Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 26 pages
Exam (elaborations)

Certified in Healthcare Privacy and Security (CHPS®) Exam 2025/2026 – Certified Questions, Verified Correct Answers & Detailed Explanations | Privacy & Security Program Management, Compliance & Regulatory Frameworks

Document preview thumbnail
Preview 3 out of 26 pages

This Comprehensive AHIMA Certified in Healthcare Privacy and Security (CHPS®) Exam Review for the 2025/2026 edition includes the complete set of actual exam-style questions with correct, verified answers and detailed explanations. Covering all CHPS® exam domains, it provides in-depth preparation in healthcare privacy program management, healthcare privacy program compliance, healthcare security program management, and healthcare security program compliance. Fully aligned with AHIMA’s CHPS® Exam Content Outline and the latest regulatory frameworks, this resource is ideal for professionals managing or auditing privacy and security programs in healthcare settings, ensuring readiness for certification and mastery of privacy and security best practices.

Content preview

Certified in Healthcare Privacy and Security
(CHPS®) Exam | Complete Certified Questions and
Correct Verified Answers | 2025/2026 Edition​
Comprehensive AHIMA CHPS® Exam Review | 2025/2026 Updated Edition | Includes the full set of
actual exam-style questions with correct, verified answers and detailed explanations | Covers all CHPS®
domains: Healthcare Privacy Program Management, Healthcare Privacy Program Compliance, Healthcare
Security Program Management, and Healthcare Security Program Compliance — fully aligned with
AHIMA’s CHPS® Exam Content Outline and current regulatory frameworks.




Introduction​
This document contains the fully updated Certified in Healthcare Privacy and Security (CHPS®) exam
questions and answers for the 2025/2026 testing cycle. All answers are verified as correct and include
detailed rationales based on HIPAA, HITECH, NIST Cybersecurity Framework, healthcare security risk
management practices, and privacy program compliance requirements.

Answer Format​
Each question is directly followed by the correct answer in bold green, accompanied by a clear
explanation and authoritative references. Explanations integrate legal requirements, industry best
practices, and AHIMA’s published guidance to ensure accuracy and exam readiness.



1. What is the primary purpose of a healthcare privacy program?​
a) To manage patient care​
b) To protect patient health information​
c) To schedule patient procedures​
d) To audit hospital finances​
b) To protect patient health information​
Rationale: A healthcare privacy program protects patient health information (PHI) to ensure compliance
with HIPAA Privacy Rule (45 CFR §164.502), per AHIMA’s CHPS® guidelines.​
Domain: Healthcare Privacy Program Management​
Example: Implementing policies to restrict PHI access to authorized personnel.​
Test-Taking Tip: Privacy programs focus on PHI protection.

2. Under HIPAA, what is required when a data breach affects more than 500
individuals?​
a) Notify affected individuals within 90 days​
b) Notify HHS and the media within 60 days​
c) Conduct a security audit​
d) Delete the breached data​
b) Notify HHS and the media within 60 days​
Rationale: HIPAA Breach Notification Rule (45 CFR §164.408) requires notification to HHS and the
media within 60 days for breaches affecting over 500 individuals.​
Domain: Healthcare Privacy Program Compliance​

,Example: Reporting a breach of 600 patient records to HHS and local media.​
Test-Taking Tip: Large breaches require HHS and media notification.

3. What is the purpose of a security risk assessment in a healthcare organization?​
a) To schedule patient procedures​
b) To identify and mitigate security vulnerabilities​
c) To document clinical outcomes​
d) To audit hospital finances​
b) To identify and mitigate security vulnerabilities​
Rationale: A security risk assessment identifies and mitigates vulnerabilities to protect PHI, per HIPAA
Security Rule (45 CFR §164.308) and NIST SP 800-30.​
Domain: Healthcare Security Program Management​
Example: Assessing EHR system vulnerabilities to prevent unauthorized access.​
Test-Taking Tip: Risk assessments focus on security vulnerabilities.

