HIPAA disclosures and minimum necessary

The CCMA does not ask you to recite HIPAA. It hands you a caller, a fax, a subpoena, or an answering machine and asks what is allowed to leave the office. Nearly every miss comes from one of two overcorrections: releasing to someone who sounds entitled to the information, or refusing a release the Privacy Rule actually permits. Learn the permitted disclosures as a short list, because everything not on it needs a signed authorization.

Treatment, payment, operationsNo authorization needed (45 CFR 164.506) — but you must still verify the identity AND the authority of a requester you do not know (45 CFR 164.514(h))
Minimum necessaryLimit every use, disclosure and request to the least PHI needed for the purpose (45 CFR 164.502(b))
Where minimum necessary does NOT applyProvider-to-provider for treatment, disclosure to the patient, anything under a signed authorization, disclosures required by other law, and reporting to HHS for compliance
Family membersSpouse, adult child or parent is not authorization. 45 CFR 164.510(b) permits only information directly relevant to that person's involvement in the care, with the patient's agreement — a full release needs authorization or personal-representative status
Public health reportingA notifiable disease such as active TB goes to the state or local health department without authorization (45 CFR 164.512(b)). The health department, not your office, transmits it to CDC, and the patient's objection does not suspend the report
Subpoena signed by an attorneyNot a court order. Release requires satisfactory assurances — notice to the patient with a chance to object, or a qualified protective order (45 CFR 164.512(e)). Route it to the provider or privacy officer
Breach notice to individualsWithout unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404); 500+ residents of a state also triggers prominent media notice and notice to HHS within the same 60 days
Right of accessAct on the request within 30 days, with one 30-day extension (45 CFR 164.524). An unpaid balance is never a reason to withhold — that is also information blocking under 45 CFR Part 171
Voicemail and answering machinesPermitted: practice name, callback number, request to call. Not permitted: test results, the specialist's name, the reason for a referral
DisposalShred, burn or pulp so PHI cannot be read or reconstructed (45 CFR 164.530(c)). A recycling bin is a reportable breach

Where the point is lost: Two numbers get swapped constantly: 60 calendar days is breach notification to individuals, 30 days is acting on a right-of-access request. And identity is not authority — a caller who correctly recites the patient's date of birth has proved who he is, not that he is entitled to anything. Verification and authorization are two separate gates, and a question that offers you "ask for the date of birth first" is testing exactly that.

HIPAA disclosures and minimum necessary

12 questions on HIPAA minimum necessary standard, each with an explanation and statute citation.

12 questions

Pass line: 78%, same as the real exam

Questions and answers, explained

All 12 questions above, with the correct answer and why it is correct. Everything here is on hipaa disclosures and minimum necessary.

  1. A medical assistant documents a telephone message from a patient. All of the following belong in the message EXCEPT:

    • AThe date and time of the call
    • BThe caller's name, date of birth, and callback number
    • CThe reason for the call, the action taken, and the name of the person taking the message
    • DThe patient's full Social Security number, for identity confirmationCorrect

    Why: A complete phone message contains the date and time, the caller and patient identity, a callback number, the reason for the call, the action taken, and who took it — all of which become part of the record. A full Social Security number is not an accepted patient identifier and is not needed to identify a patient: the standard identifiers are name, date of birth, medical record number, and at most the last four digits of the SSN. Recording a full SSN in a routine message puts unnecessary sensitive data into circulation and raises identity-theft risk.

    Reference Domain 6, 6G and k204; NHA patient identifiers (Domain 3A, k43); HHS HIPAA safeguards for PHI

  2. A new patient reads the practice's Notice of Privacy Practices at registration but refuses to sign the acknowledgment. How should the medical assistant proceed?

    • AExplain that treatment cannot be provided until the acknowledgment is signed.
    • BDocument the good-faith effort and her refusal, then continue with the visit.Correct
    • CSign the form herself as a witness that the notice was handed to the patient.
    • DSkip the form entirely, since the notice is posted in the waiting room already.

    Why: A provider with a direct treatment relationship must make a good-faith effort to obtain written acknowledgment that the patient received the notice, no later than the first date of service, and when that acknowledgment is not obtained must document the effort and the reason. The acknowledgment is a receipt, not a consent: refusing to sign it does not block care and does not stop the practice from using protected health information for treatment, payment, and operations. Staff never sign in the patient's place, and posting the notice does not replace the acknowledgment step.

