Privacy Standards, Policies, and Procedures
13%of exam
Privacy Compliance Program Oversight
25%of exam
Screening/Evaluation of Employees, Vendors, Agents
7%of exam
Communication, Education and Training on Privacy Issues
12%of exam
Privacy Monitoring, Auditing, and Internal Reporting Systems
16%of exam
Discipline for Non-Compliance
10%of exam
Investigations and Remedial Measures
17%of exam
Quick Facts
- Exam
- CHPC
- Credential
- Healthcare Privacy Compliance
- Items
- 120 total, 100 scored
- Time
- 2 hours
- Pass
- Angoff cut, not published
- Domains
- 7 content areas
- Fee
- $350 member, $450 non-member
- Delivery
- PSI center, remote, paper
- Eligibility
- 1 year or 1,500 hours
- Entry CEUs
- 20 CCB, 10 live
- Renewal
- 2 years, 40 CEUs
- Retake
- 180 days after two fails
Individual Rights Clocks
Access 30, Amendment 60, Accounting 6
Privacy Rule vs Security Rule
Privacy Rule
- All PHI, any medium
- Uses and disclosures
- Privacy official required
Security Rule
- Electronic PHI only
- Administrative, physical, technical
- Risk analysis required
All PHI vs electronic only
PHI Scope and Exclusions
- PHI
- Identifiable health information
- Any medium
- Paper, oral, electronic
- ePHI
- Electronic PHI onlySecurity Rule
- FERPA records
- Excluded from PHI
- Employment records
- Held as employerExcluded
- Dead over 50 years
- No longer PHI
- Designated record set
- Records used for decisions
- De-identified data
- Outside the Privacy Rule
Minimum Necessary Exceptions
Treatment, Individual, Authorization, Secretary, Law, Rules
Use vs Disclosure
Use
- Inside the entity
- Employ, examine, analyze
- Minimum necessary applies
Disclosure
- Outside the entity
- Release or transfer
- May need accounting
Internal handling vs release
De-Identification Paths
- Safe Harbor
- Remove 18 listed identifiers
- Actual knowledge
- Defeats Safe Harbor
- Expert Determination
- Very small re-identification risk
- Limited data set
- 16 direct identifiers removedStill PHI
- LDS keeps
- Dates, city, state, ZIP
- Data use agreement
- Required for limited datasets
- Re-identification code
- Not derived from data
HIPAA vs 42 CFR Part 2
HIPAA
- TPO without authorization
- All protected health information
- No court order needed
Part 2
- Substance use disorder records
- One consent covers TPO
- Court order for proceedings
Part 2 guards legal use
Permitted Uses and Disclosures
- TPO
- Treatment, payment, operationsNo authorization
- Required by law
- Limited to the requirement
- Public health
- Reporting to authorities
- Abuse or neglect
- Victim reporting
- Health oversight
- Audits, inspections, licensure
- Judicial proceedings
- Order or qualified subpoena
- Law enforcement
- Narrow, purpose-specific
- Serious threat
- Avert imminent harm
- Decedents
- Coroner, funeral director
- Workers compensation
- As state law authorizes
Individual Rights Clocks
- Access
- 30 days, one extension
- Access fee
- Reasonable, cost-based only
- Amendment
- 60 days, one extension
- Accounting lookback
- Six years before request
- Accounting response
- 60 days, one extension
- Self-pay restriction
- Must be granted
- Confidential communications
- Accommodate reasonable requests
- Notice of Privacy Practices
- By first service delivery
- OCR complaint
- Within 180 days
Part 2 and Other Laws
- 42 CFR Part 2
- Substance use disorder records
- Part 2 compliance
- February 16, 2026
- Single consent
- Covers future TPO
- Court order
- Needed for proceedings
- Reproductive health rule
- Vacated June 18, 2025
- Surviving notice change
- Due February 16, 2026
- FERPA
- Education records
- GINA
- Genetic information
- GLBA
- Financial privacy notices
- FTC Health Breach Rule
- Non-HIPAA health apps
OIG Seven Elements
Policies, Officer, Training, Lines, Auditing, Discipline, Response
State Law Preemption Picker
- State law is more stringent→Follow state law(HIPAA is a floor)
- Contrary and less protective→Follow HIPAA(State preempted)
- State public health reporting→Follow state law(Express exception)
- Health plan reporting or audit→Follow state law(Express exception)
- Secretary granted an exception→Follow state law(Fraud, insurance, substances)
- Both rules can be met→Follow both(Not contrary)
- Program spans several states→Map law per state(No single policy)
Scored Items by Domain
- Total scored
- 100 of 120 items
- Policies
- 13 scored items
- Oversight
- 25 scored itemsLargest
- Screening
- 7 scored itemsSmallest
- Training
- 12 scored items
- Monitoring
- 16 scored items
- Discipline
- 10 scored items
- Investigations
- 17 scored items
- General items
- 10 per form maximum
- Research items
- 5 per form maximum
OIG Seven Elements
- Element 1
- Written policies and standards
- Element 2
- Compliance officer and committee
- Element 3
- Effective training and education
- Element 4
- Open lines of communication
- Element 5
- Internal monitoring and auditing
- Element 6
- Publicized disciplinary guidelines
- Element 7
- Prompt response, corrective action
- Source
- Federal Sentencing Guidelines
Roles and Governance
- Privacy official
- Required designation
- Contact person
- Receives complaints
- Security official
- Required for ePHI
- Compliance committee
- Defined goals and functions
- Governing board
- Owns oversight duty
- Annual work plan
- Turns risk into actions
- Internal controls
- Design, test, evidence
- Three lines model
- Own, oversee, assure
- Outside expertise
- Recognize the need
Covered Entity vs Business Associate
Covered entity
- Provider, plan, clearinghouse
- Issues the privacy notice
- Notifies individuals
Business associate
- Serves the covered entity
- Signs an agreement
- Notifies the covered entity
Both are directly liable
Which Agreement Applies
- Vendor performs service using PHI→Business associate agreement
- Vendor hires its own subcontractor→Subcontractor agreement(Flows down)
- Releasing a limited data set→Data use agreement
- Courier moves sealed records→No agreement(Conduit exception)
- Employee or volunteer→No agreement(Workforce member)
- Another provider treating patient→No agreement(Treatment disclosure)
- Health information exchange→Business associate agreement(Handles PHI)
Vendors and Workforce Screening
- Business associate
- Uses PHI for you
- Subcontractor
- Needs its own agreement
- Conduit exception
- Transports, no routine access
- Workforce
- Under your direct control
- Job descriptions
- State privacy obligations
- Job evaluations
- Include privacy performance
- Background checks
- As applicable law requires
- Sanction screening
- Federal exclusion lists
- Exit interview
- Confidentiality survives departure
- Access revocation
- At separation
BAA vs Data Use Agreement
BAA
- Service on your behalf
- Full PHI access
- Breach duties flow down
Data use agreement
- Limited data set only
- Research, public health, operations
- No re-identification or contact
Service vs limited data set
Training Requirements
- New workforce
- Within a reasonable time
- Material change
- Retrain affected members
- Role-based training
- Matched to job function
- Risk-specific training
- Targets a flagged behavior
- Security awareness
- Separate Security Rule program
- Beyond payroll
- Volunteers, students, board
- Tracking
- Roster, date, and content
- Retention
- Six years
- Guidance channel
- Encourage asking before acting
Monitoring vs Auditing
Monitoring
- Continuous
- Owned by the unit
- Operational checks
Auditing
- Periodic and formal
- Independent of the unit
- Criteria set beforehand
Ongoing vs independent snapshot
Monitoring and Auditing
- Monitoring
- Continuous and operational
- Auditing
- Periodic and independent
- Risk analysis
- Required, not addressable
- Audit plan
- Scope and criteria first
- Activity review
- Someone reads the logs
- Snooping flags
- Same surname, VIP, coworker
- Trending
- Track, evaluate, benchmark
- Independence
- Not the audited unit
- External audits
- OCR, CMS, accreditors
Anonymity vs Confidentiality
Anonymity
- Identity never captured
- No follow-up possible
Confidentiality
- Identity known, protected
- Limited by law
Promise only what holds
Internal Reporting Systems
- Hotline
- One reporting channel
- Open door
- Named person to call
- Drop box
- Offline reporting option
- Publicize
- Separate stated obligation
- Anonymity
- Identity never captured
- Confidentiality
- Known but protected
- Non-retaliation
- Rule and written policy
- Whistleblower safe harbor
- Good-faith oversight disclosure
- Crime victim disclosure
- Protected workforce conduct
Sanction vs Exclusion
Sanction
- Internal discipline
- Employer imposes it
- Required by both rules
Exclusion
- Federal program bar
- Imposed by OIG
- Screen before hiring
Internal penalty vs federal bar
Sanctions and Discipline
- Sanction policy
- Privacy and Security Rules
