Certified HIPAA Professional (CHP) Exam — Questions and Answers
Question 1: Which of the following workforce actions would most likely result in criminal penalties under HIPAA as strengthened by HITECH?
- Failing to encrypt an internal email containing PHI
- Accidentally sending a patient appointment reminder to the wrong email address
- Intentionally accessing and selling patient records for personal financial gain (Correct answer)
- Sharing a login password with a trusted colleague temporarily
Correct answer: Intentionally accessing and selling patient records for personal financial gain
Knowingly and intentionally obtaining or disclosing PHI for personal gain, commercial advantage, or malicious harm can result in criminal penalties including fines and imprisonment.
Question 2: To what extent is a covered entity responsible for the HIPAA-related actions of its business associates?
- Not responsible at all — business associates bear sole liability
- Only if the covered entity had advance knowledge of the violation
- To the extent defined by the BAA terms and its own oversight obligations (Correct answer)
- Fully responsible for all violations, even those beyond its control
Correct answer: To the extent defined by the BAA terms and its own oversight obligations
Covered entities are responsible to the extent defined by BAA terms and must take corrective action when violations become known.
Question 3: What is the purpose of documenting a covered entity's contingency plan?
- To provide marketing material for clients
- To satisfy IRS tax documentation requirements
- To comply with state building codes
- To demonstrate preparedness for ePHI access during system emergencies and ensure continuity (Correct answer)
Correct answer: To demonstrate preparedness for ePHI access during system emergencies and ensure continuity
Documenting the contingency plan under the Security Rule ensures the organization has a tested, retrievable plan for maintaining access to ePHI during system failures, disasters, or emergencies.
Question 4: The Patient Self-Determination Act (PSDA) requires healthcare organizations receiving Medicare/Medicaid funds to:
- Provide advance directive forms to all inpatients upon admission (Correct answer)
- Mandate that patients complete a living will before treatment
- Report all advance directives to the state health department
- Require a physician to co-sign every advance directive
Correct answer: Provide advance directive forms to all inpatients upon admission
The PSDA requires organizations to inform patients of their right to create advance directives and provide relevant forms upon admission.
Question 5: A small rural clinic experiences a breach affecting 12 individuals. The clinic cannot afford to send individual letters. What is NOT an acceptable substitute notification method under HIPAA?
- Providing a toll-free phone number for at least 90 days
- Posting a notice on the clinic's website for 90 days
- Posting a notice in a major print or broadcast media in the service area
- Sending a mass text message to all clinic patients (Correct answer)
Correct answer: Sending a mass text message to all clinic patients
HIPAA's substitute notice options include website posting, major print/broadcast media, and a toll-free phone number — mass text messaging is not a recognized substitute method.
Question 6: A covered entity discovers that a business associate improperly disclosed PHI for 520 individuals. Who must notify the affected individuals?
- HHS on behalf of the covered entity
- The state attorney general
- The covered entity (Correct answer)
- The business associate directly
Correct answer: The covered entity
The covered entity retains responsibility for notifying affected individuals even when the breach is caused by a business associate.
Question 7: A hospital is considering a policy to share patient data with a commercial partner for marketing purposes. Ethical review should prioritize:
- Patient privacy, explicit consent, and whether the use aligns with patient expectations (Correct answer)
- Revenue generation potential for the institution
- Compliance with the hospital's accreditation standards only
- The commercial partner's data security certifications alone
Correct answer: Patient privacy, explicit consent, and whether the use aligns with patient expectations
Marketing use of PHI requires explicit patient authorization under HIPAA, and ethical review must center patient trust and privacy as primary values.
Question 8: Which OSHA standard works in conjunction with HIPAA to protect healthcare workers from bloodborne pathogen exposure risks?
- OSHA Respiratory Protection Standard (29 CFR 1910.134)
- OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030) (Correct answer)
- OSHA Personal Protective Equipment Standard (29 CFR 1910.132)
- OSHA Hazard Communication Standard (HazCom)
Correct answer: OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030)
OSHA's Bloodborne Pathogens Standard requires employers to protect workers from exposure to blood and other potentially infectious materials, complementing HIPAA's privacy protections for patient information related to these exposures.
