CCMA Study Guide

CCMA HIPAA and Patient Privacy: PHI, Authorization, Minimum Necessary, and Consent

CCMA HIPAA study guide: PHI basics, TPO vs authorization, minimum necessary rule, family phone requests, workstation security, consent types, and high-yield exam scenarios.

By MedCertPrep Team · Updated August 27, 2026

This guide covers HIPAA and patient privacy concepts tested on the NHA CCMA exam: what protected health information (PHI) is, when disclosure is allowed without written authorization, the minimum necessary standard, and the scenario patterns that appear in Medical Law and Ethics and Communication domains. It is written for candidates who need rule-based answers for front-desk, phone, and EHR situations, not legal memorization. For domain weights and study order, see the CCMA study guide. For timed scenario practice, use Medical Law and Ethics and Communication and Customer Service.

HIPAA rules come from federal law and HHS guidance. Clinic policy may add stricter steps. Verify current language on HHS HIPAA pages and the NHA CCMA Test Plan before exam day.

What is HIPAA, and what counts as PHI on the CCMA?

HIPAA (Health Insurance Portability and Accountability Act) includes a Privacy Rule that limits how covered entities use and disclose protected health information (PHI). On the CCMA, PHI is any individually identifiable health information held or transmitted by a covered entity in any form: oral, paper, or electronic.

TermCCMA-level definitionExamples
Covered entityHealth plans, health care clearinghouses, and most health care providers that transmit health information electronically for standard transactionsClinic, hospital, billing office
Business associatePerson or company that performs functions involving PHI for a covered entityBilling vendor, cloud EHR host, transcription service
PHIHealth information that identifies the patient or could reasonably identify themName plus diagnosis, MRN plus lab result, photo of face plus treatment note
De-identified informationData stripped of identifiers per HIPAA standardsAggregate quality reports with no patient link

PHI is not limited to the chart. A waiting-room conversation, a voicemail, a fax cover sheet, or a screen visible to another patient can all create a HIPAA violation if identifiers and clinical details are exposed.

Pro Tip: If a stem names a patient and a clinical fact together, assume PHI is in play. The exam tests whether you protect it, not whether you can quote the statute number.

When can PHI be shared without a HIPAA authorization?

Routine health care operations rely on TPO: Treatment, Payment, and health care Operations. Disclosures for TPO are permitted under the Privacy Rule without a separate HIPAA authorization form, though clinic policy may still require consent workflows for treatment.

TPO categoryWhat it coversCCMA example
TreatmentSharing PHI to provide, coordinate, or manage careMA sends relevant chart information to a specialist for a referral
PaymentBilling, claims, eligibility, collectionsBilling staff submits diagnosis and procedure codes to the payer
OperationsQuality improvement, training, accreditation, business planning tied to health careDe-identified quality review; credentialing files

Treatment disclosures are exempt from the minimum necessary standard (see below). That allows full information sharing when another provider needs it to treat the patient. Payment and operations disclosures still must follow minimum necessary limits.

Disclosures outside TPO generally require a valid HIPAA authorization or another specific legal basis (court order, mandatory reporting law, patient request for their own records, etc.).

CCMA HIPAA TPO treatment payment operations versus authorization decision flow

What is a HIPAA authorization, and how is it different from consent?

On exam stems, authorization and general treatment consent are not interchangeable.

DocumentPurposeCCMA trap
General informed consent for treatmentPermission to receive careDoes not authorize sharing records with a family member or employer
HIPAA authorizationWritten permission for a specific disclosure not otherwise permittedRequired before releasing records to third parties outside TPO
Release of Information (ROI)Clinic form implementing an authorized disclosureMust match who receives what information and for what purpose

A valid HIPAA authorization typically includes:

  • Description of information to be disclosed
  • Who may disclose and who may receive
  • Purpose of the disclosure
  • Expiration date or expiration event
  • Right to revoke in writing
  • Signature and date from the patient or personal representative

If a spouse, parent of an adult patient, or friend calls for results and no authorization or legal authority is on file, the MA must not release clinical details. Verify identity per policy, offer to take a message, or ask the patient to sign an ROI. Relationship and urgency do not override HIPAA.

