The Hipaa Minimum Necessary Standard Applies
5 community-sourced questions and answers. Free — no login.
If you're unsure about the particulars of HIPAA research requirements at your organization or have questions, you can usually consult with:
An organizational IRB or Privacy Board, privacy officer ("Privacy Officer"), or privacy official ("Privacy Official"), depending on the issue.
A covered entity may use or disclose PHI without an authorization, or documentation of a waiver or an alteration of authorization, for all of the following EXCEPT:
Data that does not cross state lines when disclosed by the covered entity.
HIPAA's protections for health information used for research purposes...
Supplement those of the Common Rule and FDA.
A HIPAA authorization has which of the following characteristics:
Uses "plain language" that the data subject can understand, similar to the requirement for an informed consent document.
The HIPAA "minimum necessary" standard applies...
to all human subjects research that uses PHI without an authorization from the data subject.
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials