HCCA CHPC Study Questions 2026..
HCCA CHPC Study Questions 2026 | CHPC
Exam Prep & Practice Questions
1. What are the required core elements of a VALID Authorization. Ref. 45 CFR 164.508(b)
1. Description
2. Purpose use/disclosure
3. Recipient
4. Authorized person making the disclosure
5. Expiration date
6. Signature/dates
38 U.S.C. 7332 deals with confidentially of patient medical record information related to:
a. drug abuse, sexually transmitted diseases, and tuberculosis
b. HIV/AIDS status
c. drug abuse, alcoholism, infection with the HIV virus, and sickle cell anemia
d. mental illness, HIV status, drug and alcohol abuse
c. drug abuse, alcoholism, infection with the HIV virus, and sickle cell anemia
45 CFR 164 - Subpart C outlines the three safeguards to ensure the _____, ____, ____ of ePHI that both,
CE and BA must implement to ensure compliance and protect against anticipated threats, and/or
reasonably anticipated uses/disclosures (incidental/inadvertent/unintentional)
Confidentiality, integrity, availability
Note: Accidental - must be reported. An accidental HIPAA violation refers to the unauthorized disclosure
of PHI (protected health information) without intent. Despite having safeguards and protective
Page 1
,HCCA CHPC Study Questions 2026..
measures in place, there is still a possibility of breaching HIPAA regulations. These types of violations
could include an employee accidentally seeing a different patient's medical records, an email being sent
to the wrong person or the loss or theft of a personal device that contains PHI.
https://www.hipaajournal.com/accidental-hipaa-violation/
An agency investigating a complaint of a HIPAA privacy violation contacts the facility for patient
information. The facility's policy should be to disclose all information:
a. If a search warrant is presented
b. That is required by state law
c. If the patients have been informed
d. Requested except for PHI
b. That is required by state law
Also known as the "Stimulus Act" or the "Recovery Act", enacted in 2009; its main purpose was to create
jobs and stimulate economic growth; it also included provisions to promote health information
technology
American Recovery and Reinvestment Act (ARRA)
Are Nursing Records considered part of the Educational Records:
a. Yes, nurses don't diagnose or treat individuals, and by licensure, they can't practice medicine. For
instance records created/maintained by a public health or school nurse providing immunizations to
students
b. No, student health or nurse records are not part of the Educational Records, even if they receive
funding from the Department of Education
a. Yes, nurses don't diagnose or treat individuals, and by licensure, they can't practice medicine. For
instance records created/maintained by a public health or school nurse providing immunizations to
students.
School health records are considered part of the Educational Records.
Page 2
,HCCA CHPC Study Questions 2026..
For instance the American with Disabilities (ADA) require schools to create certain health records about
children with special health care needs.
https://www.hhs.gov/hipaa/for-professionals/faq/514/does-hipaa-apply-to-school-student-health-
records/index.html
Are there certain rules for PHI disclosure in cases of an emergency?
a. No, especially if the patient is not able to provide consent.
b. No, there is not a separation of emergency treatment.
c. Yes, PHI can be released for emergency treatment.
d. No, PHI cannot ever be disclosed without patient consent.
c. Yes, PHI can be released for emergency treatment.
Note: practice question from AAPC CPCO Ch5
ARRA Key Privacy Provisions to existing HIPAA regulations:
Including but not limited to:
• Breach Notification requirement to BAs
• Expanded security requirements to BAs
• Request restrictions on certain disclosures of health information (for instance, accounting for
disclosures of TPO from six to three years)
See table for full list:
https://library.ahima.org/doc?oid=98112#.YlNlqOjMI2w
ARRA passed in 2009, key items to know:
ARRA - also known as "Obama Stimulus" in response to the 2008 recession
ARRA mandated government spending, tax cuts, and loan guarantees for financial relief to families.
ARRA required hospitals to computerize medical records and modernize HIT systems (HITECH).
Page 3
, HCCA CHPC Study Questions 2026..
And breach notification provision implemented under HITECH
https://en.wikipedia.org/wiki/American_Recovery_and_Reinvestment_Act_of_2009
https://www.hhs.gov/hipaa/for-professionals/breach-notification/laws-regulations/final-rule-
update/hitech/index.html
Breach is assumed unless covered entity can demonstrate _____
LoProCo (Low Probability of data Compromised)
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Breach Notification Content:
1. Brief Description and Date of Event
2. Date of Discovery
3. Description of the types of unsecured PII and PHI
4. Steps the effected individual may take to protect themselves
5. Brief description of steps taken to investigate, mitigate and protect against any further Breaches
6. Contact procedures to ask questions, including a toll-free number, email address, website, and/or
postal address
7. May include discretionary content such as a description of Workforce Member sanctions.
Breach Notification under ARRA, what is this?
