HCCA - CHPC EXAM 2026 LATEST UPDATE
QUESTIONS AND CORRECT VERIFIED
ANSWERS ALREADY GRADED A+
Request to Amend - ANS-client has the right to request an amendment to their designated
record set if they determine it may be inaccurate
Does a provider have to amend the record if a patient asks? - ANS-it is only a request. If the
provider determines the record to be accurate, they can deny the request.
What can a patient do if the provider refuse to amend the record? - ANS-client has the right to
ask that their statement of inaccuracy be placed in the file
Right to an Accounting of Disclosures - ANS-Patients are entitled to know the identity of to
whom information is disclosed, and the purpose of the
disclosure
Notice of Privacy Practice - ANS-- CE must provide a Notice of Privacy Practice (NPP).
- This statement provides the rules of the road on how an entity will use and disclose
information.
- These are the policies and procedures (P&P) that support the privacy and security of the
information and the entity's commitment to the individual.
Violations where the offender didn't realize he or she violated the Act and would have handled
the matter differently if known - ANS--- $100 fine for each violation,
-- Total not to exceed $25,000 for the calendar year.
,Violations due to reasonable cause, but not "willful neglect": - ANS--- $1,000 fine for each
violation,
-- Total not to exceed $100,000 for the calendar year.
Violations due to willful neglect that the organization ultimately corrected - ANS--- $10,000 fine
for each violation,
-- Total not to exceed $250,000 for the calendar year.
Violations of willful neglect that the
organization did not correct - ANS--- $50,000 fine for each violation,
-- Not to exceed $1,500,000 for the calendar year.
Under HITECH what can state AGs do? - ANS-- levy fines
- seek attorney's fees from covered entities.
- state courts now have the ability to award costs
Mandated Reporting of Breaches and Individual Notification - ANS-- imposes an organizational
response
- imply a client right
Who must a CE notify in a Breach? - ANS-- individuals affected
- HHS Secretary
- media
What triggers a notification to the impacted individual, HHS Secretary and media? - ANS-Affects
more than 500 people
, If a breach occurs of less than 500 people who must be notified and when? - ANS-The HHS
Secretary at least annually
When does a CE not have to report? - ANS-considered a breach only if the use or disclosure
poses some harm to the individual
Who do BAs have to notify of a breach? - ANS-The CE
If information is encrypted is it considered a breach? - ANS-No
What in addition is required of a CE beyond Policy and Procedures? - ANS-Education of the
Workforce
What is the difference between security and privacy? - ANS-Security is how things are
protected, while privacy tells us what to protect.
Security Rule says an entity must: - ANS-• Ensure the confidentiality, integrity, and availability
(CIA) of all electronic protected health information (EPHI) the CE creates, receives, maintains, or
transmits
• Support CIA through Administrative, Technical and Physical safeguards
• Protect against any reasonably anticipated threats or hazards to the security or integrity of
such information
• Protect against any reasonably anticipated uses or disclosures of such information that are not
permitted or required
• Ensure compliance by the workforce.
QUESTIONS AND CORRECT VERIFIED
ANSWERS ALREADY GRADED A+
Request to Amend - ANS-client has the right to request an amendment to their designated
record set if they determine it may be inaccurate
Does a provider have to amend the record if a patient asks? - ANS-it is only a request. If the
provider determines the record to be accurate, they can deny the request.
What can a patient do if the provider refuse to amend the record? - ANS-client has the right to
ask that their statement of inaccuracy be placed in the file
Right to an Accounting of Disclosures - ANS-Patients are entitled to know the identity of to
whom information is disclosed, and the purpose of the
disclosure
Notice of Privacy Practice - ANS-- CE must provide a Notice of Privacy Practice (NPP).
- This statement provides the rules of the road on how an entity will use and disclose
information.
- These are the policies and procedures (P&P) that support the privacy and security of the
information and the entity's commitment to the individual.
Violations where the offender didn't realize he or she violated the Act and would have handled
the matter differently if known - ANS--- $100 fine for each violation,
-- Total not to exceed $25,000 for the calendar year.
,Violations due to reasonable cause, but not "willful neglect": - ANS--- $1,000 fine for each
violation,
-- Total not to exceed $100,000 for the calendar year.
Violations due to willful neglect that the organization ultimately corrected - ANS--- $10,000 fine
for each violation,
-- Total not to exceed $250,000 for the calendar year.
Violations of willful neglect that the
organization did not correct - ANS--- $50,000 fine for each violation,
-- Not to exceed $1,500,000 for the calendar year.
Under HITECH what can state AGs do? - ANS-- levy fines
- seek attorney's fees from covered entities.
- state courts now have the ability to award costs
Mandated Reporting of Breaches and Individual Notification - ANS-- imposes an organizational
response
- imply a client right
Who must a CE notify in a Breach? - ANS-- individuals affected
- HHS Secretary
- media
What triggers a notification to the impacted individual, HHS Secretary and media? - ANS-Affects
more than 500 people
, If a breach occurs of less than 500 people who must be notified and when? - ANS-The HHS
Secretary at least annually
When does a CE not have to report? - ANS-considered a breach only if the use or disclosure
poses some harm to the individual
Who do BAs have to notify of a breach? - ANS-The CE
If information is encrypted is it considered a breach? - ANS-No
What in addition is required of a CE beyond Policy and Procedures? - ANS-Education of the
Workforce
What is the difference between security and privacy? - ANS-Security is how things are
protected, while privacy tells us what to protect.
Security Rule says an entity must: - ANS-• Ensure the confidentiality, integrity, and availability
(CIA) of all electronic protected health information (EPHI) the CE creates, receives, maintains, or
transmits
• Support CIA through Administrative, Technical and Physical safeguards
• Protect against any reasonably anticipated threats or hazards to the security or integrity of
such information
• Protect against any reasonably anticipated uses or disclosures of such information that are not
permitted or required
• Ensure compliance by the workforce.