Free CHPC Exam Flashcards
Memorize 50 essential terms and definitions for the Certified in Healthcare Privacy Compliance (CHPC). See the term, recall the definition, then flip to check yourself.
Protected health information (PHI): what is in and what is out
Individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits, in any form or medium. Four exclusions: FERPA education records, the student treatment records FERPA describes, employment records the entity holds as an employer, and information about a person dead for more than 50 years. The exclusions decide whether a privacy policy applies at all.
Filter by Topic
Jump to Card
About These CHPC Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the Certified in Healthcare Privacy Compliance (CHPC). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
Protected health information (PHI): what is in and what is out
Individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits, in any form or medium. Four exclusions: FERPA education records, the student treatment records FERPA describes, employment records the entity holds as an employer, and information about a person dead for more than 50 years. The exclusions decide whether a privacy policy applies at all.
Safe Harbor vs. Expert Determination de-identification
Safe Harbor removes 18 listed identifiers and requires no actual knowledge that the remaining data could identify someone. Expert Determination has a person with appropriate statistical and scientific expertise document that the re-identification risk is very small. Data that meets either standard is no longer PHI and leaves the Privacy Rule.
Limited data set and the data use agreement
A limited data set removes 16 direct identifiers but may keep dates, and town or city, state, and ZIP. It is still PHI. It may be used only for research, public health, or health care operations, and only under a data use agreement with the recipient.
Minimum necessary: the six situations where it does not apply
Disclosures to, or requests by, a provider for treatment; uses or disclosures to the individual; anything done under a valid authorization; disclosures to HHS for enforcement; uses or disclosures required by law; and uses or disclosures required to comply with the HIPAA rules. Everywhere else you must limit PHI to what the purpose actually needs.
Treatment, payment, and health care operations (TPO)
A covered entity may use and disclose PHI for its own TPO without an authorization. This is the default lane for most clinical and billing work, which is why staff who route a request into TPO by habit are the ones who cause impermissible disclosures.
Three uses that always require a signed authorization
Psychotherapy notes (narrow exceptions, such as use by the originator for treatment), marketing, and any sale of PHI. Marketing needs an authorization even when nobody pays for it; the only carve-outs are face-to-face communications and promotional gifts of nominal value. If a third party pays for the marketing, or a sale brings remuneration, the authorization must say so.
Right of access: the response clock
A covered entity must act on an access request within 30 days. It may take one 30-day extension, and only one, if it gives the individual a written reason and a completion date. Right-of-access failures are among the most frequently penalized HIPAA violations.
Accounting of disclosures: the six-year lookback
Individuals may request an accounting of disclosures made in the six years before the request. TPO disclosures, disclosures to the individual, disclosures under an authorization, incidental disclosures, and limited data set disclosures are all excluded, which is why the list is shorter than patients expect.
The one restriction request you cannot refuse
A covered entity may normally decline a requested restriction. It must agree when the individual (or someone other than the plan) pays for an item or service in full out of pocket and asks that it not be disclosed to a health plan for payment or health care operations, unless the disclosure is required by law.
Privacy official vs. contact person vs. security official
The Privacy Rule requires a designated privacy official responsible for policies and procedures, plus a contact person to receive complaints. The Security Rule separately requires a named security official for ePHI. All designations must be documented; one person may hold more than one role.
The OIG seven elements of an effective compliance program
Written policies and standards of conduct; a designated compliance officer and committee; effective training and education; effective lines of communication; internal monitoring and auditing; well-publicized disciplinary guidelines; and prompt response with corrective action. A privacy program is expected to show all seven.
Security Rule risk analysis is required, not addressable
Covered entities and business associates must conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI, then implement risk management to reduce them. A vendor checklist or a policy gap review is not a risk analysis, and OCR treats the substitution as a finding.
What the annual privacy work plan is for
It converts risk-assessment output into scoped, owned, and dated actions for the year, and it drives the audit and monitoring plan. Without it the program reacts to incidents; with it the privacy officer can show the board why specific risks were worked and others deferred.
Reporting privacy program activity to the governing board
The board is accountable for oversight, so it needs regular, structured reporting: risk areas, audit results, incident and breach volume, sanction trends, and open corrective actions. Governance guidance from OIG expects boards to ask for metrics, not accept assurance.
State law preemption: HIPAA is a floor, not a ceiling
A contrary state law is preempted unless it is more stringent for privacy, provides for public health reporting or health plan audits, or the Secretary has determined it is needed for fraud and abuse control, insurance regulation, cost or delivery reporting, or controlled substances. Multi-state programs must map law by state.
42 CFR Part 2 after the February 16, 2026 compliance date
Substance use disorder records rules now align with HIPAA in key ways: one written consent can cover all future treatment, payment, and operations disclosures, HIPAA breach notification applies, and HHS enforces through OCR with HIPAA-style civil and criminal penalties. Part 2 still bars use of the records in proceedings against the patient without consent or a court order.
HIPAA civil money penalty tiers (inflation-adjusted January 2026)
Four culpability tiers, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect corrected within 30 days, $14,602 to $73,011; willful neglect not corrected, $73,011 to $2,190,294. The calendar-year cap for one provision is $2,190,294, and OCR's 2019 enforcement discretion applies lower annual caps to the first three tiers.
When a business associate agreement is required
A business associate is a person or entity that creates, receives, maintains, or transmits PHI to perform a function or service for a covered entity. Workforce members are not business associates, and a mere conduit that only transports data without accessing it is generally not one either.
Subcontractors are business associates too
A business associate must execute its own agreement with any subcontractor that handles PHI, and the obligation flows down the whole chain. Since HITECH, business associates are directly liable to OCR, so a covered entity's contract does not absorb the vendor's exposure.
Business associate agreement vs. data use agreement
Use a business associate agreement when a vendor performs a service on your behalf using PHI. Use a data use agreement when you release a limited data set for research, public health, or health care operations. Signing the wrong instrument is a common vendor-file audit finding.
Workforce screening from hire through separation
Write privacy duties into job descriptions and evaluations, run background checks as applicable law requires, and apply termination procedures that cut system access when the relationship ends. Exit interviews are the last chance to document that confidentiality duties survive employment.
HIPAA privacy training: who, when, and how often
Train every workforce member on the policies and procedures relevant to their function: existing staff by the compliance date, new members within a reasonable time after joining, and affected staff again within a reasonable time after a material policy change. Document each round.
Security awareness training is a separate requirement
The Security Rule requires a security awareness and training program for the entire workforce, including management. Its implementation specifications (security reminders, malicious software protection, log-in monitoring, password management) are addressable under the current rule, so a documented alternative may substitute. The January 2025 proposed Security Rule would make them required but has not been finalized.
General training vs. risk-specific training
General privacy training gives everyone the baseline. Risk-specific training targets the group and behavior your risk assessment or audit flagged, such as a unit with repeat access violations. Repeating the general module after an incident is the classic ineffective corrective action.
Why training documentation is a six-year obligation
HIPAA documentation, including training records, must be retained for six years from creation or from the date it was last in effect, whichever is later. In an OCR review, training that cannot be evidenced by roster, date, and content did not happen.
What to tell staff about the 2024 reproductive health care privacy rule
The April 2024 rule barred using PHI to investigate lawful reproductive care and required attestations for certain requests. On June 18, 2025, a federal court in Purl v. HHS vacated most of it nationwide. Within the Notice of Privacy Practices changes, only 45 CFR 164.520(b)(1)(ii)(F), (G) and (H) were vacated; the remaining NPP modifications, including the 42 CFR Part 2 notice updates, still took effect February 16, 2026. Training, forms, and notices that still cite the attestation are outdated; state reproductive-privacy laws still apply.
Notice of Privacy Practices: delivery and acknowledgment
A provider with a direct treatment relationship must give the notice no later than the first service delivery, and must make a good-faith effort to obtain written acknowledgment. If acknowledgment is not obtained, document the effort and the reason. In an emergency, provide the notice as soon as practicable.
Who counts as workforce for training purposes
Workforce means employees, volunteers, trainees, and anyone else whose conduct is under the direct control of the entity, paid or not. Credentialed physicians, students, volunteers, and board members routinely fall outside payroll-driven training rosters and become the coverage gap.
Making it safe to ask before acting
A program that only punishes errors gets silence. Publicized guidance channels, a named person to call, and visible non-retaliation turn ambiguous requests into consultations. Volume of privacy questions is a leading indicator of culture; a drop to zero is a warning, not a win.
Continuing education for the credential itself
CHPC certification lasts two years and renews on 40 CCB continuing education units earned in that period, at least 20 from live training. Initial-eligibility CEUs cannot be reused for renewal, so the clock restarts the day you pass.
Monitoring vs. auditing, and why independence matters
Monitoring is continuous and owned by the operating unit. Auditing is periodic, formal, and conducted independently of the area under review. The content outline expects investigations to be run independently of the operational unit, so the unit cannot audit or investigate itself.
Information system activity review is a required specification
The Security Rule requires regular review of audit logs, access reports, and security incident tracking reports. Audit controls elsewhere in the rule require the recording mechanism; this specification requires that someone actually reads the output. Collecting logs nobody reviews satisfies neither.
Proactive triggers for detecting record snooping
Build flags for same-surname matches, VIP and high-profile patients, employees appearing as patients, co-worker and family lookups, and access outside a user's assigned unit. Workforce snooping is rarely self-reported, so detection depends on proactive log review rather than complaints.
Building the annual audit and monitoring plan
Start from the risk assessment, then fix scope, population, sample size, and pass criteria before testing begins. Setting criteria after seeing results makes the finding indefensible and makes trending across years impossible.
Publicizing the internal reporting system
A hotline, open-door route, drop box, or web form only works if employees, physicians, vendors, and other agents all know it exists and how to reach it. The outline treats publicizing the mechanism as a separate obligation from operating it.
Anonymity vs. confidentiality in a report
Anonymity means the reporter's identity is never captured. Confidentiality means the identity is known but protected within legal and practical limits, which a subpoena or a small fact pattern can defeat. Promise only what the process can actually deliver.
The non-retaliation standard
A covered entity may not intimidate, threaten, coerce, discriminate against, or otherwise retaliate against anyone for exercising a HIPAA right, filing a complaint, or taking part in an investigation. The rule bans the conduct; the CHPC outline separately expects the privacy officer to ensure a written non-retaliation policy exists and is publicized.
The whistleblower safe harbor
A workforce member or business associate who believes in good faith that the entity is acting unlawfully or endangering patients may disclose PHI to a health oversight agency, public health authority, accreditation body, or their own attorney. The entity has not violated the Privacy Rule when they do.
The 180-day window for an OCR complaint
A complaint must be filed with the Secretary within 180 days of when the complainant knew or should have known of the act, unless the deadline is waived for good cause. When a patient threatens to report you, that window is the reason to preserve records immediately.
Sanction policy is required by two rules at once
The Privacy Rule requires appropriate sanctions against workforce members who violate privacy policies, and the Security Rule requires the same for security policies. Both require documenting the sanctions actually applied, so an unwritten disciplinary practice fails on the documentation prong.
Proportional, tiered sanctions
Match the response to conduct and intent: an inadvertent look at the wrong chart, deliberate snooping out of curiosity, and selling PHI are three different offenses. A single automatic-termination rule for every violation suppresses self-reporting and starves the program of incidents.
Consistency is the part that gets tested
The same conduct by a physician, an executive, and a nurse must draw comparable discipline. Monitor sanction data by role, unit, and violation type. Inconsistent enforcement is what OCR, an accreditor, and opposing counsel look for first.
Conduct you must not sanction
The sanction standard does not reach a workforce member acting under the whistleblower or crime-victim provisions (disclosing in good faith to an oversight agency, accreditor, attorney, or law enforcement), or one who files a complaint, testifies, or opposes an unlawful practice in good faith. Disciplining any of them converts a defensible incident into a retaliation violation.
Unsecured PHI and the encryption safe harbor
Breach notification is triggered only by unsecured PHI. PHI encrypted or destroyed per the HHS guidance is not unsecured, so a lost encrypted laptop needs no notification unless the decryption key was also exposed. This makes device and media encryption the highest-leverage single breach control.
The breach presumption and who carries the burden
Any impermissible use or disclosure of unsecured PHI is presumed to be a breach unless the entity demonstrates a low probability that the PHI was compromised. The covered entity or business associate bears the burden of proof, so the risk assessment must be written down and kept.
The four breach risk assessment factors
1) Nature and extent of the PHI, including the types of identifiers and the likelihood of re-identification. 2) Who used it or received it. 3) Whether the PHI was actually acquired or viewed. 4) The extent to which the risk has been mitigated. All four, at minimum, must be assessed.
The three exceptions to the definition of breach
Good-faith unintentional access by a workforce member acting within scope; inadvertent disclosure between two people authorized at the same entity or organized health care arrangement; and a good-faith belief the unauthorized recipient could not retain the information. The first two also require no further impermissible use.
Breach notification clocks
Individual notice without unreasonable delay and no later than 60 days after discovery. Media notice on the same clock when more than 500 residents of one state or jurisdiction are affected. HHS notice within 60 days for 500 or more; smaller breaches are logged and filed within 60 days after the calendar year ends.
Business associate discovers a breach: who notifies whom
The business associate must notify the covered entity without unreasonable delay and no later than 60 days from discovery, with the affected individuals identified where possible. The covered entity remains responsible for individual notice but may delegate the task by contract.
Mitigation duty and the corrective action plan
A covered entity must mitigate, to the extent practicable, any known harmful effect of an improper use or disclosure. A corrective action plan then addresses the root cause rather than the single incident, with owners, dates, and effectiveness testing. OCR resolution agreements pair a payment with a monitored plan.
Frequently Asked Questions
How many questions are on the CHPC exam and how many count?
The CHPC exam has 120 multiple-choice questions and you have two hours. Only 100 are scored; the other 20 are unscored and are not identified during the test, so answer every question. CCB's Detailed Content Outline distributes those 100 scored items across seven subject areas.
What score do I need to pass the CHPC exam?
The score report shows pass or fail. Your raw score is the number of correct answers out of the 100 scored items. CCB sets the minimum passing score using the Angoff method, where expert raters estimate the probability that a minimally qualified candidate answers each item correctly and the ratings are averaged; it does not publish a fixed passing percentage. Content-area subscores are informational and do not decide pass or fail.
How are the 100 scored questions split across the CHPC content areas?
Per the content outline in the CCB CHPC Candidate Handbook (April 2025): Privacy Standards, Policies, and Procedures 13; Privacy Compliance Program Oversight 25; Screening/Evaluation of Employees, Physicians, Vendors and Other Agents 7; Communication, Education and Training on Privacy Issues 12; Privacy Monitoring, Auditing, and Internal Reporting Systems 16; Discipline for Non-Compliance 10; Investigations and Remedial Measures 17. No more than 10 items per form are classified as General and no more than 5 as Research. The older Detailed Content Outline PDF (17/16/9/17/17/9/15) is superseded.
Who is eligible to sit for the CHPC exam?
You need at least one year in a full-time compliance position, or 1,500 hours of direct compliance job duties in the two years before your application, and your duties must relate to the Detailed Content Outline. You must also submit 20 CCB-approved CEUs, at least 10 from live training, earned within the 12 months before the exam. Students completing a CCB-accredited university compliance certificate meet the experience requirement for 24 months and the CEU requirement for 12 months. SCCE or HCCA membership is not required.
What happens if I fail the CHPC exam?
You apply to retest through your CCB account and must hold 20 CCB CEUs earned within 12 months of the anticipated retest date. CCB imposes no fixed wait after one failure. If you fail two attempts within a 180-day period, you must wait 180 days from your most recent exam date before applying again.
How long does CHPC certification last?
Two years. To renew you must earn and submit 40 CCB CEUs during the renewal period, with at least 20 from live training, and pay the renewal fee. CEUs used to qualify for initial certification cannot be reused for renewal. A one-month grace period exists, and one or two additional months can be requested, but shortened periods still require the full 40 CEUs.
Explore More CCB Healthcare Compliance Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.