If a breach affects 500 or more individuals, the covered entity must notify HHS on the large-breach timeline. Media notice has a different test: it applies when more than 500 residents of one State or jurisdiction are affected. Breaches affecting fewer than 500 individuals must be maintained in a log and reported to HHS no later than 60 days after the end of the calendar year. Individual notice still has its own 60-day outer limit.

A practice question may use a simple mistake, such as emailing PHI to the wrong recipient. The right first move is to report it promptly through the organization's incident process so the responsible team can preserve facts, contain further disclosure, assess the event, and document the decision.

Business associates and BAAs

Business-associate status depends on the function or service performed and whether it involves PHI, with exceptions for workforce members, certain treatment disclosures, conduits, and other relationships described in 45 CFR 160.103. When an outside party meets that definition, the covered entity and business associate need the written assurances required by 45 CFR 164.502(e) and 164.504(e). Each party retains the duties that apply to its role.

Enforcement and penalties

The Department of Health and Human Services, Office for Civil Rights, known as OCR, is the primary enforcer of the Privacy, Security, and Breach Notification Rules. Civil monetary penalties follow a tiered structure based on culpability, ranging from cases where the entity did not know and could not reasonably have known, up to willful neglect that was never corrected. The dollar amounts and annual caps are adjusted over time, so a good test answer focuses on the tiered, culpability-based structure rather than memorizing a specific number. Accessing records out of curiosity with no work-related reason can violate the HIPAA Rules and the organization's access policy even if nothing is shared.

De-identification and the two HIPAA methods

Questions often hinge on whether data is still PHI. HIPAA recognizes two ways to de-identify information so it falls outside the Privacy Rule. The first is Safe Harbor, which removes 18 specific categories of identifiers, including names, all geographic detail smaller than a state with a narrow exception for the first three ZIP code digits, all date elements more specific than a year, phone and fax numbers, email addresses, account and record numbers, biometric identifiers, and full-face photos. The second is the expert determination method, where a qualified statistician documents that the risk of re-identification is very small. Once data is properly de-identified, it is no longer PHI and can be used more freely. The trap on a test is assuming that simply deleting a name is enough, because a date of service paired with a small town can still identify someone.

Notice of Privacy Practices and authorizations

Covered entities subject to 45 CFR 164.520 must provide a Notice of Privacy Practices that explains covered uses and disclosures, legal duties, and individual rights. The distribution and posting rules vary by entity and direct-treatment relationship. The notice is not a permission slip. A separate authorization may be required for uses such as defined marketing or a sale of PHI, while the Privacy Rule permits many other uses and disclosures without one.

Incidental disclosures versus impermissible disclosures

Not every overheard detail is a violation. The Privacy Rule tolerates incidental disclosures, the limited and unavoidable byproducts of an otherwise permitted use, as long as the entity applies reasonable safeguards and follows the minimum necessary standard. A visitor catching a fragment of a clinical conversation in a treatment area can be acceptable. An impermissible disclosure is different: sharing PHI with someone who has no legitimate reason to receive it, or sharing far more than the situation requires. The exam-friendly distinction is whether reasonable safeguards were in place and whether the underlying use was permitted. Lowering your voice, using private rooms when practical, and positioning screens away from public view are the safeguards that turn a risky moment into an acceptable incidental one.

Workforce sanctions and a culture of compliance

The Security Rule and the Privacy Rule both expect organizations to apply sanctions against workforce members who violate policies and procedures. The organization applies its sanction policy to the facts and maintains required documentation. Training, clear policies, role-based access, audit log review, and consistent enforcement work together as a program rather than as isolated rules. On a test, the sound answer in a workforce scenario combines reporting the issue, applying the policy, and documenting the outcome rather than handling it quietly or making an undocumented exception.

HITECH, the Omnibus Rule, and direct liability for vendors

The original 1996 law was strengthened by the HITECH Act in 2009 and the Omnibus Rule in 2013. Two changes matter most for a test. First, business associates became directly liable for many HIPAA requirements, so a vendor can now be investigated and penalized by OCR on its own, not only through the covered entity that hired it. Second, the breach standard shifted toward a presumption that an impermissible use or disclosure of unsecured PHI is a breach unless a documented four-factor risk assessment shows a low probability that the information was compromised. The four factors look at the nature of the PHI, who received or used it, whether it was actually viewed or acquired, and the extent to which the risk has been mitigated. If a question asks who can be held responsible for a vendor mishandling PHI, the modern answer often includes both the covered entity and the business associate.