Question 9: A physician discovers that a colleague is impaired while on duty. The physician's ethical obligation under most professional codes is to:
- Cover for the colleague until the shift ends
- Confront the colleague privately and monitor the situation
- Report the impairment to appropriate supervisory or licensing authorities (Correct answer)
- Ignore the situation to avoid workplace conflict
Correct answer: Report the impairment to appropriate supervisory or licensing authorities
Professional ethics require reporting an impaired colleague to protect patient safety, which takes precedence over collegial loyalty.
Question 10: When faced with a conflict of interest, what is the appropriate course of action?
- Ignore the conflict if it seems minor
- Proceed as normal if it benefits the client
- Discuss it only if someone complains
- Disclose the conflict and recuse yourself from the situation (Correct answer)
Correct answer: Disclose the conflict and recuse yourself from the situation
Disclosing conflicts of interest and recusing oneself ensures objective decision-making and maintains professional integrity.
Question 11: OCR may impose civil monetary penalties (CMPs) when which of the following conditions is met?
- An individual files a complaint even if no harm occurred
- A covered entity fails to comply with HIPAA and the violation is not timely corrected (Correct answer)
- A business associate reports the breach before the covered entity does
- A covered entity voluntarily self-reports a breach before any harm occurs
Correct answer: A covered entity fails to comply with HIPAA and the violation is not timely corrected
OCR may impose CMPs when a covered entity has violated HIPAA and, depending on the tier, has not timely corrected the violation after being given an opportunity to do so.
Question 12: The HITECH Act was enacted as part of which larger piece of legislation in 2009?
- Patient Protection and Affordable Care Act
- American Recovery and Reinvestment Act (Correct answer)
- Medicare Access and CHIP Reauthorization Act
- Health Insurance Portability and Accountability Act
Correct answer: American Recovery and Reinvestment Act
HITECH was enacted as part of the American Recovery and Reinvestment Act (ARRA) of 2009 to promote the adoption of electronic health records.
Question 13: Which HITECH provision most directly addressed the gap that previously exempted business associates from direct HIPAA liability?
- The Meaningful Use incentive provisions
- The tiered penalty structure for covered entity violations
- The direct applicability of Security Rule requirements to business associates (Correct answer)
- The EHR certification criteria established by ONC
Correct answer: The direct applicability of Security Rule requirements to business associates
HITECH directly applied HIPAA Security Rule requirements and certain Privacy Rule provisions to business associates, making them independently liable rather than relying solely on contractual obligations.
Question 14: A patient requests that their HIV-positive status not be documented in their electronic health record. The provider should:
- Honor the request completely and omit the diagnosis
- Explain that clinically significant information must be documented for safe care (Correct answer)
- File a complaint against the patient with hospital administration
- Transfer care to another provider who will comply
Correct answer: Explain that clinically significant information must be documented for safe care
Providers have an ethical and legal duty to maintain accurate records; withholding clinically significant information could compromise safe and coordinated care.
Question 15: How should a professional handle a situation where they lack competence?
- Accept the work to avoid losing the client
- Delegate to an unlicensed assistant
- Attempt the work and learn from mistakes
- Refer the client to a qualified professional or seek additional training (Correct answer)
Correct answer: Refer the client to a qualified professional or seek additional training
Referring to qualified professionals or obtaining additional training when facing competence limitations protects clients and upholds professional standards.
Question 16: What is the purpose of a treatment plan review?
- To justify billing codes
- To satisfy regulatory audit requirements only
- To evaluate progress and adjust interventions as needed (Correct answer)
- To reduce the number of sessions
Correct answer: To evaluate progress and adjust interventions as needed
Treatment plan reviews evaluate patient progress and allow practitioners to adjust interventions for optimal outcomes, ensuring care remains appropriate and effective.
Question 17: A breach affects 600 patients at a hospital. In addition to notifying individuals and HHS, what additional step is required?
- Provide notice to prominent media outlets in the affected area (Correct answer)
- Issue a press release on the hospital's social media
- Notify law enforcement within 24 hours
- Notify the state medical board
Correct answer: Provide notice to prominent media outlets in the affected area
Breaches affecting 500 or more individuals in a state or jurisdiction require notice to prominent media outlets serving that area.
Question 18: How does understanding tissue healing phases improve practice?
- It is relevant only in hospital settings
- It has no effect on treatment outcomes
- It guides appropriate treatment timing and technique selection (Correct answer)
- It only matters for surgical wounds
Correct answer: It guides appropriate treatment timing and technique selection
Understanding healing phases allows practitioners to select appropriate timing and techniques for each stage, optimizing recovery and preventing re-injury.
Question 19: Under HITECH, when must breaches affecting fewer than 500 individuals be reported to the Secretary of HHS?
- Within 60 days of discovering each individual breach
- Within 90 days of the end of the fiscal year
- Annually, within 60 days after the end of each calendar year (Correct answer)
- Only upon direct request from HHS investigators
Correct answer: Annually, within 60 days after the end of each calendar year
Small breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, submitting the log within 60 days after the close of each calendar year.
Question 20: What does 'Meaningful Use' refer to in the context of the HITECH Act?
- Meeting minimum system uptime requirements for EHR platforms
- Using only EHR vendors approved by the Centers for Medicare & Medicaid Services
- Documenting all patient encounters electronically within 24 hours
- Using certified EHR technology in ways that improve care quality, safety, efficiency, and patient engagement (Correct answer)
Correct answer: Using certified EHR technology in ways that improve care quality, safety, efficiency, and patient engagement
Meaningful Use refers to using certified EHR technology in a manner that improves quality, safety, and efficiency while engaging patients and reducing health disparities.
Question 21: A hospital's Privacy Officer discovers a workforce member improperly accessed 15 patient records out of curiosity with no malicious intent. What is the FIRST step the Privacy Officer should take?
- Document the breach and assess whether notification is required (Correct answer)
- Terminate the employee immediately
- Conduct a workforce sanction
- Notify the media
Correct answer: Document the breach and assess whether notification is required
The first step is to document the incident and perform a breach risk assessment to determine if notification obligations under the Breach Notification Rule are triggered.
Question 22: Which ethical framework evaluates the morality of an action based solely on its consequences and overall outcome?
- Utilitarianism (Correct answer)
- Virtue ethics
- Deontology
- Principlism
Correct answer: Utilitarianism
Utilitarianism judges actions by whether they maximize overall benefit and minimize harm across all affected parties.
Question 23: An OCR audit reveals a pattern of non-compliance at a covered entity. OCR issues a Resolution Agreement. What does this typically require?
- Criminal referral to the Department of Justice
- Immediate shutdown of all PHI systems until corrected
- Revocation of the entity's Medicare certification
- Payment of a settlement amount and implementation of a corrective action plan (Correct answer)
Correct answer: Payment of a settlement amount and implementation of a corrective action plan
Resolution Agreements resolve OCR investigations through a negotiated settlement payment and a corrective action plan to address systemic compliance deficiencies.
Question 24: Under the HITECH Act, which entities became directly liable for HIPAA compliance that were previously only bound through contractual agreements?
- Business associates (Correct answer)
- State government health agencies
- Health insurance brokers
- Pharmaceutical companies
Correct answer: Business associates
HITECH made business associates directly subject to HIPAA Security Rule requirements and certain Privacy Rule provisions, rather than being bound only through Business Associate Agreements.
Question 25: During a HIPAA compliance audit, what is the PRIMARY purpose of reviewing an organization's Notice of Privacy Practices (NPP)?
- To confirm employee background check procedures
- To evaluate the physical security of server rooms
- To verify patients receive required disclosures about PHI use (Correct answer)
- To assess the organization's revenue cycle management
Correct answer: To verify patients receive required disclosures about PHI use
The NPP must inform patients how their PHI may be used and disclosed, and auditors verify it meets all required content elements under the Privacy Rule.
Question 26: When a covered entity loans a laptop containing ePHI to a traveling clinician, which safeguard is MOST critical to implement?
- Color-coded asset tags
- Manual log-in/log-out tracking sheets
- A printed copy of the HIPAA Privacy Notice
- Full-disk encryption (Correct answer)
Correct answer: Full-disk encryption
Full-disk encryption ensures that if the device is lost or stolen, ePHI cannot be accessed without the decryption key, satisfying the Security Rule's encryption addressable specification.
Question 27: Which of the following PHI disclosure scenarios qualifies for the 'limited data set' exception and is NOT treated as a breach?
- Disclosing a full patient record to an insurer for claim processing
- Disclosing a limited data set under a data use agreement for research (Correct answer)
- Disclosing PHI with direct identifiers to a research institution without a DUA
- Disclosing PHI to a marketing firm without authorization
Correct answer: Disclosing a limited data set under a data use agreement for research
Disclosure of a limited data set (with direct identifiers removed) under a proper data use agreement (DUA) is a permitted HIPAA disclosure and does not constitute a breach.
Question 28: A covered entity discovers a breach on March 5th. What is the latest date by which affected individuals must be notified?
- April 19th (45 days later)
- June 3rd (90 days later)
- April 4th (30 days later)
- May 4th (60 days later) (Correct answer)
Correct answer: May 4th (60 days later)
Under HITECH, affected individuals must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered, making May 4th the deadline.
Question 29: What must a covered entity do if it cannot cure a material breach of a BAA by its business associate?
- Continue the relationship under a hastily revised contract
- Report the breach immediately to local law enforcement
- Obtain retroactive patient consent to continue using the business associate
- Terminate the BAA if feasible to do so (Correct answer)
Correct answer: Terminate the BAA if feasible to do so
If a material BAA breach cannot be cured, the covered entity must terminate the Business Associate Agreement if termination is feasible.
Question 30: A patient who was previously enrolled in a clinical trial withdraws consent. The research team must:
- Continue using already-collected data regardless of withdrawal
- Report the withdrawal to the FDA as an adverse event
- Charge the patient a withdrawal fee per the study contract
- Stop collecting new data and remove the participant from ongoing interventions (Correct answer)
Correct answer: Stop collecting new data and remove the participant from ongoing interventions
Upon withdrawal, researchers must stop further data collection and interventions; previously collected data use depends on the consent document terms.
Question 31: Which federal office is primarily responsible for setting certification standards for EHR technology under the HITECH Act?
- Office of the National Coordinator for Health IT (ONC) (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
- Agency for Healthcare Research and Quality (AHRQ)
- Office for Civil Rights (OCR)
Correct answer: Office of the National Coordinator for Health IT (ONC)
The Office of the National Coordinator for Health IT (ONC) is responsible for establishing standards, certification criteria, and implementation specifications for EHR technology under HITECH.
Question 32: What is required under the HIPAA Security Rule?
- Safeguards for electronic protected health information (ePHI) (Correct answer)
- Physical security of paper records only
- Encryption of all emails
- Unlimited access to data by employees
Correct answer: Safeguards for electronic protected health information (ePHI)
The HIPAA Security Rule specifically addresses the protection of electronic Protected Health Information (ePHI). It requires covered entities to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit. This rule is crucial for securing digital health records against breaches and unauthorized access.
Question 33: What is the purpose of Health Information Exchanges (HIEs) as promoted under the HITECH Act?
- To enable secure electronic sharing of patient health information across organizations to improve care coordination (Correct answer)
- To replace all paper-based records with digital equivalents by a federal deadline
- To serve as backup data storage for EHR systems during outages
- To process insurance claims and remittance advice electronically
Correct answer: To enable secure electronic sharing of patient health information across organizations to improve care coordination
HIEs facilitate the secure electronic movement of health information among organizations, improving care coordination, reducing duplicate testing, and enhancing patient safety.
Question 34: What is the 'minimum necessary' standard in HIPAA?
