AHIMA Registered Health Information Administrator Exam — Questions and Answers
Question 1: An HIM professional discovers that a physician has been signing blank medical record forms to be completed later by residents. This practice is:
- A violation of medical record integrity standards (Correct answer)
- Acceptable if the physician countersigns within 24 hours
- Required when residents lack independent credentials
- Permitted under Joint Commission safe harbor provisions
Correct answer: A violation of medical record integrity standards
Signing blank records is fraudulent and violates medical record integrity, authentication standards, and federal anti-fraud regulations.
Question 2: The primary goal of a sentinel event review under Joint Commission standards is to:
- Report findings to state licensing boards
- Identify systemic contributing factors and prevent recurrence (Correct answer)
- Assign individual accountability for adverse outcomes
- Document the event for malpractice defense purposes
Correct answer: Identify systemic contributing factors and prevent recurrence
A sentinel event root cause analysis (RCA) aims to uncover the underlying system failures that allowed the event to occur and implement corrective actions.
Question 3: Which data warehouse concept tracks historical changes to a dimension attribute, such as a patient's changing insurance plan over time?
- Bridge table design
- Star schema normalization
- Fact table partitioning
- Slowly Changing Dimension (SCD) (Correct answer)
Correct answer: Slowly Changing Dimension (SCD)
Slowly Changing Dimensions (SCDs) are warehouse techniques that preserve historical attribute values when a dimension record is updated, enabling accurate point-in-time historical analysis.
Question 4: According to the AHIMA Code of Ethics, when an employer directs an HIM professional to act in a manner that violates ethical principles, the professional should:
- Follow the employer's directive without question
- Ignore the directive and continue normal operations
- Immediately contact the media to report the issue
- Seek ethical guidance, document the conflict, and refuse to act unethically (Correct answer)
Correct answer: Seek ethical guidance, document the conflict, and refuse to act unethically
The AHIMA Code of Ethics requires professionals to uphold ethical standards even when they conflict with employer directives, documenting and escalating such conflicts appropriately.
Question 5: What is interoperability in healthcare IT?
- Connecting to the internet
- All hospitals using the same software
- Having multiple computer monitors
- The ability of different health IT systems to exchange and use information meaningfully (Correct answer)
Correct answer: The ability of different health IT systems to exchange and use information meaningfully
Interoperability enables different healthcare systems to share data in ways that can be understood and used, supporting coordinated care across organizations.
Question 6: What is an audit trail in health information?
- A patient walking route
- A hiking path through a hospital
- A chronological record showing who accessed, modified, or deleted data and when (Correct answer)
- A financial spreadsheet
Correct answer: A chronological record showing who accessed, modified, or deleted data and when
Audit trails create accountability by tracking all interactions with health data.
Question 7: Which federal law specifically prohibits offering or accepting remuneration to induce referrals for services covered by Medicare or Medicaid?
- False Claims Act
- Stark Law
- EMTALA
- Anti-Kickback Statute (Correct answer)
Correct answer: Anti-Kickback Statute
The Anti-Kickback Statute (42 USC 1320a-7b) prohibits knowingly offering, paying, soliciting, or receiving anything of value to induce or reward referrals of federal healthcare program business.
Question 8: What does an Accountable Care Organization (ACO) shared savings model incentivize?
- Care coordination and cost reduction below a benchmark, with shared savings distributed to providers (Correct answer)
- Hospital readmission rates as the sole quality metric
- Fee-for-service volume maximization among participating providers
- Capitation payments based on geographic enrollment panels
Correct answer: Care coordination and cost reduction below a benchmark, with shared savings distributed to providers
ACO shared savings models reward providers for coordinating care, improving quality, and keeping total costs below a pre-established benchmark.
Question 9: Which of the following best describes 'workforce' under HIPAA?
- Employees, volunteers, trainees, and others under the direct control of the covered entity (Correct answer)
- Only licensed healthcare professionals
- Only full-time employees of a covered entity
- Contractors who sign a BAA
Correct answer: Employees, volunteers, trainees, and others under the direct control of the covered entity
HIPAA defines workforce broadly to include all persons whose conduct is under the direct control of the covered entity, whether or not they are paid.
