HIPAA disclosures and minimum necessary
The CCMA does not ask you to recite HIPAA. It hands you a caller, a fax, a subpoena, or an answering machine and asks what is allowed to leave the office. Nearly every miss comes from one of two overcorrections: releasing to someone who sounds entitled to the information, or refusing a release the Privacy Rule actually permits. Learn the permitted disclosures as a short list, because everything not on it needs a signed authorization.
| Treatment, payment, operations | No authorization needed (45 CFR 164.506) — but you must still verify the identity AND the authority of a requester you do not know (45 CFR 164.514(h)) |
| Minimum necessary | Limit every use, disclosure and request to the least PHI needed for the purpose (45 CFR 164.502(b)) |
| Where minimum necessary does NOT apply | Provider-to-provider for treatment, disclosure to the patient, anything under a signed authorization, disclosures required by other law, and reporting to HHS for compliance |
| Family members | Spouse, adult child or parent is not authorization. 45 CFR 164.510(b) permits only information directly relevant to that person's involvement in the care, with the patient's agreement — a full release needs authorization or personal-representative status |
| Public health reporting | A notifiable disease such as active TB goes to the state or local health department without authorization (45 CFR 164.512(b)). The health department, not your office, transmits it to CDC, and the patient's objection does not suspend the report |
| Subpoena signed by an attorney | Not a court order. Release requires satisfactory assurances — notice to the patient with a chance to object, or a qualified protective order (45 CFR 164.512(e)). Route it to the provider or privacy officer |
| Breach notice to individuals | Without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404); 500+ residents of a state also triggers prominent media notice and notice to HHS within the same 60 days |
| Right of access | Act on the request within 30 days, with one 30-day extension (45 CFR 164.524). An unpaid balance is never a reason to withhold — that is also information blocking under 45 CFR Part 171 |
| Voicemail and answering machines | Permitted: practice name, callback number, request to call. Not permitted: test results, the specialist's name, the reason for a referral |
| Disposal | Shred, burn or pulp so PHI cannot be read or reconstructed (45 CFR 164.530(c)). A recycling bin is a reportable breach |
Where the point is lost: Two numbers get swapped constantly: 60 calendar days is breach notification to individuals, 30 days is acting on a right-of-access request. And identity is not authority — a caller who correctly recites the patient's date of birth has proved who he is, not that he is entitled to anything. Verification and authorization are two separate gates, and a question that offers you "ask for the date of birth first" is testing exactly that.
HIPAA disclosures and minimum necessary
12 questions on HIPAA minimum necessary standard, each with an explanation and statute citation.
12 questions
Pass line: 78%, same as the real exam
Questions and answers, explained
All 12 questions above, with the correct answer and why it is correct. Everything here is on hipaa disclosures and minimum necessary.
A medical assistant documents a telephone message from a patient. All of the following belong in the message EXCEPT:
Why: A complete phone message contains the date and time, the caller and patient identity, a callback number, the reason for the call, the action taken, and who took it — all of which become part of the record. A full Social Security number is not an accepted patient identifier and is not needed to identify a patient: the standard identifiers are name, date of birth, medical record number, and at most the last four digits of the SSN. Recording a full SSN in a routine message puts unnecessary sensitive data into circulation and raises identity-theft risk.
Reference Domain 6, 6G and k204; NHA patient identifiers (Domain 3A, k43); HHS HIPAA safeguards for PHI
A new patient reads the practice's Notice of Privacy Practices at registration but refuses to sign the acknowledgment. How should the medical assistant proceed?
Why: A provider with a direct treatment relationship must make a good-faith effort to obtain written acknowledgment that the patient received the notice, no later than the first date of service, and when that acknowledgment is not obtained must document the effort and the reason. The acknowledgment is a receipt, not a consent: refusing to sign it does not block care and does not stop the practice from using protected health information for treatment, payment, and operations. Staff never sign in the patient's place, and posting the notice does not replace the acknowledgment step.
Reference HIPAA Privacy Rule 45 CFR 164.520(c)(2)(ii) (notice acknowledgment and documentation of good-faith effort); NHA CCMA Detailed Test Plan Domain 5, k175
The HIPAA minimum necessary standard requires a covered entity to:
Why: The Privacy Rule requires covered entities to take reasonable steps to limit uses, disclosures, and requests for protected health information to the minimum necessary to accomplish the intended purpose. Option B is incorrect because HIPAA permits disclosure for treatment, payment, and health care operations without a separate authorization — and HHS states that the minimum necessary standard does not even apply to disclosures to, or requests by, a health care provider for treatment purposes.
Reference Domain 7, k214; HHS HIPAA Privacy Rule — Minimum Necessary Requirement (45 CFR 164.502(b))
A patient states she had a colonoscopy at a hospital across town three years ago, but the clinic's health maintenance record shows the screening as never done. What should the medical assistant do?
Why: Task 4B requires that documentation of preventive maintenance and screenings actually be in the patient record, which means a source document, not a verbal report. Entering the study as completed on the patient's memory alone (A) creates an unverified entry and can set the next due date incorrectly. Repeating an adequate colonoscopy (C) exposes the patient to sedation and perforation risk for no benefit. Relying on the patient to bring the report (D) is common but unreliable, and the practice remains responsible for its own record. HIPAA permits provider-to-provider disclosure for treatment without patient authorization, but most releasing facilities still require their own signed release form, so the medical assistant obtains it, requests the report, and updates the health maintenance record when it arrives.
Reference NHA CCMA Domain 4, Task 4B (documentation of preventive maintenance and screenings in the patient record); HIPAA Privacy Rule 45 CFR 164.506 (disclosures for treatment)
A caller says, "This is Mr. Ruiz — I'm calling for my wife's biopsy results." No authorization naming him is on file. What should the medical assistant do?
Why: Protected health information may not be disclosed to a family member without the patient's authorization or agreement; marriage does not create automatic access. The closest distractor, verifying the wife's date of birth first, confirms who is calling but does nothing to create authorization — identity verification and authorization are separate requirements. Releasing even a normal/abnormal summary (B) is still a disclosure of PHI, and results are the provider's to communicate in any case.
Reference Domain 6, 6G, and Domain 7, k220; HHS HIPAA Privacy Rule conditions for release of information
A fax containing another clinic's patient records arrives on the practice's machine in error. What should the medical assistant do?
Why: Protected health information received in error must not be used, copied, or disclosed further. Call the sending office right away so it can correct the fax number and evaluate the incident as a possible breach on its end, then shred the pages under the practice's disposal policy and document what was done. Scanning them plants another practice's patient in your system. Forwarding the fax is a disclosure this office has no authority to make, and pages left on an open counter are exactly the unsecured exposure the safeguards standard is written to prevent.
Reference HIPAA Privacy Rule safeguards standard 45 CFR 164.530(c) and HHS PHI disposal guidance; NHA CCMA Detailed Test Plan Domain 5, task 5O (process office mail and faxes), cross-referencing Domain 7 k219 and k220
During a well-child visit, a medical assistant notices multiple bruises in various stages of healing on a 4-year-old's back, and the parent's explanation changes twice. What is the medical assistant's legal obligation?
Why: Health care workers are mandated reporters under state laws enacted pursuant to CAPTA; the legal threshold is reasonable suspicion of abuse, not proof, and reports go to the state child protective agency or law enforcement. Mandated reporters do not investigate — option B is the reporting agency's role, and questioning the child can contaminate the investigation.
Reference Domain 7, task 7F, k222; CAPTA mandatory reporting (ACF/HHS)
A medical assistant reaches a patient's home answering machine while calling to reschedule an appointment. What message is appropriate to leave?
Why: HIPAA permits appointment-related messages, but the reasonable-safeguards and minimum-necessary provisions limit their content whenever a third party could overhear: practice name, callback number, and a request to call. The closest distractor, leaving no message at all, is a common overcorrection — the Privacy Rule does not prohibit messages, it limits what they contain. Clinical details or the reason for a referral (B, C) exceed what is necessary.
Reference Domain 6, 6G and k204; HHS HIPAA minimum necessary standard and incidental disclosures
At check-out a patient asks to be set up on the patient portal. What is the correct enrollment step?
Why: Portal enrollment is an identity-proofing step. Confirm the patient in person using the practice's identifiers, capture the email address she personally controls, and let the system send an enrollment link so she creates her own password. Staff should never generate or speak a credential, because anyone within earshot then has a path into her record. Sending the invitation to a relative gives that person standing access to protected health information without a signed authorization or a formal proxy account, even when the patient welcomes the help, and a shared office address is not the patient's own verified contact.
Reference NHA CCMA Detailed Test Plan Domain 5, task 5U (activate and facilitate use of patient portals); HIPAA Privacy Rule 45 CFR 164.508 and 164.524
Under the HIPAA Breach Notification Rule, affected individuals must be notified of a breach of unsecured protected health information no later than:
Why: Individual notice must be provided without unreasonable delay and in no case later than 60 calendar days following discovery of the breach. The 30-day option is the closest distractor because 30 calendar days is the deadline for acting on a patient's HIPAA right-of-access request — a different rule that is commonly confused with breach notification.
Reference Domain 7, k214; HHS HIPAA Breach Notification Rule (45 CFR 164.404); right of access (45 CFR 164.524)
A medical assistant needs to send a patient the preparation instructions for a colonoscopy electronically. Which action best meets professional communication etiquette and HIPAA safeguards?
Why: The patient portal is the encrypted channel the practice already maintains, and the subject line is the part of any message most likely to be seen by someone other than the patient — on a lock screen, in a shared inbox, over a shoulder. Keep the subject generic and put the detail inside the message. Note what the rule here is and is not: the minimum necessary standard does not apply to a disclosure made to the patient herself (45 CFR 164.502(b)(2)); what governs is the safeguards requirement and the limit on incidental disclosure to third parties. Copying a family member (D) discloses PHI to someone the patient has not authorized. All capitals and texting shorthand (C) read as shouting, look unprofessional, and raise the odds the patient misreads the prep. A patient may request delivery by unencrypted email, but that request must come from the patient and be documented.
Reference NHA CCMA Domain 6, 6H (prepare written/electronic communications and business correspondence) and k196/k205 (communication styles appropriate to oral, telephone, email, and text; email etiquette); HIPAA administrative safeguards, 45 CFR 164.530(c), and incidental uses and disclosures, 45 CFR 164.502(a)(1)(iii); minimum necessary exceptions, 45 CFR 164.502(b)(2)
A patient's adult son calls and asks the medical assistant to fax his mother's recent test results to him because "she gets confused." No authorization is on file. What should the medical assistant do?
Why: HIPAA permits release to a family member only with the patient's authorization or when that person is the legally designated personal representative; being a relative is not by itself authorization. Verifying a date of birth, the closest distractor, only confirms the caller knows a detail about the patient and establishes no legal right to her protected health information.
Reference Domain 7, task 7E, k220 (conditions for release of information); HHS HIPAA Privacy Rule
Drill the whole domain
- Communication and Customer Service (8%)
- Administrative Assisting (8%)
- Patient Care Coordination and Education (8%)
Other topics
- Autoclave testing: spore tests and sterilizer monitoring
- Correcting an error in the medical record
- Informed vs implied consent, and who obtains it
- Medical vs surgical asepsis and Spaulding
- Order of draw and tube additives
- OSHA Bloodborne Pathogens Standard duties
- PPE donning and doffing: the CDC order
- Medical assistant scope of practice
- Sharps, regulated waste and the red bag
- Standard vs transmission-based precautions
- Vital sign normal ranges and technique errors
- Blood pressure categories and measurement errors
- Injection routes, sites and angles
- Venipuncture vein selection and what to avoid
- Vaccine cold chain and storage
- Specimen labeling and patient identification