HIPAA practice test for business associates and vendors

Free HIPAA practice test for business associates and vendors.

You sign BAAs, host or handle client PHI, and answer to both your customers and OCR. This free practice test covers the situations vendors actually face: rush projects before the contract is signed, subcontractors who want the data, decommissioned servers, and misdirected files. See where your team stands before a client audit does it for you.

20questions per attempt
9written for business associates and vendors
Freeto take

Your test blends the vendor-specific scenarios below with questions from our core HIPAA pool, so you are scored on both your business associate obligations and the fundamentals.

Question basis: federal HIPAA rules and HHS/OCR guidance. State privacy laws and your organization's policies may be stricter.

Free practice test

Start the HIPAA practice test for business associates and vendors

20 multiple-choice questions across the Privacy Rule, Security Rule, breach notification, business associates, and real workplace scenarios. You see whether each answer is right as you go. At the end you unlock your scored results, full explanations, and a short study plan.

  • 20questions
  • Freeto take
  • Scoredresults plan

This practice test helps you study. It is not a substitute for completing the HIPAA course, passing its graded assessment, and earning a dated certificate.

Sample questions

HIPAA quiz questions and answers for business associates and vendors

Real questions from this variant, including scenarios written for business associates and vendors. The full test mixes 9 role-specific questions with core HIPAA questions every workforce member should know.

Becoming a BA

Your SaaS company hosts encrypted patient records for a clinic, and your team never opens or views the files. A sales rep says no BAA is needed because the data is unreadable to you. Who is right?

  • The sales rep, because encrypted data you cannot read is not PHI in your hands
  • The sales rep, because only vendors that actively view records become business associates
  • Neither claim holds up: a company that maintains ePHI on behalf of a covered entity is a business associate even if it never views the data, so a BAA is required
  • It depends on whether the clinic has more than 500 patients
Show answer

Correct answer: Neither claim holds up: a company that maintains ePHI on behalf of a covered entity is a business associate even if it never views the data, so a BAA is required

Maintaining or storing ePHI for a covered entity makes you a business associate regardless of whether you view the data or hold the decryption key. The narrow conduit exception covers only transient transmission services like ISPs and couriers, not persistent storage.

BAA and Permitted Uses

A new clinic client sends your transcription company a rush batch of dictation files before any contract is signed. The project manager wants to start tonight. What should happen first?

  • Execute a business associate agreement before your company receives or works on the PHI
  • Start the work and sign paperwork later, since a verbal agreement covers the gap
  • Ask the clinic to email a letter stating the files are not really PHI
  • Begin work as long as only senior transcriptionists touch the files
Show answer

Correct answer: Execute a business associate agreement before your company receives or works on the PHI

A covered entity may not disclose PHI to a vendor performing business associate functions until a BAA is in place, and accepting the files without one puts both parties at risk. Satisfactory assurances come from the signed agreement, not from job titles or verbal promises.

Subcontractors and Liability

Your billing company's BAA with a clinic limits PHI use to claims processing. A subcontractor that works your denials queue asks to keep copies of claim files to train its own analytics product. Can you agree?

  • Yes, because subcontractors set their own permitted uses in their own contracts
  • No: a subcontractor's permitted uses can never be broader than what the upstream BAA allows, and building the subcontractor's own product is not claims processing
  • Yes, as long as the subcontractor promises to delete the files within a year
  • Only if the subcontractor is located in the same state as the clinic
Show answer

Correct answer: No: a subcontractor's permitted uses can never be broader than what the upstream BAA allows, and building the subcontractor's own product is not claims processing

Permitted uses flow down the chain: each subcontractor BAA can only pass along rights the business associate itself holds. Repurposing client PHI for the subcontractor's own product falls outside claims processing and would be an impermissible use.

PHI Basics

Which of the following is protected health information (PHI) under HIPAA?

  • A patient's first name stored next to their appointment diagnosis
  • A hospital's published main phone number
  • A fully de-identified research dataset with no identifiers
  • A generic brochure about flu season
Show answer

Correct answer: A patient's first name stored next to their appointment diagnosis

PHI is individually identifiable health information transmitted or maintained by a covered entity or business associate, subject to the exclusions in 45 CFR 160.103. A name tied to a diagnosis identifies the person and reveals health information, so it qualifies.

PHI Basics

Which set of data points are all HIPAA identifiers that can make health information individually identifiable?

  • Favorite color, shoe size, and zodiac sign
  • Full name, medical record number, and email address
  • Weather, traffic data, and store hours
  • Stock prices, exchange rates, and tax brackets
Show answer

Correct answer: Full name, medical record number, and email address

HIPAA lists 18 identifiers including names, medical record numbers, and email addresses. When any of these are linked to health information, the data becomes PHI.

FAQ

HIPAA questions business associates and vendors actually ask

When does a vendor become a HIPAA business associate?

You become a business associate the moment you create, receive, maintain, or transmit PHI on behalf of a covered entity or another business associate. That includes billing and transcription services, IT contractors with access to systems holding ePHI, cloud hosts that store patient data, and shredding companies that collect records for destruction. Storing encrypted data you never open still counts. Only mere conduits like ISPs and couriers, or vendors with purely incidental exposure like janitorial crews, fall outside the definition.

Can OCR fine my company directly, or only our covered entity clients?

Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable to OCR. Your company can be investigated and fined for Security Rule failures, impermissible uses and disclosures, missing subcontractor BAAs, and blown breach reporting duties, regardless of what happens to your client. OCR has settled enforcement actions with vendors alone. A signed BAA adds contract obligations on top of that direct exposure; it does not shield you from it.

What do we do if our company discovers a breach of client PHI?

Your notification obligation runs to the covered entity, not to patients directly. Report the breach to the affected client without unreasonable delay and no later than 60 days after discovery, though most BAAs cut that window to just a few days. The covered entity then handles notification to individuals, HHS, and the media if required. Document what happened, what data was involved, and your containment steps, because the client will need those facts for its breach risk assessment.

Do our subcontractors need their own BAAs?

Yes. Any subcontractor that creates, receives, maintains, or transmits PHI for you is itself a business associate, and you, not your covered entity client, must sign a BAA with it before it touches the data. The subcontractor's permitted uses can never be broader than what your own BAA with the covered entity allows. The chain continues down: your subcontractor must do the same with its own subcontractors.

From practice to proof

Pass the practice test, then earn a verifiable certificate

The practice test sharpens your knowledge. The USA HIPAA course requires an 80% graded assessment and gives business associates and vendors a dated certificate with an online verification code employers can check.