Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

CHPC Certification: What It Is and Why Research Compliance Staff Pursue It

CHPC (Certified in Healthcare Privacy Compliance) is an HCCA/CCB credential for healthcare privacy-program operations. Here is what it covers and how it compares with CIP, CCRP, and CHRC for research staff.

CHPC, or Certified in Healthcare Privacy Compliance, is an individual professional certification administered by the Health Care Compliance Association (HCCA) through its accreditation arm, the Compliance Certification Board (CCB)®. It is one of a family of CCB credentials that also includes CHC (general healthcare compliance), CHRC (research compliance specifically), and CPCO (physician-practice compliance) — CHPC is the one focused specifically on privacy and data-protection compliance in a healthcare setting, most directly HIPAA.

For a hospital privacy officer, CHPC is a mainstream, expected credential. For research administration staff, it is a narrower and more deliberate choice: most people in HIPAA-and-research roles are not full-time privacy officers, and the generalist CHPC curriculum is built around covered-entity privacy operations, not research-specific mechanisms like waivers of authorization under 45 CFR 164.512(i), data use agreements, or de-identification for a specific study. This guide covers what CHPC actually is, what it takes to earn and maintain it, and — the part most generic coverage of CHPC skips — where it does and doesn’t fit into a research compliance career, compared with research-specific credentials like CIP, CCRP, and HCCA’s own CHRC.

What the CHPC credential covers

CHPC certifies competency across the operational domains of a healthcare privacy compliance program. Reporting aggregated from HCCA/CCB candidate materials and third-party credentialing summaries describes the exam content outline as spanning areas such as privacy standards and policy, program oversight and governance, workforce training and education, monitoring and auditing, vendor and business-associate screening, and investigations and discipline for privacy incidents. These are the mechanics of running a HIPAA privacy program: writing and maintaining policies, training a workforce, auditing access logs, vetting vendors who touch protected health information (PHI), and responding when something goes wrong.

None of that is research-specific by design — CHPC is built for the person who owns HIPAA privacy compliance across an entire covered entity (a hospital, health system, or health plan), not for someone whose privacy responsibilities are scoped to a research portfolio. That’s the key framing distinction for a research administrator evaluating whether it’s the right credential.

Eligibility, exam format, and maintenance

The figures below are drawn from HCCA/CCB candidate-handbook material and corroborating third-party credentialing summaries, not independently re-verified against a directly-fetched primary-source page this session (HCCA’s own certification pages returned an access-blocked response to automated fetch at time of writing) — treat the specifics as generally reliable but confirm current numbers directly at hcca-info.org/certification/become-certified/chpc before relying on them for an application or budget decision:

  • Eligibility: commonly reported as roughly one year of full-time work in a compliance-related position (or an equivalent number of hours of documented compliance-related job duties within a recent multi-year window), plus a required number of CCB-recognized continuing education units accrued before sitting the exam. HCCA/SCCE membership is not required to sit for or maintain a CCB certification.
  • Exam: reported as a timed, multiple-choice exam (commonly cited around 120 questions, a portion of which are unscored pretest items, within a roughly two-hour window), covering the domains described above.
  • Fee: reported in the low-to-mid hundreds of dollars, with a lower non-member rate for HCCA/SCCE members and a reduced re-exam fee within the eligibility window.
  • Recertification: reported as a roughly two-year cycle requiring a substantial block of continuing education units (commonly cited around 40) tied to the exam’s domain areas, consistent with CCB’s other individual certifications.

Because CCB periodically revises eligibility pathways, question counts, and fees, treat any number above as directional rather than exact, and confirm current requirements directly with HCCA/CCB before applying.

Why a research compliance professional would pursue CHPC specifically

Research staff who handle protected health information sit at an intersection: they operate under the HIPAA Privacy Rule as well as the Common Rule and institutional IRB oversight, and often under FDA regulations if the research involves an investigational product. A handful of scenarios make CHPC a genuinely relevant credential for this audience, not just an adjacent one:

  • Institutions where the privacy office and the research compliance office are combined or closely partnered. At many academic medical centers, one person or a small team is accountable for HIPAA compliance across both clinical operations and the research portfolio. CHPC signals command of the institution-wide privacy-program mechanics — policy, training, auditing, vendor/business-associate management — that a purely research-scoped credential doesn’t test.
  • Research use of PHI outside a specific protocol’s four corners. Preparatory-to-research activities, limited data sets with a data use agreement, and repository/biobank governance all involve privacy-program judgment calls (minimum necessary, accounting of disclosures, breach risk assessment) that sit closer to CHPC’s domain than to a study-level IRB credential’s.
  • Career positioning toward a director-level research compliance or privacy-and-research-compliance role. A combined CHPC plus a research-specific credential (see below) demonstrates both sides of the job a hybrid role actually requires: institution-wide privacy-program governance and study-level human-subjects/regulatory literacy.

Conversely, if the role is squarely IRB coordination, protocol-level regulatory support, or clinical trial coordination with no institution-wide privacy-program ownership, a research-specific credential is almost always the better first (or only) certification — CHPC’s generalist privacy-program content will be less directly applicable day to day.

CHPC compared with research-specific credentials

CHPC is frequently confused with, or asked about alongside, several credentials that are built specifically for research roles. They are not interchangeable, and a research administrator choosing between them should be clear on the difference in scope:

  • CHRC (Certified in Healthcare Research Compliance) — also an HCCA/CCB credential, but its content outline is built around research compliance specifically: human subjects protection, research billing compliance, conflicts of interest, grants management, and research-specific regulatory frameworks (FDA, NIH, OHRP). For a research compliance office that is NOT also running general HIPAA privacy operations, CHRC is the closer match to day-to-day duties than CHPC is.
  • CIP (Certified IRB Professional) — administered by the Council for Certification of IRB Professionals (CCIP) under PRIM&R, not HCCA/CCB. It certifies competency specifically in human research protection program (HRPP) and IRB operations: protocol review, informed consent, vulnerable-population protections, and the regulatory framework governing IRBs. Eligibility is commonly described as a bachelor’s degree plus two years of relevant HRPP experience (or three years without the degree), with a 130-question, three-hour exam and three-year recertification cycle. CIP is the standard credential for IRB coordinators, analysts, and administrators; CHPC does not test IRB operations at all.
  • CCRP (Certified Clinical Research Professional) — administered by SOCRA, this credential is aimed at clinical research coordinators and associates running or monitoring trial conduct under Good Clinical Practice, not privacy-program administration. See CASRAI’s CRA certification guide for how CCRP compares with ACRP’s CCRA/CCRC credentials for clinical trial staff specifically.

A useful way to think about the distinction: CIP and CCRP certify competency in running research under human-subjects and GCP regulatory frameworks; CHRC certifies competency in running a research compliance program; CHPC certifies competency in running a privacy program. Research staff whose job is substantially about protecting and governing PHI used in or generated by research — rather than running the studies themselves — are the group for whom CHPC is a genuinely relevant, rather than merely adjacent, credential.

Where CHPC fits in a research compliance career path

In practice, CHPC tends to show up in research-adjacent careers in one of two patterns: as a credential added later by someone who started in general healthcare privacy and moved into a research-heavy institution (an academic medical center privacy officer whose portfolio grew to include IRB-adjacent PHI governance, secondary-use data requests, and biobank/repository oversight), or as a second credential added by a research compliance professional who has taken on institution-wide privacy-program responsibilities alongside their research duties. It is less commonly a first credential for someone starting a research administration career from scratch — for that path, a research-specific credential (CIP for IRB/HRPP roles, CCRP/CCRA for clinical trial coordination, or CHRC for research compliance broadly) more directly matches entry-level job requirements.

Frequently asked questions

Is CHPC the right certification for a research administrator?

Only if the role includes meaningful ownership of institution-wide HIPAA privacy-program operations — policy, training, auditing, vendor management — alongside or instead of study-level research duties. If the role is IRB coordination, protocol regulatory support, or clinical trial coordination without broader privacy-program ownership, CIP, CCRP/CCRA, or CHRC are typically the closer fit.

Does CHPC require HCCA membership?

No. Membership in HCCA or its sister association SCCE is not required to sit for or maintain a CCB certification, though members typically pay a reduced exam fee.

How is CHPC different from CHRC?

Both are CCB/HCCA credentials, but CHPC’s content outline covers general healthcare privacy-program operations (principally HIPAA), while CHRC’s content outline is built specifically around research compliance — human subjects protection, research billing, conflicts of interest, and grants-related regulatory requirements. A research compliance office not also responsible for institution-wide privacy operations will usually find CHRC the closer match.

Can someone hold both CHPC and a research-specific credential like CIP or CHRC?

Yes, and it is a common pattern for professionals in hybrid privacy-and-research-compliance roles at academic medical centers, where the two credentials cover genuinely non-overlapping competency domains rather than duplicating each other.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →