Certified in Healthcare Privacy and Security (CHPS) Exam
Prep 2026 Updated Practice Questions, Comprehensive
Healthcare Privacy Review, Detailed Explanations, Verified
Answers, Complete Success Workbook
DOMAIN I: MANAGEMENT AND ADMINISTRATION (20%)
1. Which of the following is the PRIMARY purpose of the HIPAA Privacy
Rule?
A) To establish standards for electronic healthcare transactions
B) To protect the privacy of individually identifiable health information
C) To require healthcare organizations to implement technical security measures
D) To establish penalties for healthcare fraud
Answer: B) To protect the privacy of individually identifiable health
information
Rationale: The HIPAA Privacy Rule establishes national standards to protect
individuals' medical records and other individually identifiable health information
(PHI). It applies to covered entities and their business associates and gives patients
rights over their health information. The Security Rule (C) addresses technical
safeguards for electronic PHI, and HIPAA also includes provisions for transactions
(A) and fraud enforcement (D).
2. Which of the following is considered Protected Health Information (PHI)
under HIPAA?
A) Information that does not identify an individual
B) Individually identifiable health information transmitted or maintained in
any form or medium
C) Only paper-based medical records
D) Only electronic health records
Answer: B) Individually identifiable health information transmitted or
maintained in any form or medium
,Rationale: PHI includes individually identifiable health information held or
transmitted by a covered entity or its business associate, in any form or medium—
whether electronic, paper, or oral. It is not limited to electronic records (D) or
paper records (C), and information that does not identify an individual (A) is not
PHI.
3. Under the HIPAA Privacy Rule, a "covered entity" includes:
A) Only hospitals
B) Health plans, healthcare clearinghouses, and healthcare providers who transmit
health information electronically
C) Only physicians
D) Any business that handles health information
Answer: B) Health plans, healthcare clearinghouses, and healthcare providers
who transmit health information electronically
Rationale: The HIPAA Privacy Rule applies to three types of covered entities:
health plans, healthcare clearinghouses, and healthcare providers who conduct
certain healthcare transactions electronically. Business associates (D) are not
covered entities but are contractually bound to comply with HIPAA.
4. The "minimum necessary" standard under the HIPAA Privacy Rule
requires that:
A) All patients receive the minimum amount of care possible
B) Covered entities make reasonable efforts to limit the use and disclosure of
PHI to the minimum necessary to accomplish the intended purpose
C) Healthcare providers disclose all PHI to any requesting party
D) Patients receive the minimum amount of information about their rights
Answer: B) Covered entities make reasonable efforts to limit the use and
disclosure of PHI to the minimum necessary to accomplish the intended
purpose
Rationale: The minimum necessary standard is a key privacy protection requiring
covered entities to limit uses and disclosures of PHI to the minimum necessary to
achieve the intended purpose. This does not apply to disclosures made to
healthcare providers for treatment purposes.
,5. A "business associate" is defined as:
A) Any person who works for a covered entity
B) A person or entity that performs certain functions or activities on behalf of
a covered entity that involve the use or disclosure of PHI
C) Any patient of a covered entity
D) Any government agency that regulates healthcare
Answer: B) A person or entity that performs certain functions or activities on
behalf of a covered entity that involve the use or disclosure of PHI
Rationale: Under HIPAA, a business associate is a person or entity that performs
functions or activities on behalf of a covered entity that involve the use or
disclosure of PHI, such as claims processing, data analysis, or legal services.
Covered entities must have written Business Associate Agreements (BAAs) with
their business associates.
6. Which of the following disclosures of PHI does NOT require patient
authorization under the HIPAA Privacy Rule?
A) Disclosure to a life insurance company for underwriting purposes
B) Disclosure to a public health authority for disease reporting
C) Disclosure to an employer for employment decisions
D) Disclosure to a marketing company
Answer: B) Disclosure to a public health authority for disease reporting
Rationale: HIPAA permits disclosure of PHI without patient authorization for
certain public interest and benefit activities, including public health activities such
as disease reporting to public health authorities. Disclosures for life insurance
underwriting (A), employment decisions (C), and marketing (D) generally require
patient authorization.
7. A Notice of Privacy Practices (NPP) must be provided to patients:
A) Only upon written request
B) At the first point of service delivery and upon request
C) Only after treatment is completed
D) Only if the patient asks for it
, Answer: B) At the first point of service delivery and upon request
Rationale: Covered entities must provide patients with a Notice of Privacy
Practices that describes how their PHI may be used and disclosed, and their rights
regarding their information. The notice must be provided at the first point of
service delivery and made available upon request.
8. The HIPAA Privacy Rule gives patients the right to:
A) Access their PHI in the format they prefer, if readily producible
B) Request amendments to their PHI
C) Request restrictions on certain uses and disclosures of their PHI
D) All of the above
Answer: D) All of the above
Rationale: Under the HIPAA Privacy Rule, patients have the right to access their
PHI, request amendments, and request restrictions on certain uses and disclosures.
These rights are fundamental to patient control over their health information.
9. The "accounting of disclosures" requirement under HIPAA requires
covered entities to:
A) Disclose all PHI to the government
B) Provide patients with a list of certain disclosures of their PHI made by the
covered entity
C) Account for all financial transactions involving PHI
D) Disclose all PHI to business associates
Answer: B) Provide patients with a list of certain disclosures of their PHI
made by the covered entity
Rationale: Patients have the right to receive an accounting of certain disclosures of
their PHI made by the covered entity. This does not include disclosures for
treatment, payment, healthcare operations, or disclosures made with patient
authorization.
10. Which of the following is NOT a valid reason for disclosing PHI without
patient authorization?
Prep 2026 Updated Practice Questions, Comprehensive
Healthcare Privacy Review, Detailed Explanations, Verified
Answers, Complete Success Workbook
DOMAIN I: MANAGEMENT AND ADMINISTRATION (20%)
1. Which of the following is the PRIMARY purpose of the HIPAA Privacy
Rule?
A) To establish standards for electronic healthcare transactions
B) To protect the privacy of individually identifiable health information
C) To require healthcare organizations to implement technical security measures
D) To establish penalties for healthcare fraud
Answer: B) To protect the privacy of individually identifiable health
information
Rationale: The HIPAA Privacy Rule establishes national standards to protect
individuals' medical records and other individually identifiable health information
(PHI). It applies to covered entities and their business associates and gives patients
rights over their health information. The Security Rule (C) addresses technical
safeguards for electronic PHI, and HIPAA also includes provisions for transactions
(A) and fraud enforcement (D).
2. Which of the following is considered Protected Health Information (PHI)
under HIPAA?
A) Information that does not identify an individual
B) Individually identifiable health information transmitted or maintained in
any form or medium
C) Only paper-based medical records
D) Only electronic health records
Answer: B) Individually identifiable health information transmitted or
maintained in any form or medium
,Rationale: PHI includes individually identifiable health information held or
transmitted by a covered entity or its business associate, in any form or medium—
whether electronic, paper, or oral. It is not limited to electronic records (D) or
paper records (C), and information that does not identify an individual (A) is not
PHI.
3. Under the HIPAA Privacy Rule, a "covered entity" includes:
A) Only hospitals
B) Health plans, healthcare clearinghouses, and healthcare providers who transmit
health information electronically
C) Only physicians
D) Any business that handles health information
Answer: B) Health plans, healthcare clearinghouses, and healthcare providers
who transmit health information electronically
Rationale: The HIPAA Privacy Rule applies to three types of covered entities:
health plans, healthcare clearinghouses, and healthcare providers who conduct
certain healthcare transactions electronically. Business associates (D) are not
covered entities but are contractually bound to comply with HIPAA.
4. The "minimum necessary" standard under the HIPAA Privacy Rule
requires that:
A) All patients receive the minimum amount of care possible
B) Covered entities make reasonable efforts to limit the use and disclosure of
PHI to the minimum necessary to accomplish the intended purpose
C) Healthcare providers disclose all PHI to any requesting party
D) Patients receive the minimum amount of information about their rights
Answer: B) Covered entities make reasonable efforts to limit the use and
disclosure of PHI to the minimum necessary to accomplish the intended
purpose
Rationale: The minimum necessary standard is a key privacy protection requiring
covered entities to limit uses and disclosures of PHI to the minimum necessary to
achieve the intended purpose. This does not apply to disclosures made to
healthcare providers for treatment purposes.
,5. A "business associate" is defined as:
A) Any person who works for a covered entity
B) A person or entity that performs certain functions or activities on behalf of
a covered entity that involve the use or disclosure of PHI
C) Any patient of a covered entity
D) Any government agency that regulates healthcare
Answer: B) A person or entity that performs certain functions or activities on
behalf of a covered entity that involve the use or disclosure of PHI
Rationale: Under HIPAA, a business associate is a person or entity that performs
functions or activities on behalf of a covered entity that involve the use or
disclosure of PHI, such as claims processing, data analysis, or legal services.
Covered entities must have written Business Associate Agreements (BAAs) with
their business associates.
6. Which of the following disclosures of PHI does NOT require patient
authorization under the HIPAA Privacy Rule?
A) Disclosure to a life insurance company for underwriting purposes
B) Disclosure to a public health authority for disease reporting
C) Disclosure to an employer for employment decisions
D) Disclosure to a marketing company
Answer: B) Disclosure to a public health authority for disease reporting
Rationale: HIPAA permits disclosure of PHI without patient authorization for
certain public interest and benefit activities, including public health activities such
as disease reporting to public health authorities. Disclosures for life insurance
underwriting (A), employment decisions (C), and marketing (D) generally require
patient authorization.
7. A Notice of Privacy Practices (NPP) must be provided to patients:
A) Only upon written request
B) At the first point of service delivery and upon request
C) Only after treatment is completed
D) Only if the patient asks for it
, Answer: B) At the first point of service delivery and upon request
Rationale: Covered entities must provide patients with a Notice of Privacy
Practices that describes how their PHI may be used and disclosed, and their rights
regarding their information. The notice must be provided at the first point of
service delivery and made available upon request.
8. The HIPAA Privacy Rule gives patients the right to:
A) Access their PHI in the format they prefer, if readily producible
B) Request amendments to their PHI
C) Request restrictions on certain uses and disclosures of their PHI
D) All of the above
Answer: D) All of the above
Rationale: Under the HIPAA Privacy Rule, patients have the right to access their
PHI, request amendments, and request restrictions on certain uses and disclosures.
These rights are fundamental to patient control over their health information.
9. The "accounting of disclosures" requirement under HIPAA requires
covered entities to:
A) Disclose all PHI to the government
B) Provide patients with a list of certain disclosures of their PHI made by the
covered entity
C) Account for all financial transactions involving PHI
D) Disclose all PHI to business associates
Answer: B) Provide patients with a list of certain disclosures of their PHI
made by the covered entity
Rationale: Patients have the right to receive an accounting of certain disclosures of
their PHI made by the covered entity. This does not include disclosures for
treatment, payment, healthcare operations, or disclosures made with patient
authorization.
10. Which of the following is NOT a valid reason for disclosing PHI without
patient authorization?