(CHPS®) Exam | Complete Certified Questions and
Correct Verified Answers | 2025/2026 Edition
Comprehensive AHIMA CHPS® Exam Review | 2025/2026 Updated Edition | Includes the full set of
actual exam-style questions with correct, verified answers and detailed explanations | Covers all CHPS®
domains: Healthcare Privacy Program Management, Healthcare Privacy Program Compliance, Healthcare
Security Program Management, and Healthcare Security Program Compliance — fully aligned with
AHIMA’s CHPS® Exam Content Outline and current regulatory frameworks.
Introduction
This document contains the fully updated Certified in Healthcare Privacy and Security (CHPS®) exam
questions and answers for the 2025/2026 testing cycle. All answers are verified as correct and include
detailed rationales based on HIPAA, HITECH, NIST Cybersecurity Framework, healthcare security risk
management practices, and privacy program compliance requirements.
Answer Format
Each question is directly followed by the correct answer in bold green, accompanied by a clear
explanation and authoritative references. Explanations integrate legal requirements, industry best
practices, and AHIMA’s published guidance to ensure accuracy and exam readiness.
1. What is the primary purpose of a healthcare privacy program?
a) To manage patient care
b) To protect patient health information
c) To schedule patient procedures
d) To audit hospital finances
b) To protect patient health information
Rationale: A healthcare privacy program protects patient health information (PHI) to ensure compliance
with HIPAA Privacy Rule (45 CFR §164.502), per AHIMA’s CHPS® guidelines.
Domain: Healthcare Privacy Program Management
Example: Implementing policies to restrict PHI access to authorized personnel.
Test-Taking Tip: Privacy programs focus on PHI protection.
2. Under HIPAA, what is required when a data breach affects more than 500
individuals?
a) Notify affected individuals within 90 days
b) Notify HHS and the media within 60 days
c) Conduct a security audit
d) Delete the breached data
b) Notify HHS and the media within 60 days
Rationale: HIPAA Breach Notification Rule (45 CFR §164.408) requires notification to HHS and the
media within 60 days for breaches affecting over 500 individuals.
Domain: Healthcare Privacy Program Compliance
,Example: Reporting a breach of 600 patient records to HHS and local media.
Test-Taking Tip: Large breaches require HHS and media notification.
3. What is the purpose of a security risk assessment in a healthcare organization?
a) To schedule patient procedures
b) To identify and mitigate security vulnerabilities
c) To document clinical outcomes
d) To audit hospital finances
b) To identify and mitigate security vulnerabilities
Rationale: A security risk assessment identifies and mitigates vulnerabilities to protect PHI, per HIPAA
Security Rule (45 CFR §164.308) and NIST SP 800-30.
Domain: Healthcare Security Program Management
Example: Assessing EHR system vulnerabilities to prevent unauthorized access.
Test-Taking Tip: Risk assessments focus on security vulnerabilities.
4. A hospital employee accesses a patient’s PHI without authorization. What is the
best action?
a) Ignore the incident
b) Conduct an investigation and apply sanctions
c) Delete the accessed data
d) Notify the patient immediately
b) Conduct an investigation and apply sanctions
Rationale: Unauthorized access to PHI requires investigation and sanctions, per HIPAA Privacy Rule (45
CFR §164.530) and AHIMA’s CHPS® guidelines.
Domain: Healthcare Privacy Program Compliance
Example: Investigating an employee viewing a celebrity’s PHI without need.
Test-Taking Tip: Unauthorized access requires investigation.
5. What is the role of a business associate agreement (BAA)?
a) To schedule patient procedures
b) To define responsibilities for PHI handling
c) To document clinical outcomes
d) To audit hospital finances
b) To define responsibilities for PHI handling
Rationale: A BAA defines responsibilities for PHI handling between covered entities and business
associates, per HIPAA (45 CFR §164.504).
Domain: Healthcare Privacy Program Management
Example: Signing a BAA with a cloud storage provider for EHR data.
Test-Taking Tip: BAAs ensure compliance for business associates.
6. What is the purpose of encryption in a healthcare security program?
a) To improve data storage
b) To protect PHI from unauthorized access
c) To simplify data reporting
d) To schedule data collection
b) To protect PHI from unauthorized access
Rationale: Encryption protects PHI from unauthorized access, per HIPAA Security Rule (45 CFR
§164.312) and NIST SP 800-111.
Domain: Healthcare Security Program Management
, Example: Encrypting PHI during EHR data transmission.
Test-Taking Tip: Encryption is for data security.
7. Under HIPAA, when can PHI be disclosed without patient authorization?
a) For marketing purposes
b) For treatment, payment, or operations
c) For public advertising
d) For employee training
b) For treatment, payment, or operations
Rationale: HIPAA allows PHI disclosure without authorization for treatment, payment, or healthcare
operations, per 45 CFR §164.506.
Domain: Healthcare Privacy Program Compliance
Example: Sharing PHI with a billing department for claims processing.
Test-Taking Tip: TPO is a key exception for PHI disclosure.
8. What is the purpose of a data use agreement (DUA)?
a) To store clinical data
b) To define terms for limited data set sharing
c) To schedule patient procedures
d) To generate financial reports
b) To define terms for limited data set sharing
Rationale: A DUA defines terms for sharing limited data sets, per HIPAA (45 CFR §164.514).
Domain: Healthcare Privacy Program Management
Example: Establishing a DUA for sharing de-identified data with researchers.
Test-Taking Tip: DUAs are for limited data set sharing.
9. A healthcare organization experiences a ransomware attack. What is the first
step?
a) Pay the ransom
b) Contain the attack and assess the impact
c) Delete affected data
d) Notify patients immediately
b) Contain the attack and assess the impact
Rationale: Containing the attack and assessing the impact is the first step in incident response, per NIST
SP 800-61 and HIPAA Security Rule (45 CFR §164.308).
Domain: Healthcare Security Program Management
Example: Isolating affected systems to prevent further ransomware spread.
Test-Taking Tip: Containment is the first step in a security incident.
10. What is the purpose of a privacy impact assessment (PIA)?
a) To schedule patient procedures
b) To evaluate privacy risks in new systems
c) To document clinical outcomes
d) To audit hospital finances
b) To evaluate privacy risks in new systems
Rationale: A PIA evaluates privacy risks in new systems or processes, per HIPAA and AHIMA’s CHPS®
guidelines.
Domain: Healthcare Privacy Program Management
Example: Conducting a PIA for a new EHR system.
Test-Taking Tip: PIAs focus on privacy risks.