Certified HIPAA Professional (CHP) Exam — Questions and Answers
Question 1: When a patient exercises their right to an accounting of disclosures, the covered entity must track disclosures made for which purposes?
- All disclosures including those for public health purposes
- Disclosures outside of treatment, payment, and healthcare operations (Correct answer)
- Treatment, payment, and healthcare operations only
- Only disclosures made to law enforcement agencies
Correct answer: Disclosures outside of treatment, payment, and healthcare operations
HIPAA requires accounting of disclosures made for purposes other than treatment, payment, and healthcare operations (TPO), which are generally excluded.
Question 2: A small rural clinic experiences a breach affecting 12 individuals. The clinic cannot afford to send individual letters. What is NOT an acceptable substitute notification method under HIPAA?
- Providing a toll-free phone number for at least 90 days
- Posting a notice on the clinic's website for 90 days
- Posting a notice in a major print or broadcast media in the service area
- Sending a mass text message to all clinic patients (Correct answer)
Correct answer: Sending a mass text message to all clinic patients
HIPAA's substitute notice options include website posting, major print/broadcast media, and a toll-free phone number — mass text messaging is not a recognized substitute method.
Question 3: A research hospital wants to use patient data for a new study. To maintain ethical standards, participants must provide:
- Implied consent through continued treatment
- Verbal consent witnessed by one staff member
- Retrospective consent after data collection is complete
- Written informed consent that is voluntary and comprehension-based (Correct answer)
Correct answer: Written informed consent that is voluntary and comprehension-based
Research ethics require prospective, voluntary, written informed consent that ensures participants understand risks and benefits.
Question 4: A competent patient refuses a blood transfusion due to religious beliefs. The care team should:
- Administer the transfusion to preserve life
- Transfer the patient to another facility immediately
- Respect the refusal and document it thoroughly (Correct answer)
- Seek a court order to override the refusal
Correct answer: Respect the refusal and document it thoroughly
Competent patients have the right to refuse any treatment, including life-saving interventions, based on personal or religious beliefs.
Question 5: A covered entity discovers a breach on March 1. The 60-day notification clock begins on which date?
- The date individuals are notified
- The date HHS is notified
- The date the breach was discovered (Correct answer)
- The date the breach actually occurred
Correct answer: The date the breach was discovered
The 60-day notification period runs from the date of discovery of the breach, not the date the breach occurred.
Question 6: A hospital is evaluating whether to accept residual risk after implementing encryption on mobile devices. Who has the authority to formally accept this residual risk?
- The attending physicians whose patients are affected
- Senior leadership or an authorized risk owner within the organization (Correct answer)
- The business associate providing the mobile devices
- The OCR regional office overseeing the organization
Correct answer: Senior leadership or an authorized risk owner within the organization
Risk acceptance must be formally documented and approved by an appropriate organizational authority, typically senior leadership or a designated risk owner.
Question 7: Under HITECH's breach notification rule, what is the maximum timeframe for notifying affected individuals after discovery of a breach?
- 90 days
- 30 days
- 45 days
- 60 days (Correct answer)
Correct answer: 60 days
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days following the discovery of a breach of unsecured PHI.
Question 8: To what extent is a covered entity responsible for the HIPAA-related actions of its business associates?
- Not responsible at all — business associates bear sole liability
- Only if the covered entity had advance knowledge of the violation
- To the extent defined by the BAA terms and its own oversight obligations (Correct answer)
- Fully responsible for all violations, even those beyond its control
Correct answer: To the extent defined by the BAA terms and its own oversight obligations
Covered entities are responsible to the extent defined by BAA terms and must take corrective action when violations become known.
Question 9: Which of the following is a required (not addressable) implementation specification under the HIPAA workstation use standard?
- Physical barriers around workstations
- Policies specifying proper functions of workstations and how they are used (Correct answer)
- Encryption of workstation hard drives
- Screen lock policies
Correct answer: Policies specifying proper functions of workstations and how they are used
The workstation use standard requires covered entities to document the functions workstations perform and the manner in which those functions are performed — this is a required specification.
