Preview real exam-style questions before you buy—see exactly what you're getting.
Free sample questions with detailed explanations • No signup required.
The Certified in Healthcare Privacy and Security (CHPS) exam evaluates your ability to apply healthcare privacy, security, compliance, and information governance principles in practical situations—not simply recall definitions. That’s why this practice exam focuses on realistic scenarios, analytical thinking, and decision-making skills that closely reflect the challenges faced by today’s healthcare privacy professionals. Whether you’re pursuing CHPS certification for career advancement or professional development, this comprehensive practice test is designed to help you prepare with confidence.
The best way to prepare is to study the concepts and practice with realistic exam questions. This CHPS Practice Test is designed to help you build confidence before exam day by exposing you to the types of scenarios and decisions you are likely to encounter on the actual certification exam.
Whether you are taking the CHPS exam for the first time or preparing for a retake, this practice exam helps you identify weak areas, strengthen your knowledge, and improve your readiness with comprehensive explanations for every question.
What’s Included in This CHPS Practice Exam
Designed to support your certification journey from start to finish, this practice exam provides comprehensive study material that helps you strengthen your knowledge, improve decision-making skills, and build confidence before exam day.
Features Included
- 1,030 original CHPS practice questions covering the major certification domains
- Detailed answer explanations for every question to reinforce learning
- Case-based and scenario-driven questions that mirror real healthcare environments
- Executive-level decision-making exercises focused on privacy and security leadership
- Coverage of current healthcare privacy and security topics, including emerging technologies
- Questions aligned with current CHPS exam objectives and professional practice
- Realistic multiple-choice exam format to help you become comfortable with the testing style
- Unlimited online access so you can study anytime and review difficult topics as often as needed
- Self-paced learning that fits your personal study schedule
- Instant digital access immediately after purchase
Topics Covered
This practice exam provides broad coverage of the major knowledge areas commonly expected on the Certified in Healthcare Privacy and Security examination, including:
- Healthcare Privacy Programs
- HIPAA Privacy Rule
- HIPAA Security Rule
- HIPAA Breach Notification Rule
- Information Governance
- Healthcare Compliance
- Privacy Risk Assessment
- Security Risk Analysis
- Enterprise Risk Management
- Privacy Program Leadership
- Healthcare Cybersecurity
- Data Governance
- Identity and Access Management
- Healthcare AI Governance
- Responsible Artificial Intelligence
- Cloud Security
- Vendor and Third-Party Risk Management
- Business Associate Agreements
- OCR Investigations
- Healthcare Incident Response
- Business Continuity Planning
- Disaster Recovery
- Workforce Privacy Training
- Privacy by Design
- Audit and Monitoring
- Executive Governance
- Strategic Risk Management
- Data Classification
- Records Management
- Regulatory Compliance
- Healthcare Leadership
Why Trust This Practice Exam?
Passing the CHPS exam requires more than remembering definitions. You need to understand how privacy and security principles apply in real healthcare environments.
That is why this practice exam focuses on practical decision-making instead of repetitive recall questions.
Our questions are written to reflect situations that healthcare privacy officers, compliance managers, information governance leaders, HIM professionals, and healthcare security teams encounter in daily practice.
Every explanation is designed to strengthen understanding so you can confidently apply privacy, security, governance, and compliance principles during the certification exam.
How We Develop Our CHPS Practice Questions
Quality matters when preparing for a professional certification exam.
Our development process emphasizes accuracy, relevance, and practical application.
Each question is carefully created through a structured review process that includes:
- Alignment with current CHPS exam objectives
- Coverage of all major knowledge domains
- Realistic healthcare scenarios
- Executive-level decision-making situations
- Privacy and security best practices
- Information governance concepts
- Emerging healthcare technologies
- Current cybersecurity challenges
- Clear explanations for every answer
- Multiple quality assurance reviews before publication
Rather than recycling publicly available questions, we focus on creating original practice material that helps learners understand concepts and build long-term knowledge.
Realistic Exam Experience
The questions are designed to simulate the style and difficulty of the actual CHPS examination.
You’ll practice with:
- Case-based questions
- Scenario-driven questions
- Executive leadership situations
- Healthcare compliance investigations
- Privacy incident response
- OCR audit scenarios
- Governance decision-making
- Risk management exercises
- Vendor oversight situations
- Healthcare cybersecurity events
- AI governance cases
- Business continuity planning
This realistic approach helps reduce exam anxiety while improving critical thinking and decision-making skills.
Who Should Use This CHPS Practice Test?
This study resource is ideal for professionals preparing for the Certified in Healthcare Privacy and Security certification, including:
- Healthcare Privacy Officers
- HIM Professionals
- Compliance Officers
- Healthcare Security Professionals
- Information Governance Specialists
- Health Information Managers
- Risk Managers
- Healthcare Compliance Analysts
- Privacy Analysts
- Healthcare Consultants
- Healthcare IT Professionals
- Hospital Administrators
- Clinical Compliance Leaders
- Internal Auditors
- Professionals seeking CHPS certification
Whether you are preparing independently or as part of an employer-sponsored certification program, these practice questions provide valuable exam preparation.
Improve Your Exam Readiness
Reading study materials is important, but applying knowledge through practice questions helps reinforce learning and identify areas that need additional review.
Working through a large question bank allows you to:
- Measure your current knowledge
- Identify weak topics
- Improve analytical thinking
- Strengthen HIPAA understanding
- Practice executive decision-making
- Increase confidence before exam day
- Become familiar with question wording
- Improve time management during the exam
How to Study for the CHPS Exam
A well-structured study plan is one of the most effective ways to prepare for the Certified in Healthcare Privacy and Security exam. Instead of trying to memorize regulations or definitions, focus on understanding how privacy, security, compliance, and information governance principles are applied in real healthcare settings. Combining regular practice with careful review of answer explanations helps reinforce concepts, improve critical thinking, and build the confidence needed to answer scenario-based questions.
Recommended Study Strategy
- Begin with one exam domain at a time instead of studying every topic at once.
- Complete a set of practice questions under timed conditions to simulate the real exam.
- Carefully review every explanation, including questions you answered correctly.
- Keep a list of topics that require additional review and revisit them regularly.
- Focus on understanding the reasoning behind each correct answer rather than memorizing it.
- Practice case-based and executive decision-making questions to strengthen analytical skills.
- Schedule short, consistent study sessions throughout the week instead of cramming before the exam.
- Reattempt previously missed questions until you can explain the correct answer confidently.
- Review HIPAA Privacy Rule, HIPAA Security Rule, Information Governance, Enterprise Risk Management, and healthcare compliance concepts together since they are closely connected.
- Take several full-length practice sessions before your exam to improve speed, accuracy, and confidence.
Consistent practice is more valuable than studying for long hours only occasionally. By working through realistic exam questions and understanding the reasoning behind each answer, you’ll strengthen your decision-making skills and be better prepared for the types of scenarios commonly presented on the CHPS certification exam.
Common Mistakes to Avoid During CHPS Exam Preparation
Many candidates have a solid understanding of healthcare privacy and security concepts but still lose valuable points because of their study approach or exam strategy. Recognizing these common mistakes early can help you use your study time more effectively and improve your overall exam performance.
Mistakes That Can Affect Your Score
- Studying only the HIPAA Privacy Rule while overlooking Security Rule and Information Governance topics.
- Memorizing practice questions instead of understanding the underlying concepts.
- Skipping detailed answer explanations after completing practice questions.
- Ignoring scenario-based questions that require critical thinking and practical decision-making.
- Spending too much time on topics you already know while avoiding weaker areas.
- Waiting until the last few days before the exam to complete practice tests.
- Rushing through questions without carefully reading every answer choice.
- Failing to understand the responsibilities of privacy officers, compliance professionals, and healthcare security leaders.
- Neglecting newer topics such as AI governance, cloud security, vendor risk management, and enterprise risk management.
- Taking only one practice test instead of measuring improvement through repeated practice.
Successful CHPS candidates typically focus on understanding principles rather than memorizing answers. Reviewing mistakes, practicing regularly, and learning how privacy, security, governance, and compliance work together in real healthcare environments will help you approach the certification exam with greater confidence and a stronger foundation.
Start Preparing for Your CHPS Certification Today
If you’re serious about earning your Certified in Healthcare Privacy and Security (CHPS) credential, consistent practice is one of the most effective ways to prepare.
This 1,030-question CHPS Practice Test gives you extensive opportunities to strengthen your knowledge of HIPAA, healthcare privacy, security, information governance, enterprise risk management, compliance, cybersecurity, and emerging healthcare technologies.
Practice regularly, review every explanation carefully, and build the confidence you need to approach exam day prepared. Get instant access today and start practicing with one of the most comprehensive CHPS practice question collections available.
CHPS Sample Questions and Answers
Question 1
A hospital is implementing a new electronic health record (EHR) system. Before the system goes live, the privacy officer recommends conducting a comprehensive review to identify potential risks to electronic protected health information (ePHI). Which HIPAA Security Rule requirement is being fulfilled?
A. Workforce sanction policy
B. Security risk analysis
C. Business associate agreement review
D. Patient authorization verification
Correct Answer: B. Security risk analysis
Explanation:
The HIPAA Security Rule requires covered entities to perform a thorough risk analysis before implementing systems that create, receive, maintain, or transmit electronic protected health information (ePHI). A risk analysis identifies vulnerabilities, evaluates the likelihood and impact of threats, and determines appropriate safeguards to reduce risks to a reasonable level. Conducting this assessment before deploying a new EHR allows the organization to address security gaps proactively rather than after an incident occurs. While workforce sanctions, business associate agreements, and patient authorizations are important compliance activities, they do not replace the mandatory requirement to perform a formal security risk analysis.
Question 2
A physician accesses the medical record of a celebrity admitted to the hospital, even though the physician is not involved in the patient’s care. No information is disclosed to anyone else. Which statement best describes this action?
A. It is acceptable because no information was shared externally.
B. It is permitted if the physician is employed by the hospital.
C. It is an unauthorized access and violates the HIPAA Privacy Rule.
D. It is allowed if the patient is a public figure.
Correct Answer: C. It is an unauthorized access and violates the HIPAA Privacy Rule.
Explanation:
HIPAA requires workforce members to access only the protected health information necessary to perform their assigned job duties. Simply viewing a patient’s record without a legitimate treatment, payment, or healthcare operations purpose constitutes unauthorized access, regardless of whether the information is disclosed to another person. Hospitals routinely monitor audit logs to detect inappropriate access, particularly involving high-profile patients. Employees who improperly access records may face disciplinary action, termination, civil penalties, or even criminal consequences. Employment status or a patient’s public profile does not grant permission to view confidential health information.
Question 3
A healthcare organization stores patient information in a cloud-based platform managed by an outside technology company. Which action is most important before uploading protected health information?
A. Purchase cyber insurance.
B. Execute a Business Associate Agreement (BAA).
C. Notify every patient individually.
D. Register the vendor with the state licensing board.
Correct Answer: B. Execute a Business Associate Agreement (BAA).
Explanation:
When a third-party vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity, HIPAA generally requires a Business Associate Agreement (BAA). The agreement establishes each party’s responsibilities for protecting PHI, reporting security incidents, and complying with applicable HIPAA requirements. Without a valid BAA, the covered entity may face compliance violations even if the vendor has strong technical security controls. Although cyber insurance and vendor oversight are valuable risk management practices, executing a compliant BAA is a fundamental legal requirement before sharing PHI with a qualified business associate.
Question 4
During an annual security assessment, an organization discovers that several terminated employees still have active user accounts that can access electronic health records. Which security principle has been compromised?
A. Data integrity
B. Availability
C. Access control
D. Data retention
Correct Answer: C. Access control
Explanation:
Access control ensures that only authorized individuals can access electronic protected health information. User accounts belonging to terminated employees should be disabled immediately as part of the organization’s workforce termination procedures. Leaving accounts active creates unnecessary security risks, including unauthorized access, data theft, or accidental system changes. Effective identity and access management includes timely account provisioning, deactivation, periodic access reviews, and the principle of least privilege. Although integrity and availability are important elements of information security, the primary issue in this scenario is the failure to properly manage user access.
Question 5
A ransomware attack encrypts multiple hospital servers containing electronic protected health information. The organization immediately activates backup systems, isolates affected devices, and begins restoring operations. Which component of the security program is being implemented?
A. Contingency planning
B. Workforce sanction policy
C. Minimum necessary standard
D. Patient accounting of disclosures
Correct Answer: A. Contingency planning
Explanation:
Contingency planning prepares healthcare organizations to continue critical operations during emergencies such as ransomware attacks, natural disasters, or system failures. Under the HIPAA Security Rule, contingency planning includes data backup procedures, disaster recovery plans, emergency mode operations, testing, and revision of recovery processes. Activating backup systems and restoring services demonstrates that the organization has prepared for operational disruptions. Modern ransomware attacks have made contingency planning one of the most critical cybersecurity functions in healthcare because patient care often depends on continuous access to electronic health information.
Question 6
A privacy officer reviews employee access logs every month to identify unusual viewing patterns, excessive record access, or unauthorized activity. What is the primary purpose of this practice?
A. Improve network speed
B. Monitor compliance and detect inappropriate access
C. Reduce storage costs
D. Eliminate duplicate patient records
Correct Answer: B. Monitor compliance and detect inappropriate access
Explanation:
Routine audit log monitoring is a key administrative safeguard under the HIPAA Security Rule. Reviewing access logs helps organizations identify suspicious behavior, inappropriate employee access, compromised user accounts, and potential insider threats before significant harm occurs. Audit reviews also support regulatory compliance by demonstrating ongoing oversight of protected health information. Organizations should establish procedures for investigating anomalies, documenting findings, and taking corrective action when necessary. Regular monitoring strengthens accountability and serves as an effective deterrent against unauthorized access to sensitive patient information.
Question 7
A healthcare organization requires employees to authenticate using a password and a one-time verification code sent to a secure mobile application before accessing the EHR remotely. Which security safeguard is being used?
A. Data masking
B. Multifactor authentication (MFA)
C. Network segmentation
D. Encryption at rest
Correct Answer: B. Multifactor authentication (MFA)
Explanation:
Multifactor authentication (MFA) strengthens security by requiring users to provide two or more independent forms of verification before access is granted. Typically, this includes something the user knows, such as a password, combined with something they possess, such as a mobile authentication application or hardware token. MFA significantly reduces the risk of unauthorized access caused by stolen or compromised passwords and has become a cybersecurity best practice across healthcare organizations. Although HIPAA does not explicitly require MFA in every situation, it is widely recommended to protect remote access to electronic protected health information.
Question 8
A nurse accidentally emails a patient’s laboratory results to the wrong recipient outside the organization. What should occur first according to an effective incident response program?
A. Permanently delete all email accounts.
B. Assess and contain the incident.
C. Wait to determine whether the recipient responds.
D. Notify local media immediately.
Correct Answer: B. Assess and contain the incident.
Explanation:
The first priority during a privacy or security incident is to assess the situation and take immediate steps to contain any potential exposure of protected health information. This may include contacting the unintended recipient, requesting secure deletion, determining whether the information was accessed, and documenting the incident. After containment, the organization evaluates whether the event meets the definition of a reportable breach under HIPAA’s Breach Notification Rule. Prompt assessment helps minimize harm, supports regulatory compliance, and provides the information needed for appropriate notification and corrective action.
Question 9
A healthcare system is assigning user permissions for its electronic health record. Registration clerks can update demographic information but cannot view clinical notes or laboratory results. Which HIPAA concept does this demonstrate?
A. Data mining
B. Minimum necessary standard
C. Open access policy
D. Data portability
Correct Answer: B. Minimum necessary standard
Explanation:
The HIPAA Privacy Rule requires covered entities to limit the use, access, and disclosure of protected health information to the minimum necessary to accomplish a legitimate job function, except in specific situations such as treatment. Role-based access controls are one of the most effective ways to implement this requirement by restricting employees to only the information needed for their responsibilities. Registration staff generally need demographic information but not detailed clinical records. Applying the minimum necessary principle reduces privacy risks while supporting efficient healthcare operations.
Question 10
Following a comprehensive cybersecurity assessment, a healthcare organization identifies several high-risk vulnerabilities but has limited financial resources. What should leadership do first?
A. Correct every vulnerability simultaneously.
B. Ignore low-cost security improvements.
C. Prioritize remediation based on risk.
D. Delay all corrective actions until the next audit.
Correct Answer: C. Prioritize remediation based on risk.
Explanation:
Risk management focuses on reducing the greatest threats to electronic protected health information using available organizational resources. After completing a risk analysis, leadership should prioritize remediation based on the likelihood that a vulnerability will be exploited and the potential impact on patient information, operations, and regulatory compliance. High-risk vulnerabilities should be addressed first, while lower-risk issues can be scheduled according to available resources. A documented, risk-based remediation strategy demonstrates due diligence and aligns with the HIPAA Security Rule’s requirement to implement reasonable and appropriate safeguards rather than attempting to eliminate every possible risk immediately.
Question 11
A healthcare organization hires an outside company to destroy paper medical records that have reached the end of their retention period. Which responsibility remains with the covered entity under HIPAA?
A. None, because record destruction has been outsourced.
B. Ensure the vendor follows applicable privacy and security requirements.
C. Transfer all HIPAA liability to the destruction company.
D. Notify every patient before records are destroyed.
Correct Answer: B. Ensure the vendor follows applicable privacy and security requirements.
Explanation:
Outsourcing a service does not transfer a covered entity’s HIPAA responsibilities. If a vendor handles protected health information (PHI), the organization must verify that appropriate safeguards are in place and execute a Business Associate Agreement (BAA) when required. The covered entity should also evaluate the vendor’s security practices, confirm that records are destroyed using approved methods such as cross-cut shredding or secure incineration, and maintain documentation of the destruction process. Proper vendor oversight reduces the risk of unauthorized disclosure and demonstrates compliance during regulatory audits.
Question 12
A hospital plans to launch a patient portal that allows individuals to view laboratory results, schedule appointments, and communicate with providers. Which security feature should be prioritized to protect patient accounts?
A. Disable password expiration.
B. Require multifactor authentication for portal access.
C. Allow users to share login credentials with family members.
D. Permit unlimited unsuccessful login attempts.
Correct Answer: B. Require multifactor authentication for portal access.
Explanation:
Patient portals provide convenient access to health information but are frequent targets for cybercriminals attempting account takeover attacks. Multifactor authentication (MFA) significantly reduces the likelihood of unauthorized access by requiring users to verify their identity using two or more authentication factors. Combined with strong password policies, account lockout controls, encrypted communications, and session timeouts, MFA helps protect sensitive patient information from credential theft and phishing attacks. As healthcare organizations continue expanding digital services in 2026, MFA is considered one of the most effective security controls for protecting online patient accounts.
Question 13
Following a phishing attack, investigators determine that an employee unknowingly entered login credentials into a fraudulent website. Which corrective action is most likely to reduce similar incidents in the future?
A. Increase printer security.
B. Conduct targeted workforce security awareness training.
C. Reduce password length requirements.
D. Eliminate email communication.
Correct Answer: B. Conduct targeted workforce security awareness training.
Explanation:
Human error remains one of the leading causes of healthcare security incidents. Regular security awareness training teaches employees how to recognize phishing emails, suspicious links, social engineering attempts, fraudulent websites, and other common cyber threats. Effective programs include simulated phishing exercises, real-world examples, reporting procedures, and periodic refresher sessions. Although technical safeguards such as email filtering are important, well-trained employees provide an essential layer of defense. Continuous education helps build a culture of security awareness and significantly reduces the organization’s overall cybersecurity risk.
Question 14
A hospital performs quarterly reviews comparing employee job responsibilities with assigned system permissions. What is the primary purpose of this review?
A. Increase internet bandwidth.
B. Validate that access privileges remain appropriate.
C. Improve software licensing compliance.
D. Shorten patient registration times.
Correct Answer: B. Validate that access privileges remain appropriate.
Explanation:
Periodic access reviews ensure employees retain only the system permissions necessary to perform their current job duties. As employees change positions, receive promotions, transfer departments, or leave the organization, access rights should be updated promptly. Regular reviews help identify excessive privileges, inactive accounts, segregation-of-duty conflicts, and unauthorized access that may otherwise go unnoticed. Maintaining appropriate access controls supports the HIPAA Security Rule, strengthens organizational security, and reduces the risk of insider threats or accidental disclosure of protected health information.
Question 15
A covered entity determines that an unauthorized individual viewed unencrypted electronic protected health information. After completing a formal risk assessment, investigators conclude there is a significant probability the information has been compromised. What should occur next?
A. Permanently delete the affected records.
B. Follow the HIPAA Breach Notification Rule requirements.
C. Wait until the annual compliance audit.
D. Notify only internal employees.
Correct Answer: B. Follow the HIPAA Breach Notification Rule requirements.
Explanation:
When a breach of unsecured protected health information is confirmed, HIPAA requires covered entities to comply with the Breach Notification Rule. After completing the required risk assessment, organizations must provide timely notification to affected individuals and, when applicable, notify the Department of Health and Human Services (HHS) and, in certain circumstances, the media. Proper documentation, mitigation efforts, and corrective actions are also essential components of breach management. Prompt notification promotes transparency, allows affected individuals to protect themselves from potential harm, and demonstrates regulatory compliance.
Question 16
A healthcare organization encrypts all electronic protected health information stored on laptops and mobile devices. What is the primary security benefit of encryption?
A. It eliminates the need for employee training.
B. It renders stored data unreadable without authorized decryption.
C. It permanently prevents all cyberattacks.
D. It removes the need for access controls.
Correct Answer: B. It renders stored data unreadable without authorized decryption.
