← All AHIC Flashcard Decks

Health IT Policy and Governance Flashcards

7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Health IT Policy and Governance flashcards as text
  1. Which of the following best describes the purpose of the Common Rule (45 CFR Part 46) in health informatics research?

    Answer: It protects human research subjects by establishing requirements for informed consent and IRB review

    The Common Rule is the federal policy for the protection of human research subjects, requiring IRB oversight and informed consent for most federally funded research involving human participants.

  2. A healthcare organization wants to share patient data with a research institution. Under HIPAA, which mechanism allows this without individual patient authorization?

    Answer: A Data Use Agreement (DUA) for a limited data set

    A Data Use Agreement allows covered entities to share a limited data set (which excludes most direct identifiers) with researchers without individual patient authorization.

  3. In health IT policy, the term 'information governance' refers to which overarching concept?

    Answer: An organization-wide framework for managing health information as a strategic asset throughout its lifecycle

    Information governance is a comprehensive framework that encompasses the policies, standards, and processes for managing health information quality, integrity, and security across its entire lifecycle.

  4. Which federal law establishes patients' rights to access, inspect, and obtain copies of their protected health information?

    Answer: HIPAA Privacy Rule (45 CFR § 164.524)

    The HIPAA Privacy Rule at 45 CFR § 164.524 grants patients the right to access and obtain copies of their own PHI held by covered entities.

  5. Which of the following is the BEST example of a policy-level control for managing health IT governance?

    Answer: Establishing a formal IT project approval process with executive sign-off

    A formal IT project approval process with executive sign-off is a policy-level governance control that ensures organizational oversight and accountability for IT investments.

  6. The HITECH Act's Breach Notification Rule requires covered entities to notify affected individuals of a breach within how many days of discovery?

    Answer: 60 days

    The Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach.

  7. An organization is implementing a new telehealth platform. From a health IT governance perspective, which step should occur FIRST?

    Answer: Conduct a risk assessment and evaluate regulatory compliance requirements

    Governance best practice requires conducting a risk assessment and evaluating regulatory requirements (HIPAA, state telehealth laws, licensure) before vendor selection or implementation.

Health IT Policy and Governance Flashcards — AHIC Study Cards with Answers