Study Guide

CHPC Study Guide: Mapping HIPAA Fact Patterns by Rule

A fact-pattern classification approach to CHPC preparation: route each scenario to the Privacy, Security, or Breach Notification Rule, then apply the governing exceptions.

Updated September 202611 min readStudy GuideHealth Care Admin Exam
Amelia Carter

Amelia Carter

Health Care Admin Exam Editorial Team

This guide teaches a rule-mapping method for the CHPC: classify each fact pattern by the HIPAA rule it triggers, name the exception that applies, and identify the compliance program artifact it touches. Two worked scenarios, a decision table, a scored drill, and an adaptable study sequence show the method in use. For administrative details of the credential itself, such as eligibility, scheduling, and fees, rely on the issuer's current materials at https://www.hcca-info.org/certifications rather than any third-party summary.

Route every fact pattern: Privacy Rule vs. Security Rule vs. Breach Notification Rule

Classify each scenario before answering: the Privacy Rule governs uses and disclosures of PHI in any form, the Security Rule governs safeguards for electronic PHI, and the Breach Notification Rule governs response after an impermissible event.

Practice a three-question routing step on every practice item. First, does the scenario describe a use or disclosure of information? That is Privacy Rule territory. Second, does it describe a safeguard, access control, device, or transmission of electronic data? That is Security Rule territory. Third, does it describe what happens after something improper has already occurred? That is Breach Notification territory. A misdirected email containing a spreadsheet of patient names touches all three: the safeguard failure is a security issue, the improper transmission is a disclosure, and the response duty is a breach question.

The routing step matters because each rule supplies different answers. The Privacy Rule asks whether a use or disclosure was permitted, authorized, or required. The Security Rule asks whether required and addressable safeguards were implemented and documented. The Breach Notification Rule asks whether a documented risk assessment rebuts the presumption of a breach. If you misroute a question at the start, every downstream answer choice looks plausible. Drill this by labeling ten mixed practice questions with the rule name before you attempt the answers.

  • Privacy Rule: who may use or receive PHI, under what conditions, and what patients can demand.
  • Security Rule: administrative, physical, and technical safeguards for electronic PHI.
  • Breach Notification Rule: assessment, documentation, and notification duties after an impermissible use or disclosure of unsecured PHI.
RuleGovernsCore question it asksTypical fact-pattern trigger
Privacy RuleUses and disclosures of PHI in any form, plus patient rightsWas this use or disclosure permitted, authorized, or required?Records sent to an employer; a marketing letter to former patients
Security RuleElectronic PHI safeguardsWere the required safeguards implemented and documented?Shared logins; an unencrypted portable device; missing audit controls
Breach Notification RulePost-incident responseIs there a low probability the PHI was compromised, and who must be notified?A lost laptop; a fax sent to a wrong recipient; a misfiled paper record

Distinguish treatment, payment, and operations from uses that need an authorization

Treatment, payment, and health care operations may proceed without patient authorization; most other uses and disclosures require a valid signed authorization, and several look-alike activities do not qualify as operations.

Health care operations is the broadest of the three permitted categories, covering quality assessment, training, business planning, and administrative activities, and it is also the category most often stretched to cover things it does not include. Marketing a product or service generally requires authorization even when a department frames it as wellness outreach, and a sale of PHI generally requires authorization with specific protections. Fundraising has its own separate limits. When you see a commercial purpose hidden inside operations language, trace who benefits financially before accepting the label.

A valid authorization has defined core elements: a specific description of the information, the identity of the disclosing and receiving parties, a description of the purpose, an expiration date or event, and the individual's signature and date, plus statements about the right to revoke, conditioning of treatment or payment, and the potential for redisclosure. When an answer choice offers an authorization, check each element rather than accepting the form because it looks official. A missing redisclosure statement or an expiration described only as 'valid indefinitely without event' signals a defective authorization.

