CHPS Privacy Program Management 2 — Questions and Answers
Question 1: Under HIPAA, a covered entity's Privacy Officer receives a complaint from a patient who believes their PHI was improperly disclosed. What is the FIRST action the Privacy Officer should take?
- File the complaint with OCR on the patient's behalf
- Dismiss the complaint if the patient cannot name the specific workforce member involved
- Acknowledge the complaint and initiate an investigation according to the complaint management process (Correct answer)
- Immediately notify the patient's insurer of the potential disclosure
Correct answer: Acknowledge the complaint and initiate an investigation according to the complaint management process
Upon receiving a privacy complaint, the Privacy Officer must acknowledge receipt and investigate according to the organization's complaint management procedures.
Question 2: A healthcare organization implements a 'Privacy by Design' approach. Which principle best describes this concept?
- Retroactively reviewing systems for privacy risks after deployment
- Integrating privacy protections into the design and architecture of systems from the outset (Correct answer)
- Designating a privacy champion in each department
- Publishing a comprehensive privacy policy annually
Correct answer: Integrating privacy protections into the design and architecture of systems from the outset
Privacy by Design embeds privacy protections into systems and processes from the beginning of development rather than as an afterthought.
Question 3: Which of the following BEST describes the concept of 'data minimization' in healthcare privacy program management?
- Deleting all PHI after 30 days regardless of retention requirements
- Collecting and using only the minimum PHI necessary to accomplish the intended purpose (Correct answer)
- Limiting access to PHI to only the Privacy Officer and Security Officer
- Reducing the number of systems that store PHI to fewer than three
Correct answer: Collecting and using only the minimum PHI necessary to accomplish the intended purpose
Data minimization means collecting, using, and retaining only the minimum PHI necessary for the specific purpose, consistent with HIPAA's Minimum Necessary standard.
Question 4: A healthcare organization wants to share a patient's case study in a medical journal. Which is the MOST appropriate privacy approach?
- De-identify the information to Safe Harbor standards before publication (Correct answer)
- Obtain verbal consent from the patient prior to submission
- Share the case study since medical education is a permitted TPO purpose
- File an IRB waiver of authorization for research purposes
Correct answer: De-identify the information to Safe Harbor standards before publication
Publishing de-identified case studies that meet the Safe Harbor standard removes HIPAA applicability entirely and is the most appropriate approach for journal publication.
Question 5: Which of the following best describes the role of a Privacy Steering Committee in a healthcare organization?
- A committee that reviews and approves individual patient access requests
- A cross-functional body that provides governance, oversight, and strategic direction for the privacy program (Correct answer)
- A team that investigates all workforce privacy violations
- A group that reviews BAAs before execution
Correct answer: A cross-functional body that provides governance, oversight, and strategic direction for the privacy program
A Privacy Steering Committee provides enterprise-level governance, aligning the privacy program with organizational strategy and ensuring cross-departmental accountability.
Question 6: Under a comprehensive privacy program, which document maps the flow of PHI through an organization to identify privacy risks?
- Business Associate Agreement
- Data Flow Diagram or Data Map (Correct answer)
- Notice of Privacy Practices
- Risk Assessment Report
Correct answer: Data Flow Diagram or Data Map
A data flow diagram or data map visually represents how PHI moves through an organization, helping identify where it is collected, used, stored, and disclosed.
Under HIPAA, a covered entity's Privacy Officer receives a complaint from a patient who believes their PHI was improperly disclosed.
What is the FIRST action the Privacy Officer should take?