CHPS Pass Rate, Format & Study Guide
A real reference for anyone preparing for the Certified in Healthcare Privacy and Security (CHPS) — AHIMA exam — pass rate, retake policy, how it's scored, and a practical study timeline. This is independent reference content, not a sales page: everything below is sourced from CHPS's own certifying body.
What the CHPS exam is
The Certified in Healthcare Privacy and Security (CHPS) credential is administered by AHIMA (the American Health Information Management Association), an organization tracing its roots back to 1928, when the American College of Surgeons established the Association of Record Librarians of North America (ARLNA) to elevate the standards of clinical records in hospitals and other medical institutions — a lineage AHIMA has carried through several name changes as the profession itself evolved from paper medical-records management into today's much broader health information management discipline. CHPS specifically validates competency in designing, implementing, and administering comprehensive privacy and security protection programs across healthcare organizations — a genuinely specialized intersection of healthcare regulatory knowledge (particularly HIPAA) and information-security program management.
Why it matters
Healthcare data breaches and privacy violations carry real regulatory, financial, and reputational consequences for healthcare organizations, and dedicated privacy and security officer roles have grown substantially in importance as electronic health records, interoperability requirements, and cybersecurity threats have all increased the complexity of protecting patient health information. CHPS is AHIMA's credential specifically validating that a professional has command of both the healthcare-privacy regulatory landscape and the practical security-program-management skills needed to actually implement effective protections — a combination that distinguishes it from purely general information-security certifications that don't address healthcare-specific regulatory requirements, or purely compliance-focused credentials that don't address technical security-program management.
Who this exam is for
CHPS is for healthcare privacy and security officers, compliance professionals with a privacy/security focus, and health information management professionals moving into dedicated privacy/security roles. Given the credential's six distinct eligibility pathways (below), it's accessible to candidates from a genuinely wide range of educational backgrounds and prior credentials, provided their specific work experience has been in healthcare privacy or security specifically — not generic IT security or general compliance work that happens to touch healthcare tangentially.
Pass rate
AHIMA's own published first-time-taker pass rate: 68% in 2025 (107 test-takers), 65% in 2024 (97 test-takers).
If you don't pass — retake policy
Candidates who don't pass must wait 90 days before their retake application is approved, and must submit a new application along with the full exam fee again — there's no discounted retake rate.
How it's scored
Scored on a scaled system with a passing score of 300. Of the 150 total questions, only 125 are scored; the other 25 are unscored pretest items mixed in undetectably.
Format at a glance
The exam consists of 150 questions (125 scored, 25 unscored pretest items) administered over 3.5 hours.
- Ethical, Legal, and Regulatory Issues / Environmental Assessment25%
- Program Management and Administration25%
- Information Technology / Physical and Technical Safeguards25%
- Investigation, Compliance, and Enforcement25%
Full eligibility requirements and everything the CHPS study portal includes is on the CHPS product page.
What each domain actually tests
Per AHIMA's own official CHPS Exam Content Outline, the exam covers four domains that AHIMA publishes as ranges (23-27% each) rather than fixed exact percentages — meaning the domains are described as roughly, but not precisely, equally weighted, a real and deliberate distinction from a credential where all domains are stated as flat, identical percentages. The four domains span the core competencies of healthcare privacy and security program management: privacy program development and administration, security program development and administration, regulatory compliance (particularly HIPAA Privacy and Security Rules), and the operational/technical safeguards that protect patient health information in practice. Given the near-equal weighting across all four, comprehensive preparation across each domain matters more than concentrating study time on any single area.
Eligibility requirements, in full
AHIMA offers six distinct education-plus-experience eligibility pathways, all requiring the qualifying experience to be specifically in healthcare privacy or security work (not generic IT security or general compliance experience unrelated to healthcare's specific regulatory context). The pathways are: a high school diploma/GED plus 6 years of qualifying experience; an associate's degree in a relevant field plus 4 years; holding a CCA, CCS, CCS-P, or RHIT credential plus 4 years; a bachelor's degree in a relevant field plus 2 years; holding an RHIA credential plus 2 years; or a master's degree or higher (including a JD, MD, or PhD in a relevant field) plus just 1 year. Candidates should identify which specific pathway applies to their own background and confirm their qualifying experience genuinely was in healthcare privacy/security specifically, since that's the common thread across all six pathways regardless of the underlying education level.
What it actually costs
The exam fee is $259 for AHIMA members and $329 for non-members, and a retake — if a first attempt doesn't pass — costs the same amount as the initial exam, with no discounted retake pricing.
Keeping the credential — maintenance & recertification
CHPS certification runs on a 2-year renewal cycle, requiring certificants to submit the required amount of continuing education units (CEUs) and pay the recertification fee to maintain active status. AHIMA's current CE requirements (effective 2025) specify that at least 40% of a certificant's CEUs must come from AHIMA-produced content specifically, and at least 80% of CEUs must align with AHIMA's own health information and information management (HIIM) domains relevant to privacy, security, regulatory work, and information governance — meaning generic, unrelated continuing education won't satisfy the bulk of the requirement even if it technically counts as CE hours from some other source.
How to actually prepare
For a 125-scored-question, 3.5-hour exam spanning four equally-weighted domains (legal/regulatory, program management, IT/physical safeguards, investigation/compliance), 8-10 weeks of structured study is a reasonable default for a candidate already meeting the education-plus-experience eligibility bar, split evenly across the four domains with a final week of timed practice.
What's changing (2026)
AHIMA's CE-sourcing requirements for CHPS recertification (the 40%-AHIMA-content and 80%-HIIM-domain-alignment rules) took effect in 2025 — a real, dated tightening of what counts toward recertification compared to AHIMA's prior, looser CE-sourcing rules. Certificants approaching a 2026 renewal should confirm they're tracking CE activity against these current 2025-effective sourcing rules rather than an older, more permissive standard. No changes to the core 150-question/125-scored/3.5-hour exam format have been announced as of August 2026.
Want a full practice question bank built around this exact format?
See the CHPS study portal