State laws, the floor rule, and where HIPAA stops

HIPAA sets a federal floor, not a ceiling. When a state privacy law is more protective of the individual or grants greater rights, the stricter state requirement generally applies on top of HIPAA. This is why organizations in states with their own health privacy statutes follow both. It also helps to remember what HIPAA does not cover. HIPAA does not regulate every entity that touches health data, so many consumer apps, wearables, and direct-to-consumer services sit outside it, even though other laws such as state privacy statutes or Federal Trade Commission rules may still apply. HIPAA also does not restrict what individuals choose to share about their own health. Knowing the edges of the law is as useful on a test as knowing the core rules, because several questions are designed to see whether you can recognize when HIPAA simply does not apply.

Common mistakes that cost points

Watch for answers that assume encryption is always mandatory when it is an addressable specification that still must be addressed and documented. They assume a signed BAA moves all liability to the vendor when the covered entity keeps its own duties. They confuse the 30-day right of access timeline with the 60-day breach notification deadline. They treat the Notice of Privacy Practices as consent. They forget that minimum necessary does not apply to treatment disclosures between providers. And they pick the quiet option in an incident scenario when the rules require prompt reporting and documentation. Slowing down to ask which rule the question is testing, and what that rule actually requires, can prevent avoidable mistakes.

How to use your practice score

After you finish, the summary breaks your result down by topic so you can see exactly where to study. If business associates or breach notification came back weak, open the matching guides below and run the practice test again. Aim for 90 percent or higher before you sit for a graded assessment. That margin shows you understand the reasoning, which matters more than memorizing an answer key, because real situations rarely look exactly like a sample question.

Keep studying

Guides that match each practice test topic

Open the guide for any area where your score dipped, then retake the test to confirm it stuck.

Practice test FAQ

Common questions about the HIPAA practice test

Is this HIPAA practice test really free?

Yes. The practice test is free and needs no account to start. You answer the questions, then enter your email at the end to unlock your full results, answer explanations, and study plan on the page. We also email your score, focus areas, and a link for later study. It is a study aid that helps you check your knowledge before you complete a course with a graded assessment and earn a dated, verifiable certificate.

Does passing this practice test make me HIPAA certified?

No. A practice test cannot certify you. With USA HIPAA, certification requires completing the course and earning at least 80 percent on its graded assessment. The resulting dated certificate has an online verification code. A receiving employer or school sets its own requirements. The practice test only organizes topics for further study.

What score should I aim for?

USA HIPAA requires 80 percent on its graded final assessment. HIPAA itself does not set a universal passing score for private training courses. You can use 90 percent as a personal study target on this practice test, but it is not a regulatory or certification threshold. Review the explanation for every missed topic.

How many questions are on the practice test?

Each run draws 20 questions from a pool of 40, and the order changes between attempts, so you can retake it several times and see different combinations. Every question includes an explanation so you learn the reasoning, not just the answer key.

Who should take a HIPAA practice test?

Anyone whose work touches protected health information benefits: nurses, medical assistants, front-desk and billing staff, IT and security teams, remote and telehealth workers, and business associate employees at vendors that handle PHI for healthcare clients.

How long is a HIPAA certificate valid?

USA HIPAA certificates carry a one-year term, but HIPAA does not set a universal expiration date for private training. For covered entities, the Privacy Rule requires training for new workforce members and retraining when a material policy or procedure change affects their work. Covered entities and business associates subject to the Security Rule must maintain a security awareness and training program. Your employer may add its own refresh cadence, so check its rules and keep a dated certificate for the training record.

Ready to turn study time into proof? See the HIPAA certification courses or compare team pricing for employer-scheduled refreshes.

Source note: HIPAA sets workforce training and documentation duties, but it does not establish a private-course accreditor or universal exam score. See HHS guidance on private certification claims and 45 CFR 164.530(b).

From practice to proof

Pass the practice test, then earn a verifiable certificate

The practice test sharpens your knowledge. The USA HIPAA course requires an 80% graded assessment and gives you a dated certificate with an online verification record. Employers, schools, and other recipients set their own certificate requirements.