POLICIES, AND PROCEDURES EXAM
WITH QUESTIONS AND 100% CORRECT
ANSWERS REVIEWED AND APPROVED
BY EXPERT 2025 UPDATE
What organizational and informational components are subject to the HIPAA Program?
Answer: Health plans, health care clearinghouses, and any health care provider that transmits
health information in electronic form in connection with transactions defined by the rule. The
Privacy Rule protects all individually identifiable health information held or transmitted by a
covered entity or its business associate, in any form or media, whether electronic, paper, or oral.
The Privacy Rule calls this information protected health information (PHI). The standards,
requirements, and implementation specifications apply to a business associate.
What is Protected Health Information (PHI)?
Answer: PHI is "Individually identifiable health information," including demographic data, that
relates to: an individual's past, present or future physical or mental health condition; the
provision of health care to the individual; or the past, present, or future payment for the provision
of health care to the individual, and that identifies the individual or for which there is reasonable
basis to believe it can be used to identify the individual.
Are employment records considered PHI under the Privacy Rule?
Answer: No, the Privacy Rule excludes from PHI employment records that a covered entity
maintains in its capacity as an employer and education and certain other records subject to, or
defined in, the Family Educational Rights and Privacy Act (FERPA), 20 USC sec 1232g.
What is the first administrative requirement of the Rule regarding Policies and
Procedures?
Answer: A covered entity or business associate must implement policies and procedures with
respect to PHI. Policies and procedures must be designed to comply with the standards,
implementation specifications, or other requirements of the Rule.