ARRA (Amer. Recovery Reinvestment Act). Breach notification was passed as part of ARRA of 2009,
requiring covered entities to promptly notified affected individuals of a breach (when and how you
notify a PHI breach has occurred)
Page 4
HCCA CHPC Study Questions 2026 | CHPC
Exam Prep & Practice Questions
1. What are the required core elements of a VALID Authorization. Ref. 45 CFR 164.508(b)
1. Description
2. Purpose use/disclosure
3. Recipient
4. Authorized person making the disclosure
5. Expiration date
6. Signature/dates
38 U.S.C. 7332 deals with confidentially of patient medical record information related to:
a. drug abuse, sexually transmitted diseases, and tuberculosis
b. HIV/AIDS status
c. drug abuse, alcoholism, infection with the HIV virus, and sickle cell anemia
d. mental illness, HIV status, drug and alcohol abuse
c. drug abuse, alcoholism, infection with the HIV virus, and sickle cell anemia
45 CFR 164 - Subpart C outlines the three safeguards to ensure the _____, ____, ____ of ePHI that both,
CE and BA must implement to ensure compliance and protect against anticipated threats, and/or
reasonably anticipated uses/disclosures (incidental/inadvertent/unintentional)
Confidentiality, integrity, availability
Note: Accidental - must be reported. An accidental HIPAA violation refers to the unauthorized disclosure
of PHI (protected health information) without intent. Despite having safeguards and protective
Page 1
,HCCA CHPC Study Questions 2026..
measures in place, there is still a possibility of breaching HIPAA regulations. These types of violations
could include an employee accidentally seeing a different patient's medical records, an email being sent
to the wrong person or the loss or theft of a personal device that contains PHI.
https://www.hipaajournal.com/accidental-hipaa-violation/
An agency investigating a complaint of a HIPAA privacy violation contacts the facility for patient
information. The facility's policy should be to disclose all information:
a. If a search warrant is presented
b. That is required by state law
c. If the patients have been informed
d. Requested except for PHI
b. That is required by state law
Also known as the "Stimulus Act" or the "Recovery Act", enacted in 2009; its main purpose was to create
jobs and stimulate economic growth; it also included provisions to promote health information
technology
American Recovery and Reinvestment Act (ARRA)
Are Nursing Records considered part of the Educational Records:
a. Yes, nurses don't diagnose or treat individuals, and by licensure, they can't practice medicine. For
instance records created/maintained by a public health or school nurse providing immunizations to
students
b. No, student health or nurse records are not part of the Educational Records, even if they receive
funding from the Department of Education
a. Yes, nurses don't diagnose or treat individuals, and by licensure, they can't practice medicine. For
instance records created/maintained by a public health or school nurse providing immunizations to
students.
School health records are considered part of the Educational Records.
Page 2
,HCCA CHPC Study Questions 2026..
For instance the American with Disabilities (ADA) require schools to create certain health records about
children with special health care needs.
https://www.hhs.gov/hipaa/for-professionals/faq/514/does-hipaa-apply-to-school-student-health-
records/index.html
Are there certain rules for PHI disclosure in cases of an emergency?
a. No, especially if the patient is not able to provide consent.
b. No, there is not a separation of emergency treatment.
c. Yes, PHI can be released for emergency treatment.
d. No, PHI cannot ever be disclosed without patient consent.
c. Yes, PHI can be released for emergency treatment.
Note: practice question from AAPC CPCO Ch5
ARRA Key Privacy Provisions to existing HIPAA regulations:
Including but not limited to:
• Breach Notification requirement to BAs
• Expanded security requirements to BAs
• Request restrictions on certain disclosures of health information (for instance, accounting for
disclosures of TPO from six to three years)
See table for full list:
https://library.ahima.org/doc?oid=98112#.YlNlqOjMI2w
ARRA passed in 2009, key items to know:
ARRA - also known as "Obama Stimulus" in response to the 2008 recession
ARRA mandated government spending, tax cuts, and loan guarantees for financial relief to families.
ARRA required hospitals to computerize medical records and modernize HIT systems (HITECH).
Page 3
, HCCA CHPC Study Questions 2026..
And breach notification provision implemented under HITECH
https://en.wikipedia.org/wiki/American_Recovery_and_Reinvestment_Act_of_2009
https://www.hhs.gov/hipaa/for-professionals/breach-notification/laws-regulations/final-rule-
update/hitech/index.html
Breach is assumed unless covered entity can demonstrate _____
LoProCo (Low Probability of data Compromised)
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Breach Notification Content:
1. Brief Description and Date of Event
2. Date of Discovery
3. Description of the types of unsecured PII and PHI
4. Steps the effected individual may take to protect themselves
5. Brief description of steps taken to investigate, mitigate and protect against any further Breaches
6. Contact procedures to ask questions, including a toll-free number, email address, website, and/or
postal address
7. May include discretionary content such as a description of Workforce Member sanctions.
Breach Notification under ARRA, what is this?
ARRA (Amer. Recovery Reinvestment Act). Breach notification was passed as part of ARRA of 2009,
requiring covered entities to promptly notified affected individuals of a breach (when and how you
notify a PHI breach has occurred)
Page 4