Certified HIPAA Professional (CHP®) Exam Prep 2026
Updated Practice Questions – Comprehensive Healthcare
Privacy and Security Review Detailed Explanations –
Verified Answers – Complete Success Workbook
SECTION 1: HIPAA PRIVACY RULE (~35-40% of Exam)
Question 1
Under the HIPAA Privacy Rule, Protected Health Information (PHI) is defined
as:
A) Any health information maintained in electronic format only
B) Individually identifiable health information held or transmitted by a
covered entity or its business associate, in any form or medium
C) Only information related to mental health treatment
D) Information that has been completely de-identified
Rationale: PHI is defined as individually identifiable health information held or
transmitted by a covered entity or its business associate, regardless of the form or
medium (oral, paper, or electronic). It includes demographic data that relates to
past, present, or future physical or mental health conditions, treatment, or payment.
Question 2
The Minimum Necessary Standard under HIPAA requires that:
A) All patient information must be shared with all providers
B) Covered entities must make reasonable efforts to limit the use, disclosure,
and request of PHI to the minimum necessary to accomplish the intended
purpose
C) No PHI can ever be shared
D) Only physicians can access PHI
Rationale: The Minimum Necessary Standard is a core HIPAA Privacy Rule
requirement. Covered entities must make reasonable efforts to limit PHI use,
disclosure, and requests to the minimum necessary to accomplish the intended
purpose. This standard does not apply to disclosures for treatment purposes.
,Question 3
Which of the following is NOT considered a Covered Entity under HIPAA?
A) Health plan
B) Healthcare clearinghouse
C) Healthcare provider who transmits health information electronically
D) Life insurance company that does not provide health insurance
Rationale: Covered entities under HIPAA include health plans, healthcare
clearinghouses, and healthcare providers who transmit health information
electronically for covered transactions. A life insurance company that does not
provide health insurance is not a covered entity.
Question 4
A hospital is preparing to disclose PHI to a healthcare provider for treatment
purposes. Which of the following is required?
A) Written authorization from the patient
B) No authorization is required; treatment disclosures are permitted without
authorization
C) Approval from the hospital's legal department
D) A Business Associate Agreement
Rationale: The HIPAA Privacy Rule permits covered entities to disclose PHI
for treatment, payment, and healthcare operations (TPO) without patient
authorization. Treatment includes coordination of care among providers.
Question 5
Which of the following is a patient right under the HIPAA Privacy Rule?
A) The right to have all medical records destroyed
B) The right to access, inspect, and obtain a copy of their PHI
C) The right to receive free healthcare
D) The right to demand specific treatments
,Rationale: Patients have the right to access, inspect, and obtain a copy of their
PHI held by covered entities. They also have rights to request amendments, receive
an accounting of disclosures, and request restrictions on certain uses and
disclosures.
Question 6
A patient requests an amendment to their medical record. Under HIPAA, the
covered entity must:
A) Always grant the amendment
B) Respond to the request within 60 days (with one 30-day extension) and
either accept or deny the request
C) Deny all amendment requests
D) Respond within 90 days without extension
Rationale: Covered entities must respond to a request for amendment within 60
days, with the option of a single 30-day extension if the entity provides written
notice to the individual. The entity may deny the request if the record is accurate
and complete.
Question 7
The HIPAA Privacy Rule's TPO exception allows disclosures for:
A) Only treatment purposes
B) Treatment, Payment, and Healthcare Operations
C) Only payment purposes
D) Only healthcare operations
Rationale: TPO stands for Treatment, Payment, and Healthcare Operations.
This is a key exception to the authorization requirement, allowing covered entities
to use and disclose PHI for these purposes without patient authorization.
Question 8
A Notice of Privacy Practices (NPP) must be:
, A) Provided only upon patient request
B) Provided to patients at the first service encounter and made available upon
request
C) Posted only in the hospital lobby
D) Provided only to patients who ask for it
Rationale: Covered entities must provide the NPP to patients at the first service
encounter and make it available upon request. The NPP describes how PHI may
be used and disclosed, and informs patients of their privacy rights.
Question 9
A researcher requests PHI for a research study. Which of the following
is required for the disclosure?
A) No authorization is ever required for research
B) A valid authorization from the patient or a waiver of authorization from an
IRB/Privacy Board
C) Approval from the hospital CEO only
D) A Business Associate Agreement only
Rationale: Research disclosures generally require patient authorization unless
the IRB or Privacy Board grants a waiver of authorization. The research must
meet specific criteria for the waiver to be granted.
Question 10
Under the Minimum Necessary Standard, which of the following is exempt from
the requirement?
A) Disclosures to law enforcement
B) Disclosures for treatment purposes
C) Disclosures for payment purposes
D) Disclosures to business associates
Rationale: The Minimum Necessary Standard does not apply to disclosures for
treatment purposes. It also does not apply to disclosures made to the individual,
pursuant to an authorization, or as required by law.
Updated Practice Questions – Comprehensive Healthcare
Privacy and Security Review Detailed Explanations –
Verified Answers – Complete Success Workbook
SECTION 1: HIPAA PRIVACY RULE (~35-40% of Exam)
Question 1
Under the HIPAA Privacy Rule, Protected Health Information (PHI) is defined
as:
A) Any health information maintained in electronic format only
B) Individually identifiable health information held or transmitted by a
covered entity or its business associate, in any form or medium
C) Only information related to mental health treatment
D) Information that has been completely de-identified
Rationale: PHI is defined as individually identifiable health information held or
transmitted by a covered entity or its business associate, regardless of the form or
medium (oral, paper, or electronic). It includes demographic data that relates to
past, present, or future physical or mental health conditions, treatment, or payment.
Question 2
The Minimum Necessary Standard under HIPAA requires that:
A) All patient information must be shared with all providers
B) Covered entities must make reasonable efforts to limit the use, disclosure,
and request of PHI to the minimum necessary to accomplish the intended
purpose
C) No PHI can ever be shared
D) Only physicians can access PHI
Rationale: The Minimum Necessary Standard is a core HIPAA Privacy Rule
requirement. Covered entities must make reasonable efforts to limit PHI use,
disclosure, and requests to the minimum necessary to accomplish the intended
purpose. This standard does not apply to disclosures for treatment purposes.
,Question 3
Which of the following is NOT considered a Covered Entity under HIPAA?
A) Health plan
B) Healthcare clearinghouse
C) Healthcare provider who transmits health information electronically
D) Life insurance company that does not provide health insurance
Rationale: Covered entities under HIPAA include health plans, healthcare
clearinghouses, and healthcare providers who transmit health information
electronically for covered transactions. A life insurance company that does not
provide health insurance is not a covered entity.
Question 4
A hospital is preparing to disclose PHI to a healthcare provider for treatment
purposes. Which of the following is required?
A) Written authorization from the patient
B) No authorization is required; treatment disclosures are permitted without
authorization
C) Approval from the hospital's legal department
D) A Business Associate Agreement
Rationale: The HIPAA Privacy Rule permits covered entities to disclose PHI
for treatment, payment, and healthcare operations (TPO) without patient
authorization. Treatment includes coordination of care among providers.
Question 5
Which of the following is a patient right under the HIPAA Privacy Rule?
A) The right to have all medical records destroyed
B) The right to access, inspect, and obtain a copy of their PHI
C) The right to receive free healthcare
D) The right to demand specific treatments
,Rationale: Patients have the right to access, inspect, and obtain a copy of their
PHI held by covered entities. They also have rights to request amendments, receive
an accounting of disclosures, and request restrictions on certain uses and
disclosures.
Question 6
A patient requests an amendment to their medical record. Under HIPAA, the
covered entity must:
A) Always grant the amendment
B) Respond to the request within 60 days (with one 30-day extension) and
either accept or deny the request
C) Deny all amendment requests
D) Respond within 90 days without extension
Rationale: Covered entities must respond to a request for amendment within 60
days, with the option of a single 30-day extension if the entity provides written
notice to the individual. The entity may deny the request if the record is accurate
and complete.
Question 7
The HIPAA Privacy Rule's TPO exception allows disclosures for:
A) Only treatment purposes
B) Treatment, Payment, and Healthcare Operations
C) Only payment purposes
D) Only healthcare operations
Rationale: TPO stands for Treatment, Payment, and Healthcare Operations.
This is a key exception to the authorization requirement, allowing covered entities
to use and disclose PHI for these purposes without patient authorization.
Question 8
A Notice of Privacy Practices (NPP) must be:
, A) Provided only upon patient request
B) Provided to patients at the first service encounter and made available upon
request
C) Posted only in the hospital lobby
D) Provided only to patients who ask for it
Rationale: Covered entities must provide the NPP to patients at the first service
encounter and make it available upon request. The NPP describes how PHI may
be used and disclosed, and informs patients of their privacy rights.
Question 9
A researcher requests PHI for a research study. Which of the following
is required for the disclosure?
A) No authorization is ever required for research
B) A valid authorization from the patient or a waiver of authorization from an
IRB/Privacy Board
C) Approval from the hospital CEO only
D) A Business Associate Agreement only
Rationale: Research disclosures generally require patient authorization unless
the IRB or Privacy Board grants a waiver of authorization. The research must
meet specific criteria for the waiver to be granted.
Question 10
Under the Minimum Necessary Standard, which of the following is exempt from
the requirement?
A) Disclosures to law enforcement
B) Disclosures for treatment purposes
C) Disclosures for payment purposes
D) Disclosures to business associates
Rationale: The Minimum Necessary Standard does not apply to disclosures for
treatment purposes. It also does not apply to disclosures made to the individual,
pursuant to an authorization, or as required by law.