The Short Answer: Prepare From the Newer Handbook, Not a Third-Party Passing Score
The Certified in Healthcare Privacy Compliance (CHPC) exam is a two-hour, 120-question multiple-choice examination administered for the Compliance Certification Board (CCB) with PSI. One hundred questions are scored and 20 are unscored pretest items. The current application fee is $350 for SCCE or HCCA members and $450 for nonmembers; membership is not required.
The exam is built for working compliance professionals. Most applicants need either one year in a full-time compliance position or 1,500 hours of direct compliance duties earned during the two years before applying. They also need 20 approved CCB continuing education units (CEUs), including at least 10 live CEUs, earned within the 12 months before the scheduled exam.
Current CHPC Exam Snapshot
| Item | Official detail checked July 30, 2026 |
|---|---|
| Credential | Certified in Healthcare Privacy Compliance (CHPC) |
| Certification body | Compliance Certification Board (CCB) |
| Exam administrator | PSI |
| Questions | 120 multiple-choice: 100 scored and 20 pretest |
| Testing time | 2 hours |
| Language | English |
| Initial fee | $350 SCCE/HCCA member; $450 nonmember |
| Membership | Not required |
| Delivery | PSI test center, PSI remote proctoring, or paper-and-pencil after selected SCCE/HCCA events |
| Score reporting | Pass/fail plus raw performance by major category; no public fixed raw cutoff |
| Credential term | Two years |
| Renewal | 40 CCB CEUs during the renewal period, including at least 20 live CEUs |
The handbook is the primary administrative source. CCB states that policies and fees can change, so recheck it before paying or scheduling.
A Critical Official-Source Conflict: Two HCCA Outlines Are Still Online
HCCA currently serves two official CHPC outline artifacts that do not agree. The newer candidate handbook, which calls itself the primary source for certification information, lists these scored-item totals:
| Current handbook domain | Scored items | Share of 100 scored items |
|---|---|---|
| 1. Privacy Standards, Policies, and Procedures | 13 | 13% |
| 2. Privacy Compliance Program Oversight | 25 | 25% |
| 3. Screening/Evaluation of Employees, Physicians, Vendors, and Other Agents | 7 | 7% |
| 4. Communication, Education, and Training on Privacy Issues | 12 | 12% |
| 5. Privacy Monitoring, Auditing, and Internal Reporting Systems | 16 | 16% |
| 6. Discipline for Non-Compliance | 10 | 10% |
| 7. Investigations and Remedial Measures | 17 | 17% |
| Total | 100 | 100% |
A separately hosted, older standalone CHPC Detailed Content Outline still shows the prior 17/16/9/17/17/9/15 distribution. It also shows cognitive totals of 20 recall, 52 application, and 28 analysis items. The newer handbook changes the domain totals to 13/25/7/12/16/10/17 and no longer publishes a cognitive-level matrix.
Do not combine the newer domain weights with the older cognitive table and call the result one current blueprint. This guide gives precedence to the newer handbook. If the eligibility or scheduling message CCB sends you points to a different outline, ask CCB which document controls your examination form and follow the document CCB identifies.
The older matrix is still useful as historical evidence that CHPC has emphasized applied judgment, but it is not a safe basis for claiming current cognitive totals. The current handbook's sample questions reinforce the same practical style through prompts asking for the MOST critical or FIRST action.
Eligibility: Two Routes, One Deadline Problem
Route 1: Compliance professional
Both conditions apply:
- At least one year in a full-time compliance position or 1,500 hours of direct compliance job duties earned in the two years before the application date.
- Those duties must relate directly to tasks in the CHPC content outline. A healthcare title alone does not establish eligibility if the work is not privacy or compliance work.
Route 2: CCB-accredited university certificate student
Completing an accredited compliance certificate program satisfies the professional-experience requirement for 24 full months after program completion. It also satisfies the initial CEU requirement for 12 full months. After that first 12-month period, the graduate must add 20 new CCB CEUs, including at least 10 live CEUs, to remain eligible within the 24-month work-experience window.
The CEU gate for working professionals
Before applying, earn and submit 20 CCB-approved CEUs from one or more recognized compliance subject areas. At least 10 must come from live education, including face-to-face programs or real-time virtual events and webinars. All 20 must fall within the 12 months before the scheduled examination date. Recorded webinars and other self-study may earn CEUs, but they do not count as live education.
Your eligibility period is tied to the age of those CEUs. Apply early enough for CCB processing and PSI scheduling; letting the window expire can require 20 new CEUs, a new application, and the full fee.
What to Study in Each Current Domain
1. Privacy Standards, Policies, and Procedures — 13 items
Know how to develop, review, and update operational and governance policies. The handbook examples include HIPAA Privacy and Security, FERPA, GINA, non-retaliation, retention, discipline, data governance, health information exchanges, hybrid entities, privacy notices, PCI, and FTC concerns. Practice identifying whether a problem requires a policy revision, a stakeholder notice, a governance decision, or integration with organizational culture.
2. Privacy Compliance Program Oversight — 25 items
This is the largest current domain. Concentrate on program scope and resources, annual privacy work plans, internal controls, privacy-officer authority, counsel's role, committee governance, leadership reporting, regulatory interpretation, outside expertise, operational integration, effectiveness evaluation, and organizational risk assessment.
A strong answer usually identifies who owns the decision, what evidence leadership needs, and how the action fits the program rather than treating an incident as an isolated HIPAA trivia question.
3. Screening and Evaluation — 7 items
Study privacy obligations in job descriptions and evaluations, legally appropriate background or sanction checks, privacy issues in exit interviews, and due diligence for third parties. Distinguish business associate agreements, subcontracts, data use agreements, and collaborative data-sharing arrangements.
4. Communication, Education, and Training — 12 items
Be ready to translate a complex rule into understandable guidance, identify the correct audience, build general or role-based training, track completion, educate on policy, and create a reliable path for questions. The best response to a recurring error is rarely a generic annual slide deck; use the risk and audience to choose targeted education and verify its effectiveness.
5. Monitoring, Auditing, and Internal Reporting — 16 items
Know the difference between a risk assessment, an audit, and ongoing monitoring. Study annual audit plans, risk-priority action plans, tracking and trend analysis, reporting channels, anonymity and confidentiality within legal limits, and responses to external audits. Questions may ask what should be monitored next or how an observation becomes a defensible corrective plan.
6. Discipline for Non-Compliance — 10 items
Focus on proportionate discipline, consistency across organizational levels, documented action, management coordination, and incentives that reward compliant conduct. The privacy officer recommends and monitors a defensible process; arbitrary punishment and undocumented exceptions undermine the program.
7. Investigations and Remedial Measures — 17 items
Study fair, independent, timely, and discreet investigations; defined escalation channels; preservation of attorney-client or peer-review privilege when applicable; root-cause analysis; corrective-action development; effectiveness monitoring; breach coordination; and regulatory communication. Preserve evidence before conclusions, avoid promises of absolute anonymity, and document why notification was or was not required.
HIPAA Rules to Turn Into Decision Drills
The content outline names many laws and regulators, but HHS Office for Civil Rights material should anchor core HIPAA questions. Use these primary-source rules to build scenarios:
- Minimum necessary: A covered entity generally makes reasonable efforts to limit uses, disclosures, and requests to the minimum PHI needed. Important exceptions include provider-to-provider treatment disclosures, disclosures to the individual, uses authorized by the individual, disclosures to HHS for enforcement, and uses required by law. See the HHS minimum-necessary guidance.
- Individual access: A covered entity generally must act on an access request within 30 calendar days. One additional 30-day extension is possible if the individual receives timely written notice explaining the delay and expected completion date. See the HHS right-of-access guidance.
- Breach presumption: An impermissible use or disclosure is presumed to be a breach unless an exception applies or a documented assessment demonstrates a low probability that PHI was compromised. The four factors address the PHI involved, the unauthorized person, whether PHI was actually acquired or viewed, and mitigation.
- Notification timing: Individual notice must be sent without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more individuals also require prompt notice to HHS; smaller breaches may be reported annually within 60 days after the calendar year's end. Confirm details on the HHS Breach Notification Rule page.