    Reference HIPAA Privacy Rule 45 CFR 164.520(c)(2)(ii) (notice acknowledgment and documentation of good-faith effort); NHA CCMA Detailed Test Plan Domain 5, k175

  3. The HIPAA minimum necessary standard requires a covered entity to:

    • ALimit the use, disclosure, and request of protected health information to the least amount needed to accomplish the intended purposeCorrect
    • BObtain a signed patient authorization before any use or disclosure of protected health information
    • CRelease the complete medical record whenever a payer requests documentation
    • DRestrict all access to protected health information to physicians only

    Why: The Privacy Rule requires covered entities to take reasonable steps to limit uses, disclosures, and requests for protected health information to the minimum necessary to accomplish the intended purpose. Option B is incorrect because HIPAA permits disclosure for treatment, payment, and health care operations without a separate authorization — and HHS states that the minimum necessary standard does not even apply to disclosures to, or requests by, a health care provider for treatment purposes.

    Reference Domain 7, k214; HHS HIPAA Privacy Rule — Minimum Necessary Requirement (45 CFR 164.502(b))

  4. A patient states she had a colonoscopy at a hospital across town three years ago, but the clinic's health maintenance record shows the screening as never done. What should the medical assistant do?

    • ARecord the colonoscopy as completed based on what the patient reported today
    • BRequest the report from that hospital using its release form and file it in the chartCorrect
    • CLeave the record blank and let the provider order a repeat colonoscopy today
    • DAsk the patient to bring a copy of the report to her next scheduled visit

    Why: Task 4B requires that documentation of preventive maintenance and screenings actually be in the patient record, which means a source document, not a verbal report. Entering the study as completed on the patient's memory alone (A) creates an unverified entry and can set the next due date incorrectly. Repeating an adequate colonoscopy (C) exposes the patient to sedation and perforation risk for no benefit. Relying on the patient to bring the report (D) is common but unreliable, and the practice remains responsible for its own record. HIPAA permits provider-to-provider disclosure for treatment without patient authorization, but most releasing facilities still require their own signed release form, so the medical assistant obtains it, requests the report, and updates the health maintenance record when it arrives.

    Reference NHA CCMA Domain 4, Task 4B (documentation of preventive maintenance and screenings in the patient record); HIPAA Privacy Rule 45 CFR 164.506 (disclosures for treatment)

  5. A caller says, "This is Mr. Ruiz — I'm calling for my wife's biopsy results." No authorization naming him is on file. What should the medical assistant do?

    • ARelease the results, since a spouse is automatically authorized to receive them in full
    • BRelease only whether the result was normal or abnormal, nothing more
    • CExplain results cannot be released without authorization, and offer a release formCorrect
    • DAsk the caller for his wife’s date of birth and then release the results

    Why: Protected health information may not be disclosed to a family member without the patient's authorization or agreement; marriage does not create automatic access. The closest distractor, verifying the wife's date of birth first, confirms who is calling but does nothing to create authorization — identity verification and authorization are separate requirements. Releasing even a normal/abnormal summary (B) is still a disclosure of PHI, and results are the provider's to communicate in any case.

    Reference Domain 6, 6G, and Domain 7, k220; HHS HIPAA Privacy Rule conditions for release of information

  6. A fax containing another clinic's patient records arrives on the practice's machine in error. What should the medical assistant do?

    • AScan the pages into the practice's own records before returning the call.
    • BFax the pages on to the clinic named in the header of the document.
    • CLeave the fax at the front desk until the sender calls to ask about it.
    • DNotify the sending office and destroy the pages per the office's policy.Correct

    Why: Protected health information received in error must not be used, copied, or disclosed further. Call the sending office right away so it can correct the fax number and evaluate the incident as a possible breach on its end, then shred the pages under the practice's disposal policy and document what was done. Scanning them plants another practice's patient in your system. Forwarding the fax is a disclosure this office has no authority to make, and pages left on an open counter are exactly the unsecured exposure the safeguards standard is written to prevent.

    Reference HIPAA Privacy Rule safeguards standard 45 CFR 164.530(c) and HHS PHI disposal guidance; NHA CCMA Detailed Test Plan Domain 5, task 5O (process office mail and faxes), cross-referencing Domain 7 k219 and k220

  7. During a well-child visit, a medical assistant notices multiple bruises in various stages of healing on a 4-year-old's back, and the parent's explanation changes twice. What is the medical assistant's legal obligation?

    • AReport the findings to the provider and follow mandatory reporting; suspicion is enoughCorrect
    • BInvestigate by questioning the child alone until his story becomes completely consistent
    • CTake no action at all unless the child states that someone hurt him
    • DConfront the parent about the inconsistency before documenting anything

    Why: Health care workers are mandated reporters under state laws enacted pursuant to CAPTA; the legal threshold is reasonable suspicion of abuse, not proof, and reports go to the state child protective agency or law enforcement. Mandated reporters do not investigate — option B is the reporting agency's role, and questioning the child can contaminate the investigation.

    Reference Domain 7, task 7F, k222; CAPTA mandatory reporting (ACF/HHS)

  8. A medical assistant reaches a patient's home answering machine while calling to reschedule an appointment. What message is appropriate to leave?

