CertQuestUSA
Transportation70+AK/AL/AR +moreConstruction & Safety39+CAEnvironmental98+AL/AR/AZ +moreHealthcare & Clinical183+AL/AR/AZ +moreProfessional Licensing307+AL/AR/AZ +moreEducation & Teacher Certification17Aviation & FAA Certification9Finance & Securities Licensing19View all sectors ›

HIPAA General Workforce (North Carolina)

First published: September 1, 2026Last verified: September 2, 2026Reviewed by the CertQuestUSA team
TL;DR

HIPAA General Workforce (North Carolina): a 138-question practice bank for the real Healthcare & Pharmacy Certification standard, 3 full papers of 50 questions each with no repeats, every question citing the real regulation it comes from.

Where these questions come from

Every question in this bank cites a real source -- primarily 45 CFR (80%) and N.C.G.S. (19%) of this exam's citations.

Not sure where you stand? Take the free diagnostic — 10 real questions across the exam's domains, no sign-up required, with a domain-by-domain breakdown at the end.
Start diagnostic
3
full papers, no repeats
50
questions per paper
138
questions in the bank
What this exam covers
5 real sample questions
Under North Carolina's Identity Theft Protection Act, within what specific timeframe must a business notify affected individuals after discovering a security breach involving personal information?
A. Within 30 days of discovery
B. Within 45 days of discovery
C. Within 60 days of discovery
D. There is no fixed number of days; notice must be given without unreasonable delay
Source: N.C.G.S. 75-65
In addition to notifying affected individuals, North Carolina's Identity Theft Protection Act requires a business to notify which state entity about a security breach?
A. The Consumer Protection Division of the NC Attorney General's Office
B. The NC Department of Health and Human Services
C. The NC Medical Board
D. The NC Insurance Commissioner
Source: N.C.G.S. 75-65
Under North Carolina's Identity Theft Protection Act, when must a business also notify nationwide consumer reporting agencies of a breach?
A. Whenever any breach occurs, regardless of size
B. Only if the breach involves Social Security numbers
C. When the business must notify more than 1,000 persons at one time
D. Never - NC law does not require notifying consumer reporting agencies
Source: N.C.G.S. 75-65(e)
A hospital's business office in North Carolina experiences unauthorized access to a database containing patient diagnosis codes and treatment histories, but no Social Security numbers, driver's license numbers, or financial account numbers. Does this trigger notice obligations under North Carolina's general Identity Theft Protection Act (G.S. Chapter 75)?
A. Yes, because medical diagnosis and treatment information is expressly listed as 'personal information' under the statute
B. No, because the Identity Theft Protection Act's definition of 'personal information' is built around identity-theft data elements (like SSNs, driver's license numbers, and financial account numbers) and does not itself include medical or health insurance information
C. Yes, but only if the patient is a minor
D. No, because HIPAA entirely preempts North Carolina from having any breach notification law
Source: N.C.G.S. 75-61, 14-113.20(b)
Under North Carolina's Identity Theft Protection Act, if personal information is encrypted and the decryption key was NOT also compromised, how is this generally treated?
A. It is automatically still treated as a reportable security breach regardless of encryption
B. It generally falls outside the statute's definition of 'security breach,' since that definition is built around unauthorized access to unencrypted and unredacted data (or encrypted data plus the key)
C. It must be reported to HHS OCR but not to the NC Attorney General
D. North Carolina law prohibits the use of encryption for personal information
Source: N.C.G.S. 75-61
Same exam, other states
ARAZCAFLGAILINKSMAMIMSNJNYOHPATNTXVAWA

Frequently asked questions

How many questions are on the CertQuestUSA HIPAA General Workforce (North Carolina) practice test?
138 questions total, split into 3 full papers of 50 each with no repeats across papers.
What topics does the HIPAA General Workforce (North Carolina) test cover?
10 domains, with the heaviest weight on Privacy Rule Fundamentals (29%), Security Rule Safeguards (23%), and Breach Notification Basics (16%).
Where do CertQuestUSA's HIPAA General Workforce (North Carolina) questions come from?
Primarily 45 CFR (80%) and N.C.G.S. (19%) of this bank's citations -- computed directly from this exam's own question sources, not a generic description.
Is there a free diagnostic for HIPAA General Workforce (North Carolina)?
Yes -- 10 real questions across the exam's domains, no sign-up required, with a domain-by-domain breakdown at the end.
Composing your paper...