CCMA Study Guide
CCMA HIPAA and Patient Privacy: PHI, Authorization, Minimum Necessary, and Consent
CCMA HIPAA study guide: PHI basics, TPO vs authorization, minimum necessary rule, family phone requests, workstation security, consent types, and high-yield exam scenarios.
By MedCertPrep Team · Updated August 27, 2026
This guide covers HIPAA and patient privacy concepts tested on the NHA CCMA exam: what protected health information (PHI) is, when disclosure is allowed without written authorization, the minimum necessary standard, and the scenario patterns that appear in Medical Law and Ethics and Communication domains. It is written for candidates who need rule-based answers for front-desk, phone, and EHR situations, not legal memorization. For domain weights and study order, see the CCMA study guide. For timed scenario practice, use Medical Law and Ethics and Communication and Customer Service.
HIPAA rules come from federal law and HHS guidance. Clinic policy may add stricter steps. Verify current language on HHS HIPAA pages and the NHA CCMA Test Plan before exam day.
What is HIPAA, and what counts as PHI on the CCMA?
HIPAA (Health Insurance Portability and Accountability Act) includes a Privacy Rule that limits how covered entities use and disclose protected health information (PHI). On the CCMA, PHI is any individually identifiable health information held or transmitted by a covered entity in any form: oral, paper, or electronic.
| Term | CCMA-level definition | Examples |
|---|---|---|
| Covered entity | Health plans, health care clearinghouses, and most health care providers that transmit health information electronically for standard transactions | Clinic, hospital, billing office |
| Business associate | Person or company that performs functions involving PHI for a covered entity | Billing vendor, cloud EHR host, transcription service |
| PHI | Health information that identifies the patient or could reasonably identify them | Name plus diagnosis, MRN plus lab result, photo of face plus treatment note |
| De-identified information | Data stripped of identifiers per HIPAA standards | Aggregate quality reports with no patient link |
PHI is not limited to the chart. A waiting-room conversation, a voicemail, a fax cover sheet, or a screen visible to another patient can all create a HIPAA violation if identifiers and clinical details are exposed.
Pro Tip: If a stem names a patient and a clinical fact together, assume PHI is in play. The exam tests whether you protect it, not whether you can quote the statute number.
When can PHI be shared without a HIPAA authorization?
Routine health care operations rely on TPO: Treatment, Payment, and health care Operations. Disclosures for TPO are permitted under the Privacy Rule without a separate HIPAA authorization form, though clinic policy may still require consent workflows for treatment.
| TPO category | What it covers | CCMA example |
|---|---|---|
| Treatment | Sharing PHI to provide, coordinate, or manage care | MA sends relevant chart information to a specialist for a referral |
| Payment | Billing, claims, eligibility, collections | Billing staff submits diagnosis and procedure codes to the payer |
| Operations | Quality improvement, training, accreditation, business planning tied to health care | De-identified quality review; credentialing files |
Treatment disclosures are exempt from the minimum necessary standard (see below). That allows full information sharing when another provider needs it to treat the patient. Payment and operations disclosures still must follow minimum necessary limits.
Disclosures outside TPO generally require a valid HIPAA authorization or another specific legal basis (court order, mandatory reporting law, patient request for their own records, etc.).

What is a HIPAA authorization, and how is it different from consent?
On exam stems, authorization and general treatment consent are not interchangeable.
| Document | Purpose | CCMA trap |
|---|---|---|
| General informed consent for treatment | Permission to receive care | Does not authorize sharing records with a family member or employer |
| HIPAA authorization | Written permission for a specific disclosure not otherwise permitted | Required before releasing records to third parties outside TPO |
| Release of Information (ROI) | Clinic form implementing an authorized disclosure | Must match who receives what information and for what purpose |
A valid HIPAA authorization typically includes:
- Description of information to be disclosed
- Who may disclose and who may receive
- Purpose of the disclosure
- Expiration date or expiration event
- Right to revoke in writing
- Signature and date from the patient or personal representative
If a spouse, parent of an adult patient, or friend calls for results and no authorization or legal authority is on file, the MA must not release clinical details. Verify identity per policy, offer to take a message, or ask the patient to sign an ROI. Relationship and urgency do not override HIPAA.
Practice authorization stems in Medical Law and Ethics.
What is the HIPAA minimum necessary standard?
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the least amount needed for the purpose. It applies to most permitted disclosures, especially payment and operations.
| Situation | Minimum necessary applies? | Best MA action on the exam |
|---|---|---|
| Treatment referral to another provider | No (treatment exception) | Share relevant clinical information needed for continuity of care |
| Insurance eligibility check | Yes | Confirm coverage; do not read full chart aloud |
| Employer calling for "everything" on a patient | Yes | No disclosure without authorization unless law requires |
| Patient asks for own records | No (disclosure to the individual) | Follow clinic ROI process for patient access |
| Authorized ROI for specific labs only | Follows authorization | Release only what the authorization covers |
Example: a payer requests documentation to support a prior authorization. Send the clinical note pages that support medical necessity, not the entire psychiatric history if it is unrelated.
Example: a family member asks for "all test results" by phone. Without ROI on file, do not read results. Offer to have the patient call back or sign an authorization.
Official guidance: HHS minimum necessary requirement.
Practice: minimum necessary standard, caller asks neighbor diagnosis, and lock computer when leaving.

What HIPAA scenarios appear most often on the CCMA?
Medical Law and Ethics (~7 scored items) and Communication (~12 items) overlap heavily on privacy. These patterns repeat in practice banks and reported exam items.
Family or friend phone requests
| Stem pattern | Wrong answer | Correct direction |
|---|---|---|
| "I'm his wife, give me the biopsy results" | Read results to confirm relationship | Verify authorization or call patient directly; minimum necessary if ROI exists |
| "I'm picking her up, what was she seen for?" | Describe visit reason in waiting room | Do not disclose; patient can share if she chooses |
| Minor patient (varies by state law on exam) | Treat all minors like adults | Follow stem: emancipated minor, parent with custody, or court order language |
Waiting room and hallway privacy
- Call patients by first name only if policy allows, or use sign-in number systems
- Do not discuss diagnoses, test results, or insurance problems where others can hear
- Lower voice; move to private area for sensitive intake
Voicemail, text, and email
- Minimum necessary content only
- Avoid detailed clinical results in voicemail unless patient has agreed to that channel per policy
- Confirm correct number or portal before sending messages
Workstation and EHR security
| Action | Why the exam cares |
|---|---|
| Log out or lock screen before leaving desk | Prevents unauthorized viewing of PHI |
| Position monitor away from public view | Shoulder surfing is a privacy breach |
| Close chart when finished | Open chart on unattended screen is a violation pattern |
| Do not share login credentials | Individual accountability under HIPAA Security Rule themes |
Fax and release of records
- Confirm fax number before sending ROI packets
- Use cover sheets with minimum identifiers
- Release only records covered by a signed authorization
For phone tone plus privacy combined stems, drill Communication and Customer Service.
How does the CCMA test informed consent and consent withdrawal?
Consent questions sit beside HIPAA but test a different framework: permission for procedures and treatment, not record release.
| Consent type | When it applies | CCMA note |
|---|---|---|
| Informed consent | Patient receives explanation of procedure, risks, benefits, alternatives, and voluntary agreement | Documented verbal or written per policy |
| Implied consent | Routine low-risk care with patient cooperation (vitals, venipuncture after appointment) | Not a substitute for surgical or high-risk procedure consent |
| Emergency / implied emergency | Patient incapacitated and immediate treatment needed to prevent serious harm | Treat first; full consent process when stable |
High-yield rules:
- A signed consent form can be withdrawn at any time before or during a procedure. Stop and notify the provider.
- The MA explains logistics but does not replace the provider for risk counseling on complex procedures.
- Minors, guardians, and incapacitated patients follow stem-specific authority (parent, legal guardian, durable power of attorney for health care).
If a patient withdraws consent mid-procedure, the first action is to pause and notify the provider, not to continue because the form was signed earlier.
How do ROI, ABN, and prior authorization differ?
Administrative forms are often confused on the exam. Coding details live in CCMA ICD-10 vs CPT; privacy stems test form purpose.
| Form | Primary purpose | Privacy link |
|---|---|---|
| Release of Information (ROI) | Authorize disclosure of PHI to a named recipient | HIPAA authorization content |
| Advanced Beneficiary Notice (ABN) | Medicare patient acknowledgment that a service may not be covered | Financial liability, not a substitute for ROI |
| Prior authorization | Payer approval before service | Clinical info sent to payer under payment rules; minimum necessary |
| General treatment consent | Permission to treat | Does not authorize family disclosure |
Pro Tip: If the stem mentions Medicare non-coverage, think ABN. If it mentions records to an employer or ex-spouse, think ROI/authorization. If it mentions payer approval before MRI, think prior auth workflow in Administrative Assisting.
What mandatory reporting and ethics topics overlap with HIPAA?
HIPAA allows disclosures required by law without patient authorization. CCMA items may include:
| Topic | Exam direction |
|---|---|
| Abuse or neglect of child, elder, or dependent adult | Report to designated agency per state law; document per policy |
| Gunshot wounds or other reportable injuries | Follow mandatory reporting law in the stem |
| Public health reporting | Communicable disease reporting to health department when law requires |
| Court orders | Release only what the order specifies |
Professional boundary stems (gifts, social media friend requests, dating patients) are ethics, not HIPAA, but appear in the same domain. Decline relationships that impair objectivity; follow clinic social media policy.
What mistakes cost the most points on HIPAA items?
| Mistake | Why it fails |
|---|---|
| "She is family, so it is fine" | Relationship is not authorization |
| Reading full chart to satisfy a curious caller | Violates minimum necessary |
| Leaving EHR open while walking to the printer | Workstation security violation |
| Using detailed clinical voicemail without patient agreement | Impermissible disclosure channel |
| Confusing treatment consent with ROI | Wrong form for the stem |
| Continuing procedure after patient says stop | Ignores withdrawal of consent |
Rewrite each miss as a one-line rule. Example: "No ROI on file: verify callback number, no clinical details."
Frequently Asked Questions
How many HIPAA questions are on the CCMA?
HIPAA content is tested primarily in Medical Law and Ethics (7 items) and Communication and Customer Service (12 items). Expect scenario-based items, not statute recall. Some Administrative Assisting stems touch authorization paperwork and payer disclosures.
Does HIPAA require patient authorization for treatment, payment, and operations?
No separate HIPAA authorization is required for most TPO disclosures. Treatment sharing between providers, billing claims, and many operational uses are permitted under the Privacy Rule. Disclosures to family, employers, or media require authorization or another legal basis.
What should a medical assistant do when a patient's spouse demands lab results by phone?
Verify whether a valid ROI or HIPAA authorization is on file for that recipient. If not, do not release results. Offer to have the patient call, sign an authorization, or receive results through the approved patient portal per policy.
When does the minimum necessary standard not apply?
Common exceptions tested on the CCMA include treatment disclosures to other providers, disclosures to the patient, disclosures made under a valid authorization, disclosures required by law, and certain HIPAA compliance disclosures. Payment and operations still require reasonable limits.
Can a patient withdraw consent after signing a procedure consent form?
Yes. Withdrawal must be honored. Stop the procedure if it has not reached the point of no return per provider judgment, and notify the provider immediately. The MA supports the process; the provider manages clinical decisions.
Is texting a patient their diagnosis a HIPAA violation?
It can be if the channel is not secure, the patient has not agreed to that method, or the message includes unnecessary detail visible to others. Exam answers favor portal messaging, minimum necessary content, and verified contact information per policy.
What is the first action when leaving a workstation in a shared front desk area?
Log out or lock the EHR session so PHI is not visible to the next person walking by. This pattern appears more often than obscure legal definitions.
Next steps for CCMA HIPAA prep
- Read the Medical Law and Ethics section of the CCMA study guide.
- Try scenario items: minimum necessary standard, unauthorized caller, and lock workstation.
- Complete 15 to 20 scenario items in Medical Law and Ethics and Communication.
- Add Week 3 HIPAA blocks from the CCMA study plan if you are on a calendar schedule.
- Run a timed mixed set on free CCMA practice and tag every privacy miss by rule type (authorization, minimum necessary, workstation, consent).
- For full exam structure context, review CCMA exam format and passing score.
For unlimited domain drills and score tracking, see CCMA pricing and the CCMA landing page.
Practice what you just read
Use blueprint-aligned questions and timed mocks for CCMA to turn this guide into exam-day readiness.