Question 10: A patient asks a nurse not to tell their spouse about a terminal diagnosis. The nurse should:
- Inform the spouse anyway to prevent family distress
- Refer the decision to hospital administration
- Respect the patient's confidentiality and honor the request (Correct answer)
- Document the request and then disclose to the spouse
Correct answer: Respect the patient's confidentiality and honor the request
Patient confidentiality protects the right to control disclosure of personal health information, including to family members.
Question 11: Which federal legislation made business associates directly subject to HIPAA compliance obligations?
- The Affordable Care Act (ACA)
- The Health Information Technology for Economic and Clinical Health (HITECH) Act (Correct answer)
- The Medicare Modernization Act of 2003
- The Sarbanes-Oxley Act
Correct answer: The Health Information Technology for Economic and Clinical Health (HITECH) Act
The HITECH Act of 2009 made business associates directly liable for HIPAA compliance, extending obligations beyond covered entities.
Question 12: What is the correct order for donning personal protective equipment?
- Gloves, gown, mask, eye protection
- Gown, mask, eye protection, gloves (Correct answer)
- Any order is acceptable
- Mask, gloves, gown, eye protection
Correct answer: Gown, mask, eye protection, gloves
The correct donning sequence (gown, mask, eye protection, gloves) ensures complete coverage and prevents contamination of already-donned items.
Question 13: What is the correct response to suspected equipment malfunction?
- Continue using with adjusted settings
- Let the next shift handle it
- Remove from service immediately, tag as defective, and report to maintenance (Correct answer)
- Wait for the next scheduled maintenance check
Correct answer: Remove from service immediately, tag as defective, and report to maintenance
Immediately removing malfunctioning equipment from service prevents potential harm and ensures only properly functioning equipment is used for professional services.
Question 14: Under HITECH, what is the role of the Office for Civil Rights (OCR) in relation to HIPAA enforcement?
- Overseeing the operation of state-level health information exchanges
- Managing financial incentive payments for EHR adoption by eligible providers
- Investigating HIPAA complaints, conducting audits, and imposing civil monetary penalties (Correct answer)
- Developing and maintaining EHR certification criteria and standards
Correct answer: Investigating HIPAA complaints, conducting audits, and imposing civil monetary penalties
OCR within HHS is the primary enforcement authority for HIPAA Privacy and Security Rules, responsible for investigating complaints, conducting compliance reviews, and imposing civil monetary penalties.
Question 15: What is the primary obligation of a certified professional regarding patient/client confidentiality?
- Disclose information when it benefits the practice
- Share information freely with other professionals
- Protect all personal information and disclose only with proper authorization (Correct answer)
- Keep records only if the patient requests it
Correct answer: Protect all personal information and disclose only with proper authorization
Protecting confidential information and disclosing only with proper authorization is a fundamental ethical and legal obligation of all certified professionals.
Question 16: Under HIPAA, subcontractors of business associates who handle PHI are treated as:
- Covered entities subject to the Privacy Rule only
- Business associates with direct HIPAA obligations (Correct answer)
- Exempt third parties not covered by HIPAA
- Workforce members of the original covered entity
Correct answer: Business associates with direct HIPAA obligations
Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves considered business associates with direct HIPAA obligations.
Question 17: A hospital is considering a policy to share patient data with a commercial partner for marketing purposes. Ethical review should prioritize:
- The commercial partner's data security certifications alone
- Compliance with the hospital's accreditation standards only
- Revenue generation potential for the institution
- Patient privacy, explicit consent, and whether the use aligns with patient expectations (Correct answer)
Correct answer: Patient privacy, explicit consent, and whether the use aligns with patient expectations
Marketing use of PHI requires explicit patient authorization under HIPAA, and ethical review must center patient trust and privacy as primary values.
Question 18: The Medicare and Medicaid EHR Incentive Programs created under HITECH are now referred to by which name?
- Promoting Interoperability Programs (Correct answer)
- Digital Health Advancement Program
- Health IT Achievement Program
- Electronic Care Quality Initiative
Correct answer: Promoting Interoperability Programs
The Medicare and Medicaid EHR Incentive Programs were rebranded as the Promoting Interoperability Programs to better reflect the current focus on health information exchange and interoperability.
Question 19: Which of the following is an example of an emergency access procedure under HIPAA technical access controls?
- Using personal email to share ePHI when systems are down
- Granting all staff admin rights during a system outage
- Disabling audit logs to speed up emergency workflows
- A break-glass protocol allowing temporary elevated ePHI access during emergencies (Correct answer)
Correct answer: A break-glass protocol allowing temporary elevated ePHI access during emergencies
Emergency access procedures (break-glass protocols) allow authorized personnel to access ePHI in emergency situations while maintaining accountability through logging.
Question 20: Which entity typically has authority to establish practice standards?
- State licensing boards and professional regulatory bodies (Correct answer)
- Individual practitioners
- Insurance companies
- Equipment manufacturers
Correct answer: State licensing boards and professional regulatory bodies
State licensing boards and professional regulatory bodies have the legal authority to establish and enforce practice standards within their jurisdiction.
Question 21: Which of the following is TRUE about the HIPAA Security Rule's applicability?
- It applies only to hospitals and large health systems
- It applies to all PHI in any format
- It applies only to ePHI created or maintained by covered entities and their business associates (Correct answer)
- It applies to paper records stored in electronic filing systems
Correct answer: It applies only to ePHI created or maintained by covered entities and their business associates
The Security Rule applies exclusively to electronic protected health information (ePHI) and covers both covered entities and, since 2013, their business associates.
Question 22: A patient requests an amendment to their medical record, which the provider denies. What must the provider include with the denial?
- A referral to the state medical board
- A mandatory 30-day waiting period before resubmission
- An automatic forwarding to the Office for Civil Rights
- A written denial with the basis for denial and information on how the individual may submit a statement of disagreement (Correct answer)
Correct answer: A written denial with the basis for denial and information on how the individual may submit a statement of disagreement
When denying an amendment request, the covered entity must provide a written denial explaining the basis and inform the patient of their right to submit a statement of disagreement.
Question 23: A covered entity's subcontractor improperly disposes of PHI. Under HIPAA post-HITECH, who bears direct liability?
- Only the original business associate that hired the subcontractor
- No liability exists unless the disposal was intentional
- The subcontractor directly, as a business associate of a business associate (Correct answer)
- Only the covered entity, since it is ultimately responsible
Correct answer: The subcontractor directly, as a business associate of a business associate
Post-HITECH, subcontractors who handle PHI on behalf of business associates are themselves treated as business associates and bear direct HIPAA liability.
Question 24: What constitutes a boundary violation in professional practice?
- Following organizational policies
- Maintaining strict professional communication
- Attending continuing education events
- Engaging in dual relationships that could impair professional judgment (Correct answer)
Correct answer: Engaging in dual relationships that could impair professional judgment
Dual relationships that could impair professional judgment represent boundary violations, potentially compromising the quality and objectivity of professional services.
Question 25: A Security Risk Analysis under the HIPAA Security Rule must assess:
- Business associate agreements for all vendors
- Potential threats and vulnerabilities to all ePHI the entity creates, receives, maintains, or transmits (Correct answer)
- The cost of implementing encryption for all systems
- Only electronic PHI stored on portable devices
Correct answer: Potential threats and vulnerabilities to all ePHI the entity creates, receives, maintains, or transmits
The Security Rule requires a thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI in the entity's environment.
Question 26: Which patient right under the HIPAA Privacy Rule allows a patient to request restrictions on how their PHI is used or disclosed?
- Right to request restriction (Correct answer)
- Right to accounting of disclosures
- Right to access
- Right to confidential communications
Correct answer: Right to request restriction
The right to request restriction (45 CFR §164.522) allows patients to ask covered entities to limit certain uses or disclosures of their PHI.
Question 27: Which blood vessels carry oxygenated blood away from the heart?
- Veins
- Capillaries
- Venules
- Arteries (Correct answer)
Correct answer: Arteries
Arteries carry oxygenated blood away from the heart to the body's tissues (with the exception of the pulmonary arteries).
Question 28: Which of the following workforce actions would most likely result in criminal penalties under HIPAA as strengthened by HITECH?
- Failing to encrypt an internal email containing PHI
- Sharing a login password with a trusted colleague temporarily
- Intentionally accessing and selling patient records for personal financial gain (Correct answer)
- Accidentally sending a patient appointment reminder to the wrong email address
Correct answer: Intentionally accessing and selling patient records for personal financial gain
Knowingly and intentionally obtaining or disclosing PHI for personal gain, commercial advantage, or malicious harm can result in criminal penalties including fines and imprisonment.
Question 29: Which federal agency handles criminal prosecution of knowing HIPAA violations?
- HHS Office for Civil Rights
- Centers for Medicare & Medicaid Services
- Federal Trade Commission
- Department of Justice (Correct answer)
Correct answer: Department of Justice
The Department of Justice (DOJ) is responsible for prosecuting knowing violations of HIPAA that rise to the level of criminal conduct.
Question 30: A nurse overhears a colleague sharing identifiable patient information in a hospital elevator. The nurse's BEST course of action is to:
- Remind the colleague that PHI conversations in public areas violate HIPAA (Correct answer)
- Join the conversation and add clinical input
- Ignore the conversation since it is between coworkers
- Report the colleague to law enforcement immediately
Correct answer: Remind the colleague that PHI conversations in public areas violate HIPAA
HIPAA requires reasonable safeguards to prevent incidental disclosures, including avoiding PHI discussions in public or non-private areas.
Question 31: A patient requests that their HIV-positive status not be documented in their electronic health record. The provider should:
- Explain that clinically significant information must be documented for safe care (Correct answer)
- Honor the request completely and omit the diagnosis
- File a complaint against the patient with hospital administration
- Transfer care to another provider who will comply
Correct answer: Explain that clinically significant information must be documented for safe care
Providers have an ethical and legal duty to maintain accurate records; withholding clinically significant information could compromise safe and coordinated care.
Question 32: What must be included in a breach notification to individuals?
- Only the name of the responsible employee.
- Financial compensation estimates.
- A list of past breaches.
- Detailed breach information and response steps (Correct answer)
Correct answer: Detailed breach information and response steps
A breach notification to individuals must contain specific, detailed information to be compliant with HIPAA. This includes a description of the breach, the types of unsecured protected health information (PHI) involved, the steps individuals should take to protect themselves, and the covered entity's contact information. It also typically outlines what the entity is doing to investigate and mitigate the breach.
Question 33: Which HITECH provision requires a covered entity to honor a patient's request to restrict disclosure of PHI to a health plan?
- The minimum necessary standard restriction
- The notice of privacy practices amendment requirement
- The individual access expansion provision
- The right to restrict disclosures when a patient pays out of pocket in full (Correct answer)
Correct answer: The right to restrict disclosures when a patient pays out of pocket in full
HITECH requires covered entities to honor a patient's request to restrict disclosure to a health plan if the patient pays out of pocket in full for the item or service.
Question 34: Which type of facility control helps prevent contamination of PHI-containing systems in a clinical environment by limiting access to clean versus dirty zones?
- Physical separation or zoning protocols (Correct answer)
- Logical access controls
- Encryption at rest
- Audit log reviews
Correct answer: Physical separation or zoning protocols
Physical separation of clean and dirty zones is an infection control and safety measure that also supports HIPAA physical safeguard requirements by limiting unauthorized access.
Question 35: Under HITECH, what expanded accounting of disclosures right applies specifically to electronic health records?
- Patients can opt out of any EHR disclosure except for emergency treatment
- Business associates must send patients monthly summaries of all PHI disclosures
- Patients may request a list of all individuals who accessed their EHR for treatment, payment, and operations purposes (Correct answer)
- Covered entities must disclose all EHR access logs to state health departments quarterly
Correct answer: Patients may request a list of all individuals who accessed their EHR for treatment, payment, and operations purposes
HITECH expanded the accounting of disclosures requirement to include disclosures made through an EHR for treatment, payment, and healthcare operations, allowing patients to see who accessed their records.
Question 36: What is the purpose of Health Information Exchanges (HIEs) as promoted under the HITECH Act?
- To process insurance claims and remittance advice electronically
- To replace all paper-based records with digital equivalents by a federal deadline
- To serve as backup data storage for EHR systems during outages
- To enable secure electronic sharing of patient health information across organizations to improve care coordination (Correct answer)
Correct answer: To enable secure electronic sharing of patient health information across organizations to improve care coordination
HIEs facilitate the secure electronic movement of health information among organizations, improving care coordination, reducing duplicate testing, and enhancing patient safety.
Question 37: A hospital's laptop containing unencrypted PHI is stolen. The hospital determines 480 individuals are affected. What is the correct breach notification sequence?
- Notify HHS first, then individuals within 60 days
- Notify individuals within 60 days and HHS within 60 days (Correct answer)
- Notify media first, then individuals, then HHS
- Notify individuals within 60 days and HHS by the next annual reporting deadline
Correct answer: Notify individuals within 60 days and HHS within 60 days
For breaches affecting fewer than 500 individuals, covered entities must notify individuals and HHS within 60 days of discovery.
Question 38: A covered entity's breach notification to affected individuals must be written in what manner to comply with HIPAA?
- In the official language of the state where the entity is headquartered
- In legal terminology consistent with the entity's standard privacy notice
- In technical terms so individuals understand the severity of the breach
- In plain language that is understandable to the affected individuals (Correct answer)
Correct answer: In plain language that is understandable to the affected individuals
HIPAA requires breach notifications to be written in plain language so that affected individuals can understand what happened and what they should do.
Question 39: What does 'Meaningful Use' refer to in the context of the HITECH Act?
- Using certified EHR technology in ways that improve care quality, safety, efficiency, and patient engagement (Correct answer)
- Documenting all patient encounters electronically within 24 hours
- Meeting minimum system uptime requirements for EHR platforms
- Using only EHR vendors approved by the Centers for Medicare & Medicaid Services
Correct answer: Using certified EHR technology in ways that improve care quality, safety, efficiency, and patient engagement
Meaningful Use refers to using certified EHR technology in a manner that improves quality, safety, and efficiency while engaging patients and reducing health disparities.
Question 40: Under the HIPAA Breach Notification Rule, how long must documentation of a breach investigation and notification be retained?
- 6 years (Correct answer)
- 1 year
- 3 years
- 10 years
Correct answer: 6 years
Breach notification documentation, including the investigation, risk assessment, and notification records, must be retained for 6 years per HIPAA's standard documentation retention requirement.
Question 41: A covered entity discovers that an employee accessed PHI out of curiosity with no intent to harm or disclose. What HIPAA enforcement tier most likely applies?
- Reasonable cause — should have known with reasonable diligence (Correct answer)
- No knowledge — the entity was unaware
- Willful neglect not corrected
- Willful neglect corrected in time
Correct answer: Reasonable cause — should have known with reasonable diligence
Employees accessing PHI without a job-related need is a reasonably foreseeable risk; failure to prevent it through training and access controls typically qualifies as 'reasonable cause.'
Question 42: What is the role of the HHS Office for Civil Rights (OCR) in HIPAA enforcement?
- Investigating complaints and enforcing the Privacy and Security Rules (Correct answer)
- Issuing HIPAA licenses to covered entities
- Setting state-level breach notification deadlines
- Prosecuting criminal HIPAA violations directly
Correct answer: Investigating complaints and enforcing the Privacy and Security Rules
OCR investigates complaints, conducts compliance reviews, and enforces the HIPAA Privacy, Security, and Breach Notification Rules.
Question 43: An individual files a HIPAA complaint with OCR against a covered entity. OCR investigates and finds no violation. What is the most likely outcome?
