CHP Cheat Sheet 2026
The 30 highest-yield CHP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
60 min time limit
70% to pass
- Under the HITECH Act, which entities became directly liable for HIPAA compliance that were previously only bound through contractual agreements? → Business associates
- A hospital is evaluating whether to de-identify clinical assessment data for research. Under the Expert Determination method, de-identification requires: → A qualified statistical expert certifying very small re-identification risk
- Which HIPAA Security Rule standard specifically requires covered entities to protect against unauthorized physical access to systems storing ePHI? → Physical Safeguards — Facility Access Controls
- Which element is NOT required to be included in a Business Associate Agreement under HIPAA? → The specific dollar amount of penalties if the business associate causes a breach
- A provider's treatment protocol inadvertently includes PHI of a patient who was not the intended recipient of a fax. Under HIPAA, this is considered: → An impermissible disclosure that may require breach analysis
- If a business associate agreement (BAA) is amended, what must the covered entity do with the original BAA? → Retain the original BAA for 6 years from when it was last in effect
- A hospital must provide an accounting of disclosures to a patient. What is the standard timeframe for fulfilling this request? → 30 days, with one 30-day extension if needed
- Which of the following best describes the 'conduit exception' under HIPAA? → Entities that only transmit PHI without routine access are not business associates
- Which patient right under the HIPAA Privacy Rule allows a patient to request restrictions on how their PHI is used or disclosed? → Right to request restriction
- A staff member posts a general comment about a 'difficult patient day' on social media without naming any patient. This action is BEST described as: → A potential HIPAA violation if the post could identify a patient in context
- Which audit control is specifically required by the HIPAA Security Rule to track activity in information systems containing ePHI? → Hardware, software, and procedural mechanisms that record and examine activity
- Which federal legislation made business associates directly subject to HIPAA compliance obligations? → The Health Information Technology for Economic and Clinical Health (HITECH) Act
- Which HITECH provision most directly addressed the gap that previously exempted business associates from direct HIPAA liability? → The direct applicability of Security Rule requirements to business associates
- A nurse overhears a colleague sharing identifiable patient information in a hospital elevator. The nurse's BEST course of action is to: → Remind the colleague that PHI conversations in public areas violate HIPAA
- Which of the following best describes a 'downstream' business associate under HIPAA? → A subcontractor of a business associate that also handles PHI
- A physical therapist uses a tablet at multiple patient locations throughout the day. Which HIPAA-compliant practice should govern use of this device? → A screen lock with a PIN or biometric should activate automatically after each session
- During a mock HIPAA audit, an assessor requests documentation of the organization's sanction policy. What does this policy MUST address? → Penalties for workforce members who violate privacy and security policies
- A patient asks a nurse not to tell their spouse about a terminal diagnosis. The nurse should: → Respect the patient's confidentiality and honor the request
- A patient who was previously enrolled in a clinical trial withdraws consent. The research team must: → Stop collecting new data and remove the participant from ongoing interventions
- Which body system is most relevant to understanding tissue response to treatment? → The musculoskeletal and integumentary systems
- How often should HIPAA risk assessments be conducted? → Annually or as needed
- Which HIPAA concept requires organizations to implement security measures that are reasonable and appropriate based on their size, complexity, and capabilities? → Flexibility and scalability standard
- A HIPAA audit reveals an organization has not updated its risk assessment in four years. Why is this problematic under the Security Rule? → Risk assessments must reflect current threats, vulnerabilities, and operational changes
- What is the primary purpose of administrative safeguards under HIPAA? → To manage workforce security and access control
- A covered entity discovers a breach on March 1. By what date must it notify the Secretary of HHS if fewer than 500 individuals were affected? → Within 60 days after the end of the calendar year in which the breach was discovered
- What is the primary purpose of the HIPAA Breach Notification Rule? → To notify individuals and authorities about data breaches
- Under HIPAA, subcontractors of business associates who handle PHI are treated as: → Business associates with direct HIPAA obligations
- What does PHI stand for in the context of HIPAA? → Protected Health Information
- What are the four tiers of civil monetary penalties established by HITECH, listed from least to most severe? → Did not know, reasonable cause, willful neglect corrected, willful neglect not corrected
- What is the primary obligation of a certified professional regarding patient/client confidentiality? → Protect all personal information and disclose only with proper authorization
Turn these facts into recall:
Was this helpful?