CHPS Cheat Sheet 2026

The 30 highest-yield CHPS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
210 min time limit
70.00% to pass
  1. What is 'workforce' as defined under HIPAA, and does it include volunteers and trainees? Employees, volunteers, trainees, and other persons under the entity's direct control
  2. Which privacy principle requires that only the minimum amount of PHI necessary to accomplish the intended purpose be used or disclosed? Data minimization / Minimum necessary standard
  3. What is 'de-identification' of PHI under HIPAA, and what are the two accepted methods? Removing 18 specific identifiers (Safe Harbor) or statistical expert determination
  4. In the context of the HIPAA Security Rule, what does 'integrity' of ePHI mean? ePHI has not been altered or destroyed in an unauthorized manner
  5. Under HIPAA, what is the maximum civil monetary penalty per identical violation category per calendar year? $1,919,173
  6. Under the HIPAA Security Rule, what must a covered entity do when it terminates a workforce member's employment? Implement a termination procedure that includes removal of system access
  7. A healthcare organization shares ePHI with a cloud storage vendor. Under HIPAA, the vendor is BEST classified as a: Business associate
  8. Which safeguard category under the HIPAA Security Rule addresses workforce training and security reminders? Administrative safeguards
  9. The use of a data collection with 16 data components deleted by a research organization that has signed a data agreement. Limited data set
  10. Under the HITECH Act, which entities became directly liable for compliance with certain HIPAA Privacy and Security Rule provisions? Business associates
  11. The HIPAA Security Rule's Transmission Security standard is designed to protect ePHI when it is: Transmitted over electronic communications networks
  12. Under the Technical Safeguards of the HIPAA Security Rule, which implementation specification for Access Control is designated as 'required'? Unique user identification
  13. The four-factor risk assessment under the HIPAA Breach Notification Rule includes all of the following EXCEPT: Whether the affected individual has experienced actual identity theft
  14. A hospital must report a breach affecting 600 individuals. In addition to notifying affected individuals, the covered entity must notify: Prominent media outlets in the affected state and HHS
  15. Which security control is MOST effective at detecting unauthorized internal access to ePHI by snooping employees? User and Entity Behavior Analytics (UEBA)
  16. A hospital discovers a breach on March 15. Under HIPAA, individual breach notifications must be sent no later than: May 14 (60 days after discovery)
  17. Which concept in information security ensures that data has not been altered or destroyed in an unauthorized manner? Integrity
  18. Which HIPAA provision allows a covered entity to disclose PHI to a public health authority without patient authorization? Public interest and benefit activities exception
  19. Under the HIPAA Security Rule, which safeguard category includes workstation use policies and facility access controls? Physical Safeguards
  20. What is the goal of 'de-identification' of PHI under HIPAA? To remove identifiers so the information cannot reasonably identify an individual
  21. What does 'integrity' mean in the context of the HIPAA Security Rule's protection requirements for ePHI? ePHI has not been altered or destroyed in an unauthorized manner
  22. Which type of malware specifically encrypts healthcare data and demands payment for decryption keys, causing significant operational disruption to hospitals? Ransomware
  23. Which NIST publication provides the primary framework for federal information security programs and is widely used in healthcare security? NIST SP 800-53
  24. Under the HIPAA Breach Notification Rule, what is the deadline for notifying HHS of a breach affecting fewer than 500 individuals? Within 60 days of year-end
  25. A risk register entry shows a threat with high likelihood and high impact. According to standard risk management, the BEST initial response strategy is to: Mitigate the risk by implementing controls
  26. What is the primary purpose of a healthcare organization's sanctions policy under HIPAA? To define consequences for workforce members who violate privacy and security policies
  27. What is the legal document that governs the relationship between a covered entity and a Business Associate under HIPAA? Business Associate Agreement (BAA)
  28. Which HIPAA provision requires covered entities to provide patients with an accounting of certain disclosures of their PHI? Right to an Accounting of Disclosures
  29. When a business associate discovers a breach of PHI, within what timeframe must it notify the covered entity? Without unreasonable delay and within 60 days of discovery
  30. Which technology provides the strongest protection for ePHI stored on a lost or stolen laptop under HIPAA? Full-disk encryption using FIPS 140-2 validated modules
Turn these facts into recall:
Was this helpful?