- OCR closes the case with a finding of no violation (Correct answer)
- The covered entity is fined a minimum baseline penalty
- OCR issues a corrective action plan regardless
- The case is automatically referred to the DOJ
Correct answer: OCR closes the case with a finding of no violation
When OCR finds no violation after investigation, it closes the case and notifies both the complainant and the covered entity.
Question 44: What safeguard would audit control systems fall under?
- Administrative safeguard
- Data entry safeguard
- Technical safeguard (Correct answer)
- Physical safeguard
Correct answer: Technical safeguard
Audit control systems are automated processes that record and examine activity in information systems. They fall under technical safeguards because they involve the use of technology (software, hardware) to monitor access and changes to electronic protected health information (ePHI). This technological monitoring helps ensure accountability and detect potential security violations.
Question 45: For a breach affecting 500 or more individuals in a state or jurisdiction, what entities must a covered entity notify?
- Only the Secretary of HHS within 60 days
- Affected individuals, prominent media outlets in the affected area, and the Secretary of HHS (Correct answer)
- Local law enforcement, HHS, and state attorneys general
- Affected individuals and their employers only
Correct answer: Affected individuals, prominent media outlets in the affected area, and the Secretary of HHS
Breaches affecting 500 or more individuals in a state or jurisdiction require simultaneous notification to affected individuals, prominent media outlets serving that area, and the Secretary of HHS.
Question 46: What are the consequences for failing to report a HIPAA breach?
- Civil penalties and enforcement actions (Correct answer)
- Promotion of responsible parties.
- Waiver of further obligations.
- Public commendation.
Correct answer: Civil penalties and enforcement actions
Failing to report a HIPAA breach in accordance with the Breach Notification Rule can lead to significant consequences for covered entities and business associates. The Office for Civil Rights (OCR) can impose substantial civil monetary penalties, ranging from thousands to millions of dollars, depending on the level of culpability. Additionally, enforcement actions may include corrective action plans and public scrutiny.
Question 47: Under HITECH, which element is NOT required to be included in a breach notification letter sent to affected individuals?
- A description of what happened and the types of PHI involved
- Contact information and toll-free number for individuals to ask questions
- The name and title of the specific employee responsible for the breach (Correct answer)
- Steps individuals should take to protect themselves from potential harm
Correct answer: The name and title of the specific employee responsible for the breach
Breach notifications must include a description of the breach, the types of PHI involved, protective steps, and contact information, but do not require identifying the responsible employee.
Question 48: Under HIPAA, a covered entity must respond to a patient's request to amend their PHI within:
- 30 days, with one 30-day extension if needed
- 60 days, with one 30-day extension if needed (Correct answer)
- 90 days, with no extensions permitted
- 14 days, with no extensions permitted
Correct answer: 60 days, with one 30-day extension if needed
HIPAA's Privacy Rule requires covered entities to act on amendment requests within 60 days, extendable by 30 days with written notice.
Question 49: What is the significance of obtaining a thorough patient history?
- It replaces the need for physical examination
- It reveals relevant conditions that may affect treatment planning (Correct answer)
- It is optional for returning patients
- It is only needed for legal protection
Correct answer: It reveals relevant conditions that may affect treatment planning
A thorough patient history reveals pre-existing conditions, allergies, medications, and other factors that directly influence treatment decisions and safety precautions.
Question 50: Under HIPAA, a Business Associate Agreement (BAA) is required when a vendor does which of the following?
- Sells medical supplies directly to patients
- Delivers food and catering services to a healthcare facility
- Provides building maintenance services to a hospital
- Creates, receives, maintains, or transmits PHI on behalf of a covered entity (Correct answer)
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is required whenever a vendor creates, receives, maintains, or transmits PHI while performing services or functions on behalf of a covered entity.
Certified HIPAA Professional (CHP) Exam
The Certified HIPAA Professional (CHP) certification validates an individual's knowledge of HIPAA regulations, including privacy, security, and breach notification rules.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds