HCCA CHPC STUDY COMPREHENSIVE TEST
PAPER 2026 QUESTIONS WITH ANSWERS
GRADED A+
⩥ Paper medical records are destroyed by Answer: Burning, shredding,
pulverizing, and pulping
⩥ Permissions and Required under the HIPAA rule are NOT the same
thing. Explain Answer: "Permissions" can still be denied, and
"Required" is mandatory
⩥ PHI or protected health information that is collected by an individual
or received by a covered entity can be used or disclosed by these four
areas. Name them. Answer: 1- TPO (Tx, Pymt, Healthcare Operations)
2- public interest/public crisis or emergency
3-with an opportunity to object
4-authorization, permission granted
⩥ Privacy incident categories Answer: Unintentional or inadvertent
violation (accidental);
Failure to follow established policies and procedures;
Deliberate or purposeful violation without harmful intent;
Willful and malicious violation with harmful intent.
,⩥ The Social Security Act Section 1128C(a), as established by the ___
___ ___ and ___ Act, created the Health Care Fraud and Abuse Control
Program, a far reaching program to combat fraud and abuse in health
care, including both public and private health plans Answer: Health
Insurance Portability and Accountability (HIPAA)
⩥ The two instances PHI does not require authorization: Answer: 1 -
directly to patient
2 - to government or HHS for investigation of alleged privacy violation
⩥ True or False
A vendor that stores encrypted copies of files from a CE is not a
Business Associate of that CE because the ePHI is unreadable, unusable,
and indecipherable. Answer: FALSE - the vendor is a Business Associate
as it is maintaining (through its storage functions) the encrypted ePHI.
⩥ True or False
Covered Entities and their Business Associates must comply with all of
the Security and Privacy Rules Answer: FALSE - Business Associates
are not required to comply with all of the Privacy Rules.
⩥ True or False
Encryption is required under HIPAA Answer: FALSE - it is an
addressable implementation specification.
,⩥ True or False
The designated privacy official and the designated security official under
HIPAA must be different individuals Answer: FALSE - the same official
may be designated both roles.
⩥ True of False:
Certificates of Confidentiality (Certificate or CoC) protect the privacy of
research participants by prohibiting disclosure of identifiable, sensitive
research information to anyone not connected to the research except
when the participant consents or in a few other specific situations.
Answer: TRUE
https://grants.nih.gov/policy/humansubjects/coc/information-protected-
CoC.htm
⩥ True or False:
Protection of human subjects in research at 45CFR 46 Subpart A -
Common Rule, list the protections for all research involving human
subjects Answer: TRUE
https://www.hhs.gov/ohrp/regulations-and-policy/regulations/45-cfr-
46/index.html
⩥ Re: Privacy and Reproductive Health Care
, An individual goes to a hospital emergency department while
experiencing complications related to a miscarriage during the tenth
week of pregnancy. A hospital workforce member suspects the
individual of having taken medication to end their pregnancy. State or
other law prohibits abortion after six weeks of pregnancy.
Is the hospital required to report individuals to law enforcement?
a. yes, hospital is required to do so IF state law expressly requires such
reporting
b. no, this would be impermissible and constitute a breach regardless of
state law requirements Answer: a. yes, hospital is required to do so IF
state law expressly requires such reporting.
For instance Louisiana is one of 28 states that require the reporting of
abortion complications, even if the procedure was done legally for
medical reasons.
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/phi-
reproductive-health/index.html#footnote10_jc1ucm2
⩥ Re: Privacy and Reproductive Health Care
A law enforcement official goes to a reproductive health care clinic and
requests records of abortions performed at the clinic.
Would the clinic be required to fulfill the request?
PAPER 2026 QUESTIONS WITH ANSWERS
GRADED A+
⩥ Paper medical records are destroyed by Answer: Burning, shredding,
pulverizing, and pulping
⩥ Permissions and Required under the HIPAA rule are NOT the same
thing. Explain Answer: "Permissions" can still be denied, and
"Required" is mandatory
⩥ PHI or protected health information that is collected by an individual
or received by a covered entity can be used or disclosed by these four
areas. Name them. Answer: 1- TPO (Tx, Pymt, Healthcare Operations)
2- public interest/public crisis or emergency
3-with an opportunity to object
4-authorization, permission granted
⩥ Privacy incident categories Answer: Unintentional or inadvertent
violation (accidental);
Failure to follow established policies and procedures;
Deliberate or purposeful violation without harmful intent;
Willful and malicious violation with harmful intent.
,⩥ The Social Security Act Section 1128C(a), as established by the ___
___ ___ and ___ Act, created the Health Care Fraud and Abuse Control
Program, a far reaching program to combat fraud and abuse in health
care, including both public and private health plans Answer: Health
Insurance Portability and Accountability (HIPAA)
⩥ The two instances PHI does not require authorization: Answer: 1 -
directly to patient
2 - to government or HHS for investigation of alleged privacy violation
⩥ True or False
A vendor that stores encrypted copies of files from a CE is not a
Business Associate of that CE because the ePHI is unreadable, unusable,
and indecipherable. Answer: FALSE - the vendor is a Business Associate
as it is maintaining (through its storage functions) the encrypted ePHI.
⩥ True or False
Covered Entities and their Business Associates must comply with all of
the Security and Privacy Rules Answer: FALSE - Business Associates
are not required to comply with all of the Privacy Rules.
⩥ True or False
Encryption is required under HIPAA Answer: FALSE - it is an
addressable implementation specification.
,⩥ True or False
The designated privacy official and the designated security official under
HIPAA must be different individuals Answer: FALSE - the same official
may be designated both roles.
⩥ True of False:
Certificates of Confidentiality (Certificate or CoC) protect the privacy of
research participants by prohibiting disclosure of identifiable, sensitive
research information to anyone not connected to the research except
when the participant consents or in a few other specific situations.
Answer: TRUE
https://grants.nih.gov/policy/humansubjects/coc/information-protected-
CoC.htm
⩥ True or False:
Protection of human subjects in research at 45CFR 46 Subpart A -
Common Rule, list the protections for all research involving human
subjects Answer: TRUE
https://www.hhs.gov/ohrp/regulations-and-policy/regulations/45-cfr-
46/index.html
⩥ Re: Privacy and Reproductive Health Care
, An individual goes to a hospital emergency department while
experiencing complications related to a miscarriage during the tenth
week of pregnancy. A hospital workforce member suspects the
individual of having taken medication to end their pregnancy. State or
other law prohibits abortion after six weeks of pregnancy.
Is the hospital required to report individuals to law enforcement?
a. yes, hospital is required to do so IF state law expressly requires such
reporting
b. no, this would be impermissible and constitute a breach regardless of
state law requirements Answer: a. yes, hospital is required to do so IF
state law expressly requires such reporting.
For instance Louisiana is one of 28 states that require the reporting of
abortion complications, even if the procedure was done legally for
medical reasons.
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/phi-
reproductive-health/index.html#footnote10_jc1ucm2
⩥ Re: Privacy and Reproductive Health Care
A law enforcement official goes to a reproductive health care clinic and
requests records of abortions performed at the clinic.
Would the clinic be required to fulfill the request?