Certified in Healthcare Privacy and Security (CHPS) โ Questions and Answers
Question 1: A covered entity discovers that a workforce member has been snooping on celebrity patient records over the past year. How many breaches does this represent?
- No breach if the workforce member did not disclose the information to anyone
- One breach per patient record impermissibly accessed (Correct answer)
- A single breach because it involves one workforce member
- One breach per year
Correct answer: One breach per patient record impermissibly accessed
Each patient's record that was impermissibly accessed represents a separate potential breach requiring individual analysis under the four-factor risk assessment.
Question 2: Under HIPAA, which of the following statements about the Right of Access is TRUE?
- Covered entities must provide access within 15 days
- Access may be permanently denied if the record is voluminous
- Covered entities may charge a reasonable cost-based fee for copies (Correct answer)
- Psychotherapy notes must be provided upon request
Correct answer: Covered entities may charge a reasonable cost-based fee for copies
Covered entities may charge a reasonable, cost-based fee for providing copies of PHI, covering labor, supplies, and postage, but may not profit from access requests.
Question 3: A healthcare organization uses a firewall, intrusion detection system, and antivirus software as layers of protection. This approach is known as:
- Security through obscurity
- Zero-trust architecture
- Defense in depth (Correct answer)
- Least privilege principle
Correct answer: Defense in depth
Defense in depth uses multiple, overlapping security controls so that if one layer fails, additional layers continue to protect ePHI from compromise.
Question 4: Under the HITECH Act, which entity tier has a maximum annual civil monetary penalty of $1.9 million per violation category?
- Willful neglect โ not corrected (Correct answer)
- Willful neglect โ corrected
- Did not know and could not have known
- Reasonable cause
Correct answer: Willful neglect โ not corrected
Willful neglect that is not corrected carries the highest penalty tier, up to $1.9 million per identical violation category per calendar year.
Question 5: Which access control mechanism grants permissions based on an individual's role within an organization rather than their specific identity?
- Role-Based Access Control (RBAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions according to job roles (e.g., nurse, billing clerk), simplifying administration and supporting the minimum necessary principle required by HIPAA.
Question 6: What is the HIPAA standard for de-identification using the Expert Determination method?
- Removing all 18 types of identifiers listed in the Safe Harbor method
- A qualified statistical expert determines the risk of identifying an individual is very small (Correct answer)
- Applying a pseudonym to replace direct identifiers
- Encrypting all data fields using AES-256 encryption
Correct answer: A qualified statistical expert determines the risk of identifying an individual is very small
Expert Determination requires a qualified statistical or scientific expert to certify that the risk of re-identification is very small using generally accepted principles.
Question 7: Under the HIPAA Security Rule, what must a covered entity do when it terminates a workforce member's employment?
- Implement a termination procedure that includes removal of system access (Correct answer)
- Only notify the Privacy Officer of the termination
- Submit a workforce change notification to HHS
- Archive the employee's ePHI access logs for 6 years
Correct answer: Implement a termination procedure that includes removal of system access
Workforce Security standards require covered entities to implement termination procedures including removing system access to prevent unauthorized use of ePHI post-employment.
Question 8: Under the HIPAA Security Rule, which safeguard category includes workstation use policies and facility access controls?
- Physical Safeguards (Correct answer)
- Technical Safeguards
- Organizational Safeguards
- Administrative Safeguards
Correct answer: Physical Safeguards
Physical Safeguards govern physical access to facilities and workstations, including facility access controls, workstation use policies, and device and media controls.
Question 9: Under HIPAA's Right of Access, what is the maximum fee a covered entity may charge for electronic copies of PHI maintained electronically?
- A fee not exceeding $6.50 per request under the safe harbor (Correct answer)
- A reasonable cost-based fee for labor, supplies, and postage
- A flat fee of $25
- No fee may be charged for electronic records
Correct answer: A fee not exceeding $6.50 per request under the safe harbor
The OCR established a $6.50 safe harbor fee for providing individuals with electronic copies of their PHI when maintained electronically.
Question 10: A covered entity's risk management plan should achieve which primary goal per the HIPAA Security Rule?
- Transfer all residual risk to business associates
- Reduce risks to ePHI to a reasonable and appropriate level (Correct answer)
- Eliminate all identified risks to ePHI
- Document every potential vulnerability in detail
Correct answer: Reduce risks to ePHI to a reasonable and appropriate level
Risk management under the Security Rule aims to reduce risks and vulnerabilities to ePHI to a reasonable and appropriate level โ not necessarily eliminate them entirely.
Question 11: A covered entity receives a valid subpoena for a patient's records. Under HIPAA, what must the covered entity do before disclosing the PHI?
