CHPS Exam Prep Free practice test →

Free CHPS Practice Questions

10 free, exam-style Certified in Healthcare Privacy and Security (CHPS) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CHPS practice test to study every exam domain.

Question 1

A state law requires covered entities to provide patients a copy of their records within 15 days, while the HIPAA Privacy Rule permits up to 30 days. When both apply, which standard governs?

  1. The HIPAA 30-day standard, because federal law preempts contrary state law
  2. Whichever standard the covered entity adopts in its own policies
  3. The state 15-day standard, because it is more stringent
  4. The HIPAA standard, unless the state obtained an exception from HHS
Show answer & explanation

Correct answer: C - The state 15-day standard, because it is more stringent

Question 2

A university operates a health clinic that treats only enrolled students. Under federal law, the students' treatment records maintained by the clinic are generally governed by:

  1. The HIPAA Privacy Rule, since the clinic is a health care provider
  2. FERPA, because HIPAA excludes FERPA-covered records from the definition of PHI
  3. Both HIPAA and FERPA, applying whichever is more protective of the student
  4. State medical-records law only, as federal privacy law does not reach schools
Show answer & explanation

Correct answer: B - FERPA, because HIPAA excludes FERPA-covered records from the definition of PHI

Question 3

A patient submits a written request for a paper copy of their record. Under the HIPAA right of access, the covered entity MAY charge a fee that includes:

  1. Labor for copying, plus the cost of supplies and postage
  2. Staff time spent searching for and retrieving the record
  3. The cost of verifying the requester's identity and authority
  4. A flat per-page rate that need not reflect the actual cost of copying
Show answer & explanation

Correct answer: A - Labor for copying, plus the cost of supplies and postage

Question 4

A covered entity hires a cloud vendor to store encrypted ePHI. The vendor holds only encrypted data and lacks the decryption key, so it cannot view the information. Under HIPAA, the vendor is:

  1. Not a business associate, because it cannot access the unencrypted ePHI
  2. Exempt under the conduit exception, since it only stores data it is sent
  3. A business associate only if it voluntarily agrees to that status in writing
  4. A business associate that must enter into a business associate agreement
Show answer & explanation

Correct answer: D - A business associate that must enter into a business associate agreement

Question 5

A data set is being de-identified under the Safe Harbor method and includes patients aged 92, 95, and 101. To comply, these ages must be:

  1. Reported as listed, since age alone is not one of the 18 identifiers
  2. Aggregated into a single category of '90 or older'
  3. Replaced with each patient's year of birth instead of age
  4. Offset by a consistent random number of days to mask them
Show answer & explanation

Correct answer: B - Aggregated into a single category of '90 or older'

Question 6

An organization's risk analysis shows that an addressable implementation specification in the Security Rule is not reasonable and appropriate for its environment. The organization must:

  1. Skip the specification, since addressable items are optional and need not be implemented
  2. Implement it exactly as written anyway, because every specification is mandatory
  3. Document its rationale and adopt a reasonable equivalent measure
  4. Obtain written approval from OCR before deviating from the specification
Show answer & explanation

Correct answer: C - Document its rationale and adopt a reasonable equivalent measure

Question 7

A hospital implements two-factor authentication for access to its EHR. Which combination meets the definition of true two-factor authentication?

  1. A fingerprint scan plus a one-time code from a mobile token
  2. A password plus the answer to a personal security challenge question
  3. A username entered together with an account password
  4. Two distinct passwords entered on two separate screens
Show answer & explanation

Correct answer: A - A fingerprint scan plus a one-time code from a mobile token

Question 8

To satisfy the Security Rule's risk analysis requirement, an organization's analysis must:

  1. Cover only the systems that store its highest-volume ePHI
  2. Consist of an annual third-party penetration test of the network perimeter
  3. Be a one-time checklist comparing existing written policies to the rule's text
  4. Assess risks to all ePHI it creates, receives, maintains, or transmits
Show answer & explanation

Correct answer: D - Assess risks to all ePHI it creates, receives, maintains, or transmits

Question 9

A workforce member emails a spreadsheet of unsecured PHI to the wrong external recipient. Under the Breach Notification Rule, this impermissible disclosure is:

  1. Automatically a reportable breach that requires immediate individual notification
  2. Presumed a breach unless a risk assessment shows a low probability of compromise
  3. Not a breach if the recipient verbally agrees to delete the email
  4. Exempt because it was an accident rather than an intentional disclosure
Show answer & explanation

Correct answer: B - Presumed a breach unless a risk assessment shows a low probability of compromise

Question 10

A covered entity discovers a breach of unsecured PHI affecting 120 individuals. When must it report this breach to the HHS Secretary?

  1. Without unreasonable delay, within 60 days of discovering the breach
  2. Within 24 hours, since all breaches require immediate federal notice
  3. In the annual breach log submitted within 60 days after year-end
  4. Only if one or more affected individuals later file a complaint with OCR
Show answer & explanation

Correct answer: C - In the annual breach log submitted within 60 days after year-end

Ready for the real thing?

Practice hundreds more CHPS questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing