CHC LATEST 2026 EXAM QUESTIONS AND SOLUTIONS
RATED A+
✔✔Training Certification and Tracking (*) - ✔✔1. know who has been trained by topic
2. keep information accessible
3. attestation (attendance, received code of conduct, understanding, intend to comply)
✔✔Why Evaluate Training? - ✔✔1. identify areas of improvement
2. should training be repeated as is?
3. is training changing behavior?
✔✔Levels of Training Evaluation - ✔✔1. reaction
2. learning
3. behavior
4. results
✔✔Training Evaluation Methods - ✔✔1. pre and post testing
2. case study
3. evaluation forms
✔✔Training Evaluation - Pre and Post Testing - ✔✔ensure effectiveness by...
1. creating guiding objectives
2. developing a focused testing instrument
3. providing continuous follow-up based on the results of the test
✔✔Training Evaluation - Case Study - ✔✔1. presentation
2. interaction
3. discussion
4. effectiveness based on outcome
✔✔Training Evaluation Forms - ✔✔1. balance questions
2. easy yes/no and open-ended questions
3. value feedback
4. use to enhance programs and increase effectiveness
✔✔Follow-Up Training (*) - ✔✔1. one hour
2. new issues
3. changes in laws and regulations
4. overview of previous compliance issues
✔✔Training for New Hires (*) - ✔✔1. 30 min to 1 hour
2. orientation
3. direct delivery
3. immediately
,✔✔Compliance Training Requirements - ✔✔1. engaging
2. through provoking
3. positive call for action
✔✔Health Insurance Portability and Accountability Act (HIPAA) - ✔✔1. 1996
2. standardization - establishes a common "language" for transmission of electronic
claims, payment, and administrative information
3. attempts to improve security in the age of ever-changing electronic data interchange
4. uniformity of the law - minimum standard for privacy laws nationwide
✔✔HIPAA Enforcement - ✔✔1. Office of Civil Rights (OCR) - privacy and security civil
complaints
2. CMS - transactions and code sets
3. Department of Justice (DOJ) - privacy criminal complaints (*)
✔✔Federal HIPAA law overrides state law unless... - ✔✔...state law provides more
protection/access.
✔✔HIPAA General Rule (*) - ✔✔a covered entity may not use or disclose protected
health information, except as permitted or required
✔✔HIPAA Covered Entities (*) - ✔✔1. Health Plans
2. Providers
3. Clearinghouses
✔✔HIPAA Affiliated Covered Entity (ACE) - ✔✔HIPAA designation - legally separate
entities with the same owner(s)
✔✔HIPAA Hybrid Covered Entities - ✔✔HIPAA designation - only some components of
the business are a covered entity
✔✔An individual can request accounting of PHI disclosures, to include: - ✔✔1. date
disclosure was made
2. brief description of disclosure
3. purpose of disclosure
4. who received the information
✔✔An individual can request account of PHI disclosures up to a ____ period. - ✔✔6
year
✔✔Notice of _______ Practices is required to be provided to patients. - ✔✔Privacy
✔✔HIPAA - Definition of Use - ✔✔with respect to individually identifiable health
informant, the sharing, employment, application, utilization, examination, or analysis of
such information within an entity that maintains such information
, ✔✔HIPAA - Definition of Disclosure - ✔✔the release, transfer, provision of, access to, or
divulging in any other manner of information outside the entity holding the information
✔✔Protected Health Information (PHI) - ✔✔1. health information collected from an
individual, created or received by a covered entity
2. relates to the past, present, or future physical or mental health/condition/provision of
health care/payment for healthcare of an individual
3. identifies the individual (reasonably could be used to identify them)
4. maintained by electronic or any other form other than educational/employment
records
✔✔De-Identified Information (*) - ✔✔1. all identifiers listed in the regulations are
stripped out
2. not PHI
3. not protected under HIPAA
✔✔Limited Data Sets (*) - ✔✔1. contain some information and may be shared under a
Data Use Agreement
2. listed as what may not be included
✔✔HIPAA Exceptions (*) - ✔✔1. uses and disclosures for payment, treatment, and
health care operations
2. required disclosures
3. uses and disclosures with authorization (*)
4. uses and disclosures with an opportunity to object
5. uses and disclosures for which an authorization or an opportunity to object is not
required
✔✔HIPAA Exceptions - Payment, Treatment, and Healthcare Operations - ✔✔1. audits
2. peer reviews
3. quality improvement
4. physician consults
✔✔HIPAA Exceptions - Required Disclosures - ✔✔1. to the patient with some
exceptions
2. Office of Civil Rights requests
3. to DHH to investigate alleged privacy violation
✔✔HIPAA Exceptions - Authorizations - ✔✔1. authorization required if use/disclosure is
not explicitly required or allowed under regulation
2. ensure all requirements are satisfied (including state)
3. often trump card - use when possible
✔✔HIPAA Exceptions - Opportunity to Object (*) - ✔✔1. made for the hospital setting
RATED A+
✔✔Training Certification and Tracking (*) - ✔✔1. know who has been trained by topic
2. keep information accessible
3. attestation (attendance, received code of conduct, understanding, intend to comply)
✔✔Why Evaluate Training? - ✔✔1. identify areas of improvement
2. should training be repeated as is?
