Cheat sheet

CHPC Cheat Sheet

Privacy Standards, Policies, and Procedures

13%of exam

Privacy Compliance Program Oversight

25%of exam

OIG Seven ElementsRoles and GovernanceState Law Preemption PickerAnnual privacy work planProgram effectiveness review

Screening/Evaluation of Employees, Vendors, Agents

7%of exam

Communication, Education and Training on Privacy Issues

12%of exam

Training RequirementsRole-based trainingRisk-specific trainingSix-year training records

Privacy Monitoring, Auditing, and Internal Reporting Systems

16%of exam

Discipline for Non-Compliance

10%of exam

Sanctions and DisciplineExclusion vs SanctionProportional sanctionsConsistency across all levels

Investigations and Remedial Measures

17%of exam

Quick Facts

Exam
CHPC
Credential
Healthcare Privacy Compliance
Items
120 total, 100 scored
Time
2 hours
Pass
Angoff cut, not published
Domains
7 content areas
Fee
$350 member, $450 non-member
Delivery
PSI center, remote, paper
Eligibility
1 year or 1,500 hours
Entry CEUs
20 CCB, 10 live
Renewal
2 years, 40 CEUs
Retake
180 days after two fails

Individual Rights Clocks

Access 30, Amendment 60, Accounting 6

Access: 30 plus 30 daysAmendment: 60 plus 30 daysAccounting: six-year lookbackComplaint: 180 days

Privacy Rule vs Security Rule

Privacy Rule

  • All PHI, any medium
  • Uses and disclosures
  • Privacy official required

Security Rule

  • Electronic PHI only
  • Administrative, physical, technical
  • Risk analysis required

All PHI vs electronic only

Is Authorization Required

  1. Your own treatment or billingNo authorization(TPO)
  2. Giving PHI to patientNo authorization(Their own record)
  3. Law compels the disclosureNo authorization(Limit to requirement)
  4. Psychotherapy notes requestedAuthorization(Narrow exceptions)
  5. Promotional message about productAuthorization(Even when unpaid)
  6. Spoken face-to-faceNo authorization(Marketing exception)
  7. Nominal promotional giftNo authorization(Marketing exception)
  8. Payment for the disclosureAuthorization(Sale of PHI)
  9. Research on identifiable dataAuthorization or waiver(IRB or board)
  10. Limited data set releaseData use agreement(Not authorization)

PHI Scope and Exclusions

PHI
Identifiable health information
Any medium
Paper, oral, electronic
ePHI
Electronic PHI onlySecurity Rule
FERPA records
Excluded from PHI
Employment records
Held as employerExcluded
Dead over 50 years
No longer PHI
Designated record set
Records used for decisions
De-identified data
Outside the Privacy Rule

Minimum Necessary Exceptions

Treatment, Individual, Authorization, Secretary, Law, Rules

Treatment: provider requestsIndividual: their own PHIAuthorization: valid and signedSecretary: HHS enforcementLaw: required by lawRules: HIPAA compliance

Use vs Disclosure

Use

  • Inside the entity
  • Employ, examine, analyze
  • Minimum necessary applies

Disclosure

  • Outside the entity
  • Release or transfer
  • May need accounting

Internal handling vs release

De-Identification Paths

Safe Harbor
Remove 18 listed identifiers
Actual knowledge
Defeats Safe Harbor
Expert Determination
Very small re-identification risk
Limited data set
16 direct identifiers removedStill PHI
LDS keeps
Dates, city, state, ZIP
Data use agreement
Required for limited datasets
Re-identification code
Not derived from data

HIPAA vs 42 CFR Part 2

HIPAA

  • TPO without authorization
  • All protected health information
  • No court order needed

Part 2

  • Substance use disorder records
  • One consent covers TPO
  • Court order for proceedings

Part 2 guards legal use

Permitted Uses and Disclosures

TPO
Treatment, payment, operationsNo authorization
Required by law
Limited to the requirement
Public health
Reporting to authorities
Abuse or neglect
Victim reporting
Health oversight
Audits, inspections, licensure
Judicial proceedings
Order or qualified subpoena
Law enforcement
Narrow, purpose-specific
Serious threat
Avert imminent harm
Decedents
Coroner, funeral director
Workers compensation
As state law authorizes

Authorization Always Required

Psychotherapy notes
Narrow originator exceptions
Marketing
Even when unpaid
Sale of PHI
Remuneration for disclosure
Face-to-face
Marketing exception
Nominal gift
Marketing exception
Third-party payment
Must be stated
Core elements
Description, purpose, expiration, signature
Right to revoke
In writing, prospective

Individual Rights Clocks

Access
30 days, one extension
Access fee
Reasonable, cost-based only
Amendment
60 days, one extension
Accounting lookback
Six years before request
Accounting response
60 days, one extension
Self-pay restriction
Must be granted
Confidential communications
Accommodate reasonable requests
Notice of Privacy Practices
By first service delivery
OCR complaint
Within 180 days