Question 10: In predictive modeling, 'overfitting' occurs when a model:
- Is applied to a patient population outside its originally intended scope
- Includes too few predictor variables to explain meaningful outcome variation
- Performs well on training data but poorly generalizes to new, unseen data (Correct answer)
- Is trained on a dataset too small to be statistically representative
Correct answer: Performs well on training data but poorly generalizes to new, unseen data
An overfitted model memorizes noise specific to the training sample, causing it to lose predictive accuracy when applied to new data—a critical risk in healthcare risk stratification models.
Question 11: Which of the following BEST describes 'information lifecycle management' in health information governance?
- Monitoring EHR vendor contract renewals
- Governing data from creation through use, storage, archiving, and destruction (Correct answer)
- Managing the career development of HIM professionals
- Tracking patient encounters across the care continuum
Correct answer: Governing data from creation through use, storage, archiving, and destruction
Information lifecycle management is the governance discipline that oversees data from the moment it is created through every stage until its authorized destruction.
Question 12: A telehealth platform must ensure video sessions are encrypted and patient privacy is protected. Which technical safeguard is MOST critical?
- End-to-end encryption of media streams (Correct answer)
- Automatic logoff after inactivity
- Role-based access to scheduling
- Audit logs of login attempts
Correct answer: End-to-end encryption of media streams
End-to-end encryption ensures that telehealth video and audio data cannot be intercepted or accessed by unauthorized parties during transmission.
Question 13: Ambulatory care professionals are more likely than acute care providers to use the information available in the ______________________.
- discharge summary
- transfer record
- interdisciplinary patient care plan
- problem list (Correct answer)
Correct answer: problem list
Ambulatory care professionals, who manage ongoing outpatient visits, rely heavily on a problem list to track a patient's chronic and acute health issues over time. This list provides a concise, longitudinal summary of all active and inactive problems, facilitating continuity of care and informed decision-making across multiple encounters. Acute care, being more episodic, focuses more on the immediate admission and discharge diagnoses.
Question 14: Which claim form is required for professional/physician billing to Medicare?
- CMS-1500 (Correct answer)
- HIPAA 837I
- UB-04
- ADA Dental Claim Form
Correct answer: CMS-1500
The CMS-1500 is the standard claim form used by non-institutional providers, including physicians, for professional billing to Medicare.
Question 15: A patient explicitly prohibits the sharing of their substance abuse treatment records through the HIE. Which federal regulation specifically restricts the disclosure of substance abuse treatment records?
- 21 CFR Part 11
- HIPAA Privacy Rule (45 CFR Part 164)
- 42 CFR Part 2 (Correct answer)
- 45 CFR Part 170
Correct answer: 42 CFR Part 2
42 CFR Part 2 imposes stricter confidentiality requirements on substance use disorder treatment records than HIPAA, requiring explicit patient consent for most disclosures.
Question 16: Which role is MOST accountable for the overall strategic direction of health information governance across an enterprise?
- Medical records technician
- Chief Information Governance Officer (CIGO) or equivalent executive (Correct answer)
- Release of information specialist
- Data steward
Correct answer: Chief Information Governance Officer (CIGO) or equivalent executive
A CIGO or equivalent executive-level role holds enterprise-wide accountability for the strategic direction, policies, and culture of information governance.
Question 17: A hospital's record retention policy must account for which special population that may require extended retention beyond standard adult periods?
- Patients with chronic conditions
- Minor patients, whose records are often retained until they reach the age of majority plus the standard retention period (Correct answer)
- Patients over age 65
- Patients who paid out-of-pocket
Correct answer: Minor patients, whose records are often retained until they reach the age of majority plus the standard retention period
Records for minors are typically retained until the patient reaches the age of majority plus the standard retention period, to preserve their future rights.
