AHIC Health IT Policy and Governance 3 — Questions and Answers
Question 1: Which of the following best describes a Business Associate Agreement (BAA) under HIPAA?
- A contract between two competing health plans
- A legal agreement requiring vendors handling PHI to meet HIPAA privacy and security standards (Correct answer)
- A government mandate for EHR interoperability
- An internal policy document for workforce training
Correct answer: A legal agreement requiring vendors handling PHI to meet HIPAA privacy and security standards
A BAA is a contract between a covered entity and a business associate that specifies how PHI will be protected in accordance with HIPAA requirements.
Question 2: The HITECH Act enhanced HIPAA by doing which of the following?
- Replacing HIPAA entirely with new privacy law
- Strengthening enforcement, increasing penalties, and extending HIPAA obligations to business associates (Correct answer)
- Eliminating patient access rights to medical records
- Creating a new federal health records system
Correct answer: Strengthening enforcement, increasing penalties, and extending HIPAA obligations to business associates
HITECH strengthened HIPAA by increasing civil penalties, requiring breach notifications, and directly applying HIPAA security requirements to business associates.
Question 3: Which of the following is an example of an administrative safeguard under the HIPAA Security Rule?
- Installing firewalls on servers
- Conducting regular workforce security training (Correct answer)
- Using encryption on mobile devices
- Placing physical locks on server rooms
Correct answer: Conducting regular workforce security training
Workforce security training is an administrative safeguard — policies and procedures designed to manage the selection, development, and training of the workforce.
Question 4: What is the primary purpose of a health IT governance charter?
- To document all software bugs in a system
- To define the authority, scope, and responsibilities of the IT governance body (Correct answer)
- To serve as the official EHR user manual
- To satisfy Joint Commission accreditation requirements
Correct answer: To define the authority, scope, and responsibilities of the IT governance body
A governance charter formally establishes the mandate, structure, roles, and decision-making authority of a governance committee or board.
Question 5: Under the ONC's interoperability framework, FHIR (Fast Healthcare Interoperability Resources) serves primarily as which of the following?
- A privacy regulation for telehealth
- A standard for electronic health data exchange using modern web APIs (Correct answer)
- A reimbursement methodology for EHR vendors
- A clinical decision support algorithm
Correct answer: A standard for electronic health data exchange using modern web APIs
FHIR is an HL7 standard that uses RESTful APIs to enable the exchange of healthcare information in modern, interoperable formats.
Question 6: Which principle of healthcare data governance ensures that data is accurate, complete, and reliable for decision-making?
- Data sovereignty
- Data quality (Correct answer)
- Data minimization
- Data portability
Correct answer: Data quality
Data quality in governance refers to the accuracy, completeness, consistency, and reliability of data used for clinical and administrative decision-making.
Question 7: A hospital's IT governance board must decide between two EHR upgrade proposals. The BEST governance practice is to evaluate proposals based on which primary criteria?
- Vendor relationship history and volume discounts
- Alignment with strategic goals, cost-benefit analysis, and risk assessment (Correct answer)
- The preferences of the highest-ranking physician
- Time required for IT staff to learn the new system
Correct answer: Alignment with strategic goals, cost-benefit analysis, and risk assessment
Sound IT governance requires evaluating proposals against strategic alignment, return on investment, and risk to make objective, organization-wide decisions.
Which of the following best describes a Business Associate Agreement (BAA) under HIPAA?