โ† All AHIC Flashcard Decks

Health IT Policy and Governance Flashcards

7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Health IT Policy and Governance flashcards as text
  1. The CMS Interoperability and Patient Access Final Rule requires payers to use which API standard to give patients access to their health data?

    Answer: FHIR-based Patient Access API

    The CMS rule mandates that payers implement FHIR-based Patient Access APIs so members can access their health information through third-party applications.

  2. Which of the following describes the 'minimum necessary' standard under HIPAA?

    Answer: Covered entities must limit PHI use and disclosure to the minimum needed to accomplish the intended purpose

    The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI access, use, and disclosure to what is needed for the specific purpose.

  3. In the context of health IT policy, what does 'meaningful use' refer to?

    Answer: Meeting specific criteria for EHR use that qualify providers for CMS incentive payments

    Meaningful Use was a CMS program (now part of Promoting Interoperability) that provided incentive payments to providers who used certified EHRs in specified, measurable ways.

  4. An organization is conducting a HIPAA Security Risk Analysis. Which element is REQUIRED as part of this assessment?

    Answer: Identifying threats and vulnerabilities to ePHI

    A required element of the HIPAA Security Rule is conducting a thorough risk analysis that identifies potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

  5. Which of the following is TRUE about de-identified data under HIPAA?

    Answer: It is no longer considered PHI and is not subject to HIPAA

    Under HIPAA, properly de-identified data is no longer considered PHI and can be used and disclosed without the restrictions that apply to identifiable health information.

  6. The role of a Chief Privacy Officer (CPO) in a healthcare organization primarily involves which responsibility?

    Answer: Overseeing compliance with privacy laws and policies protecting patient information

    The CPO is responsible for developing and enforcing organizational privacy policies, ensuring compliance with HIPAA and other privacy laws, and managing privacy risk.

  7. Under federal anti-kickback statutes, EHR donation arrangements between hospitals and physicians are permitted under a specific safe harbor. What key condition must be met?

    Answer: The physician recipient must not be in a position to make referrals to the donating entity

    The EHR donation safe harbor requires that the physician recipient not be in a position to make or influence referrals to the donor entity, among other conditions.