Practice authorization stems in Medical Law and Ethics.

What is the HIPAA minimum necessary standard?

The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the least amount needed for the purpose. It applies to most permitted disclosures, especially payment and operations.

SituationMinimum necessary applies?Best MA action on the exam
Treatment referral to another providerNo (treatment exception)Share relevant clinical information needed for continuity of care
Insurance eligibility checkYesConfirm coverage; do not read full chart aloud
Employer calling for "everything" on a patientYesNo disclosure without authorization unless law requires
Patient asks for own recordsNo (disclosure to the individual)Follow clinic ROI process for patient access
Authorized ROI for specific labs onlyFollows authorizationRelease only what the authorization covers

Example: a payer requests documentation to support a prior authorization. Send the clinical note pages that support medical necessity, not the entire psychiatric history if it is unrelated.

Example: a family member asks for "all test results" by phone. Without ROI on file, do not read results. Offer to have the patient call back or sign an authorization.

Official guidance: HHS minimum necessary requirement.

Practice: minimum necessary standard, caller asks neighbor diagnosis, and lock computer when leaving.

CCMA HIPAA minimum necessary standard exceptions for treatment patient access and authorization

What HIPAA scenarios appear most often on the CCMA?

Medical Law and Ethics (~7 scored items) and Communication (~12 items) overlap heavily on privacy. These patterns repeat in practice banks and reported exam items.

Family or friend phone requests

Stem patternWrong answerCorrect direction
"I'm his wife, give me the biopsy results"Read results to confirm relationshipVerify authorization or call patient directly; minimum necessary if ROI exists
"I'm picking her up, what was she seen for?"Describe visit reason in waiting roomDo not disclose; patient can share if she chooses
Minor patient (varies by state law on exam)Treat all minors like adultsFollow stem: emancipated minor, parent with custody, or court order language

Waiting room and hallway privacy

  • Call patients by first name only if policy allows, or use sign-in number systems
  • Do not discuss diagnoses, test results, or insurance problems where others can hear
  • Lower voice; move to private area for sensitive intake

Voicemail, text, and email

  • Minimum necessary content only
  • Avoid detailed clinical results in voicemail unless patient has agreed to that channel per policy
  • Confirm correct number or portal before sending messages

Workstation and EHR security

ActionWhy the exam cares
Log out or lock screen before leaving deskPrevents unauthorized viewing of PHI
Position monitor away from public viewShoulder surfing is a privacy breach
Close chart when finishedOpen chart on unattended screen is a violation pattern
Do not share login credentialsIndividual accountability under HIPAA Security Rule themes

Fax and release of records

  • Confirm fax number before sending ROI packets
  • Use cover sheets with minimum identifiers
  • Release only records covered by a signed authorization

For phone tone plus privacy combined stems, drill Communication and Customer Service.

How does the CCMA test informed consent and consent withdrawal?

Consent questions sit beside HIPAA but test a different framework: permission for procedures and treatment, not record release.

Consent typeWhen it appliesCCMA note
Informed consentPatient receives explanation of procedure, risks, benefits, alternatives, and voluntary agreementDocumented verbal or written per policy
Implied consentRoutine low-risk care with patient cooperation (vitals, venipuncture after appointment)Not a substitute for surgical or high-risk procedure consent
Emergency / implied emergencyPatient incapacitated and immediate treatment needed to prevent serious harmTreat first; full consent process when stable

High-yield rules:

  1. A signed consent form can be withdrawn at any time before or during a procedure. Stop and notify the provider.
  2. The MA explains logistics but does not replace the provider for risk counseling on complex procedures.
  3. Minors, guardians, and incapacitated patients follow stem-specific authority (parent, legal guardian, durable power of attorney for health care).

If a patient withdraws consent mid-procedure, the first action is to pause and notify the provider, not to continue because the form was signed earlier.

How do ROI, ABN, and prior authorization differ?

Administrative forms are often confused on the exam. Coding details live in CCMA ICD-10 vs CPT; privacy stems test form purpose.

