2026 CHPS Study Guide: Certified in
Healthcare Privacy and Security —Questions
with Answer Explanations HIPAA Privacy |
Cybersecurity | Risk Management |
Compliance Review
Section 1: HIPAA Privacy Rule (Questions 1–30)
1. The HIPAA Privacy Rule applies to which of the following?
• A. All employers
• B. Covered entities and their business associates
• C. Only hospitals
• D. Only insurance companies
Correct Answer: B
Rationale: The HIPAA Privacy Rule applies to covered entities (health plans,
healthcare clearinghouses, and healthcare providers who transmit health
information electronically) and their business associates.
2. What is the primary purpose of the HIPAA Privacy Rule?
• A. To reduce healthcare costs
• B. To protect the privacy of individually identifiable health information
• C. To standardize electronic transactions
• D. To regulate medical licensing
Correct Answer: B
Rationale: The Privacy Rule establishes national standards to protect
,individuals' medical records and other individually identifiable health information
(IIHI).
3. Which of the following is considered Protected Health Information (PHI)?
• A. A patient's name and diagnosis
• B. Aggregate data with no identifiers
• C. Public health statistics
• D. De-identified data
Correct Answer: A
Rationale: PHI includes any information that identifies an individual and
relates to their health condition, treatment, or payment for healthcare.
4. Under HIPAA, patients have the right to:
• A. Access their medical records
• B. Destroy their medical records
• C. Sell their medical records
• D. Alter physician notes without authorization
Correct Answer: A
Rationale: The Privacy Rule grants patients the right to access and obtain a
copy of their PHI, with limited exceptions.
5. What is the "minimum necessary" standard?
• A. Minimum staff required to run a hospital
• B. Using or disclosing only the least amount of PHI needed to accomplish
the purpose
, • C. Minimum insurance coverage required
• D. Minimum time to retain records
Correct Answer: B
Rationale: The minimum necessary standard requires covered entities to
make reasonable efforts to limit PHI use and disclosure to the minimum needed
for the intended purpose.
6. Which of the following is NOT a permitted disclosure without patient
authorization?
• A. Treatment purposes
• B. Payment purposes
• C. Healthcare operations
• D. Marketing a new product to the patient
Correct Answer: D
Rationale: Marketing generally requires patient authorization unless it falls
under a specific exception (e.g., face-to-face communication or a nominal-value
gift).
7. What is a "Notice of Privacy Practices"?
• A. A legal document for employees
• B. A document describing how a covered entity may use and disclose PHI
• C. A billing statement
• D. A malpractice waiver
, Correct Answer: B
Rationale: The NPP informs patients of their privacy rights and how their PHI
may be used and disclosed.
8. How long must a covered entity retain HIPAA compliance documentation?
• A. 1 year
• B. 3 years
• C. 6 years
• D. 10 years
Correct Answer: C
Rationale: HIPAA requires covered entities to retain compliance
documentation for six years from the date of creation or the date it was last in
effect.
9. What is the maximum civil penalty per violation for willful neglect (not
corrected) under HIPAA?
• A. $10,000
• B. $50,000
• C. $1,000,000
• D. $1,500,000
Correct Answer: D
Rationale: The maximum annual civil penalty for willful neglect (not
corrected) is $1.5 million per violation category per year, adjusted for inflation.
10. Which of the following is an example of a HIPAA privacy breach?
Healthcare Privacy and Security —Questions
with Answer Explanations HIPAA Privacy |
Cybersecurity | Risk Management |
Compliance Review
Section 1: HIPAA Privacy Rule (Questions 1–30)
1. The HIPAA Privacy Rule applies to which of the following?
• A. All employers
• B. Covered entities and their business associates
• C. Only hospitals
• D. Only insurance companies
Correct Answer: B
Rationale: The HIPAA Privacy Rule applies to covered entities (health plans,
healthcare clearinghouses, and healthcare providers who transmit health
information electronically) and their business associates.
2. What is the primary purpose of the HIPAA Privacy Rule?
• A. To reduce healthcare costs
• B. To protect the privacy of individually identifiable health information
• C. To standardize electronic transactions
• D. To regulate medical licensing
Correct Answer: B
Rationale: The Privacy Rule establishes national standards to protect
,individuals' medical records and other individually identifiable health information
(IIHI).
3. Which of the following is considered Protected Health Information (PHI)?
• A. A patient's name and diagnosis
• B. Aggregate data with no identifiers
• C. Public health statistics
• D. De-identified data
Correct Answer: A
Rationale: PHI includes any information that identifies an individual and
relates to their health condition, treatment, or payment for healthcare.
4. Under HIPAA, patients have the right to:
• A. Access their medical records
• B. Destroy their medical records
• C. Sell their medical records
• D. Alter physician notes without authorization
Correct Answer: A
Rationale: The Privacy Rule grants patients the right to access and obtain a
copy of their PHI, with limited exceptions.
5. What is the "minimum necessary" standard?
• A. Minimum staff required to run a hospital
• B. Using or disclosing only the least amount of PHI needed to accomplish
the purpose
, • C. Minimum insurance coverage required
• D. Minimum time to retain records
Correct Answer: B
Rationale: The minimum necessary standard requires covered entities to
make reasonable efforts to limit PHI use and disclosure to the minimum needed
for the intended purpose.
6. Which of the following is NOT a permitted disclosure without patient
authorization?
• A. Treatment purposes
• B. Payment purposes
• C. Healthcare operations
• D. Marketing a new product to the patient
Correct Answer: D
Rationale: Marketing generally requires patient authorization unless it falls
under a specific exception (e.g., face-to-face communication or a nominal-value
gift).
7. What is a "Notice of Privacy Practices"?
• A. A legal document for employees
• B. A document describing how a covered entity may use and disclose PHI
• C. A billing statement
• D. A malpractice waiver
, Correct Answer: B
Rationale: The NPP informs patients of their privacy rights and how their PHI
may be used and disclosed.
8. How long must a covered entity retain HIPAA compliance documentation?
• A. 1 year
• B. 3 years
• C. 6 years
• D. 10 years
Correct Answer: C
Rationale: HIPAA requires covered entities to retain compliance
documentation for six years from the date of creation or the date it was last in
effect.
9. What is the maximum civil penalty per violation for willful neglect (not
corrected) under HIPAA?
• A. $10,000
• B. $50,000
• C. $1,000,000
• D. $1,500,000
Correct Answer: D
Rationale: The maximum annual civil penalty for willful neglect (not
corrected) is $1.5 million per violation category per year, adjusted for inflation.
10. Which of the following is an example of a HIPAA privacy breach?