4. A hospital employee accesses a patient’s PHI without authorization. What is the
best action?​
a) Ignore the incident​
b) Conduct an investigation and apply sanctions​
c) Delete the accessed data​
d) Notify the patient immediately​
b) Conduct an investigation and apply sanctions​
Rationale: Unauthorized access to PHI requires investigation and sanctions, per HIPAA Privacy Rule (45
CFR §164.530) and AHIMA’s CHPS® guidelines.​
Domain: Healthcare Privacy Program Compliance​
Example: Investigating an employee viewing a celebrity’s PHI without need.​
Test-Taking Tip: Unauthorized access requires investigation.

5. What is the role of a business associate agreement (BAA)?​
a) To schedule patient procedures​
b) To define responsibilities for PHI handling​
c) To document clinical outcomes​
d) To audit hospital finances​
b) To define responsibilities for PHI handling​
Rationale: A BAA defines responsibilities for PHI handling between covered entities and business
associates, per HIPAA (45 CFR §164.504).​
Domain: Healthcare Privacy Program Management​
Example: Signing a BAA with a cloud storage provider for EHR data.​
Test-Taking Tip: BAAs ensure compliance for business associates.

6. What is the purpose of encryption in a healthcare security program?​
a) To improve data storage​
b) To protect PHI from unauthorized access​
c) To simplify data reporting​
d) To schedule data collection​
b) To protect PHI from unauthorized access​
Rationale: Encryption protects PHI from unauthorized access, per HIPAA Security Rule (45 CFR
§164.312) and NIST SP 800-111.​
Domain: Healthcare Security Program Management​

, Example: Encrypting PHI during EHR data transmission.​
Test-Taking Tip: Encryption is for data security.

7. Under HIPAA, when can PHI be disclosed without patient authorization?​
a) For marketing purposes​
b) For treatment, payment, or operations​
c) For public advertising​
d) For employee training​
b) For treatment, payment, or operations​
Rationale: HIPAA allows PHI disclosure without authorization for treatment, payment, or healthcare
operations, per 45 CFR §164.506.​
Domain: Healthcare Privacy Program Compliance​
Example: Sharing PHI with a billing department for claims processing.​
Test-Taking Tip: TPO is a key exception for PHI disclosure.

8. What is the purpose of a data use agreement (DUA)?​
a) To store clinical data​
b) To define terms for limited data set sharing​
c) To schedule patient procedures​
d) To generate financial reports​
b) To define terms for limited data set sharing​
Rationale: A DUA defines terms for sharing limited data sets, per HIPAA (45 CFR §164.514).​
Domain: Healthcare Privacy Program Management​
Example: Establishing a DUA for sharing de-identified data with researchers.​
Test-Taking Tip: DUAs are for limited data set sharing.

9. A healthcare organization experiences a ransomware attack. What is the first
step?​
a) Pay the ransom​
b) Contain the attack and assess the impact​
c) Delete affected data​
d) Notify patients immediately​
b) Contain the attack and assess the impact​
Rationale: Containing the attack and assessing the impact is the first step in incident response, per NIST
SP 800-61 and HIPAA Security Rule (45 CFR §164.308).​
Domain: Healthcare Security Program Management​
Example: Isolating affected systems to prevent further ransomware spread.​
Test-Taking Tip: Containment is the first step in a security incident.

10. What is the purpose of a privacy impact assessment (PIA)?​
a) To schedule patient procedures​
b) To evaluate privacy risks in new systems​
c) To document clinical outcomes​
d) To audit hospital finances​
b) To evaluate privacy risks in new systems​
Rationale: A PIA evaluates privacy risks in new systems or processes, per HIPAA and AHIMA’s CHPS®
guidelines.​
Domain: Healthcare Privacy Program Management​
Example: Conducting a PIA for a new EHR system.​
Test-Taking Tip: PIAs focus on privacy risks.

Document information

Uploaded on
August 16, 2025
Number of pages
26
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
£19.64

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BestSellerStuvia
3.6
(676)
Sold
4801
Followers
2080
Items
6225
Last sold
14 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions