CHPC CERTIFIED IN
HEALTHCARE PRIVACY
COMPLIANCE PRACTICE
EXAM COMPLETE
Question 1: A university operates a medical center and several non-health business units. It wants HIPAA to apply only to the functions that perform covered activities.What organizational step is most appropriate?
Choices:
1) Designate the covered health care components in a documented hybrid-entity structure 2) Treat every university department as a business associate 3) Exclude the medical center from the university legal entity 4) Create a separate Notice of Privacy Practices for every employee Correct Answer: Designate the covered health care components in a documented hybrid- entity structure Explanation: A legal entity that performs both covered and noncovered functions may designate health care components and operate as a hybrid entity. The designation should be documented so HIPAA requirements are applied to the covered components and appropriate shared functions.Page 1
Question 2: As of February 16, 2026, a HIPAA covered health care provider that
creates or maintains Part 2 records should ensure its Notice of Privacy Practices does which of the following?
Choices:
1) Omits all references to substance use disorder records 2) Explains applicable uses, disclosures, responsibilities, and rights involving Part 2 records 3) States that Part 2 records may always be disclosed for law enforcement purposes 4) Requires every patient to sign a HIPAA authorization before treatment Correct Answer: Explains applicable uses, disclosures, responsibilities, and rights involving Part 2 records Explanation: HHS requires covered providers and health plans that create or maintain Part 2 records to include the applicable Part 2 information in their NPPs beginning February 16, 2026.The notice must describe privacy practices, responsibilities, and patient rights related to those records.Question 3: A hospital is revising its internal access policy for billing sta. Which policy design best reects the HIPAA minimum necessary standard?
Choices:
1) Give every billing employee full-chart access to avoid workow delays 2) Permit access based on the PHI categories needed for assigned job functions 3) Require a patient authorization for every billing access 4) Limit only paper records because minimum necessary does not apply to electronic PHI Correct Answer: Permit access based on the PHI categories needed for assigned job functions Explanation: For internal uses, a covered entity should implement role-based access policies that identify who needs access and the categories of PHI needed to perform job duties. Blanket full-record access is not appropriate merely for convenience.Page 2
Question 4: How long must a HIPAA covered entity generally retain documentation
required by the Privacy Rule?
Choices:
1) Two years from creation 2) Three years from the end of the calendar year 3) Six years from creation or the date last in eect, whichever is later 4) Indenitely in every case Correct Answer: Six years from creation or the date last in eect, whichever is later Explanation: HIPAA Privacy Rule documentation generally must be retained for six years from the date of creation or the date it last was in eect, whichever is later. This HIPAA documentation rule is distinct from state medical-record retention laws.Question 5: A FERPA-covered university student receives care at the university's campus health clinic. The clinic's records on that student are generally governed by which federal privacy framework?
Choices:
1) HIPAA only, because the clinic provides health care 2) FERPA, because student education or treatment records are excluded from HIPAA PHI 3) The FTC Health Breach Notication Rule only 4) GLBA only Correct Answer: FERPA, because student education or treatment records are excluded from
HIPAA PHI
Explanation: Health records maintained by a FERPA-covered postsecondary institution about its student patients are generally education records or treatment records under FERPA and are excluded from the HIPAA denition of PHI. HIPAA may still apply to records of nonstudent patients if the institution is a covered entity.Page 3