• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 50 pages
Exam (elaborations)

2026 CHPS Study Guide: Certified in Healthcare Privacy and Security —Questions with Answer Explanations HIPAA Privacy | Cybersecurity | Risk Management | Compliance Review

Document preview thumbnail
Preview 4 out of 50 pages

2026 CHPS Study Guide: Certified in Healthcare Privacy and Security —Questions with Answer Explanations HIPAA Privacy | Cybersecurity | Risk Management | Compliance Review

Content preview

2026 CHPS Study Guide: Certified in
Healthcare Privacy and Security —Questions
with Answer Explanations HIPAA Privacy |
Cybersecurity | Risk Management |
Compliance Review

SECTION 1: ETHICAL, LEGAL & REGULATORY ISSUES (Questions 1–
25)
Question 1. Which of the following is the primary federal law that established
national standards for the protection of personal health information?
A) The Medicare Modernization Act
B) The Affordable Care Act
C) The Health Insurance Portability and Accountability Act (HIPAA)
D) The 21st Century Cures Act
Rationale: HIPAA, enacted in 1996, included the "Administrative Simplification"
subtitle that required promulgation of privacy and security standards to protect
health data in recognition of the increased risk to health information posed by
electronic data use and exchange within the health care system.


Question 2. A covered entity must obtain a patient's written authorization for
which of the following uses or disclosures of PHI?
A) Treatment, payment, and health care operations
B) Disclosure of psychotherapy notes to a life insurance company
C) Disclosure to the patient's treating physician
D) Reporting a wound to law enforcement as required by law
Rationale: Psychotherapy notes receive special protection under the Privacy Rule
and generally require the patient's written authorization for disclosure, except for
limited purposes such as the originator's own treatment, training, or legal defense.
Treatment, payment, and health care operations do not require authorization.

,Question 3. Under the HIPAA Privacy Rule, which of the following is an
exception to the definition of a "breach" requiring notification?
A) A hacker accessed unencrypted ePHI on a server
B) The inadvertent disclosure of PHI by an authorized person to another
authorized person at the same covered entity, where the information cannot
be further used or disclosed impermissibly
C) A laptop containing unencrypted PHI was stolen
D) An employee emailed PHI to the wrong patient
Rationale: OCR outlines three exceptions to the definition of a breach: (1)
unintentional acquisition, access, or use by a workforce member acting in good
faith within the scope of authority; (2) inadvertent disclosure by an authorized
person to another authorized person at the same covered entity, where the
information cannot be further used or disclosed impermissibly; and (3) a good faith
belief that the unauthorized recipient would not have been able to retain the
information.


Question 4. What is the maximum civil monetary penalty per violation category
for willful neglect that was not corrected under HIPAA's four-tier penalty
structure?
A) $36,500
B) $146,000
C) $365,000
**D) More than $2.1 million**
Rationale: Tier 4, the most serious penalty category, covers willful neglect that
was not corrected within the required period. Per-violation penalties start at
$73,011, and the annual cap exceeds $2.1 million. Penalty amounts are adjusted
annually for inflation, and these figures reflect the rates in effect following the
January 2026 update.


Question 5. What is the primary purpose of the HIPAA Breach Notification Rule?

,A) To establish reimbursement rates for breach-related services
B) To require covered entities and business associates to notify affected
individuals, HHS, and possibly the media following a breach of unsecured
PHI
C) To certify privacy officers
D) To regulate the use of medical devices
Rationale: The HIPAA Breach Notification Rule requires covered entities and
business associates to notify affected individuals, the Department of Health and
Human Services (HHS), and possibly the media following a breach of unsecured
protected health information.


Question 6. Within how many days must a covered entity notify affected
individuals of a breach of unsecured PHI?
A) 30 days
B) 60 days
C) 90 days
D) 120 days
Rationale: Covered entities must notify affected individuals of a breach of
unsecured PHI without unreasonable delay and in no case later than 60 calendar
days after discovery of a breach. If applicable state law requires faster notice, the
state law time period would apply.


Question 7. Which of the following is a key difference between the HIPAA
Privacy Rule and the HIPAA Security Rule?
A) The Privacy Rule applies only to paper records; the Security Rule applies only
to electronic records
B) The Privacy Rule governs all forms of PHI; the Security Rule governs only
electronic PHI (ePHI)
C) The Privacy Rule applies only to hospitals; the Security Rule applies to all
providers
D) The Privacy Rule carries criminal penalties; the Security Rule carries only civil
penalties

, Rationale: The HIPAA Privacy Rule governs the use and disclosure of protected
health information in any form (paper, electronic, or oral), while the HIPAA
Security Rule establishes standards specifically for protecting electronic protected
health information (ePHI).


Question 8. What is the "minimum necessary" standard under the HIPAA Privacy
Rule?
A) Disclose the entire medical record for any request
B) Make reasonable efforts to limit the use, disclosure, and request of PHI to
the minimum amount needed to accomplish the intended purpose
C) Obtain patient authorization for every disclosure
D) Refuse all requests for PHI
Rationale: The minimum necessary standard requires covered entities and
business associates to make reasonable efforts to limit the disclosure and use of
protected health information to the minimum necessary to accomplish the purpose
of the proposed disclosure and use.


Question 9. A patient requests an amendment to their medical record because they
believe it contains an error. What is the covered entity's obligation under HIPAA?
A) Immediately amend the record as requested
B) Act on the request within 60 days, with a possible 30-day extension, and
either make the amendment or provide a written denial with the patient's
right to submit a statement of disagreement
C) Ignore the request
D) Require the patient to obtain a court order
Rationale: Under the HIPAA Privacy Rule, individuals have the right to request
amendments to their PHI. The covered entity must act on the request within 60
days (with a possible 30-day extension) and either make the amendment or provide
a written denial explaining the basis and the patient's right to submit a statement of
disagreement.

Document information

Uploaded on
September 18, 2026
Number of pages
50
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
26
Followers
0
Items
3462
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions