Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 36 pages
Exam (elaborations)

CHPC Exam – Certified in Healthcare Privacy Compliance Comprehensive Practice 2026/2027 Edition

Document preview thumbnail
Preview 4 out of 36 pages

This document provides a comprehensive practice resource for the Certified in Healthcare Privacy Compliance (CHPC) Exam, designed to help candidates review healthcare privacy and compliance concepts and prepare for certification. It covers essential topics including healthcare privacy regulations, compliance programs, confidentiality, patient rights, data security, privacy risk management, incident response, and organizational responsibilities. The practice material is designed to reinforce healthcare privacy and compliance knowledge, support self-assessment, and improve overall certification exam readiness.

Content preview

H E A LT H C A R E P R I V A C Y C O M P L I A N C E C E R T I F I C A T I O N P R A C T I C E




CHPC EXAM
Certified in Healthcare Privacy Compliance – COMPREHENSIVE PRACTICE – 2026/2027
EDITION


120 Questions (Official Length) 7 Domains Answers & Rationales 5 Case Studies




I M P O RTA N T N O T I C E

This is an original practice examination aligned with the CHPC examination blueprint
and current healthcare privacy law (HIPAA Privacy, Security, and Breach Notification Rules;
HITECH; 42 CFR Part 2; state privacy laws such as CCPA/CPRA). It is not the actual CHPC
examination, is not affiliated with or endorsed by the Health Care Compliance Association
(HCCA) or the Compliance Certification Board (CCB), and contains no proprietary exam
items. It is intended for self-study and preparation only.

Exam facts reflected here per the published program: 120 multiple-choice items (100
scored + 20 pretest), 2-hour computer-based testing, and CHPC renewal every 2 years (40
CCB CEUs, including 20 live). Laws and enforcement positions change — verify against
current official sources (HHS/OCR guidance, CCB program materials) before relying on any
answer.




HOW TO USE THIS EXAM

Sit for all 120 questions in one timed 2-hour session to simulate test-day pacing (one
minute per item). Correct answers are marked [CORRECT] with a rationale addressing the
distractors — cover the marked line to self-test. Five integrated case studies (shaded
boxes) present multi-step compliance scenarios with linked items. Domain weights mirror
the blueprint; Domain 3 carries the regulation-heavy load (Privacy, Security, and Breach
Notification Rules).




CONTENTS

1. Domain 1 Privacy Compliance Program Infrastructure (15)
2. Domain 2 Privacy Policies, Procedures, and Workforce Training (15)
3. Domain 3 Privacy Standards, Regulations, and Requirements (35): Privacy Rule •
Security Rule • Breach Notification Rule
4. Domain 4 Privacy Program Oversight and Governance (15)
5. Domain 5 Vendor and Business Associate Screening (10)
6. Domain 6 Investigations, Incident Response, and Breach Management (15)




Page 1 of 36

, CHPC Exam —Comprehensive Practice (2026/2027 Edition)




7. Domain 7 Discipline, Enforcement, and Non-Retaliation (15)




Page 2 of 36

, CHPC Exam —Comprehensive Practice (2026/2027 Edition)




Domain 1: Privacy Compliance Program Infrastructure (15
questions)

Q1: A health system has just appointed its first Chief Privacy Officer. According to established
compliance program guidance, what should be the officer's FIRST step in building the privacy
compliance program?
A. Terminate all vendors immediately pending review
B. Conduct a baseline risk assessment to identify existing policies, gaps, and highest privacy risks
[CORRECT]
C. Revise employee job descriptions
D. Wait for the government to publish new rules before starting
Correct Answer: B
Rationale: Programs are built on a documented understanding of current-state gaps and risk priorities,
so a baseline risk assessment comes first; mass terminations and HR revisions act before information is
gathered, and waiting leaves the organization exposed.



Q2: To whom should the privacy officer report for maximum program independence and effectiveness?
A. The organization's outside billing vendor
B. Directly to senior leadership and the board or its designated compliance committee [CORRECT]
C. Only to the department director whose staff causes the most complaints
D. To the marketing department
Correct Answer: B
Rationale: Privacy officers need independence, authority, and direct access to governance; reporting to
an operating department the officer must police (or to an unrelated function) undermines independence
and objectivity.



Q3: Which HIPAA Privacy Rule provision makes designation of a privacy official mandatory?
A. 45 CFR 164.530(a) — privacy official and contact person designation [CORRECT]
B. 45 CFR 164.502(f)
C. 45 CFR 164.514(d)
D. 45 CFR 164.528
Correct Answer: A
Rationale: Section 164.530(a) requires every covered entity to designate a privacy official responsible
for developing and implementing policies and to designate a contact person for complaints; the other
sections address minimum necessary, de-identification, and accounting respectively.



Q4: What is the primary purpose of a written compliance committee charter?
A. To eliminate the need for policies
B. To define the committee's purpose, membership, authority, responsibilities, and meeting
structure so accountability is explicit [CORRECT]
C. To serve as the notice of privacy practices
D. To replace the code of conduct
Correct Answer: B
Rationale: A charter formally establishes scope, authority, and accountability for oversight; it does not
substitute for policies, the NPP, or the code of conduct.




Page 3 of 36

, CHPC Exam —Comprehensive Practice (2026/2027 Edition)




Q5: The board of a nonprofit hospital learns of a systemic privacy failure but defers action to avoid
upsetting the medical staff. Which governance concept has the board violated?
A. The duty of obedience — ensuring the organization complies with its legal obligations
[CORRECT]
B. The standard of feasibility
C. The minimum necessary standard
D. The common rule
Correct Answer: A
Rationale: Directors' duty of obedience requires ensuring legal compliance; ignoring known systemic
violations exposes the board personally and organizationally, and it is unrelated to research regulation or
HIPAA's minimum necessary rule.



Q6: Under HIPAA's documentation retention requirement, written privacy policies, procedures, and
required communications must be retained for how long?
A. 1 year
B. 3 years
C. 6 years from creation or last effective date, whichever is later [CORRECT]
D. Permanently for all documents
Correct Answer: C
Rationale: 45 CFR 164.530(j) requires 6-year retention of documentation (policies, authorizations, risk
assessments) from creation or last effective date; 1 and 3 years fall short, and permanent retention is not
required.



Q7: A solo-practice physician asks how extensive her privacy program must be. What is the best
guidance?
A. Programs must be identical across all covered entities regardless of size
B. HIPAA expects programs scaled to the entity's size, complexity, and resources, while still meeting
each requirement [CORRECT]
C. Small practices are fully exempt from the Privacy Rule
D. Only hospitals need privacy officials
Correct Answer: B
Rationale: HIPAA is scalable — the same obligations apply, but implementation effort matches
organizational size and complexity; there is no small-practice exemption and all covered entities need a
privacy official.



Q8: In a mid-size hospital, how should the privacy officer and security officer roles be structured?
A. They must never be held by the same person
B. They are distinct required roles; they may be held by one qualified individual if properly
documented, but responsibilities must remain separate and clear [CORRECT]
C. Both roles belong to the IT help desk supervisor
D. Only the security role is legally required
Correct Answer: B
Rationale: HIPAA requires a designated privacy official (Privacy Rule) and security official (Security Rule);
combining them is permissible with documented coverage, but the distinct responsibility sets remain —
and both designations are legally required.




Page 4 of 36

Document information

Uploaded on
August 27, 2026
Number of pages
36
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$14.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
winnieolisa
1.0
(1)
Sold
4
Followers
0
Items
252
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions