CHPS Privacy Program Management 1 — Questions and Answers
Question 1: Which framework is most widely used by healthcare organizations to build a comprehensive privacy program structure?
- NIST Cybersecurity Framework (CSF)
- Generally Accepted Privacy Principles (GAPP) (Correct answer)
- ISO/IEC 27001
- COBIT 5 for Information Security
Correct answer: Generally Accepted Privacy Principles (GAPP)
GAPP, developed by the AICPA and CICA, provides 10 privacy principles widely used as a framework for building privacy programs in healthcare and other sectors.
Question 2: In a healthcare privacy program, which document formally authorizes the Privacy Officer's role and defines the scope of the privacy program?
- Privacy Notice
- Business Associate Agreement
- Privacy Policy Charter or Program Charter (Correct answer)
- Risk Management Plan
Correct answer: Privacy Policy Charter or Program Charter
A Privacy Program Charter formally establishes the privacy program, defines its scope, and grants authority to the Privacy Officer to develop and enforce privacy policies.
Question 3: A healthcare organization conducts a Privacy Impact Assessment (PIA). What is its primary purpose?
- To audit workforce compliance with HIPAA training requirements
- To evaluate how a new system or process will collect, use, and protect personal health information (Correct answer)
- To assess vendor security practices before signing a BAA
- To measure patient satisfaction with privacy practices
Correct answer: To evaluate how a new system or process will collect, use, and protect personal health information
A PIA systematically evaluates the privacy risks of new or changed systems or business processes involving PHI before implementation.
Question 4: Which of the following is a key component of an effective healthcare privacy training program?
- Training should occur only at onboarding and need not be repeated
- Training should be role-based, addressing the specific PHI access and risks for each job function (Correct answer)
- All workforce members should receive identical training content regardless of their role
- Training is only required for workforce members who handle paper records
Correct answer: Training should be role-based, addressing the specific PHI access and risks for each job function
Effective privacy training is role-based, tailoring content to the specific privacy risks and PHI handling responsibilities of each workforce role.
Question 5: What is the primary purpose of a healthcare organization's sanctions policy under HIPAA?
- To establish financial penalties for patients who misuse the patient portal
- To define consequences for workforce members who violate privacy and security policies (Correct answer)
- To document procedures for reporting breaches to HHS
- To create a framework for denying patient access requests
Correct answer: To define consequences for workforce members who violate privacy and security policies
The sanctions policy (required by 45 CFR §164.530(e)) defines appropriate disciplinary actions for workforce members who fail to comply with privacy and security policies.
Question 6: In healthcare privacy program management, which metric best measures the effectiveness of a privacy training program?
- The number of privacy policies published on the intranet
- The rate of privacy incidents following retraining compared to baseline incident rates (Correct answer)
- The percentage of workforce who clicked 'complete' in the LMS
- Annual budget allocated to the privacy program
Correct answer: The rate of privacy incidents following retraining compared to baseline incident rates
Measuring incident rates before and after training provides outcome-based evidence of training effectiveness rather than just completion metrics.
Which framework is most widely used by healthcare organizations to build a comprehensive privacy program structure?