3. is training changing behavior?
✔✔Levels of Training Evaluation - ✔✔1. reaction
2. learning
3. behavior
4. results
✔✔Training Evaluation Methods - ✔✔1. pre and post testing
2. case study
3. evaluation forms
✔✔Training Evaluation - Pre and Post Testing - ✔✔ensure effectiveness by...
1. creating guiding objectives
2. developing a focused testing instrument
3. providing continuous follow-up based on the results of the test
✔✔Training Evaluation - Case Study - ✔✔1. presentation
2. interaction
3. discussion
4. effectiveness based on outcome
✔✔Training Evaluation Forms - ✔✔1. balance questions
2. easy yes/no and open-ended questions
3. value feedback
4. use to enhance programs and increase effectiveness
✔✔Follow-Up Training (*) - ✔✔1. one hour
2. new issues
3. changes in laws and regulations
4. overview of previous compliance issues
✔✔Training for New Hires (*) - ✔✔1. 30 min to 1 hour
2. orientation
3. direct delivery
3. immediately
,✔✔Compliance Training Requirements - ✔✔1. engaging
2. through provoking
3. positive call for action
✔✔Health Insurance Portability and Accountability Act (HIPAA) - ✔✔1. 1996
2. standardization - establishes a common "language" for transmission of electronic
claims, payment, and administrative information
3. attempts to improve security in the age of ever-changing electronic data interchange
4. uniformity of the law - minimum standard for privacy laws nationwide
✔✔HIPAA Enforcement - ✔✔1. Office of Civil Rights (OCR) - privacy and security civil
complaints
2. CMS - transactions and code sets
3. Department of Justice (DOJ) - privacy criminal complaints (*)
✔✔Federal HIPAA law overrides state law unless... - ✔✔...state law provides more
protection/access.
✔✔HIPAA General Rule (*) - ✔✔a covered entity may not use or disclose protected
health information, except as permitted or required
✔✔HIPAA Covered Entities (*) - ✔✔1. Health Plans
2. Providers
3. Clearinghouses
✔✔HIPAA Affiliated Covered Entity (ACE) - ✔✔HIPAA designation - legally separate
entities with the same owner(s)
✔✔HIPAA Hybrid Covered Entities - ✔✔HIPAA designation - only some components of
the business are a covered entity
✔✔An individual can request accounting of PHI disclosures, to include: - ✔✔1. date
disclosure was made
2. brief description of disclosure
3. purpose of disclosure
4. who received the information
✔✔An individual can request account of PHI disclosures up to a ____ period. - ✔✔6
year
✔✔Notice of _______ Practices is required to be provided to patients. - ✔✔Privacy
✔✔HIPAA - Definition of Use - ✔✔with respect to individually identifiable health
informant, the sharing, employment, application, utilization, examination, or analysis of
such information within an entity that maintains such information
, ✔✔HIPAA - Definition of Disclosure - ✔✔the release, transfer, provision of, access to, or
divulging in any other manner of information outside the entity holding the information
✔✔Protected Health Information (PHI) - ✔✔1. health information collected from an
individual, created or received by a covered entity
2. relates to the past, present, or future physical or mental health/condition/provision of
health care/payment for healthcare of an individual
3. identifies the individual (reasonably could be used to identify them)
4. maintained by electronic or any other form other than educational/employment
records
✔✔De-Identified Information (*) - ✔✔1. all identifiers listed in the regulations are
stripped out
2. not PHI
3. not protected under HIPAA
✔✔Limited Data Sets (*) - ✔✔1. contain some information and may be shared under a
Data Use Agreement
2. listed as what may not be included
✔✔HIPAA Exceptions (*) - ✔✔1. uses and disclosures for payment, treatment, and
health care operations
2. required disclosures
3. uses and disclosures with authorization (*)
4. uses and disclosures with an opportunity to object
5. uses and disclosures for which an authorization or an opportunity to object is not
required
✔✔HIPAA Exceptions - Payment, Treatment, and Healthcare Operations - ✔✔1. audits
2. peer reviews
3. quality improvement
4. physician consults
✔✔HIPAA Exceptions - Required Disclosures - ✔✔1. to the patient with some
exceptions
2. Office of Civil Rights requests
3. to DHH to investigate alleged privacy violation
✔✔HIPAA Exceptions - Authorizations - ✔✔1. authorization required if use/disclosure is
not explicitly required or allowed under regulation
2. ensure all requirements are satisfied (including state)
3. often trump card - use when possible
✔✔HIPAA Exceptions - Opportunity to Object (*) - ✔✔1. made for the hospital setting