CCMA - Medical Law and Ethics - Section 7.1

Apply HIPAA Privacy and Security Rule requirements to protect patient health information in clinical and administrative contexts.

Apply the HIPAA Privacy Rule and Security Rule to protect patient protected health information in clinical and administrative workflows. Distinguish permissible disclosures from those requiring patient authorisation, and identify the administrative, physical, and technical safeguards required under the Security Rule.

HIPAAProtected health informationPrivacy RuleSecurity Rule

Practice question for this objective

Free sampleMedical Law and Ethicsmedium

Which statement best distinguishes the HIPAA Security Rule from the HIPAA Privacy Rule with respect to safeguards?

  • AThe Privacy Rule lists administrative, physical, and technical safeguards, while the Security Rule governs only patient authorisations.
  • BThe Security Rule sets administrative, physical, and technical safeguards specifically for electronic protected health information held by covered entities and business associates. Correct
  • CThe Security Rule covers oral and paper PHI, while the Privacy Rule covers only electronic transmissions between covered entities.
  • DThe Security Rule requires patient consent for every electronic disclosure, while the Privacy Rule imposes no consent requirements.
Differentiate the HIPAA Security Rule from the Privacy Rule by scope and required administrative, physical, and technical safeguards. The HIPAA Security Rule applies specifically to electronic protected health information and requires three categories of safeguards. Administrative safeguards include risk analysis, workforce training, and sanction policies. Physical safeguards include facility access controls, workstation security, and device and media controls. Technical safeguards include access control, audit controls, integrity controls, and transmission security. The Privacy Rule, by contrast, covers PHI in any medium and governs uses, disclosures, and patient rights rather than the technical mechanics of protecting electronic data.

Why A is wrong: Tempting because both rules use safeguard language, but the three-category safeguard framework actually belongs to the Security Rule, and authorisations sit within the Privacy Rule, so the assignment is reversed.

Why B is correct: This is the defining scope of the Security Rule: it applies to electronic PHI and requires administrative safeguards such as workforce training and risk analysis, physical safeguards such as facility access controls, and technical safeguards such as access controls and audit logs.

Why C is wrong: Tempting if a candidate confuses the rules, but the Security Rule is restricted to electronic PHI, and the Privacy Rule covers PHI in any form, including oral and paper, so this option inverts both scopes.

Why D is wrong: Tempting because consent and authorisation feel like security concerns, but consent and authorisation rules sit within the Privacy Rule, and the Security Rule instead mandates safeguards rather than per-disclosure consent.

See more CCMA practice questions, answers explained.

More in this domain

Back to all Medical Law and Ethics objectives, or the CCMA cert hub.

Examworthy is not affiliated with or endorsed by National Healthcareer Association. Original, blueprint-aligned practice material only.