CertQuestUSA
Transportation70+AK/AL/AR +moreConstruction & Safety39+CAEnvironmental98+AL/AR/AZ +moreHealthcare & Clinical183+AL/AR/AZ +moreProfessional Licensing307+AL/AR/AZ +moreEducation & Teacher Certification17Aviation & FAA Certification9Finance & Securities Licensing19View all sectors ›

HIPAA General Workforce (California)

First published: September 2, 2026Last verified: September 2, 2026Reviewed by the CertQuestUSA team
TL;DR

HIPAA General Workforce (California): a 150-question practice bank for the real HIPAA / Healthcare Compliance standard, 3 full papers of 40 questions each with no repeats, every question citing the real regulation it comes from.

Where these questions come from

Every question in this bank cites a real source -- primarily 45 CFR (73%) and leginfo.legislature.ca.gov (26%) of this exam's citations.

Not sure where you stand? Take the free diagnostic — 10 real questions across the exam's domains, no sign-up required, with a domain-by-domain breakdown at the end.
Start diagnostic
3
full papers, no repeats
40
questions per paper
150
questions in the bank
What this exam covers
5 real sample questions
Under CMIA, how does the administrative fine change for a licensed healthcare professional who commits repeated knowing and willful unauthorized disclosures of medical information?
A. The fine escalates with each violation: up to $2,500 for a first violation, up to $10,000 for a second, and up to $25,000 for a third or subsequent violation
B. CMIA does not distinguish between a first violation and repeat violations for licensed professionals
C. The fine decreases with each subsequent violation to account for the professional's prior corrective action
D. The fine is a single flat $50,000 penalty regardless of how many violations occur
Source: California Civil Code §56.36(b) — escalating penalty tiers for licensed healthcare professionals with repeat violations ($2,500 first, $10,000 second, $25,000 third and subsequent); https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.36
A California healthcare workforce member is trained on both federal HIPAA and California's Confidentiality of Medical Information Act (CMIA). Which statement correctly compares the two laws' scope of protected information?
A. CMIA and HIPAA protect an identical set of information, so compliance with one automatically satisfies the other
B. CMIA only protects information held by hospitals, while HIPAA protects information held by any business
C. CMIA's definition of "medical information" is broader than HIPAA's PHI definition, and CMIA can apply even when no HIPAA-covered entity is involved
D. CMIA does not define "medical information" at all and instead defers entirely to the federal HIPAA definition of PHI
Source: California Civil Code §56.05 — defines "medical information" under CMIA as individually identifiable information, in electronic or physical form, regarding a patient's medical history, mental or physical condition, or treatment; https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.05
A California patient's medical information is negligently released by a clinic employee. Under CMIA, what legal remedy is available to the patient that is NOT available to a patient whose PHI is mishandled under HIPAA alone?
A. The patient's only recourse is a complaint to the California Medical Board against the treating physician
B. The patient may bring a private civil lawsuit directly against the entity that negligently released the information
C. The patient may request only that the entity issue a written apology, with no monetary remedy available
D. The patient may file a complaint only with the U.S. Department of Health and Human Services
Source: California Civil Code §56.36(b) — private right of action for negligent release of medical information; https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.36
Under federal law, who is authorized to bring an enforcement action for a HIPAA violation?
A. Any individual patient, directly in federal court, without involving any government agency
B. The Secretary of Health and Human Services, and state Attorneys General on behalf of residents
C. Only the patient's employer, if the employer is also a HIPAA covered entity
D. Any licensed physician who becomes aware of the violation, regardless of involvement in the patient's care
Source: 42 U.S.C. §1320d-5 — HIPAA civil penalty enforcement authority rests with the HHS Secretary and state Attorneys General, not private individuals; https://www.law.cornell.edu/uscode/text/42/1320d-5
Under CMIA's private right of action, what must a patient prove to recover the statutory nominal damages amount, even if they cannot show any actual financial harm?
A. That the patient suffered documented financial losses of at least $1,000 as a direct result of the disclosure
B. That the entity had a prior criminal conviction for a similar violation
C. That the disclosure was made with actual malice and specific intent to harm the patient
D. Only that the entity negligently released the patient's confidential medical information; actual harm need not be shown
Source: California Civil Code §56.36(b) — nominal damages of $1,000 available without proof of actual harm; https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.36
Same exam, other states
ARAZFLGAILINKSMAMIMSNCNJNYOHPATNTXVAWA

Frequently asked questions

How many questions are on the CertQuestUSA HIPAA General Workforce (California) practice test?
150 questions total, split into 3 full papers of 40 each with no repeats across papers.
What topics does the HIPAA General Workforce (California) test cover?
6 domains, with the heaviest weight on Privacy Rule Fundamentals (27%), CA Confidentiality of Medical Information Act (CMIA) (25%), and Security Rule Safeguards (21%).
Where do CertQuestUSA's HIPAA General Workforce (California) questions come from?
Primarily 45 CFR (73%) and leginfo.legislature.ca.gov (26%) of this bank's citations -- computed directly from this exam's own question sources, not a generic description.
Is there a free diagnostic for HIPAA General Workforce (California)?
Yes -- 10 real questions across the exam's domains, no sign-up required, with a domain-by-domain breakdown at the end.
Composing your paper...