Part 2 and Other Laws

42 CFR Part 2
Substance use disorder records
Part 2 compliance
February 16, 2026
Single consent
Covers future TPO
Court order
Needed for proceedings
Reproductive health rule
Vacated June 18, 2025
Surviving notice change
Due February 16, 2026
FERPA
Education records
GINA
Genetic information
GLBA
Financial privacy notices
FTC Health Breach Rule
Non-HIPAA health apps

OIG Seven Elements

Policies, Officer, Training, Lines, Auditing, Discipline, Response

Policies: written standardsOfficer: and committeeTraining: role-basedLines: open reportingAuditing: monitor and testDiscipline: publicizedResponse: corrective action

State Law Preemption Picker

  1. State law is more stringentFollow state law(HIPAA is a floor)
  2. Contrary and less protectiveFollow HIPAA(State preempted)
  3. State public health reportingFollow state law(Express exception)
  4. Health plan reporting or auditFollow state law(Express exception)
  5. Secretary granted an exceptionFollow state law(Fraud, insurance, substances)
  6. Both rules can be metFollow both(Not contrary)
  7. Program spans several statesMap law per state(No single policy)

Scored Items by Domain

Total scored
100 of 120 items
Policies
13 scored items
Oversight
25 scored itemsLargest
Screening
7 scored itemsSmallest
Training
12 scored items
Monitoring
16 scored items
Discipline
10 scored items
Investigations
17 scored items
General items
10 per form maximum
Research items
5 per form maximum

OIG Seven Elements

Element 1
Written policies and standards
Element 2
Compliance officer and committee
Element 3
Effective training and education
Element 4
Open lines of communication
Element 5
Internal monitoring and auditing
Element 6
Publicized disciplinary guidelines
Element 7
Prompt response, corrective action
Source
Federal Sentencing Guidelines

Roles and Governance

Privacy official
Required designation
Contact person
Receives complaints
Security official
Required for ePHI
Compliance committee
Defined goals and functions
Governing board
Owns oversight duty
Annual work plan
Turns risk into actions
Internal controls
Design, test, evidence
Three lines model
Own, oversee, assure
Outside expertise
Recognize the need

Covered Entity vs Business Associate

Covered entity

  • Provider, plan, clearinghouse
  • Issues the privacy notice
  • Notifies individuals

Business associate

  • Serves the covered entity
  • Signs an agreement
  • Notifies the covered entity

Both are directly liable

Which Agreement Applies

  1. Vendor performs service using PHIBusiness associate agreement
  2. Vendor hires its own subcontractorSubcontractor agreement(Flows down)
  3. Releasing a limited data setData use agreement
  4. Courier moves sealed recordsNo agreement(Conduit exception)
  5. Employee or volunteerNo agreement(Workforce member)
  6. Another provider treating patientNo agreement(Treatment disclosure)
  7. Health information exchangeBusiness associate agreement(Handles PHI)

Vendors and Workforce Screening

Business associate
Uses PHI for you
Subcontractor
Needs its own agreement
Conduit exception
Transports, no routine access
Workforce
Under your direct control
Job descriptions
State privacy obligations
Job evaluations
Include privacy performance
Background checks
As applicable law requires
Sanction screening
Federal exclusion lists
Exit interview
Confidentiality survives departure
Access revocation
At separation

BAA vs Data Use Agreement

BAA

  • Service on your behalf
  • Full PHI access
  • Breach duties flow down

Data use agreement

  • Limited data set only
  • Research, public health, operations
  • No re-identification or contact

Service vs limited data set

Training Requirements

New workforce
Within a reasonable time
Material change
Retrain affected members
Role-based training
Matched to job function
Risk-specific training
Targets a flagged behavior
Security awareness
Separate Security Rule program
Beyond payroll
Volunteers, students, board
Tracking
Roster, date, and content
Retention
Six years
Guidance channel
Encourage asking before acting

Monitoring vs Auditing

Monitoring

  • Continuous
  • Owned by the unit
  • Operational checks

Auditing

  • Periodic and formal
  • Independent of the unit
  • Criteria set beforehand

Ongoing vs independent snapshot

Monitoring and Auditing

Monitoring
Continuous and operational
Auditing
Periodic and independent
Risk analysis
Required, not addressable
Audit plan
Scope and criteria first
Activity review
Someone reads the logs
Snooping flags
Same surname, VIP, coworker
Trending
Track, evaluate, benchmark
Independence
Not the audited unit
External audits
OCR, CMS, accreditors

Anonymity vs Confidentiality

Anonymity

  • Identity never captured
  • No follow-up possible

Confidentiality

  • Identity known, protected
  • Limited by law

Promise only what holds

Internal Reporting Systems

Hotline
One reporting channel
Open door
Named person to call
Drop box
Offline reporting option
Publicize
Separate stated obligation
Anonymity
Identity never captured
Confidentiality
Known but protected
Non-retaliation
Rule and written policy
Whistleblower safe harbor
Good-faith oversight disclosure
Crime victim disclosure
Protected workforce conduct

Sanction vs Exclusion

Sanction

  • Internal discipline
  • Employer imposes it
  • Required by both rules

Exclusion

  • Federal program bar
  • Imposed by OIG
  • Screen before hiring

Internal penalty vs federal bar

Sanctions and Discipline

Sanction policy
Privacy and Security Rules
Proportionality
Match conduct and intent
Consistency
Same across all levels
Documentation
Record the action taken
Retention
Six years
Corrective action
Coordinate with management
Incentives
Reward compliant behavior
Protected conduct
Never sanction whistleblowers

Four Breach Factors

Nature, Recipient, Acquired, Mitigated

Nature: identifiers and re-identificationRecipient: who received itAcquired: viewed or takenMitigated: how far reduced

Breach vs Incident

Incident

  • Any suspected event
  • Triage and investigate
  • May be permissible

Breach

  • Unsecured PHI compromised
  • Presumed after impermissible use
  • Notification clock runs

Investigate first, then notify

Breach Notification Picker

  1. Encrypted per HHS guidanceNo notification(Not unsecured)
  2. Impermissible use occurredPresume a breach(You rebut it)
  3. Workforce good-faith accessException applies(No further use)
  4. Inadvertent between authorized staffException applies(Same entity)
  5. Recipient could not retainException applies(Good faith)
  6. Low compromise probability shownNo notification(Document it)
  7. Fewer than 500 affectedLog for HHS(File after year-end)
  8. Over 500 in stateNotify prominent media(Same 60 days)
  9. 500 or more totalNotify HHS(Within 60 days)
  10. Business associate discovered itTell covered entity(Within 60 days)
  11. 10 or more unreachableSubstitute notice(Website 90 days)

Breach Notification Clocks

Individual notice
60 days from discovery
No delay rule
Without unreasonable delay
Media notice
Over 500 in state
HHS large breach
60 days from discovery
HHS small breach
60 days after year-end
Associate to entity
60 days from discovery
Substitute notice
10 or more unreachable
Website posting
90 days conspicuous
Toll-free line
Active 90 days

Three Breach Exceptions

Unintentional, Inadvertent, Cannot Retain

Unintentional: workforce, in scopeInadvertent: authorized to authorizedCannot retain: recipient unableAll require good faith

Breach Risk Assessment

Unsecured PHI
The notification trigger
Encryption safe harbor
Meets HHS guidance
Presumption
Impermissible use is breach
Burden of proof
On the entity
Factor 1
Nature and extent
Factor 2
Who received it
Factor 3
Actually acquired or viewed
Factor 4
Extent of mitigation
Rebuttal
Low probability of compromise
Mitigation duty
Practicable harm reduction

Penalty Tier Ladder

Unknown, Reasonable, Corrected, Uncorrected

Unknown: $145 minimumReasonable cause: $1,461Willful, corrected: $14,602Willful, uncorrected: $73,011

Penalties and Enforcement

Tier 1
No knowledge, $145 minimum
Tier 2
Reasonable cause, $1,461 minimum
Tier 3
Willful, corrected, $14,602 minimum
Tier 4
Willful, uncorrected, $73,011 minimum
Tiers 1-3 maximum
$73,011 per violation
Tier 4 maximum
$2,190,294 per violation
Annual cap
$2,190,294 per provision
Adjusted
January 28, 2026
Criminal
Up to 10 years
State attorneys general
HITECH gave them authority

Common Traps

Two outlines are online

Handbook outline is current Linked PDF dates to 2019

Consent is not authorization

Consent is an optional courtesy Authorization has required elements

Encryption is not low risk

Encrypted PHI is not unsecured Low risk still needs documentation

60 days is a ceiling

Not a waiting period Notify without unreasonable delay

Media threshold is per state

Over 500 in one state Not 500 nationwide

Accounting excludes TPO

Treatment and billing are excluded Patients expect a longer list

Gap review is not risk analysis

Risk analysis is required A vendor checklist is not

Contracts do not shift liability

Business associates are directly liable Covered entity keeps its duty

Marketing needs no payment

Unpaid marketing still needs authorization Face-to-face is the exception

Not every violation is sanctionable

Whistleblowers must not be sanctioned Complainants are protected too

Last Minute

  1. 1.Scored items: 100 of 120
  2. 2.Oversight domain: 25 scored items
  3. 3.Investigations domain: 17 scored items
  4. 4.Screening domain: 7 scored items
  5. 5.Access request: 30 plus 30
  6. 6.Accounting looks back six years
  7. 7.OCR complaint window: 180 days
  8. 8.Breach notice: 60 days maximum
  9. 9.Media notice at 500 residents
  10. 10.Encrypted PHI needs no notification
  11. 11.Four breach factors, all assessed
  12. 12.Marketing and sale need authorization
  13. 13.BAA for service, DUA for datasets
  14. 14.Monitoring continuous, auditing stays independent
  15. 15.Sanctions documented, proportional, and consistent
  16. 16.Stricter state law beats HIPAA
  17. 17.Part 2 compliance: February 16, 2026
  18. 18.Tier 4 minimum penalty: $73,011
Same family resources

Explore More CCB Healthcare Compliance Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.