CHPS Cheat Sheet 2026
The 30 highest-yield CHPS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
210 min time limit
70.00% to pass
- What is 'workforce' as defined under HIPAA, and does it include volunteers and trainees? → Employees, volunteers, trainees, and other persons under the entity's direct control
- Which privacy principle requires that only the minimum amount of PHI necessary to accomplish the intended purpose be used or disclosed? → Data minimization / Minimum necessary standard
- What is 'de-identification' of PHI under HIPAA, and what are the two accepted methods? → Removing 18 specific identifiers (Safe Harbor) or statistical expert determination
- In the context of the HIPAA Security Rule, what does 'integrity' of ePHI mean? → ePHI has not been altered or destroyed in an unauthorized manner
- Under HIPAA, what is the maximum civil monetary penalty per identical violation category per calendar year? → $1,919,173
- Under the HIPAA Security Rule, what must a covered entity do when it terminates a workforce member's employment? → Implement a termination procedure that includes removal of system access
- A healthcare organization shares ePHI with a cloud storage vendor. Under HIPAA, the vendor is BEST classified as a: → Business associate
- Which safeguard category under the HIPAA Security Rule addresses workforce training and security reminders? → Administrative safeguards
- The use of a data collection with 16 data components deleted by a research organization that has signed a data agreement. → Limited data set
- Under the HITECH Act, which entities became directly liable for compliance with certain HIPAA Privacy and Security Rule provisions? → Business associates
- The HIPAA Security Rule's Transmission Security standard is designed to protect ePHI when it is: → Transmitted over electronic communications networks
- Under the Technical Safeguards of the HIPAA Security Rule, which implementation specification for Access Control is designated as 'required'? → Unique user identification
- The four-factor risk assessment under the HIPAA Breach Notification Rule includes all of the following EXCEPT: → Whether the affected individual has experienced actual identity theft
- A hospital must report a breach affecting 600 individuals. In addition to notifying affected individuals, the covered entity must notify: → Prominent media outlets in the affected state and HHS
- Which security control is MOST effective at detecting unauthorized internal access to ePHI by snooping employees? → User and Entity Behavior Analytics (UEBA)
- A hospital discovers a breach on March 15. Under HIPAA, individual breach notifications must be sent no later than: → May 14 (60 days after discovery)
- Which concept in information security ensures that data has not been altered or destroyed in an unauthorized manner? → Integrity
- Which HIPAA provision allows a covered entity to disclose PHI to a public health authority without patient authorization? → Public interest and benefit activities exception
- Under the HIPAA Security Rule, which safeguard category includes workstation use policies and facility access controls? → Physical Safeguards
- What is the goal of 'de-identification' of PHI under HIPAA? → To remove identifiers so the information cannot reasonably identify an individual
- What does 'integrity' mean in the context of the HIPAA Security Rule's protection requirements for ePHI? → ePHI has not been altered or destroyed in an unauthorized manner
- Which type of malware specifically encrypts healthcare data and demands payment for decryption keys, causing significant operational disruption to hospitals? → Ransomware
- Which NIST publication provides the primary framework for federal information security programs and is widely used in healthcare security? → NIST SP 800-53
- Under the HIPAA Breach Notification Rule, what is the deadline for notifying HHS of a breach affecting fewer than 500 individuals? → Within 60 days of year-end
- A risk register entry shows a threat with high likelihood and high impact. According to standard risk management, the BEST initial response strategy is to: → Mitigate the risk by implementing controls
- What is the primary purpose of a healthcare organization's sanctions policy under HIPAA? → To define consequences for workforce members who violate privacy and security policies
- What is the legal document that governs the relationship between a covered entity and a Business Associate under HIPAA? → Business Associate Agreement (BAA)
- Which HIPAA provision requires covered entities to provide patients with an accounting of certain disclosures of their PHI? → Right to an Accounting of Disclosures
- When a business associate discovers a breach of PHI, within what timeframe must it notify the covered entity? → Without unreasonable delay and within 60 days of discovery
- Which technology provides the strongest protection for ePHI stored on a lost or stolen laptop under HIPAA? → Full-disk encryption using FIPS 140-2 validated modules
Turn these facts into recall:
Was this helpful?