Healthcare14 min read

CHPC Exam Guide 2026: Healthcare Privacy Compliance Format, Eligibility, Domains, and Free Practice

A current 2026 CHPC certification guide: CCB/HCCA eligibility, CEUs, fees, 120-question exam format, seven-domain outline, HIPAA privacy topics, breach response, and free practice questions.

Ran Chen, EA, CFP®May 6, 2026

Key Facts

  • The CHPC exam has 120 multiple-choice questions, of which 100 are scored and 20 are pretest questions.
  • The CHPC testing window is 2 hours.
  • The exam fee is $350 for HCCA/SCCE members and $450 for non-members.
  • Most candidates need at least 1 year in a full-time compliance position or 1,500 hours of direct compliance duties in the 2 years before application.
  • Candidates need 20 CCB-approved CEUs before the exam, including at least 10 live CEUs earned within the required window.
  • CHPC certification is renewed every 2 years with 40 CCB CEUs, including 20 live CEUs.
  • The official detailed content outline has 7 domains and 100 scored items.
  • The detailed outline totals 20 recall, 52 application, and 28 analysis scored items, so scenario judgment matters more than memorization.
  • Open Exam Prep provides 100 CHPC practice questions covering all 7 official domains.

CHPC Tests Healthcare Privacy Compliance Work, Not Just HIPAA Definitions

The Certified in Healthcare Privacy Compliance (CHPC) credential is offered by the Compliance Certification Board through HCCA. It is designed for professionals who manage healthcare privacy obligations, including HIPAA Privacy Rule operations, policy management, training, monitoring, investigations, discipline, vendor oversight, breach response, and program reporting.

The current SERP is split between the official HCCA pages, generic HIPAA summaries, flashcard sets, and paid practice banks. The gap is practical exam framing. CHPC questions are built around compliance work experience. You need to know privacy law, but you also need to know how a privacy officer runs a program.

free CHPC practice questionsPractice questions with detailed explanations

Exam Snapshot

Item2026 detail
CredentialCertified in Healthcare Privacy Compliance
Exam ownerCompliance Certification Board / HCCA
Questions120 multiple-choice questions: 100 scored and 20 pretest
Time limit2 hours
Fee$350 HCCA/SCCE member; $450 non-member
DeliveryPSI test center or remote proctored testing
EligibilityCompliance experience plus CCB-approved CEUs, or approved student pathway
RenewalEvery 2 years with 40 CCB CEUs, including 20 live CEUs
Best next stepFree CHPC practice and CHPC study guide

Eligibility: Do Not Skip the CEU Gate

Most candidates qualify as compliance professionals. The 2025 handbook says this means at least 1 year in a full-time compliance position or 1,500 hours of direct compliance duties earned in the 2 years before application, with duties tied to the CHPC Detailed Content Outline.

You also need 20 CCB-approved CEUs earned within the 12 months before the exam date. At least 10 must be live CEUs. CCB-accredited university certificate students may satisfy some requirements through that pathway, but they still need to follow the handbook timing rules.

Official CHPC Domain Weights

DomainScored itemsWeight
Privacy Standards, Policies, and Procedures1717%
Privacy Compliance Program Oversight1616%
Screening and Evaluation of Employees, Physicians, Vendors, and Other Agents99%
Communication, Education, and Training on Compliance Issues1717%
Privacy Monitoring, Auditing, and Internal Reporting Systems1717%
Discipline for Non-Compliance99%
Investigations and Remedial Measures1515%

No single domain dominates. The exam is broad, and 80 of the 100 scored items are application or analysis rather than simple recall in the detailed outline totals.

High-Yield Topic Map

HIPAA privacy foundations: Know PHI, covered entities, business associates, minimum necessary, permitted uses and disclosures, authorizations, patient rights, Notice of Privacy Practices, accounting of disclosures, amendments, restrictions, confidential communications, and complaint rights. Use HHS as your baseline source for the HIPAA Privacy Rule.

Breach response: Know the four-factor risk assessment, when an impermissible use or disclosure is presumed to be a breach, and notification expectations. HHS explains the federal Breach Notification Rule, including notification without unreasonable delay and no later than 60 days after discovery for affected individuals.

Program oversight: Study annual work plans, risk assessments, internal controls, privacy officer authority, governance reporting, regulatory interpretation, emerging technology review, and when to involve legal counsel or outside expertise.

Training and communication: CHPC questions often ask what a privacy officer should do after a regulatory change, audit finding, repeated employee mistake, or targeted department risk. Role-based training, tracking, documentation, and culture matter.

Monitoring and investigations: Know audit plans, hotline or reporting mechanisms, non-retaliation, confidentiality, independent investigation structure, corrective action plans, trend analysis, and regulator interactions.

Vendors and BAAs: Be able to distinguish business associate agreements, data use agreements, vendor due diligence, subcontractor flow-down expectations, and privacy clauses in contracts.

Study Plan for Working Compliance Professionals

PhaseFocusHours
1HIPAA privacy basics, patient rights, PHI, permitted uses, authorizations25
2Privacy program governance, policies, annual work plans, risk assessments25
3Vendor screening, BAAs, training, communication, discipline20
4Monitoring, auditing, reporting systems, investigations, breach response30
5Timed CHPC practice questions, error log, handbook review20

If you work in privacy compliance every day, 8 to 10 weeks is realistic. If your compliance background is broader than privacy, plan 12 to 16 weeks and spend extra time on HIPAA patient rights, BAAs, breach response, and OCR expectations.

Practice Strategy

For each practice question, ask which role you are playing: privacy officer, compliance committee, investigator, trainer, vendor manager, or governance reporter. Then choose the answer that best preserves independence, documentation, consistency, legal privilege where appropriate, non-retaliation, and corrective action.

Open Exam Prep CHPC questionsPractice questions with detailed explanations

Official Sources

Test Your Knowledge
Question 1 of 4

How many CHPC exam questions are scored?

A
80 of 100
B
100 of 120
C
120 of 120
D
150 of 170
Learn More with AI

10 free AI interactions per day

CHPCCertified in Healthcare Privacy ComplianceHCCACCBHIPAAHealthcare PrivacyCompliance CertificationPrivacy OfficerBreach Notification2026

Related Articles

Stay Updated

Get free exam tips and study guides delivered to your inbox.

Free exam tips & study guides. Unsubscribe anytime.