- Business associates: A covered entity normally documents satisfactory assurances through a compliant contract. If it learns of a material pattern or practice violating the agreement, it must take reasonable steps to cure or end the violation. A BAA is not a substitute for due diligence, incident escalation, or access support.
- State and other federal law: HIPAA is a federal floor, not the only privacy rule. A CHPC candidate should recognize when state law, 42 CFR Part 2, FERPA, GINA, FTC authority, or another requirement needs comparison or specialized advice rather than assuming HIPAA automatically controls.
An Eight-Week Plan Weighted to the Newer Handbook
| Week | Work product | Why it matters |
|---|---|---|
| 1 | Eligibility audit, handbook read, baseline mixed quiz | Prevents an application surprise and identifies actual weak areas |
| 2 | HIPAA uses/disclosures, minimum necessary, access, notices | Builds the rule base used across several domains |
| 3 | Program scope, annual plan, controls, authority, governance | Starts the 25-item Program Oversight domain |
| 4 | Risk assessment, effectiveness, external expertise, emerging operations | Finishes the largest domain with scenario practice |
| 5 | Monitoring, audit design, reporting channels, trend analysis | Covers the 16-item evidence and reporting workflow |
| 6 | Investigations, breach response, root cause, corrective action | Covers the 17-item response domain |
| 7 | Policies, vendors, training, discipline | Integrates the four smaller operational domains |
| 8 | Two timed 120-question simulations, error-log remediation, exam logistics | Tests pacing and converts recurring errors into final drills |
If privacy work is already your daily role, compress the rule review and spend more time on unfamiliar governance tasks. If your background is general healthcare compliance, add time for patient rights, BA relationships, data-sharing arrangements, and breach analysis. A universal claim such as “everyone needs 120 hours” is less useful than a baseline test and an error log.
A Repeatable Method for CHPC Scenarios
For every scenario, write five short prompts before choosing an answer:
- What is the privacy or program risk? Separate the observed fact from an assumption.
- Who owns the next decision? Privacy officer, counsel, management, governing committee, investigator, or operational leader may have different roles.
- What must be preserved? Evidence, confidentiality, privilege, non-retaliation, consistency, and required deadlines may control sequence.
- What is the first defensible action? Verify scope and facts before escalating, notifying, disciplining, or redesigning policy.
- How will effectiveness be demonstrated? Look for documentation, root cause, targeted correction, monitoring, and governance reporting.
Application, Results, Retesting, and Renewal
After CCB approves an application, PSI supplies scheduling instructions. Remote candidates should run the system check on the actual personal device and network they will use; the handbook warns that corporate firewalls, VPNs, and some work or Mac computers may prevent launch even after an initial check.
Answer all 120 items. Pretest questions are not identified. Most U.S. test-center candidates receive a score report immediately, and remote candidates usually receive immediate pass/fail results with a detailed report mailed later. Paper-and-pencil results can take four to six weeks. Category raw scores are diagnostic only; the overall examination determines pass or fail.
If you do not pass, you still need 20 current CCB CEUs for a retest. The handbook lists a $75 re-exam or rescheduling fee subject to the CEUs on file; if eligibility expires, the full application fee can apply. After two failed attempts within 180 days, wait 180 days from the most recent exam date before applying again.
CHPC certification lasts two years. Renewal requires earning and submitting 40 CCB CEUs during the renewal period, including at least 20 live CEUs. Initial-certification CEUs cannot be reused for renewal. The current renewal fee is $145 for SCCE/HCCA members and $265 for nonmembers.
Official Sources and Final Checklist
- HCCA CHPC certification page
- Current CHPC Candidate Handbook
- HCCA certification FAQ — includes the no-official-study-guide statement
- Older standalone CHPC DCO — use only with the source-conflict warning above
- HHS summary of the HIPAA Privacy Rule
- HHS Breach Notification Rule
- HHS right-of-access guidance
Before scheduling, confirm that your experience matches CHPC tasks, all 20 CEUs are approved and current, at least 10 are live, your identification matches your application, and the outline in your CCB instructions matches the one you studied. There is no official study guide to buy and no official pass-rate promise to chase: use the handbook, primary law guidance, and documented scenario practice.
