CHPC EXAM
Certified in Healthcare Privacy Compliance – COMPREHENSIVE PRACTICE – 2026/2027
EDITION
120 Questions (Official Length) 7 Domains Answers & Rationales 5 Case Studies
I M P O RTA N T N O T I C E
This is an original practice examination aligned with the CHPC examination blueprint
and current healthcare privacy law (HIPAA Privacy, Security, and Breach Notification Rules;
HITECH; 42 CFR Part 2; state privacy laws such as CCPA/CPRA). It is not the actual CHPC
examination, is not affiliated with or endorsed by the Health Care Compliance Association
(HCCA) or the Compliance Certification Board (CCB), and contains no proprietary exam
items. It is intended for self-study and preparation only.
Exam facts reflected here per the published program: 120 multiple-choice items (100
scored + 20 pretest), 2-hour computer-based testing, and CHPC renewal every 2 years (40
CCB CEUs, including 20 live). Laws and enforcement positions change — verify against
current official sources (HHS/OCR guidance, CCB program materials) before relying on any
answer.
HOW TO USE THIS EXAM
Sit for all 120 questions in one timed 2-hour session to simulate test-day pacing (one
minute per item). Correct answers are marked [CORRECT] with a rationale addressing the
distractors — cover the marked line to self-test. Five integrated case studies (shaded
boxes) present multi-step compliance scenarios with linked items. Domain weights mirror
the blueprint; Domain 3 carries the regulation-heavy load (Privacy, Security, and Breach
Notification Rules).
CONTENTS
1. Domain 1 Privacy Compliance Program Infrastructure (15)
2. Domain 2 Privacy Policies, Procedures, and Workforce Training (15)
3. Domain 3 Privacy Standards, Regulations, and Requirements (35): Privacy Rule •
Security Rule • Breach Notification Rule
4. Domain 4 Privacy Program Oversight and Governance (15)
5. Domain 5 Vendor and Business Associate Screening (10)
6. Domain 6 Investigations, Incident Response, and Breach Management (15)
Page 1 of 36
, CHPC Exam —Comprehensive Practice (2026/2027 Edition)
7. Domain 7 Discipline, Enforcement, and Non-Retaliation (15)
Page 2 of 36
, CHPC Exam —Comprehensive Practice (2026/2027 Edition)
Domain 1: Privacy Compliance Program Infrastructure (15
questions)
Q1: A health system has just appointed its first Chief Privacy Officer. According to established
compliance program guidance, what should be the officer's FIRST step in building the privacy
compliance program?
A. Terminate all vendors immediately pending review
B. Conduct a baseline risk assessment to identify existing policies, gaps, and highest privacy risks
[CORRECT]
C. Revise employee job descriptions
D. Wait for the government to publish new rules before starting
Correct Answer: B
Rationale: Programs are built on a documented understanding of current-state gaps and risk priorities,
so a baseline risk assessment comes first; mass terminations and HR revisions act before information is
gathered, and waiting leaves the organization exposed.
Q2: To whom should the privacy officer report for maximum program independence and effectiveness?
A. The organization's outside billing vendor
B. Directly to senior leadership and the board or its designated compliance committee [CORRECT]
C. Only to the department director whose staff causes the most complaints
D. To the marketing department
Correct Answer: B
Rationale: Privacy officers need independence, authority, and direct access to governance; reporting to
an operating department the officer must police (or to an unrelated function) undermines independence
and objectivity.
Q3: Which HIPAA Privacy Rule provision makes designation of a privacy official mandatory?
A. 45 CFR 164.530(a) — privacy official and contact person designation [CORRECT]
B. 45 CFR 164.502(f)
C. 45 CFR 164.514(d)
D. 45 CFR 164.528
Correct Answer: A
Rationale: Section 164.530(a) requires every covered entity to designate a privacy official responsible
for developing and implementing policies and to designate a contact person for complaints; the other
sections address minimum necessary, de-identification, and accounting respectively.
Q4: What is the primary purpose of a written compliance committee charter?
A. To eliminate the need for policies
B. To define the committee's purpose, membership, authority, responsibilities, and meeting
structure so accountability is explicit [CORRECT]
C. To serve as the notice of privacy practices
D. To replace the code of conduct
Correct Answer: B
Rationale: A charter formally establishes scope, authority, and accountability for oversight; it does not
substitute for policies, the NPP, or the code of conduct.
Page 3 of 36
, CHPC Exam —Comprehensive Practice (2026/2027 Edition)
Q5: The board of a nonprofit hospital learns of a systemic privacy failure but defers action to avoid
upsetting the medical staff. Which governance concept has the board violated?
A. The duty of obedience — ensuring the organization complies with its legal obligations
[CORRECT]
B. The standard of feasibility
C. The minimum necessary standard
D. The common rule
Correct Answer: A
Rationale: Directors' duty of obedience requires ensuring legal compliance; ignoring known systemic
violations exposes the board personally and organizationally, and it is unrelated to research regulation or
HIPAA's minimum necessary rule.
Q6: Under HIPAA's documentation retention requirement, written privacy policies, procedures, and
required communications must be retained for how long?
A. 1 year
B. 3 years
C. 6 years from creation or last effective date, whichever is later [CORRECT]
D. Permanently for all documents
Correct Answer: C
Rationale: 45 CFR 164.530(j) requires 6-year retention of documentation (policies, authorizations, risk
assessments) from creation or last effective date; 1 and 3 years fall short, and permanent retention is not
required.
Q7: A solo-practice physician asks how extensive her privacy program must be. What is the best
guidance?
A. Programs must be identical across all covered entities regardless of size
B. HIPAA expects programs scaled to the entity's size, complexity, and resources, while still meeting
each requirement [CORRECT]
C. Small practices are fully exempt from the Privacy Rule
D. Only hospitals need privacy officials
Correct Answer: B
Rationale: HIPAA is scalable — the same obligations apply, but implementation effort matches
organizational size and complexity; there is no small-practice exemption and all covered entities need a
privacy official.
Q8: In a mid-size hospital, how should the privacy officer and security officer roles be structured?
A. They must never be held by the same person
B. They are distinct required roles; they may be held by one qualified individual if properly
documented, but responsibilities must remain separate and clear [CORRECT]
C. Both roles belong to the IT help desk supervisor
D. Only the security role is legally required
Correct Answer: B
Rationale: HIPAA requires a designated privacy official (Privacy Rule) and security official (Security Rule);
combining them is permissible with documented coverage, but the distinct responsibility sets remain —
and both designations are legally required.
Page 4 of 36