CHPS validates deep, U.S. healthcare-specific privacy and security expertise for roughly $259, while CIPM validates globally applicable privacy program management skill for $550, and the choice comes down to whether your career is anchored specifically in U.S. healthcare or needs to travel across industries and jurisdictions.
The direct answer: Choose CHPS, AHIMA’s Certification in Healthcare Privacy and Security, if your work is specifically U.S. healthcare privacy, HIPAA compliance, breach response, and OCR enforcement, and you plan to stay in the healthcare sector. Choose CIPM, IAPP’s Certified Information Privacy Manager, if you want a credential that works across any industry and any jurisdiction, or if your healthcare organization operates internationally and needs GDPR-level privacy program management, not just HIPAA. Many senior healthcare privacy officers eventually hold both. Full official details live on AHIMA’s CHPS certification page and IAPP’s CIPM certification page.
CHPS vs CIPM at a Glance
| Detail | CHPS | CIPM |
| Full name | Certified in Healthcare Privacy and Security | Certified Information Privacy Manager |
| Issuing body | AHIMA | IAPP |
| Industry scope | U.S. healthcare specifically | Any industry, globally applicable |
| Regulatory focus | HIPAA, U.S. healthcare law | No single jurisdiction, program management framework applicable under GDPR, CCPA, or any regional law |
| Cost, exam | Approximately $259, member rate | $550 |
| Question count | Domain-weighted, 3.5-hour exam | 90 questions |
| Duration | 3.5 hours | 150 minutes, 2.5 hours |
| Domains | 4 | 6 |
| Renewal | Continuing education cycle through AHIMA | $250 every 2 years, or waived with active IAPP membership |
| Active holder population | 715 as of December 31, 2025 | Far larger, CIPM is one of the most widely held privacy credentials globally |
Important: CHPS costs less than half of CIPM’s exam fee, but that gap reflects genuinely different scope, not a value judgment. CHPS goes deep on one country’s healthcare regulatory framework. CIPM goes broad across privacy program management principles applicable anywhere, in any industry, under any privacy law.
What CHPS Actually Tests
CHPS is built around the operational and regulatory demands of protecting patient information within U.S. healthcare specifically.
| Domain | Focus |
| Risk assessment and management | Healthcare-specific risk analysis methodology, including the four-factor breach risk assessment |
| Security policy and enforcement | Developing and maintaining organizational privacy and security policy |
| Regulatory compliance | HIPAA Privacy and Security Rule specifics, OCR enforcement patterns, business associate agreement structure |
| Breach response and incident handling | Managing and reporting actual privacy and security incidents under U.S. healthcare law |
Key point: Every domain in CHPS assumes you are operating specifically within U.S. healthcare regulation. There is no equivalent domain for GDPR, no coverage of international data transfer mechanisms, and no content addressing privacy frameworks outside HIPAA and adjacent U.S. healthcare law.
What CIPM Actually Tests
CIPM is built around the discipline of operating any organization’s privacy program, regardless of industry or which specific privacy law applies.
| Domain | Focus |
| Developing a Framework | Creating a company vision, structuring the privacy team, defining program scope |
| Establishing Program Governance | Privacy policy frameworks, stakeholder communication, defining metrics |
| Assessing Data | Documenting your organization’s privacy baseline, vendor and processor assessments |
| Protecting Personal Data | Data life cycle management, information security practices, Privacy by Design |
| Sustaining Program Performance | Ongoing measurement, auditing, alignment, monitoring |
| Responding to Requests and Incidents | Data subject access requests, breach response, regulatory reporting obligations |
Note: CIPM tests operational and managerial judgment, not memorization of a specific law. A healthcare organization operating only in the United States can apply CIPM’s framework using HIPAA as the underlying regulation, while a healthcare organization operating in the EU applies the identical framework using GDPR instead. This portability is CIPM’s core value proposition, and it is exactly what CHPS does not offer.
Cost Breakdown
Required Costs
| Item | CHPS | CIPM |
| Exam fee | Approximately $259, member rate | $550 |
| Retake fee | Contact AHIMA directly for current retake pricing | $375 |
Strongly Recommended Supplementary Costs
| Item | CHPS | CIPM |
| Official study materials | Approximately $110 for the official exam prep book | $75 for the official textbook, $55 for the official practice exam |
| Structured prep program | $500 to $700 for AHIMA’s cohort program | Varies by third-party provider |
| Membership, if joining first | AHIMA membership required for member-rate pricing | $295 per year for IAPP professional membership |
Renewal Costs
| Item | CHPS | CIPM |
| Renewal structure | Periodic continuing education through AHIMA | $250 every 2 years, waived entirely with active IAPP membership |
The honest total: A CHPS candidate using AHIMA’s cohort program spends roughly $370 to $970 all in. A CIPM candidate paying for membership, the exam, and official study materials spends roughly $845 to $975. The two land in a similar realistic total range once you account for CIPM’s membership discount on the biennial maintenance fee, even though CIPM’s sticker exam price is more than double CHPS’s.
CHPS and CIPM Cost Outside the United States
| Region | CHPS (approximate) | CIPM (approximate) |
| United States | $259 | $550 |
| United Kingdom | Limited availability, CHPS is U.S.-focused | £450 |
| European Union | Limited relevance, U.S. regulatory focus | €465 |
| India | Limited availability | ₹45,600 |
| Canada | Limited availability | $745 CAD |
Note: CHPS is built specifically around U.S. healthcare regulation and is rarely pursued or recognized outside the United States for that reason. CIPM, by contrast, is priced and delivered globally through Pearson VUE testing centers, reflecting its industry- and jurisdiction-agnostic design.
Who Should Pursue CHPS, and Who Should Pursue CIPM
Privacy or compliance officers working exclusively at U.S. hospitals or health systems. CHPS’s deep HIPAA-specific content maps directly onto daily responsibilities in a way a globally applicable credential cannot match at the same price point.
Privacy managers at healthcare organizations operating internationally, or considering a move outside healthcare. CIPM’s portability across GDPR, CCPA, and any other privacy framework makes it the stronger long-term investment if your career might not stay confined to U.S. healthcare specifically.
HIM professionals who already hold RHIA or RHIT and want to specialize in privacy within their existing healthcare career track. CHPS, built by the same organization, is the more natural next step. For the full context on why CHPS has become the standard healthcare privacy and security credential following HCISPP’s retirement, see our HCISPP vs CHPS guide.
Privacy professionals building a broad, portable privacy career that happens to currently include healthcare. CIPM is the stronger choice, and pairing it with CIPP for jurisdiction-specific legal depth is a common, well-recognized combination. See our CIPP vs CIPM comparison if you are still deciding between IAPP’s two flagship credentials specifically.
Common Mistakes When Choosing Between CHPS and CIPM
Assuming CIPM’s higher price means it is the objectively better credential. It is not inherently better, it is broader. If your career is genuinely confined to U.S. healthcare, CHPS’s lower cost and deeper regulatory specificity may serve you better despite the price difference.
Pursuing CHPS assuming it has any relevance outside U.S. healthcare regulation. It does not cover GDPR, CCPA, or any framework beyond HIPAA and adjacent U.S. healthcare law, making it a poor fit for anyone whose privacy work spans multiple jurisdictions.
Underestimating CIPM’s applicability within healthcare specifically. Some healthcare privacy professionals assume CIPM is built for non-healthcare industries and skip it, missing that its framework applies directly to healthcare privacy programs, it simply is not healthcare-exclusive the way CHPS is.
Forgetting that CHPS eligibility requires healthcare-specific experience. General IT security or general compliance experience does not qualify you for CHPS, unlike CIPM, which has no formal prerequisite at all.
Assuming these two credentials compete rather than complement. Many senior healthcare privacy officers hold both, using CHPS to demonstrate deep U.S. healthcare regulatory expertise and CIPM to demonstrate broader, internationally portable program management skill.
Frequently Asked Questions
What is the difference between CHPS and CIPM?
CHPS validates U.S. healthcare-specific privacy and security expertise, built around HIPAA. CIPM validates globally applicable privacy program management skill, usable across any industry and any jurisdiction’s privacy law.
Which is cheaper, CHPS or CIPM?
CHPS, at approximately $259 for the exam versus CIPM’s $550, though CIPM’s biennial maintenance fee is fully waived with active IAPP membership, narrowing the realistic total cost gap over time.
Can I hold both CHPS and CIPM?
Yes, and many senior healthcare privacy officers do, particularly those at organizations operating internationally or those who want both deep U.S. healthcare regulatory expertise and broader, portable privacy program management credibility.
Is CIPM relevant if I only work in healthcare?
Yes. CIPM’s privacy program management framework applies directly to healthcare privacy programs, it is simply not exclusively built around healthcare the way CHPS is, and it remains fully applicable if your healthcare organization operates under GDPR or other non-U.S. privacy frameworks.
Does CHPS work outside the United States?
Not well. CHPS is built specifically around U.S. healthcare regulation, particularly HIPAA, and has limited relevance or recognition for privacy work governed by other countries’ healthcare or data protection laws.
Which certification is easier to qualify for?
CIPM has no formal prerequisite. CHPS requires specific healthcare privacy or security experience through one of AHIMA’s approved education-and-experience combinations, making it harder to qualify for despite its lower exam cost.
Which certification is better for a Chief Privacy Officer track?
CIPM carries broader, more internationally recognized weight for a CPO-track role, particularly at larger or multinational organizations, while CHPS strengthens a CPO candidacy specifically within U.S. healthcare-focused organizations.
How many domains does each exam cover?
CHPS covers 4 domains focused on U.S. healthcare regulatory compliance. CIPM covers 6 domains focused on privacy program development and the operational life cycle of assessing, protecting, sustaining, and responding.
Do both certifications require renewal?
Yes. CHPS renews through AHIMA’s continuing education cycle. CIPM renews every 2 years for a $250 fee, which is waived entirely if you maintain active IAPP membership.
Which certification should I get first if I plan to eventually hold both?
There is no strict required order, but professionals already working in U.S. healthcare often start with CHPS since it validates immediately applicable job skills, then add CIPM later for broader career portability.



