AHIC Health IT Policy and Governance 2 — Questions and Answers
Question 1: Which federal agency oversees the ONC Health IT Certification Program?
- Centers for Medicare & Medicaid Services
- Office of the National Coordinator for Health Information Technology (Correct answer)
- Agency for Healthcare Research and Quality
- Food and Drug Administration
Correct answer: Office of the National Coordinator for Health Information Technology
ONC (Office of the National Coordinator for Health Information Technology) administers the health IT certification program established under the HITECH Act.
Question 2: The 21st Century Cures Act provision on information blocking prohibits actors from practices that are likely to interfere with which of the following?
- Insurance billing for EHR services
- Access, exchange, or use of electronic health information (Correct answer)
- Telehealth reimbursement schedules
- Meaningful Use incentive payments
Correct answer: Access, exchange, or use of electronic health information
The 21st Century Cures Act's information blocking rule prohibits practices that interfere with the access, exchange, or use of electronic health information (EHI).
Question 3: Under HIPAA, which of the following is considered a covered entity?
- A medical equipment manufacturer
- A health plan that pays for medical services (Correct answer)
- An employer who offers a self-funded plan administered externally
- A cloud storage vendor with no PHI access
Correct answer: A health plan that pays for medical services
Health plans that pay for medical services are classified as covered entities under HIPAA and must comply with its Privacy and Security Rules.
Question 4: Which governance framework is commonly used for IT risk management and aligns with healthcare organizations' IT governance needs?
- TOGAF
- COBIT (Correct answer)
- PRINCE2
- Six Sigma
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used in healthcare IT governance to align IT with business objectives and manage risk.
Question 5: What does the Stark Law primarily regulate in healthcare?
- Data breach notification timelines
- Physician self-referral to entities with financial relationships (Correct answer)
- Electronic prescribing standards
- Interoperability mandates for hospitals
Correct answer: Physician self-referral to entities with financial relationships
The Stark Law (Physician Self-Referral Law) prohibits physicians from referring patients to entities with which the physician has a financial relationship, unless an exception applies.
Question 6: In health IT governance, a Steering Committee is primarily responsible for which function?
- Writing code for clinical systems
- Prioritizing and approving IT investments aligned with organizational strategy (Correct answer)
- Conducting HIPAA audits
- Managing the help desk ticket queue
Correct answer: Prioritizing and approving IT investments aligned with organizational strategy
An IT Steering Committee provides governance by prioritizing IT investments, approving projects, and ensuring alignment with organizational strategic goals.
Question 7: The Health Insurance Portability and Accountability Act (HIPAA) Security Rule applies specifically to which type of information?
- All patient information in any format
- Electronic protected health information (ePHI) (Correct answer)
- Paper-based medical records only
- De-identified patient data sets
Correct answer: Electronic protected health information (ePHI)
The HIPAA Security Rule applies specifically to electronic protected health information (ePHI), requiring administrative, physical, and technical safeguards.
Which federal agency oversees the ONC Health IT Certification Program?