8. A social engineering attempt may include: A visitor asking for directions, An email requesting login credentials, A staff meeting reminder, A routine password notice. 9. An accidental disclosure occurs when: PHI is overheard despite safeguards, PHI is intentionally sold, PHI is used for treatment, PHI is unintentionally shared with someone unauthorized. 10. Civil monetary penalties for HIPAA violations can be: $1 to $50 per violation, $100 to $50,000 per violation, $500,000 minimum per violation, Only for intentional misconduct.

Answer
For question 8, social engineering involves manipulating individuals into giving up confidential information, such as login credentials, making 'An email requesting login credentials' the correct choice. For question 9, an accidental disclosure is the unintentional sharing of protected health information (PHI) to someone not authorized to view it, making 'PHI is unintentionally shared with someone unauthorized' the correct choice. For question 10, civil monetary penalties under HIPAA vary depending on the level of culpability and can range from $100 to $50,000 per violation (with annual maximums), making '$100 to $50,000 per violation' the correct choice.