    • AThe practice name, a callback number, and a request that the patient return the callCorrect
    • BThe name of the specialist she is being referred to and the reason for the referral
    • CHer test result, so she does not have to call back
    • DNo message at all, because leaving any message violates HIPAA

    Why: HIPAA permits appointment-related messages, but the reasonable-safeguards and minimum-necessary provisions limit their content whenever a third party could overhear: practice name, callback number, and a request to call. The closest distractor, leaving no message at all, is a common overcorrection — the Privacy Rule does not prohibit messages, it limits what they contain. Clinical details or the reason for a referral (B, C) exceed what is necessary.

    Reference Domain 6, 6G and k204; HHS HIPAA minimum necessary standard and incidental disclosures

  9. At check-out a patient asks to be set up on the patient portal. What is the correct enrollment step?

    • ACreate a username and temporary password and read them to her aloud.
    • BVerify her identity and send the invitation to her own verified email.Correct
    • CSend the invitation to her adult daughter's email so the daughter can help.
    • DEnroll her using the general email address the practice keeps on file.

    Why: Portal enrollment is an identity-proofing step. Confirm the patient in person using the practice's identifiers, capture the email address she personally controls, and let the system send an enrollment link so she creates her own password. Staff should never generate or speak a credential, because anyone within earshot then has a path into her record. Sending the invitation to a relative gives that person standing access to protected health information without a signed authorization or a formal proxy account, even when the patient welcomes the help, and a shared office address is not the patient's own verified contact.

    Reference NHA CCMA Detailed Test Plan Domain 5, task 5U (activate and facilitate use of patient portals); HIPAA Privacy Rule 45 CFR 164.508 and 164.524

  10. Under the HIPAA Breach Notification Rule, affected individuals must be notified of a breach of unsecured protected health information no later than:

    • A15 calendar days after discovery
    • B30 calendar days after discovery
    • C60 calendar days after discoveryCorrect
    • D90 calendar days after discovery

    Why: Individual notice must be provided without unreasonable delay and in no case later than 60 calendar days following discovery of the breach. The 30-day option is the closest distractor because 30 calendar days is the deadline for acting on a patient's HIPAA right-of-access request — a different rule that is commonly confused with breach notification.

    Reference Domain 7, k214; HHS HIPAA Breach Notification Rule (45 CFR 164.404); right of access (45 CFR 164.524)

  11. A medical assistant needs to send a patient the preparation instructions for a colonoscopy electronically. Which action best meets professional communication etiquette and HIPAA safeguards?

    • APut the procedure name in the subject line so the patient can find it later
    • BSend it through the secure patient portal with no clinical detail in the subjectCorrect
    • CUse text abbreviations and all capitals so the key steps stand out on a phone
    • DCopy the patient's adult daughter, who usually helps her with appointments

    Why: The patient portal is the encrypted channel the practice already maintains, and the subject line is the part of any message most likely to be seen by someone other than the patient — on a lock screen, in a shared inbox, over a shoulder. Keep the subject generic and put the detail inside the message. Note what the rule here is and is not: the minimum necessary standard does not apply to a disclosure made to the patient herself (45 CFR 164.502(b)(2)); what governs is the safeguards requirement and the limit on incidental disclosure to third parties. Copying a family member (D) discloses PHI to someone the patient has not authorized. All capitals and texting shorthand (C) read as shouting, look unprofessional, and raise the odds the patient misreads the prep. A patient may request delivery by unencrypted email, but that request must come from the patient and be documented.

    Reference NHA CCMA Domain 6, 6H (prepare written/electronic communications and business correspondence) and k196/k205 (communication styles appropriate to oral, telephone, email, and text; email etiquette); HIPAA administrative safeguards, 45 CFR 164.530(c), and incidental uses and disclosures, 45 CFR 164.502(a)(1)(iii); minimum necessary exceptions, 45 CFR 164.502(b)(2)

  12. A patient's adult son calls and asks the medical assistant to fax his mother's recent test results to him because "she gets confused." No authorization is on file. What should the medical assistant do?

    • AProvide the results, because an immediate family member is entitled to them
    • BGive the results verbally but decline to send them by fax
    • CAsk the son to verify the patient’s date of birth and then release the results to him
    • DExplain that a signed authorization or personal representative status is requiredCorrect

    Why: HIPAA permits release to a family member only with the patient's authorization or when that person is the legally designated personal representative; being a relative is not by itself authorization. Verifying a date of birth, the closest distractor, only confirms the caller knows a detail about the patient and establishes no legal right to her protected health information.

    Reference Domain 7, task 7E, k220 (conditions for release of information); HHS HIPAA Privacy Rule

Drill the whole domain

Other topics

See all topics · Study Guides · Full practice exam

Start the free practice examYour dashboard