- Obtain written patient authorization before disclosing
- Receive satisfactory assurances the requestor notified the patient or obtained a qualified protective order (Correct answer)
- Disclose immediately since legal process overrides HIPAA
- Notify the Department of Health and Human Services before disclosure
Correct answer: Receive satisfactory assurances the requestor notified the patient or obtained a qualified protective order
A subpoena not accompanied by a court order requires the covered entity to receive satisfactory assurances that the individual was notified or a qualified protective order is in place.
Question 12: What is the primary purpose of a risk analysis under the HIPAA Security Rule?
- To validate encryption key management procedures
- To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability (Correct answer)
- To document all workforce members with access to ePHI
- To create an audit trail for all ePHI access events
Correct answer: To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability
A risk analysis identifies and assesses potential threats and vulnerabilities to ePHI to determine the likelihood and impact of security incidents.
Question 13: What is the primary distinction between 'required' and 'addressable' implementation specifications under the HIPAA Security Rule?
- Required specs involve encryption; addressable specs involve training
- Required specs must be implemented exactly; addressable specs may be adapted or not implemented if documented (Correct answer)
- Required specs apply to large entities; addressable specs apply to small ones
- There is no meaningful distinction
Correct answer: Required specs must be implemented exactly; addressable specs may be adapted or not implemented if documented
Required specifications must be implemented as stated, while addressable specifications allow entities to assess reasonableness and document alternative measures or reasons for non-implementation.
Question 14: Under HIPAA, breach discovery is defined as the date on which which party first knows or reasonably should have known of the breach?
- The HHS Office for Civil Rights (OCR)
- The individual whose PHI was breached
- The covered entity or business associate, whichever is the data holder (Correct answer)
- The covered entity, regardless of when the business associate discovered it
Correct answer: The covered entity or business associate, whichever is the data holder
Discovery date is when the covered entity or business associate (whichever holds the data) first knew or should have known about the breach through reasonable diligence.
Question 15: Under HIPAA, which term describes a vendor that provides services to a covered entity and creates, receives, maintains, or transmits PHI in the course of providing those services?
- Business Associate (Correct answer)
- Qualified Service Organization
- Hybrid Entity
- Covered Entity
Correct answer: Business Associate
A business associate is a person or entity that performs services for a covered entity involving the use or disclosure of PHI, and must sign a Business Associate Agreement.
Question 16: When a breach affects 500 or more residents of a state or jurisdiction, a covered entity must notify which additional party?
- The Federal Trade Commission (FTC)
- Prominent media outlets serving the state or jurisdiction (Correct answer)
- The state Attorney General only
- The local police department
Correct answer: Prominent media outlets serving the state or jurisdiction
When a breach affects 500 or more residents of a state, the covered entity must provide notice to prominent media outlets in addition to individual and HHS notification.
Question 17: In a healthcare privacy program, which document formally authorizes the Privacy Officer's role and defines the scope of the privacy program?
- Business Associate Agreement
- Risk Management Plan
- Privacy Policy Charter or Program Charter (Correct answer)
- Privacy Notice
Correct answer: Privacy Policy Charter or Program Charter
A Privacy Program Charter formally establishes the privacy program, defines its scope, and grants authority to the Privacy Officer to develop and enforce privacy policies.
Question 18: Which of the following is an example of a technical safeguard under the HIPAA Security Rule?
- Policies governing workstation placement in patient areas
- Role-based access control limiting ePHI access by job function (Correct answer)
- Visitor sign-in logs at a data center
- Workforce security awareness training
Correct answer: Role-based access control limiting ePHI access by job function
Role-based access control is a technical safeguard โ it uses technology to ensure workforce members access only the ePHI necessary for their job functions.
Question 19: Which of the following best describes the concept of 'integrity' in the context of the HIPAA Security Rule?
- Restricting ePHI access to only authorized workforce members
- Ensuring ePHI is accessible to authorized users when needed
- Protecting ePHI from improper alteration or destruction (Correct answer)
- Encrypting ePHI during transmission over open networks
Correct answer: Protecting ePHI from improper alteration or destruction
Integrity under HIPAA Security Rule means that ePHI has not been altered or destroyed in an unauthorized manner, preserving its accuracy and completeness.
Question 20: A hospital's Security Officer is conducting a risk analysis. Which NIST document provides the most comprehensive guidance for conducting a risk assessment?
- NIST SP 800-122
- NIST SP 800-53
- NIST SP 800-66
- NIST SP 800-30 (Correct answer)
Correct answer: NIST SP 800-30
NIST SP 800-30 is the Guide for Conducting Risk Assessments and provides a structured framework for identifying and evaluating information security risks.
Question 21: Which of the following HIPAA Security Rule requirements addresses the need for a covered entity to restore ePHI data after a disaster?
- Disaster Recovery Plan (Correct answer)
- Emergency Mode Operation Plan
- Data Backup Plan
- Testing and Revision Procedures
Correct answer: Disaster Recovery Plan
The Disaster Recovery Plan implementation specification (45 CFR ยง164.308(a)(7)(ii)(B)) requires procedures to restore lost data in the event of an emergency or disaster.
Question 22: Which of the following events would NOT qualify as a 'breach' under the HIPAA Breach Notification Rule?
- A laptop containing unencrypted ePHI is stolen from a locked car
- A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose (Correct answer)
- A billing clerk views patient records that are unrelated to her job function
- A workforce member accidentally emails a patient's discharge summary to the wrong provider
Correct answer: A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose
Accessing PHI for legitimate treatment, payment, or operations purposes is not an impermissible use and therefore does not constitute a breach under HIPAA.
Question 23: Which federal law enacted in 2009 extended HIPAA privacy and security obligations directly to Business Associates?
- HITECH Act (Correct answer)
- ACA
- GINA
- ARRA
Correct answer: HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 made Business Associates directly liable for HIPAA compliance.
Question 24: Under HIPAA, which of the following is an acceptable substitute for individual breach notification when the covered entity has insufficient contact information?
- Posting conspicuous notice on the covered entity's website for 90 days and notifying major print/broadcast media (Correct answer)
- Calling local community organizations to distribute information
- Filing a report with the state insurance commissioner
- Posting notice on the HHS website
Correct answer: Posting conspicuous notice on the covered entity's website for 90 days and notifying major print/broadcast media
When direct contact information is unavailable, substitute notice may be provided by posting on the covered entity's website for 90 days or in major print or broadcast media serving the affected area.
Question 25: Under HIPAA, which of the following PHI disposal methods is considered a safe harbor that renders a breach not reportable?
- Applying password protection to PHI files
- Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable (Correct answer)
- Deleting files from a computer hard drive
- Moving PHI to a secure internal archive
Correct answer: Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable
PHI that has been rendered unreadable, indecipherable, or destroyed through proper methods (shredding paper, degaussing/purging media) is excluded from breach notification requirements.
Question 26: What is the goal of 'de-identification' of PHI under HIPAA?
- To convert PHI into a limited data set for research
- To remove identifiers so the information cannot reasonably identify an individual (Correct answer)
- To anonymize only the patient's name and date of birth
- To encrypt PHI so only authorized users can read it
Correct answer: To remove identifiers so the information cannot reasonably identify an individual
De-identification removes or obscures the 18 HIPAA-specified identifiers so that the remaining data cannot reasonably be used to identify an individual.
Question 27: The Contingency Plan standard under the HIPAA Security Rule's Administrative Safeguards requires which of the following implementation specifications as 'required' (not addressable)?
- Applications and data criticality analysis
- Emergency mode operation plan and testing and revision procedures
- Data backup plan and disaster recovery plan
- Both A and B (Correct answer)
Correct answer: Both A and B
The required contingency plan implementation specifications are the data backup plan, disaster recovery plan, and emergency mode operation plan; testing/revision procedures and criticality analysis are addressable.
Question 28: What is the maximum number of days a covered entity has to respond to a patient's request to access their own PHI?
- 30 days (Correct answer)
- 45 days
- 60 days
- 15 days
Correct answer: 30 days
Covered entities must act on access requests within 30 days, with one 30-day extension permitted if the entity notifies the patient of the delay and reason.
Question 29: Which HIPAA Security Rule standard requires covered entities to implement policies to prevent, detect, contain, and correct security violations?
- Evaluation
- Security Management Process (Correct answer)
- Workforce Training and Awareness
- Security Incident Procedures
Correct answer: Security Management Process
The Security Management Process standard (45 CFR ยง164.308(a)(1)) is the overarching standard requiring risk analysis, risk management, sanction policy, and activity review.
Question 30: A healthcare system's Privacy Officer is reviewing third-party vendor relationships. Which of the following vendors requires a Business Associate Agreement?
- A medical transcription company that transcribes physician notes containing PHI (Correct answer)
- A cloud storage vendor that maintains backups of encrypted ePHI where only the covered entity holds the decryption keys
- A law firm providing legal advice to the organization regarding HIPAA compliance
- A cleaning company that accesses patient care areas but not patient records
Correct answer: A medical transcription company that transcribes physician notes containing PHI
A medical transcription company creates, receives, or maintains PHI on behalf of the covered entity and is a business associate requiring a BAA.
Certified in Healthcare Privacy and Security (CHPS)
The CHPS credential, awarded by AHIMA, validates expertise in healthcare privacy and security program management, HIPAA compliance, information technology safeguards, and regulatory enforcement across healthcare organizations.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds