Health IT Policy and Governance Flashcards
7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Health IT Policy and Governance flashcards as text
Which federal agency oversees the ONC Health IT Certification Program?
Answer: Office of the National Coordinator for Health Information Technology
ONC (Office of the National Coordinator for Health Information Technology) administers the health IT certification program established under the HITECH Act.
The 21st Century Cures Act provision on information blocking prohibits actors from practices that are likely to interfere with which of the following?
Answer: Access, exchange, or use of electronic health information
The 21st Century Cures Act's information blocking rule prohibits practices that interfere with the access, exchange, or use of electronic health information (EHI).
Under HIPAA, which of the following is considered a covered entity?
Answer: A health plan that pays for medical services
Health plans that pay for medical services are classified as covered entities under HIPAA and must comply with its Privacy and Security Rules.
Which governance framework is commonly used for IT risk management and aligns with healthcare organizations' IT governance needs?
Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used in healthcare IT governance to align IT with business objectives and manage risk.
What does the Stark Law primarily regulate in healthcare?
Answer: Physician self-referral to entities with financial relationships
The Stark Law (Physician Self-Referral Law) prohibits physicians from referring patients to entities with which the physician has a financial relationship, unless an exception applies.
In health IT governance, a Steering Committee is primarily responsible for which function?
Answer: Prioritizing and approving IT investments aligned with organizational strategy
An IT Steering Committee provides governance by prioritizing IT investments, approving projects, and ensuring alignment with organizational strategic goals.
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule applies specifically to which type of information?
Answer: Electronic protected health information (ePHI)
The HIPAA Security Rule applies specifically to electronic protected health information (ePHI), requiring administrative, physical, and technical safeguards.