- Proportionality
- Match conduct and intent
- Consistency
- Same across all levels
- Documentation
- Record the action taken
- Retention
- Six years
- Corrective action
- Coordinate with management
- Incentives
- Reward compliant behavior
- Protected conduct
- Never sanction whistleblowers
Four Breach Factors
Nature, Recipient, Acquired, Mitigated
Breach vs Incident
Incident
- Any suspected event
- Triage and investigate
- May be permissible
Breach
- Unsecured PHI compromised
- Presumed after impermissible use
- Notification clock runs
Investigate first, then notify
Breach Notification Picker
- Encrypted per HHS guidance→No notification(Not unsecured)
- Impermissible use occurred→Presume a breach(You rebut it)
- Workforce good-faith access→Exception applies(No further use)
- Inadvertent between authorized staff→Exception applies(Same entity)
- Recipient could not retain→Exception applies(Good faith)
- Low compromise probability shown→No notification(Document it)
- Fewer than 500 affected→Log for HHS(File after year-end)
- Over 500 in state→Notify prominent media(Same 60 days)
- 500 or more total→Notify HHS(Within 60 days)
- Business associate discovered it→Tell covered entity(Within 60 days)
- 10 or more unreachable→Substitute notice(Website 90 days)
Breach Notification Clocks
- Individual notice
- 60 days from discovery
- No delay rule
- Without unreasonable delay
- Media notice
- Over 500 in state
- HHS large breach
- 60 days from discovery
- HHS small breach
- 60 days after year-end
- Associate to entity
- 60 days from discovery
- Substitute notice
- 10 or more unreachable
- Website posting
- 90 days conspicuous
- Toll-free line
- Active 90 days
Three Breach Exceptions
Unintentional, Inadvertent, Cannot Retain
Breach Risk Assessment
- Unsecured PHI
- The notification trigger
- Encryption safe harbor
- Meets HHS guidance
- Presumption
- Impermissible use is breach
- Burden of proof
- On the entity
- Factor 1
- Nature and extent
- Factor 2
- Who received it
- Factor 3
- Actually acquired or viewed
- Factor 4
- Extent of mitigation
- Rebuttal
- Low probability of compromise
- Mitigation duty
- Practicable harm reduction
Penalty Tier Ladder
Unknown, Reasonable, Corrected, Uncorrected
Penalties and Enforcement
- Tier 1
- No knowledge, $145 minimum
- Tier 2
- Reasonable cause, $1,461 minimum
- Tier 3
- Willful, corrected, $14,602 minimum
- Tier 4
- Willful, uncorrected, $73,011 minimum
- Tiers 1-3 maximum
- $73,011 per violation
- Tier 4 maximum
- $2,190,294 per violation
- Annual cap
- $2,190,294 per provision
- Adjusted
- January 28, 2026
- Criminal
- Up to 10 years
- State attorneys general
- HITECH gave them authority
Common Traps
Two outlines are online
Handbook outline is current ≠ Linked PDF dates to 2019
Consent is not authorization
Consent is an optional courtesy ≠ Authorization has required elements
Encryption is not low risk
Encrypted PHI is not unsecured ≠ Low risk still needs documentation
60 days is a ceiling
Not a waiting period ≠ Notify without unreasonable delay
Media threshold is per state
Over 500 in one state ≠ Not 500 nationwide
Accounting excludes TPO
Treatment and billing are excluded ≠ Patients expect a longer list
Gap review is not risk analysis
Risk analysis is required ≠ A vendor checklist is not
Contracts do not shift liability
Business associates are directly liable ≠ Covered entity keeps its duty
Marketing needs no payment
Unpaid marketing still needs authorization ≠ Face-to-face is the exception
Not every violation is sanctionable
Whistleblowers must not be sanctioned ≠ Complainants are protected too
Last Minute
- 1.Scored items: 100 of 120
- 2.Oversight domain: 25 scored items
- 3.Investigations domain: 17 scored items
- 4.Screening domain: 7 scored items
- 5.Access request: 30 plus 30
- 6.Accounting looks back six years
- 7.OCR complaint window: 180 days
- 8.Breach notice: 60 days maximum
- 9.Media notice at 500 residents
- 10.Encrypted PHI needs no notification
- 11.Four breach factors, all assessed
- 12.Marketing and sale need authorization
- 13.BAA for service, DUA for datasets
- 14.Monitoring continuous, auditing stays independent
- 15.Sanctions documented, proportional, and consistent
- 16.Stricter state law beats HIPAA
- 17.Part 2 compliance: February 16, 2026
- 18.Tier 4 minimum penalty: $73,011
Explore More CCB Healthcare Compliance Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.