HIPAA Practice Question: What is the 'minimum necessary' standard under the Privacy Rule? | CyberCertPrep
HHSHIPAAPrivacy RuleEASYFree question
What is the 'minimum necessary' standard under the Privacy Rule?
A.All PHI must be encrypted at all times
B.Patients must provide the minimum amount of personal information
C.Only the minimum PHI needed for a specific purpose should be used or disclosed
D.Providers must keep the minimum number of patient records
Why C is correct
The minimum necessary standard requires covered entities to limit PHI use, disclosure, and requests to the minimum amount needed to accomplish the intended purpose.
Know someone studying for HIPAA? Send them this one.
Where this fits in the HIPAA exam
Privacy Rule
Covers privacy rule concepts and practices within HIPAA.
This question belongs to the "HIPAA Privacy Rule" domain, which makes up about 25% of the HIPAA exam.
CyberCertPrep gives you 20 free HIPAA questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
HIPAA and HHS are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by HHS or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Which use of PHI does NOT require patient authorization under the Privacy Rule?