- Only minimal PHI relevant to the task should be shared (Correct answer)
- All available PHI should be disclosed.
- No PHI can be shared under any circumstances.
- All PHI must be encrypted before sharing.
Correct answer: Only minimal PHI relevant to the task should be shared
The 'minimum necessary' standard under HIPAA requires covered entities to make reasonable efforts to limit the use, disclosure, and requests of protected health information (PHI) to the minimum necessary amount to accomplish the intended purpose. This principle ensures that only the specific PHI relevant to a particular task or request is accessed or shared, thereby enhancing patient privacy.
Question 35: Why is continuing education important for maintaining ethical practice?
- It is only needed to maintain certification status
- It is optional for experienced practitioners
- It ensures practitioners stay current with evolving standards and best practices (Correct answer)
- It replaces the need for experience
Correct answer: It ensures practitioners stay current with evolving standards and best practices
Continuing education ensures practitioners stay current with evolving standards, new research, and best practices, directly supporting ethical and competent practice.
Question 36: A telehealth platform used on clinic-owned tablets sends video directly through a public internet connection without a BAA in place with the software vendor. This is:
- Acceptable under the HIPAA Safe Harbor provision for small practices
- A HIPAA violation because the vendor is a business associate without a BAA (Correct answer)
- Acceptable if the sessions are less than 15 minutes
- Compliant because video is not considered ePHI
Correct answer: A HIPAA violation because the vendor is a business associate without a BAA
A telehealth software vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate, and a BAA is required before use.
Question 37: What is the maximum civil monetary penalty per violation category under HITECH's highest penalty tier?
- $10,000 per violation with a $250,000 annual cap
- $100,000 per violation with a $2 million annual cap
- $50,000 per violation with a $1.5 million annual cap (Correct answer)
- $1 million per violation with a $5 million annual cap
Correct answer: $50,000 per violation with a $1.5 million annual cap
Under HITECH, willful neglect violations not corrected within 30 days carry a maximum penalty of $50,000 per violation and $1.5 million per calendar year for identical violations.
Question 38: Which of the following is an example of required Security Rule documentation?
- Marketing campaign records
- Patient financial billing records
- Facility access logs and audit trails for ePHI systems (Correct answer)
- Employee birthday lists
Correct answer: Facility access logs and audit trails for ePHI systems
The Security Rule requires documentation of audit logs, access controls, and other safeguards implemented to protect ePHI from unauthorized access.
Question 39: Which of the following is a hallmark of an effective HIPAA sanctions policy?
- Applied only to employees with direct patient contact
- Applied only to repeat offenders after a warning
- Scaled exclusively based on years of employment
- Applied uniformly regardless of employee role or tenure (Correct answer)
Correct answer: Applied uniformly regardless of employee role or tenure
An effective HIPAA sanctions policy must be applied consistently and uniformly to all workforce members to be defensible and credible.
Question 40: Under HIPAA's Privacy Rule, covered entities must train workforce members on privacy policies within what timeframe after hiring?
- 30 days
- A reasonable period of time after joining the workforce (Correct answer)
- 90 days
- 60 days
Correct answer: A reasonable period of time after joining the workforce
The HIPAA Privacy Rule requires training within a reasonable period of time after a person joins the workforce, with no specific day count mandated.
Question 41: What must follow a completed HIPAA risk analysis?
- Distribution of analysis results to all workforce members
- Implementation of a risk management plan addressing identified risks (Correct answer)
- Archiving the results without further required action
- Submission of the analysis results to HHS OCR
Correct answer: Implementation of a risk management plan addressing identified risks
A risk analysis must be followed by a risk management plan that prioritizes and addresses the identified risks to ePHI.
Question 42: A nurse accidentally emails PHI for 3 patients to the wrong physician. The information is returned unread and deleted. After a risk assessment, the entity documents a low probability of compromise. What should the covered entity do?
- Report to OCR but not the patients
- Notify all 3 patients and HHS immediately
- Suspend the nurse pending a full investigation
- Document the assessment findings and treat it as a non-breach (Correct answer)
Correct answer: Document the assessment findings and treat it as a non-breach
If all four risk assessment factors support a low probability of compromise, the entity may document its conclusion and forego notification.
Question 43: Why is knowledge of the circulatory system important for practitioners?
- It has no relevance to non-medical treatments
- It is only important for emergency situations
- It is only needed for phlebotomy
- It helps identify contraindications and understand treatment effects on blood flow (Correct answer)
Correct answer: It helps identify contraindications and understand treatment effects on blood flow
Understanding the circulatory system helps practitioners identify contraindications and predict how treatments will affect blood flow, tissue oxygenation, and healing.
Question 44: Which of the following is a 'required' implementation specification under the HIPAA Security Rule?
- Workforce security clearance program
- Encryption of ePHI at rest
- Risk analysis and risk management (Correct answer)
- Automatic logoff for workstations
Correct answer: Risk analysis and risk management
Risk analysis and risk management are 'required' implementation specifications — covered entities must perform them regardless of size or resources.
Question 45: A hospital ethics committee is most appropriately consulted when:
- A provider needs rapid authorization for a routine procedure
- Insurance coverage for a treatment is denied
- A patient's bill is disputed
- There is a conflict between patient wishes, family demands, and medical recommendations (Correct answer)
Correct answer: There is a conflict between patient wishes, family demands, and medical recommendations
Ethics committees provide guidance on complex value conflicts involving patient autonomy, family interests, and clinical judgment.
Question 46: Which of the following constitutes a 'breach' under the HIPAA Breach Notification Rule?
- Accessing aggregated statistical health data without a password
- Sharing of de-identified data without authorization
- Impermissible use or disclosure of PHI that compromises its security or privacy (Correct answer)
- Accidental access to PHI by an authorized employee who immediately reports it
Correct answer: Impermissible use or disclosure of PHI that compromises its security or privacy
A breach is defined as an impermissible use or disclosure of PHI that poses a significant risk of financial, reputational, or other harm to the individual.
Question 47: Which of the following BEST describes the ethical concept of 'fidelity' in healthcare?
- Acting in ways that maximize patient benefit
- Keeping promises and honoring commitments made to patients (Correct answer)
- Distributing healthcare resources fairly among all patients
- Avoiding actions that cause unnecessary harm
Correct answer: Keeping promises and honoring commitments made to patients
Fidelity requires healthcare providers to keep their promises and remain faithful to the commitments made to their patients.
Question 48: A covered entity sends breach notifications on day 58 after discovery. Are they compliant with HIPAA's Breach Notification Rule?
- Yes, because the 60-day deadline has not passed (Correct answer)
- No, because media notification was required first
- Yes, only if HHS was notified before the individuals
- No, notifications must be sent within 30 days
Correct answer: Yes, because the 60-day deadline has not passed
HIPAA requires breach notifications to be provided without unreasonable delay and no later than 60 calendar days after discovery, so day 58 is compliant.
Question 49: What is an example of a physical safeguard?
- Locked doors and secure areas (Correct answer)
- Password protection for files.
- Data encryption tools.
- Workstation use policies.
Correct answer: Locked doors and secure areas
Physical safeguards under HIPAA are measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion. Locked doors, secure server rooms, and restricted access areas are examples of physical safeguards that prevent unauthorized physical access to ePHI and the facilities where it is stored. These measures are crucial for securing the physical environment where sensitive data resides.
Question 50: Following HITECH, a business associate that knowingly violates HIPAA can be subject to:
- Criminal prosecution only, handled by the Department of Justice
- Civil monetary penalties only, with no criminal exposure
- No direct penalties — only the covered entity retains liability
- Both civil monetary penalties and criminal prosecution (Correct answer)
Correct answer: Both civil monetary penalties and criminal prosecution
Since the HITECH Act, business associates are directly subject to both HIPAA civil monetary penalties and criminal prosecution.
Certified HIPAA Professional (CHP) Exam
The Certified HIPAA Professional (CHP) certification validates an individual's knowledge of HIPAA regulations, including privacy, security, and breach notification rules.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds