1.1 CHPC Exam Overview, Eligibility & Test-Taking Strategy

Key Takeaways

  • The Compliance Certification Board (CCB) and Health Care Compliance Association (HCCA) administer the CHPC credential to validate specialized competence in healthcare privacy program governance, statutory mandates, and operational compliance.
  • The CHPC examination comprises 120 multiple-choice questions (100 scored, 20 unscored pretest items) administered within a strict 2-hour testing window, requiring a pacing tempo of one question per minute.
  • Scoring is established via the criterion-referenced modified Angoff methodology, which sets a scaled cut-score based on minimum professional competence rather than grading on a relative curve or fixed raw percentage.
  • The Detailed Content Outline allocates the 100 scored items as 13 / 25 / 7 / 12 / 16 / 10 / 17 across seven content areas covering 45 discrete privacy-officer tasks.
  • Eligibility requires 1 year of full-time compliance work (or 1,500 hours within 2 years) plus 20 CCB CEUs (10 live) earned in the prior 12 months; renewal every 2 years requires 40 CEUs (20 live).
Last updated: August 2026

CHPC Exam Overview, Eligibility & Test-Taking Strategy

The Certified in Healthcare Privacy Compliance (CHPC) credential is the premier national benchmark for healthcare privacy compliance professionals. Established and governed by the Compliance Certification Board (CCB) in partnership with the Health Care Compliance Association (HCCA), the CHPC designation demonstrates an individual's advanced competence in navigating complex federal and state healthcare privacy statutes, managing institutional privacy risk, implementing effective oversight mechanisms, and directing remedial and investigative actions.

Achieving the CHPC credential requires a rigorous synthesis of legal requirements, administrative regulations, information security fundamentals, and operational healthcare compliance workflows. This section outlines the structural architecture of the examination, formal eligibility and recertification mandates, cognitive testing levels, and proven test-taking strategies required to master scenario-based compliance questions.


1. Credentialing Framework & Governance

The CHPC credentialing ecosystem is administered under the auspices of the Compliance Certification Board (CCB), an independent body established in 1999 that develops and maintains professional compliance certifications across healthcare and corporate sectors. HCCA serves as the affiliated professional membership association providing specialized educational resources, research publications, and accredited continuing education units (CEUs).

+-----------------------------------------------------------------------------+
|                   CCB / HCCA CREDENTIALING GOVERNANCE                       |
|                                                                             |
|   +---------------------------------------------------------------------+   |
|   |              COMPLIANCE CERTIFICATION BOARD (CCB)                   |   |
|   |  - Independent governing body setting certification standards       |   |
|   |  - Determines candidate eligibility and ethical compliance          |   |
|   |  - Oversees psychometric test development and Angoff cut-scoring    |   |
|   +---------------------------------------------------------------------+   |
|                                      |                                      |
|                                      v                                      |
|   +---------------------------------------------------------------------+   |
|   |             HEALTH CARE COMPLIANCE ASSOCIATION (HCCA)               |   |
|   |  - Professional association delivering accredited training          |   |
|   |  - Provider of approved Continuing Education Units (CEUs)           |   |
|   |  - Publishes compliance practice guidance and industry benchmarks   |   |
|   +---------------------------------------------------------------------+   |
|                                      |                                      |
|                                      v                                      |
|   +---------------------------------------------------------------------+   |
|   |            CERTIFIED IN HEALTHCARE PRIVACY COMPLIANCE (CHPC)        |   |
|   |  - Specialized designation validating healthcare privacy mastery    |   |
|   |  - Focus: Standards, Governance, Risk, Training, Auditing, Remediation| |
|   +---------------------------------------------------------------------+   |
+-----------------------------------------------------------------------------+

2. Exam Format, Structure & Timing

The CHPC examination is a computer-based, proctored test administered globally through approved testing centers and secure remote proctoring environments.

Examination ParameterSpecific Requirement / Metric
Total Items120 multiple-choice questions
Scored Items100 scored items evaluating core privacy compliance domains
Unscored Items20 pretest items (psychometrically evaluated for future exam forms)
Testing Window2 hours (120 minutes total seat time)
Target PacingExactly 1.0 minute (60 seconds) per item
Question Format4-option multiple-choice (single best answer)
Scoring ModelCriterion-referenced scaled scoring (modified Angoff cut score, maintained by pre-equating)
Score ReportPass/fail, plus raw scores by major content category (content-area scores are informational only and are not used in the pass/fail decision)
Test AdministratorPSI — computer-based testing at a PSI test center, PSI remote proctored testing, or paper-and-pencil at approved events
Exam Application Fee$350 for SCCE or HCCA members; $450 for non-members
Re-Exam / Rescheduling Fee$75 (re-exam fees depend on the CEUs already submitted and approved within the eligibility window)

[!IMPORTANT] Pretest Item Mechanics: The 20 unscored pretest questions are distributed randomly throughout the 120-item examination and cannot be distinguished from scored items. Candidates must approach every question with equal diligence, as pretest items serve exclusively to validate statistical difficulty and discrimination indices before being added to future scored item banks.


3. Scoring Methodology: The Modified Angoff Standard

The CCB does not utilize a fixed percentage passing grade (such as 70% or 75%), nor does it curve scores against candidate cohort performance. Instead, the CHPC examination relies on the modified Angoff criterion-referenced method, an internationally recognized psychometric standard for professional licensure and credentialing.

+-----------------------------------------------------------------------------+
|                  MODIFIED ANGOFF SCORING ARCHITECTURE                       |
|                                                                             |
|   [SUBJECT MATTER EXPERT PANEL (CHPC PROFESSIONALS)]                        |
|   - Evaluates each individual item on the examination form                  |
|   - Estimates the probability that a "minimally competent candidate"        |
|     would answer the specific item correctly                                |
|                             |                                               |
|                             v                                               |
|   [SUMMATION OF ITEM PROBABILITIES = RAW CUT SCORE]                         |
|   - Aggregates individual item ratings to determine passing baseline        |
|   - Reflects the exact difficulty of that specific examination form         |
|                             |                                               |
|                             v                                               |
|   [SCALED SCORING CONVERSION]                                               |
|   - Converts raw performance to a standardized scaled cut score             |
|   - Guarantees fairness across different exam versions of varying difficulty|
+-----------------------------------------------------------------------------+

Under this criterion-referenced methodology:

  • Candidates compete solely against an objective standard of minimum professional competence rather than against fellow test-takers.
  • If an examination form contains an item pool of slightly higher average difficulty, the required raw cut score adjusts proportionally downward to maintain parity.
  • The scaled passing score represents equivalent proficiency regardless of the specific testing date or form delivered.

4. Eligibility Prerequisites & Candidate Pathways

To sit for the CHPC examination, candidates must satisfy both professional work experience and accredited continuing education requirements within defined timeframes.

+-----------------------------------------------------------------------------+
|                        CHPC ELIGIBILITY PATHWAYS                            |
|                                                                             |
|   CRITERION 1: PROFESSIONAL WORK EXPERIENCE (Must satisfy ONE)              |
|   +-----------------------------------+   +-----------------------------+   |
|   | Pathway A: Full-Time Experience   |   | Pathway B: Part-Time Hours  |   |
|   | 1 year of continuous, full-time   |OR | 1,500 hours of direct       |   |
|   | healthcare compliance employment  |   | healthcare compliance duties|   |
|   | within the preceding 2 years      |   | accumulated within 2 years  |   |
|   +-----------------------------------+   +-----------------------------+   |
|                                     +                                       |
|   CRITERION 2: CONTINUING EDUCATION UNITS (Mandatory)                       |
|   +---------------------------------------------------------------------+   |
|   | 20 CCB-Approved Continuing Education Units (CEUs)                   |   |
|   | - Must be earned within the 12 months immediately preceding the exam|   |
|   | - Minimum of 10 CEUs must be from LIVE (interactive/real-time) events|  |
|   | - Maximum of 10 CEUs may be earned via self-paced/pre-recorded media|   |
|   +---------------------------------------------------------------------+   |
+-----------------------------------------------------------------------------+

Qualifying Experience Guidelines

Qualifying compliance experience must involve direct operational responsibility for healthcare compliance processes, including developing privacy policies, conducting privacy audits, investigating unauthorized disclosures, delivering workforce privacy training, or managing business associate agreements. General clinical practice, legal representation without direct compliance operational duties, or standard medical records coding does not satisfy the professional experience threshold unless integrated into a formal compliance program structure.


5. Recertification & Continuing Competence

To preserve credential validity and ensure practitioners stay current with evolving statutory, regulatory, and technological developments, CHPC designees must recertify every two years.

+-----------------------------------------------------------------------------+
|                     CHPC RECERTIFICATION CYCLE (2 YEARS)                    |
|                                                                             |
|   [40 CCB-APPROVED CEUs REQUIRED EVERY 2 YEARS]                             |
|   |                                                                         |
|   +---> Minimum 20 Live CEUs (Real-time conferences, webinars, workshops)   |
|   |                                                                         |
|   +---> Maximum 20 Non-Live CEUs (Approved self-study, on-demand modules)    |
|   |                                                                         |
|   +---> Ethical Affirmation (Compliance with CCB Code of Professional Ethics)|
|   |                                                                         |
|   +---> Submission of Recertification Application & Renewal Fee              |
+-----------------------------------------------------------------------------+

[!WARNING] Inactive vs. Lapsed — CCB Draws a Sharp Line: Certification expires on the last day of the month, two years from the month you originally passed. CCB grants a one-month grace period, extendable by one or two additional months via a Renewal Extension Request at $50 per month (two-month maximum). If the CEUs are earned but the renewal fee is unpaid, the credential goes inactive and can be reactivated by paying for up to two consecutive renewal periods (four years of inactivity); after that, retesting is the only route. If the 40 CEUs themselves were never earned and submitted by the end of the grace and extension periods, the credential lapses — CCB states there are no appeals — and regaining it requires meeting current eligibility, paying the full application fee, and passing the exam again. Note also that using a grace or extension period shortens the next renewal window below 24 months without reducing the 40-CEU requirement.


6. How CCB Classifies Exam Items

The CHPC Candidate Handbook describes the Detailed Content Outline as identifying the areas and tasks tested and the number of questions drawn from each subject area. Within a subject area, CCB classifies items by cognitive demand using two labels — Recall and Application — and the printed outline in the current handbook publishes a single TOTAL item count per content area.

[!IMPORTANT] Do not memorize a cognitive-level percentage split. CCB does not publish a percentage breakdown of Recall versus Application items, and the handbook states plainly that "Task and Cognitive level item allocations will serve as targets only." Any prep source quoting a precise "X% analysis / Y% application" mix for the CHPC is inventing it. What CCB does publish is the item count per content area — those seven numbers, reproduced immediately below, are the only allocation figures you should study.

CCB Item ClassificationDefinition (Candidate Handbook)What It Looks Like on the Exam
Recall"Require recollection of specific knowledge related to the subject area.""Under 45 CFR § 164.524, what is the deadline for a covered entity to act on an individual's access request?" (30 calendar days, one 30-day extension)
Application"Require application of recalled knowledge to discern the final answer.""A hospital receives an attorney-signed subpoena for psychotherapy notes with no court order and no authorization. How should the privacy officer respond?" (apply § 164.508(a)(2) against § 164.512(e))

Two Published Item-Classification Caps

The Detailed Content Outline carries two constraints that candidates routinely miss because they sit in footnotes rather than the outline table:

  • A maximum of 10 items per examination form may be classified as General.
  • A maximum of 5 items per examination form may be classified as Research.

Practically, that means clinical-research privacy — IRB waivers, recruitment, decedent research, limited data sets for research — is worth studying but is capped at roughly one twentieth of the scored exam. Candidates who spend a third of their preparation on research privacy are optimizing against a 5-item ceiling while under-preparing Privacy Compliance Program Oversight, which alone carries 25 scored items.

Reading a Scenario Item at Each Level

  • Recall: the stem asks for a number, a definition, a statutory category, or a named party. Answer it and move on; these are the items that protect your clock.
  • Application: the stem builds a fact pattern, then asks what the privacy officer must do first, next, or at minimum. The distractors are usually all defensible compliance activities — only one is the action the regulation compels at that moment.

7. The Official Detailed Content Outline (Scored Item Allocation)

The Detailed Content Outline on pages 19–20 of the CHPC Candidate Handbook allocates the 100 scored items across seven content areas. Because the totals are item counts out of 100, each number is simultaneously a percentage of the scored exam. Map your study hours to this table, not to intuition about what "feels" important.

#Content AreaScored ItemsTasks in the OutlineWhere This Guide Teaches It
1Privacy Standards, Policies, and Procedures13A–F (6)Chapter 2
2Privacy Compliance Program Oversight25A–K (11)Chapters 3 and 4
3Screening/Evaluation of Employees, Physicians, Vendors and Other Agents7A–D (4)Chapter 5
4Communication, Education and Training on Privacy Issues12A–E (5)Chapter 6
5Privacy Monitoring, Auditing, and Internal Reporting Systems16A–G (7)Chapter 7
6Discipline for Non-Compliance10A–E (5)Chapter 8
7Investigations and Remedial Measures17A–G (7)Chapter 9
Total10045 tasks

[!IMPORTANT] Area 2 is the exam. Privacy Compliance Program Oversight (25 items) plus Investigations and Remedial Measures (17 items) plus Monitoring, Auditing, and Internal Reporting (16 items) equal 58 of the 100 scored items. All three are program-management domains, not statute-recitation domains. The CHPC tests whether you can run a privacy program — scope it, resource it, staff it, audit it, investigate it, and remediate it — far more than it tests whether you can recite the eighteen Safe Harbor identifiers. Candidates who study the CHPC as a HIPAA-trivia exam consistently under-prepare the majority of the item pool.

A second structural point: the outline is written as a list of tasks a privacy officer performs — "Develop annual privacy work plan," "Assure background/sanction checks are conducted," "Coordinate investigations to preserve defined privileges." Items are written from that same task perspective. When a stem describes a situation, ask which outline task is being performed here before you evaluate the options; that alone eliminates distractors drawn from a different content area.


8. High-Yield Test-Taking Strategies for Privacy Scenarios

Scenario-based questions on the CHPC examination require a structured analytical methodology. Candidates should utilize the following four-step framework when approaching scenario items:

+-----------------------------------------------------------------------------+
|               FOUR-STEP PRIVACY SCENARIO TRIAGE FRAMEWORK                   |
|                                                                             |
|   STEP 1: IDENTIFY THE LEGAL CAPACITY & ROLE                                |
|   - Is the actor a Covered Entity, Business Associate, Subcontractor,       |
|     Hybrid Entity component, or Employer?                                   |
|                                                                             |
|   STEP 2: CLASSIFY THE DATA TYPE & REGULATORY JURISDICTION                  |
|   - Is the data PHI, ePHI, an Employment Record, FERPA Record, 42 CFR       |
|     Part 2 SUD data, or a De-Identified / Limited Data Set?                 |
|                                                                             |
|   STEP 3: IDENTIFY THE DISCLOSURE PATHWAY & LEGAL BASIS                     |
|   - Is it Treatment, Payment, Operations (TPO), a Permitted Public Priority |
|     Exception (§ 164.512), an Authorized Disclosure, or an Impermissible Use?|
|                                                                             |
|   STEP 4: DISTINGUISH MINIMUM MANDATE VS. BEST PRACTICE                     |
|   - Does the question ask what the regulation STRICTLY REQUIRES, or what    |
|     the Privacy Officer SHOULD do as an optimal compliance measure?         |
+-----------------------------------------------------------------------------+

Critical Compliance Traps to Avoid:

  1. The Employer vs. Covered Entity Trap: Healthcare systems frequently act as both healthcare providers (covered entities) and employers. Employment physicals, FMLA documentation, and OSHA records maintained by the entity in its role as employer are not PHI under 45 CFR § 160.103.
  2. The "Required by Law" Misconception: A subpoena signed by an attorney is not a court order. Disclosing PHI in response to an attorney subpoena without a satisfactory assurance of notice (or qualified protective order) is an impermissible disclosure under § 164.512(e).
  3. Strict Liability vs. Reasonable Diligence: Under the HITECH tiered penalty structure, lack of knowledge is not a total defense if the covered entity would have known of the violation through the exercise of reasonable diligence.
  4. Over-Disclosing Psychotherapy Notes: Psychotherapy notes maintained separately from the rest of the medical record require express, standalone patient authorization for almost all uses and disclosures, even for general treatment by other providers (with narrow exceptions for the originator's own treatment, training, or defending legal action).
Loading diagram...
CHPC Scenario-Based Decision Framework
Test Your Knowledge

Which of the following correctly reflects the continuing education requirements to qualify for the CCB Certified in Healthcare Privacy Compliance (CHPC) examination?

A
B
C
D
Test Your Knowledge

How is the passing score determined for the CCB CHPC examination?

A
B
C
D
Test Your Knowledge

When analyzing a scenario-based item on the CHPC examination involving an unauthorized disclosure, what is the essential first step in the compliance triage framework?

A
B
C
D