FormPrimary purposePrivacy link
Release of Information (ROI)Authorize disclosure of PHI to a named recipientHIPAA authorization content
Advanced Beneficiary Notice (ABN)Medicare patient acknowledgment that a service may not be coveredFinancial liability, not a substitute for ROI
Prior authorizationPayer approval before serviceClinical info sent to payer under payment rules; minimum necessary
General treatment consentPermission to treatDoes not authorize family disclosure

Pro Tip: If the stem mentions Medicare non-coverage, think ABN. If it mentions records to an employer or ex-spouse, think ROI/authorization. If it mentions payer approval before MRI, think prior auth workflow in Administrative Assisting.

What mandatory reporting and ethics topics overlap with HIPAA?

HIPAA allows disclosures required by law without patient authorization. CCMA items may include:

TopicExam direction
Abuse or neglect of child, elder, or dependent adultReport to designated agency per state law; document per policy
Gunshot wounds or other reportable injuriesFollow mandatory reporting law in the stem
Public health reportingCommunicable disease reporting to health department when law requires
Court ordersRelease only what the order specifies

Professional boundary stems (gifts, social media friend requests, dating patients) are ethics, not HIPAA, but appear in the same domain. Decline relationships that impair objectivity; follow clinic social media policy.

What mistakes cost the most points on HIPAA items?

MistakeWhy it fails
"She is family, so it is fine"Relationship is not authorization
Reading full chart to satisfy a curious callerViolates minimum necessary
Leaving EHR open while walking to the printerWorkstation security violation
Using detailed clinical voicemail without patient agreementImpermissible disclosure channel
Confusing treatment consent with ROIWrong form for the stem
Continuing procedure after patient says stopIgnores withdrawal of consent

Rewrite each miss as a one-line rule. Example: "No ROI on file: verify callback number, no clinical details."

Frequently Asked Questions

How many HIPAA questions are on the CCMA?

HIPAA content is tested primarily in Medical Law and Ethics (7 items) and Communication and Customer Service (12 items). Expect scenario-based items, not statute recall. Some Administrative Assisting stems touch authorization paperwork and payer disclosures.

Does HIPAA require patient authorization for treatment, payment, and operations?

No separate HIPAA authorization is required for most TPO disclosures. Treatment sharing between providers, billing claims, and many operational uses are permitted under the Privacy Rule. Disclosures to family, employers, or media require authorization or another legal basis.

What should a medical assistant do when a patient's spouse demands lab results by phone?

Verify whether a valid ROI or HIPAA authorization is on file for that recipient. If not, do not release results. Offer to have the patient call, sign an authorization, or receive results through the approved patient portal per policy.

When does the minimum necessary standard not apply?

Common exceptions tested on the CCMA include treatment disclosures to other providers, disclosures to the patient, disclosures made under a valid authorization, disclosures required by law, and certain HIPAA compliance disclosures. Payment and operations still require reasonable limits.

Can a patient withdraw consent after signing a procedure consent form?

Yes. Withdrawal must be honored. Stop the procedure if it has not reached the point of no return per provider judgment, and notify the provider immediately. The MA supports the process; the provider manages clinical decisions.

Is texting a patient their diagnosis a HIPAA violation?

It can be if the channel is not secure, the patient has not agreed to that method, or the message includes unnecessary detail visible to others. Exam answers favor portal messaging, minimum necessary content, and verified contact information per policy.

What is the first action when leaving a workstation in a shared front desk area?

Log out or lock the EHR session so PHI is not visible to the next person walking by. This pattern appears more often than obscure legal definitions.

Next steps for CCMA HIPAA prep

  1. Read the Medical Law and Ethics section of the CCMA study guide.
  2. Try scenario items: minimum necessary standard, unauthorized caller, and lock workstation.
  3. Complete 15 to 20 scenario items in Medical Law and Ethics and Communication.
  4. Add Week 3 HIPAA blocks from the CCMA study plan if you are on a calendar schedule.
  5. Run a timed mixed set on free CCMA practice and tag every privacy miss by rule type (authorization, minimum necessary, workstation, consent).
  6. For full exam structure context, review CCMA exam format and passing score.

For unlimited domain drills and score tracking, see CCMA pricing and the CCMA landing page.

Practice what you just read

Use blueprint-aligned questions and timed mocks for CCMA to turn this guide into exam-day readiness.