HCISPP is being sunset by ISC2, with its final exam delivered December 1, 2023 and the credential going fully inactive on December 1, 2026, which leaves CHPS, AHIMA’s Certification in Healthcare Privacy and Security, as the only currently obtainable healthcare-specific privacy and security certification of the two.
The direct answer: You cannot earn HCISPP anymore. New candidates should pursue CHPS, which costs roughly $259 for AHIMA members, covers 4 domains, and remains the active, growing credential in this space. If you already hold HCISPP, it stays listed on your ISC2 profile but loses active certified status after December 1, 2026, so you should plan your next move now rather than after that date arrives. Full official details are on AHIMA’s CHPS certification page and ISC2’s HCISPP sunset notice.
HCISPP vs CHPS at a Glance
| Detail | HCISPP | CHPS |
| Status | Sunset, final exam December 1, 2023, inactive December 1, 2026 | Active, currently the only obtainable credential of the two |
| Issuing body | ISC2 | AHIMA |
| Domains | 7 | 4 |
| Exam duration | 3 hours | 3.5 hours |
| Cost | No longer available to earn | Approximately $259 for AHIMA members |
| Passing score | 700 out of 1000 | 300, scaled |
| Focus | Broad security and privacy combining technical cybersecurity skills with healthcare privacy | Heavy emphasis on U.S. healthcare law, privacy regulation, and compliance management |
| Active holder population | Declining, no new candidates since 2023 | 715 active holders as of December 31, 2025, up from 666 at end of 2023 |
Important: If you are researching this pairing because you found HCISPP mentioned in an older guide, job posting, or study forum, know that the information is outdated. ISC2 stopped accepting new HCISPP candidates over 2 years before this guide was published, and the credential formally loses active status in just a few months.
Why HCISPP Was Sunset
Key point: ISC2 has not published extensive public reasoning for the HCISPP sunset, but the pattern is consistent with broader consolidation across ISC2’s certification catalog, where lower-volume, narrower-scope credentials get folded into or replaced by more actively maintained alternatives. HCISPP combined general cybersecurity fundamentals with healthcare-specific privacy content across 7 domains, effectively duplicating ground that CISSP already covers at a broader level while adding healthcare context that CHPS, a purpose-built healthcare credential from AHIMA, already served more directly.
What CHPS Actually Tests
CHPS validates the ability to protect patient information and maintain regulatory compliance across a healthcare organization’s privacy and security program.
| Domain | Focus |
| Domain content areas, 4 total | Risk assessment methodology, security policy development and enforcement, HIPAA and regulatory compliance, breach response and incident handling |
Note: The four-factor breach risk assessment, the specific HIPAA Security Rule risk analysis requirement under §164.308(a)(1)(ii)(A), OCR enforcement patterns, and business associate agreement structure are consistently cited by recent CHPS candidates as the material demanding the deepest study time. This reflects CHPS’s core positioning: less about generic security theory and more about the specific regulatory mechanics of U.S. healthcare privacy law.
CHPS Eligibility Requirements
| Path | Requirement |
| Education plus experience combinations | AHIMA accepts 6 different combinations, all requiring healthcare-specific privacy or security experience, not generic IT security or general compliance work |
| Degree requirement | A relevant field, Health Information Management, Health Informatics, Information Technology, or similar |
| Prior credential path | Some paths accept holding another AHIMA credential, such as RHIA or RHIT, combined with relevant experience |
Important: AHIMA is specific that qualifying experience must be in healthcare privacy or security work directly. General IT security experience at a non-healthcare organization, or general healthcare experience without a privacy or security component, does not satisfy CHPS eligibility. Verify your specific path against AHIMA’s current published eligibility requirements before applying, since third-party sites sometimes cite outdated experience minimums.
CHPS Cost and Preparation
| Cost Item | Amount |
| Exam fee, AHIMA member | Approximately $259 |
| Official CHPS Exam Preparation book | Approximately $110 |
| Cohort-based prep program | Roughly $500 to $700 |
| Third-party practice question banks | $30 to $100 |
The honest total: Most candidates preparing seriously spend $300 to $900 depending on how much structured prep they use. The cohort-based prep program shows a striking difference in outcomes, an 81 percent pass rate among cohort participants versus 48 percent for candidates who prepare independently, making it one of the stronger prep investments available for this specific credential.
What If You Already Hold HCISPP
| Situation | What Happens |
| You hold active HCISPP today | It remains on your ISC2 profile but loses active certified status after December 1, 2026 |
| You want to maintain active healthcare privacy and security credentialing | Pursue CHPS as your forward path, since no direct ISC2 replacement has been announced |
| You hold HCISPP alongside CISSP | CISSP remains fully active and unaffected, HCISPP’s sunset does not touch your other ISC2 credentials |
Note: ISC2 has not announced a direct successor credential to HCISPP as of publication. Professionals who built their healthcare security specialization around HCISPP should treat CHPS as the practical forward path, even though it comes from a different certifying body with a somewhat different focus, more regulatory and compliance-heavy, less generalist cybersecurity theory.
Who Should Pursue CHPS
Privacy officers and compliance managers at hospitals or health systems. CHPS’s regulatory depth, HIPAA specifics, OCR enforcement patterns, breach response mechanics, maps directly onto the daily responsibilities of this role.
HIM professionals expanding into privacy and security specifically. If you already hold RHIA or RHIT and want to specialize further into the privacy and security side of health information management, CHPS is a natural next credential built by the same organization.
IT security professionals moving into healthcare specifically. If your background is general cybersecurity and you are transitioning into a healthcare-focused role, CHPS demonstrates the healthcare-specific regulatory knowledge that a general security background alone does not prove. For a broader look at how CHPS and other AHIMA credentials fit together, see our Best Paying Healthcare Certifications guide.
CHPS is a weaker fit if your role is purely general cybersecurity with no healthcare-specific regulatory component, in which case CISSP or a broader security credential likely serves you better than a healthcare-specific niche credential.
Common Mistakes When Researching This Space
Assuming HCISPP is still available because it appears in older study guides, forums, or job postings. The final exam was administered December 1, 2023, and the credential itself becomes fully inactive December 1, 2026.
Confusing CHPS eligibility with general healthcare or general IT experience. AHIMA requires experience specifically in healthcare privacy or security work, and applications built on adjacent but non-qualifying experience get denied.
Underestimating the regulatory depth CHPS requires. Candidates coming from a general cybersecurity background sometimes underestimate how much of the exam focuses on specific HIPAA mechanics and OCR enforcement patterns rather than generic security principles.
Assuming a direct ISC2 replacement for HCISPP exists. As of publication, none has been announced. CHPS is the practical path forward, but it comes from a different organization with a different exam structure and focus.
FAQS
Can I still get HCISPP certified?
No. ISC2 administered the final HCISPP exam on December 1, 2023, and no new candidates can earn the credential. It becomes fully inactive on December 1, 2026.
What replaced HCISPP?
ISC2 has not announced a direct successor. AHIMA’s CHPS has become the practical standard for healthcare-specific privacy and security certification, though it comes from a different certifying body with a different structure.
What happens to my HCISPP certification after December 1, 2026?
It remains listed on your ISC2 profile but loses active certified status. Your other ISC2 credentials, such as CISSP, are unaffected.
How much does CHPS cost?
Approximately $259 for AHIMA members for the exam alone. Total preparation costs, including study materials or a cohort prep program, typically run $300 to $900.
How many domains does the CHPS exam cover?
4 domains, covering risk assessment, security policy development, regulatory compliance, and breach response and incident handling.
What is the CHPS pass rate?
Approximately 68 percent overall, though candidates who use AHIMA’s cohort-based prep program report an 81 percent pass rate versus 48 percent for those preparing independently.
Do I need a specific degree for CHPS eligibility?
AHIMA accepts several education-plus-experience combinations. A degree in Health Information Management, Health Informatics, or Information Technology satisfies the education component for most paths, combined with qualifying healthcare privacy or security experience.
Is CHPS harder to qualify for than it is to pass?
For many candidates, yes. AHIMA’s eligibility requirements specifically demand healthcare privacy or security experience, not general IT security or general healthcare experience, which disqualifies more candidates at the application stage than the exam itself does.
How many people currently hold CHPS?
715 active holders as of December 31, 2025, up from 666 at the end of 2023, a small but growing population that reflects the credential’s specialized, healthcare-specific focus.
Should I pursue CHPS if I already hold CISSP?
Yes, if your work involves healthcare-specific privacy and security responsibilities. CISSP validates broad security management competence, while CHPS validates the specific regulatory and compliance knowledge unique to U.S. healthcare privacy law, and the two credentials complement rather than duplicate each other.



