CHP Cheat Sheet 2026

The 30 highest-yield CHP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

50 questions
60 min time limit
70% to pass
  1. Under the HITECH Act, which entities became directly liable for HIPAA compliance that were previously only bound through contractual agreements? Business associates
  2. A hospital is evaluating whether to de-identify clinical assessment data for research. Under the Expert Determination method, de-identification requires: A qualified statistical expert certifying very small re-identification risk
  3. Which HIPAA Security Rule standard specifically requires covered entities to protect against unauthorized physical access to systems storing ePHI? Physical Safeguards — Facility Access Controls
  4. Which element is NOT required to be included in a Business Associate Agreement under HIPAA? The specific dollar amount of penalties if the business associate causes a breach
  5. A provider's treatment protocol inadvertently includes PHI of a patient who was not the intended recipient of a fax. Under HIPAA, this is considered: An impermissible disclosure that may require breach analysis
  6. If a business associate agreement (BAA) is amended, what must the covered entity do with the original BAA? Retain the original BAA for 6 years from when it was last in effect
  7. A hospital must provide an accounting of disclosures to a patient. What is the standard timeframe for fulfilling this request? 30 days, with one 30-day extension if needed
  8. Which of the following best describes the 'conduit exception' under HIPAA? Entities that only transmit PHI without routine access are not business associates
  9. Which patient right under the HIPAA Privacy Rule allows a patient to request restrictions on how their PHI is used or disclosed? Right to request restriction
  10. A staff member posts a general comment about a 'difficult patient day' on social media without naming any patient. This action is BEST described as: A potential HIPAA violation if the post could identify a patient in context
  11. Which audit control is specifically required by the HIPAA Security Rule to track activity in information systems containing ePHI? Hardware, software, and procedural mechanisms that record and examine activity
  12. Which federal legislation made business associates directly subject to HIPAA compliance obligations? The Health Information Technology for Economic and Clinical Health (HITECH) Act
  13. Which HITECH provision most directly addressed the gap that previously exempted business associates from direct HIPAA liability? The direct applicability of Security Rule requirements to business associates
  14. A nurse overhears a colleague sharing identifiable patient information in a hospital elevator. The nurse's BEST course of action is to: Remind the colleague that PHI conversations in public areas violate HIPAA
  15. Which of the following best describes a 'downstream' business associate under HIPAA? A subcontractor of a business associate that also handles PHI
  16. A physical therapist uses a tablet at multiple patient locations throughout the day. Which HIPAA-compliant practice should govern use of this device? A screen lock with a PIN or biometric should activate automatically after each session
  17. During a mock HIPAA audit, an assessor requests documentation of the organization's sanction policy. What does this policy MUST address? Penalties for workforce members who violate privacy and security policies
  18. A patient asks a nurse not to tell their spouse about a terminal diagnosis. The nurse should: Respect the patient's confidentiality and honor the request
  19. A patient who was previously enrolled in a clinical trial withdraws consent. The research team must: Stop collecting new data and remove the participant from ongoing interventions
  20. Which body system is most relevant to understanding tissue response to treatment? The musculoskeletal and integumentary systems
  21. How often should HIPAA risk assessments be conducted? Annually or as needed
  22. Which HIPAA concept requires organizations to implement security measures that are reasonable and appropriate based on their size, complexity, and capabilities? Flexibility and scalability standard
  23. A HIPAA audit reveals an organization has not updated its risk assessment in four years. Why is this problematic under the Security Rule? Risk assessments must reflect current threats, vulnerabilities, and operational changes
  24. What is the primary purpose of administrative safeguards under HIPAA? To manage workforce security and access control
  25. A covered entity discovers a breach on March 1. By what date must it notify the Secretary of HHS if fewer than 500 individuals were affected? Within 60 days after the end of the calendar year in which the breach was discovered
  26. What is the primary purpose of the HIPAA Breach Notification Rule? To notify individuals and authorities about data breaches
  27. Under HIPAA, subcontractors of business associates who handle PHI are treated as: Business associates with direct HIPAA obligations
  28. What does PHI stand for in the context of HIPAA? Protected Health Information
  29. What are the four tiers of civil monetary penalties established by HITECH, listed from least to most severe? Did not know, reasonable cause, willful neglect corrected, willful neglect not corrected
  30. What is the primary obligation of a certified professional regarding patient/client confidentiality? Protect all personal information and disclose only with proper authorization
Turn these facts into recall:
Was this helpful?