Worked scenario: marketing disguised as health care operations

When a third party profits from patient contact, the activity is marketing, not operations, and it requires authorization subject to narrow exceptions such as face-to-face communication.

Scenario: a hospital foundation plans to hire a vendor to contact discharged cardiology patients by phone about a paid heart-coaching program, and the project lead tells the compliance analyst it is 'health care operations because it improves wellness.' The tempting mistake is to accept the operations label and approve the contact list without further review, since wellness framing sounds clinical. The better decision is to trace the money and the purpose: a third-party vendor profits from selling the program, so the communication is marketing and the patient list release requires a valid authorization meeting the core elements, subject only to narrow exceptions.

Why the distinction matters: approving it as operations would produce an impermissible disclosure of PHI to the vendor and an impermissible use for marketing, neither of which is cured by good intentions or a later authorization. In a paper scenario like this, the defensible analyst response has three parts: name the category the activity actually fits, identify the authorization requirement, and document the analysis in a written determination. Practicing that three-part response builds the habit of tracing who benefits financially, a skill that transfers directly to any scenario where operations language wraps around a commercial purpose.

Apply minimum necessary without blocking treatment or patient access

Limit uses, disclosures, and requests to the least PHI needed for the purpose, except for treatment, disclosures to the patient, uses under an authorization, and other defined exceptions.

Minimum necessary is a standard to be applied by role and purpose, not a blanket rule that shrinks every record. Treatment is expressly excluded, so a treating physician may access a full chart, while a billing clerk should see only the elements payment requires. Role-based access design is the operational expression of the standard: define job functions, map each to the data elements it needs, and configure systems accordingly. Psychotherapy notes carry an extra separation requirement, so they sit outside routine record access even for clinical staff who hold general privileges.

Apply the standard when reviewing outbound disclosures as well. If a disability determination requests dates of service and discharge status, releasing the entire record exceeds the purpose, but if the patient requests their own record, minimum necessary does not apply at all, because the patient is entitled to access. Note the conceptual contrast: the same request from two different requesters produces opposite answers, which is exactly why requester identity should be one of the first details you confirm in any access scenario. When auditing, sample access logs and compare the records touched against each user's documented job function, treating mismatches as training and sanction inputs rather than assuming misuse.

Handle patient rights correctly: access, amendment, and the accounting trap

Patients may access and copy their records, request amendment, receive an accounting of certain disclosures, seek restrictions, request confidential communications, and receive the notice of privacy practices.

Access and amendment differ in scope and in the grounds for denial. Access denials are narrow, covering items such as psychotherapy notes or information compiled for legal proceedings, and reviewable denials allow the patient to have the decision reviewed. Amendment may be denied on broader grounds, for example when the entity did not create the information or believes the record is accurate and complete, and a denial must let the patient file a statement of disagreement that stays with the record. Keep the two denial frameworks separate in your notes; blending them produces wrong answers in both directions.

The accounting of disclosures has a structural trap: it covers disclosures outside treatment, payment, and operations and outside disclosures made pursuant to an authorization, with a defined list of exceptions to those exclusions. A staff member who dutifully lists every treatment disclosure to other providers and every payment disclosure to the payer has misunderstood which disclosures are countable. Train yourself to filter each disclosure through three questions before it goes on an accounting: was it TPO, was it authorized, and does a specific exception bring it back in?

Worked scenario: the stolen laptop and the four-factor risk assessment

An impermissible use or disclosure of unsecured PHI is presumed a breach unless a documented four-factor assessment shows a low probability that the PHI was compromised.

Scenario: an unencrypted laptop holding 400 patients' names and diagnoses is stolen from a staff member's car. The tempting mistake is to close the file after the employee says 'I don't think anyone opened the files,' treating the absence of evidence as proof of no compromise. The better decision is to run the four factors in writing: the nature and extent of the PHI and its identifiability, who the unauthorized person was, whether the PHI was actually acquired or viewed, and the extent to which risk was mitigated. Since encryption would have made the PHI secured, the absence of encryption is itself a Security Rule finding to record.

Because the assessment cannot rebut the presumption on these facts, notification follows: the affected individuals without unreasonable delay and the Secretary. The media notification duty is a separate, general conditional: breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets serving that area, and this 400-patient scenario falls below that threshold, so media notice would not apply here. The lesson to carry into the exam is that the conclusion matters less than the documentation. A written four-factor analysis that ends in a no-breach conclusion is a defensible artifact; an undocumented hunch is not, and answer choices that skip the analysis should be eliminated on sight.

Scored fact-pattern drill, self-check rubric, and an adaptable study sequence

Run a weekly drill that classifies each practice question by rule, exception, and program artifact, then score yourself against a rubric before adding new content to your review.

The drill: take fifteen mixed practice questions each week and complete a four-column entry for every one: the rule it triggers, the exception or requirement that decides it, the compliance program artifact it touches (policy, training, business associate agreement, risk analysis, or sanction process), and the correct outcome. Expected observations: by the third week you should classify most items without rereading the stem, and your errors should shift from rule confusion to exception details, which tells you the routing layer is built and refinement can begin.

An adaptable sequence: spend the first stretch building the rule map and the TPO-versus-authorization categories; the second on patient rights and minimum necessary contrasts; the third drilling the four-factor breach assessment until you can write it from memory; the fourth on Security Rule safeguards, required versus addressable, and the enforcement structure; and the final stretch on program administration with full mixed sets. Treat self-check scores as learning milestones only, not predictions of a result. If a category stalls, return to the scenario table above and rebuild that row rather than rereading everything.

Readiness checks before you finish: you can state the four breach factors and produce a written conclusion for an invented scenario; you can list the core elements of a valid authorization and spot a defective one; you can sort ten mixed questions into Privacy, Security, and Breach correctly and explain each sort; you can identify which disclosures belong on an accounting and which are excluded; and you can explain why addressable does not mean optional in the Security Rule.

  • Rubric item 1: classification accuracy on mixed questions, with a written one-line rationale per item.
  • Rubric item 2: exception recall, checked by writing the deciding exception before revealing the answer key.
  • Rubric item 3: artifact linkage, naming the policy, agreement, or process the scenario implicates.
  • Milestone, not prediction: rubric self-check scores track study progress only.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for HCCA Certified in Healthcare Privacy Compliance (CHPC).

How should I study the Privacy Rule and Security Rule differently?
Privacy Rule content is organized around permitted uses, authorizations, and patient rights, so drill category boundaries and exceptions. Security Rule content is organized around administrative, physical, and technical safeguards and a documented risk analysis, so drill safeguard names, the required-versus-addressable distinction, and why addressable does not mean optional.
Do I need to memorize penalty dollar amounts?
Understand the tiered structure conceptually: penalties scale with culpability, from unknowing violations up to willful neglect, with per-violation and annual cap concepts, and business associates carry direct liability for the Security Rule. Current dollar amounts are adjusted over time, so verify figures with the official enforcement source rather than memorizing from a study aid.
What is the fastest way to spot the accounting-of-disclosures trap?
Filter every disclosure through three questions: was it for treatment, payment, or operations; was it made pursuant to an authorization; and does a specific exception bring it back into the accounting. TPO and authorized disclosures are generally excluded, so an accounting that lists routine treatment disclosures signals a misunderstanding of the rule.
How do HIPAA and state privacy law interact?
HIPAA sets a federal privacy floor, and state law that is more protective of privacy is not displaced by it. Keep the preemption concept general in your notes: federal rule first, then check whether state law offers greater protection or greater restrictions. Match the depth of state-law study to what your credential's current materials define as in scope.
When am I ready to stop content review and focus on practice?
When your drill rubric shows rule classification is automatic, your errors have shifted from category confusion to exception detail, and you can write the four-factor breach assessment and authorization elements from memory. At that point, shift time toward mixed scenario sets and use the section table to rebuild any rule row that keeps producing errors.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.