Explanation:
Encryption protects electronic protected health information by converting readable data into an unreadable format that can only be accessed using an authorized cryptographic key. If an encrypted laptop or mobile device is lost or stolen, the information remains protected from unauthorized viewing, greatly reducing the likelihood of a reportable breach. Encryption is considered an addressable implementation specification under the HIPAA Security Rule, meaning organizations should implement it whenever reasonable and appropriate. Combined with strong authentication and device management, encryption provides a critical safeguard against data loss.
Question 17
A healthcare organization classifies patient medical records as “Highly Confidential,” while internal administrative documents are classified as “Internal Use Only.” What is the primary purpose of data classification?
A. Increase internet performance.
B. Apply security controls based on the sensitivity of information.
C. Reduce the number of employee accounts.
D. Eliminate the need for document retention policies.
Correct Answer: B. Apply security controls based on the sensitivity of information.
Explanation:
Data classification enables organizations to categorize information according to its sensitivity, regulatory requirements, and business value. Once classified, appropriate security measures such as encryption, access restrictions, monitoring, retention schedules, and disposal procedures can be applied consistently. Highly confidential information, including protected health information, generally requires stronger safeguards than routine administrative documents. An effective classification program supports information governance, improves compliance with HIPAA requirements, and helps organizations allocate security resources where they are needed most.
Question 18
An employee reports that a laptop containing electronic protected health information has been stolen from a locked vehicle. Which action should occur immediately after the report is received?
A. Ignore the incident if the laptop belonged to an employee.
B. Initiate the organization’s incident response procedures.
C. Wait until law enforcement completes its investigation.
D. Purchase replacement equipment before conducting an assessment.
Correct Answer: B. Initiate the organization’s incident response procedures.
Explanation:
Every suspected security incident involving protected health information should trigger the organization’s established incident response process. Immediate actions include documenting the event, determining whether encryption was enabled, remotely disabling or wiping the device when possible, assessing the information at risk, notifying appropriate leadership, and preserving evidence for investigation. Delaying the response can increase organizational risk and complicate compliance with HIPAA breach notification requirements. A structured incident response process helps contain potential damage, supports regulatory obligations, and improves overall organizational resilience.
Question 19
During an internal audit, a compliance officer discovers that several employees completed mandatory HIPAA privacy training more than three years ago and have received no refresher education since then. What is the most appropriate recommendation?
A. Eliminate annual privacy training requirements.
B. Provide ongoing privacy and security education at regular intervals.
C. Limit training to newly hired employees only.
D. Require training only after a breach occurs.
Correct Answer: B. Provide ongoing privacy and security education at regular intervals.
Explanation:
Privacy and security training should be an ongoing process rather than a one-time event. Cyber threats, regulatory expectations, organizational policies, and healthcare technologies continue to evolve, making periodic refresher training essential. Regular education reinforces employees’ understanding of HIPAA requirements, secure handling of protected health information, phishing awareness, password security, incident reporting, and emerging cybersecurity risks. Organizations that invest in continuous workforce education strengthen compliance, reduce preventable security incidents, and foster a culture of privacy and accountability throughout the organization.
Question 20
A healthcare organization’s executive leadership is reviewing annual privacy and security objectives. Which metric would provide the most meaningful measure of the effectiveness of its information security program?
A. Number of desktop computers purchased.
B. Number of employee parking spaces.
C. Trends in security incidents, risk remediation, audit findings, and compliance performance.
D. Total pages printed during the year.
Correct Answer: C. Trends in security incidents, risk remediation, audit findings, and compliance performance.
Explanation:
Effective information security programs rely on measurable performance indicators rather than assumptions. Leadership should evaluate metrics such as the number and severity of security incidents, vulnerability remediation rates, audit findings, workforce training completion, phishing simulation results, access review outcomes, and compliance with HIPAA requirements. Analyzing trends over time helps determine whether security controls are improving organizational resilience and reducing risk. These metrics also support strategic decision-making, resource allocation, and continuous improvement, ensuring the privacy and security program remains aligned with evolving healthcare threats and regulatory expectations.
Question 21
A large academic medical center recently acquired three outpatient specialty clinics. During post-acquisition integration, the CHPS professional discovers that one clinic stores scanned insurance cards and driver’s licenses in a shared cloud folder accessible by every employee, including scheduling staff, billing clerks, volunteers, and temporary workers. The folder has been used this way for several years because it is considered “convenient.”
No inappropriate access has yet been identified.
The Chief Operating Officer asks whether the organization should immediately notify affected patients.
What is the MOST appropriate recommendation?
A. Notify every patient immediately because any security weakness automatically constitutes a reportable breach.
B. First conduct a documented risk assessment to determine whether unauthorized acquisition, access, use, or disclosure occurred before deciding whether breach notification requirements apply.
C. Delete the cloud folder immediately without documenting the issue.
D. Wait until regulators identify the problem during an audit.
Correct Answer: B
Explanation:
A security weakness alone does not necessarily constitute a reportable breach. The Privacy Rule and Breach Notification Rule require organizations to evaluate whether protected health information (PHI) was actually compromised. The CHPS professional should coordinate a documented risk assessment examining who had access, whether inappropriate access occurred, the sensitivity of the information, audit log evidence, workforce roles, and the probability that PHI was compromised. Only after completing this assessment can the organization determine whether notification obligations exist. Immediate notification without evidence could create unnecessary legal and reputational consequences, while delaying evaluation would violate sound incident response practices.
Question 22
During the quarterly Enterprise Risk Committee meeting, the board requests funding for only one of the following cybersecurity initiatives due to budget limitations.
- Replace aging firewalls.
- Expand phishing awareness training.
- Implement privileged access management.
- Purchase a new compliance reporting dashboard.
Recent assessments identified administrator credential compromise as the organization’s highest cyber risk.
Which initiative should receive highest priority?
A. Compliance reporting dashboard
B. Phishing awareness training
C. Privileged Access Management implementation
D. Firewall replacement
Correct Answer: C
Explanation:
Risk-based governance requires investments to address the organization’s highest identified risks. Since privileged credential compromise represents the greatest enterprise risk, implementing Privileged Access Management (PAM) provides the largest reduction in organizational exposure. PAM limits standing administrative privileges, secures privileged credentials, records administrative sessions, supports just-in-time access, and reduces opportunities for attackers to gain persistent control. While firewall modernization and workforce education remain valuable, governance principles emphasize prioritizing investments according to documented enterprise risk assessments rather than general technology improvements.
Question 23
During an internal privacy audit, the following findings are reported:
| Finding | Number |
|---|---|
| Unauthorized record snooping | 2 |
| Unencrypted laptops | 0 |
| Shared user accounts | 14 |
| Missing annual privacy training | 5 |
| Improper record disposal | 1 |
Which finding presents the greatest governance concern?
A. Improper record disposal
B. Missing privacy training
C. Shared user accounts
D. Unauthorized record snooping
Correct Answer: C
Explanation:
Although every finding requires attention, shared user accounts undermine one of the most fundamental security principles—individual accountability. Without unique user identification, audit logs become unreliable, incident investigations are compromised, sanctions cannot be accurately applied, and regulatory compliance may be affected across multiple systems. Because this issue impacts authentication, accountability, and access control throughout the organization, it represents the highest governance priority despite the relatively small number of documented snooping incidents.
Question 24
A ransomware attack encrypts the hospital’s payroll system Friday evening.
Electronic health records remain fully operational.
The Chief Financial Officer insists on paying the ransom because employee payroll is due Monday morning.
Which response best reflects mature CHPS governance?
A. Pay immediately without consulting anyone.
B. Activate the organization’s incident response and business continuity plans, involve executive leadership, legal counsel, cybersecurity specialists, and evaluate recovery options before considering payment.
C. Shut down every clinical application.
D. Ignore the incident until payroll employees arrive Monday morning.
Correct Answer: B
Explanation:
Ransom decisions should never be made by a single executive under pressure. Mature governance requires activating established incident response procedures involving executive leadership, legal counsel, information security, business continuity teams, communications, and law enforcement where appropriate. Recovery alternatives, backup integrity, operational impact, legal considerations, sanctions compliance, cyber insurance requirements, and patient safety implications should all be evaluated before any decision regarding ransom payment is considered.
Question 25
Following a successful phishing attack, investigators discover:
- No MFA
- Weak password policy
- Delayed patching
- No email filtering
- No user awareness program
Which weakness should be addressed FIRST to provide the greatest immediate reduction in account compromise risk?
A. Replace employee laptops.
B. Implement multifactor authentication.
C. Purchase additional servers.
D. Increase internet bandwidth.
Correct Answer: B
Explanation:
Multifactor authentication provides one of the most effective immediate defenses against compromised credentials. Even if attackers obtain usernames and passwords through phishing, MFA significantly reduces the likelihood of successful account compromise. Although additional improvements such as email security, awareness training, and patch management remain essential, implementing MFA offers the most immediate reduction in credential-based attack risk.
Question 26
A hospital contracts with a third-party transcription company that qualifies as a Business Associate. The Business Associate discovers that an employee downloaded dictated reports containing PHI onto an unencrypted personal laptop before resigning. The laptop has not been recovered.
The Business Associate immediately notifies the hospital and begins an internal investigation.
As the hospital’s CHPS professional, what is the MOST appropriate next step?
A. Assume the Business Associate is solely responsible and take no further action.
B. Coordinate with the Business Associate to conduct a documented breach risk assessment, verify contractual obligations were followed, determine whether PHI was compromised, and prepare for any required notifications.
C. Immediately terminate the Business Associate without reviewing the facts.
D. Notify every patient before confirming whether the downloaded files contained PHI.
Correct Answer: B
Explanation:
Although the Business Associate is responsible for promptly reporting the incident, the covered entity remains accountable for understanding the event and ensuring appropriate HIPAA compliance. The CHPS professional should coordinate the investigation, verify the scope of the exposure, review contractual obligations, evaluate the probability that PHI has been compromised, and determine whether breach notification requirements apply. Decisions should be based on documented evidence rather than assumptions or automatic responses.
Question 27
During an OCR audit, investigators ask the organization to demonstrate how workforce members receive only the access necessary for their job responsibilities.
Which evidence would provide the STRONGEST support?
A. A documented role-based access control program with periodic access reviews, manager approvals, audit logs, and removal of unnecessary permissions.
B. Password complexity requirements.
C. Annual fire evacuation training.
D. Daily antivirus updates.
Correct Answer: A
Explanation:
OCR expects organizations to demonstrate that access to PHI is managed according to workforce roles and the minimum necessary principle. A mature access governance program includes documented role definitions, management approval workflows, periodic access certifications, audit logs, and prompt removal of unnecessary permissions. These controls help ensure workforce members receive only the access required to perform their assigned responsibilities.
Question 29
A 950-bed academic medical center recently completed a digital transformation initiative that included:
- Migration of its EHR to a cloud-hosted environment
- AI-assisted clinical documentation
- Remote patient monitoring
- Patient self-scheduling
- Expanded research partnerships
- Acquisition of three outpatient clinics
Six months later, Internal Audit reports the following observations:
- Each department performs its own privacy reviews.
- Vendor security assessments use different criteria.
- Data retention schedules differ between legacy hospitals.
- AI governance decisions are made by individual departments.
- Enterprise risks are reported differently across business units.
The CEO asks:
“What single governance initiative would most improve our ability to manage these issues?”
A. Purchase an enterprise SIEM platform.
B. Establish an enterprise-wide governance framework with standardized oversight, common policies, executive accountability, and multidisciplinary governance committees.
C. Increase password complexity requirements.
D. Require quarterly antivirus scans.
Correct Answer: B
Explanation:
The deficiencies described are governance failures rather than technology failures. Different departments are making independent decisions regarding privacy, AI, vendor management, retention, and risk reporting, creating inconsistency across the organization. An enterprise governance framework establishes standardized policies, executive accountability, multidisciplinary oversight, common risk methodologies, and coordinated decision-making. While technologies such as SIEM platforms provide valuable operational capabilities, they cannot resolve fragmented governance structures. Mature CHPS programs integrate governance across the enterprise rather than allowing isolated departmental practices.
Question 30
During the annual strategic retreat, the Board Chair asks:
“Cybersecurity spending has increased by 38% over four years. How do we know whether these investments are actually reducing organizational risk?”
Which response BEST demonstrates governance maturity?
A. Present trends showing reductions in enterprise risks, improvements in resilience, maturity assessment results, audit outcomes, and strategic risk indicators rather than simply reporting technology purchases.
B. Present the total number of firewall alerts.
C. Show how many passwords employees changed.
D. Count the number of laptops purchased.
Correct Answer: A
Explanation:
Boards evaluate outcomes rather than activities. Strategic reporting should demonstrate whether cybersecurity investments reduce enterprise risk, improve resilience, strengthen governance, support regulatory compliance, and protect patient care. Technology metrics are useful operationally but provide limited value for governance oversight unless translated into business impact.