Question 18: Population health management analytics is designed primarily to:
- Streamline hospital billing and revenue cycle processing workflows
- Optimize scheduling efficiency for outpatient appointment booking systems
- Proactively identify health risks and manage outcomes for defined patient groups (Correct answer)
- Automate clinical documentation entry within the electronic health record
Correct answer: Proactively identify health risks and manage outcomes for defined patient groups
Population health management uses data analytics to stratify risk, coordinate care, and implement targeted interventions that improve outcomes and reduce costs across defined patient populations.
Question 19: The AHIMA Certified Coding Specialist (CCS) credential is primarily designed for professionals coding in which healthcare setting?
- Physician offices
- Long-term care facilities only
- Home health agencies
- Hospital and facility-based settings (Correct answer)
Correct answer: Hospital and facility-based settings
The CCS credential focuses on hospital and facility-based inpatient and outpatient coding using ICD-10 and CPT codes.
Question 20: Which ICD-10-CM coding guideline instructs coders to code conditions to the 'highest degree of certainty' for inpatient settings?
- The uncertain diagnosis guideline, allowing coding of conditions documented as 'possible' or 'probable' at discharge (Correct answer)
- The UHDDS rule
- The principal diagnosis selection rule
- The present on admission guideline
Correct answer: The uncertain diagnosis guideline, allowing coding of conditions documented as 'possible' or 'probable' at discharge
For inpatient coding, ICD-10-CM guidelines allow coding of conditions documented as 'possible,' 'probable,' or 'suspected' at the time of discharge if no definitive diagnosis is established.
Question 21: Incidence rate differs from prevalence in that incidence specifically measures:
- The mortality rate associated with a specific disease over a five-year window
- New cases of a condition arising within a specified population and time period (Correct answer)
- The total number of existing disease cases in a population at a single point in time
- The proportion of patients who recover from a disease within one year
Correct answer: New cases of a condition arising within a specified population and time period
Incidence counts new cases occurring during a defined time window, while prevalence counts all existing cases—both new and pre-existing—at a given moment.
Question 22: Under HIPAA, which of the following describes a Hybrid Entity?
- A covered entity with facilities in more than one state
- An organization that performs both covered and non-covered healthcare functions and designates its covered components (Correct answer)
- An organization that is both a covered entity and a business associate simultaneously
- An entity that uses both paper and electronic health records
Correct answer: An organization that performs both covered and non-covered healthcare functions and designates its covered components
A hybrid entity is a single legal entity that performs both HIPAA-covered and non-covered functions and formally designates its healthcare components.
Question 23: What is the primary purpose of a data dictionary in health information governance?
- To store patient demographic information
- To track employee access logs
- To manage release of information requests
- To define standard meanings and formats for data elements (Correct answer)
Correct answer: To define standard meanings and formats for data elements
A data dictionary provides standardized definitions, formats, and acceptable values for data elements to ensure consistent interpretation across the organization.
Question 24: An HIM professional who misrepresents their credentials on a job application has violated which core principle of the AHIMA Code of Ethics?
- Advocacy for patient rights
- Compliance with ICD-10 coding guidelines
- Honesty and integrity in professional conduct (Correct answer)
- Confidentiality of protected health information
Correct answer: Honesty and integrity in professional conduct
Falsifying or misrepresenting credentials violates the honesty and integrity principle of the AHIMA Code of Ethics.
Question 25: Which database model is best suited for storing and querying highly variable, unstructured patient-generated health data from wearables?
- Hierarchical
- Network model
- NoSQL document store (Correct answer)
- Relational (SQL)
Correct answer: NoSQL document store
NoSQL document stores like MongoDB handle schema-flexible, unstructured data efficiently, making them well suited for variable wearable device outputs.
Question 26: Which root operation in ICD-10-PCS describes cutting out or off, without replacement, a portion of a body part?
- Detachment
- Resection
- Destruction
- Excision (Correct answer)
Correct answer: Excision
Excision (value B) involves cutting out or off a portion of a body part without replacement.
Question 27: A p-value of 0.03 in a healthcare outcome study indicates:
- There is a 3% probability that the treatment was effective
- The result is statistically significant at the 0.05 alpha level (Correct answer)
- The sample size was too small for valid conclusions
- The finding has strong clinical significance
Correct answer: The result is statistically significant at the 0.05 alpha level
A p-value of 0.03 falls below the conventional 0.05 significance threshold, indicating the result is statistically significant, though this does not automatically imply clinical significance.
Question 28: Which statistical measure is most resistant to outliers when analyzing patient length-of-stay data?
- Mean
- Variance
- Median (Correct answer)
- Standard deviation
Correct answer: Median
The median is the middle value of an ordered dataset and is unaffected by extreme outliers, making it more reliable than the mean for skewed distributions like length of stay.
Question 29: What is 'query compliance' in CDI practice?
- The rate at which physicians respond to queries
- The number of queries issued per 100 discharges
- Adherence to established guidelines ensuring queries are non-leading, clinically supported, and properly documented (Correct answer)
- The percentage of queries that result in a higher MS-DRG
Correct answer: Adherence to established guidelines ensuring queries are non-leading, clinically supported, and properly documented
Query compliance refers to following established industry guidelines to ensure queries are ethical, non-leading, clinically supported, and appropriately formatted.
Question 30: Encoding software was deployed at your facility two years ago. The coders are well-trained in it and like utilizing it. It works great and just requires ICD code revisions once a year. In terms of the Information Systems Life Cycle stages, the coding system is probably in the ________________.
- operation and maintenance phase (Correct answer)
- implementation phase
- design phase
- obsolescence or decline phase
Correct answer: operation and maintenance phase
The Information Systems Life Cycle (ISLC) describes the stages of an information system. Since the encoding software has been deployed for two years, is well-liked, works effectively, and only requires annual updates, it is actively in use and being maintained. This indicates that the system is currently in the operation and maintenance phase, where it provides value and receives ongoing support.
Question 31: Under the MS-DRG system, what factors most directly determine a patient's DRG assignment?
- The attending physician's specialty and hospital type
- The principal diagnosis, secondary diagnoses (CCs/MCCs), and major procedures (Correct answer)
- The patient's insurance type and length of stay
- The patient's age and gender
Correct answer: The principal diagnosis, secondary diagnoses (CCs/MCCs), and major procedures
MS-DRG assignment is driven primarily by the principal diagnosis, the presence of complications or comorbidities (CCs/MCCs), and major procedures performed.
Question 32: Which KPI measures the average number of days to collect payment after service delivery?
- Denial Rate
- Clean Claim Rate
- Net Collection Rate
- Days in Accounts Receivable (AR) (Correct answer)
Correct answer: Days in Accounts Receivable (AR)
Days in AR measures the average elapsed time between service delivery and receipt of payment, indicating collection efficiency.
Question 33: What is the correct action when an error is discovered in a paper-based medical record?
- Draw a single line through the error, date, and initial it (Correct answer)
- Remove the page and rewrite it accurately
- Delete the entry and write 'error' in the margin
- Use correction fluid (white-out) to cover the error neatly
Correct answer: Draw a single line through the error, date, and initial it
The correct method is to draw a single line through the error, add the date and initials, and write the correct information—never obliterate the original entry.
Question 34: The Joint Commission does not authorize automatic authentication of health record inputs. The fundamental argument against this approach is:
- electronic signatures are not accepted in all states
- evidence cannot be presented that the physician really reviewed and authorized each report (Correct answer)
- tampering happens too often with this type of authentication
- it is too simple to delegate the usage of computer passwords
Correct answer: evidence cannot be presented that the physician really reviewed and authorized each report
Automatic authentication of health record inputs is problematic because it removes the direct, explicit action of a physician reviewing and approving each entry. Without individual physician action for each input, it becomes difficult to legally and clinically prove that the physician genuinely reviewed and authorized the specific content. This lack of direct evidence undermines accountability and the integrity of the health record.
Question 35: What is population health management?
- Managing hospital populations
- An approach to improving health outcomes for a defined group by analyzing data and implementing targeted interventions (Correct answer)
- Treating one patient at a time
- Counting census data
Correct answer: An approach to improving health outcomes for a defined group by analyzing data and implementing targeted interventions
Population health management uses data to identify at-risk groups, implement preventive interventions, and monitor outcomes across entire populations.
Question 36: Which terminology standard is used to represent nursing diagnoses, interventions, and outcomes in clinical information systems?
- SNOMED CT
- NANDA-I / NIC / NOC (Correct answer)
- ICD-10-CM
- LOINC
Correct answer: NANDA-I / NIC / NOC
NANDA-I (diagnoses), NIC (interventions), and NOC (outcomes) form the standardized nursing terminology used in clinical documentation systems.
Question 37: Which quantitative analysis component ensures that all required forms and reports are present in the medical record?
- Authentication check
- Record completion check
- Transcription verification
- Content review (Correct answer)
Correct answer: Content review
Content review in quantitative analysis verifies that all required forms, reports, and elements are present in the health record.
Question 38: Which character position in an ICD-10-PCS code defines the 'approach'?
- 6th character
- 3rd character
- 5th character (Correct answer)
- 4th character
Correct answer: 5th character
The 5th character in ICD-10-PCS specifies the approach, such as Open, Percutaneous, or Endoscopic.
Question 39: Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?
- Workstation use policies
- Facility access controls
- Security management process (Correct answer)
- Transmission security
Correct answer: Security management process
The security management process is a required administrative safeguard that includes risk analysis, risk management, sanction policy, and information system activity review.
Question 40: What is prior authorization?
- Approval from an insurance company required before certain services are provided (Correct answer)
- A patient's signature on a consent form
- A doctor's license verification
- A hospital's accreditation
Correct answer: Approval from an insurance company required before certain services are provided
Prior authorization requires providers to obtain insurance company approval before delivering specific services, ensuring medical necessity and coverage.
Question 41: Which state law generally takes precedence when it provides greater privacy protections than HIPAA?
- State law prevails when it is more stringent (more protective of patient privacy) than HIPAA (Correct answer)
- Federal law always preempts state law for health records
- State law applies only to Medicaid patients
- HIPAA always supersedes state law
Correct answer: State law prevails when it is more stringent (more protective of patient privacy) than HIPAA
HIPAA establishes a federal floor of privacy protections, but states may enact stricter laws; in such cases, the more stringent state law applies.
Question 42: Which interoperability profile from IHE defines how documents are registered, stored, and retrieved in a document-sharing network?
- PIX (Patient Identity Cross-Reference)
- ATNA (Audit Trail and Node Authentication)
- XDS (Cross-Enterprise Document Sharing) (Correct answer)
- PDQ (Patient Demographics Query)
Correct answer: XDS (Cross-Enterprise Document Sharing)
IHE XDS (Cross-Enterprise Document Sharing) defines the infrastructure for storing and querying clinical documents across enterprise boundaries.
Question 43: Which governance concept requires that the person requesting access to health information be the person they claim to be?
- Auditing
- Accounting
- Authorization
- Authentication (Correct answer)
Correct answer: Authentication
Authentication is the process of verifying the identity of a user before granting access to protected health information or systems.
Question 44: An HIM director is developing a data governance charter. Which element is MOST critical to include first?
- Defined roles and responsibilities for data stewardship (Correct answer)
- Vendor contract summaries
- Employee training schedules
- List of approved software tools
Correct answer: Defined roles and responsibilities for data stewardship
A data governance charter must first establish clear roles and responsibilities so accountability for data assets is unambiguous.
Question 45: What is a claim denial?
- A hospital closing a department
- An insurance company's refusal to pay for a submitted healthcare claim (Correct answer)
- A patient refusing treatment
- A doctor denying a referral
Correct answer: An insurance company's refusal to pay for a submitted healthcare claim
Claim denials occur when insurers refuse payment due to errors, lack of authorization, non-covered services, or insufficient documentation.
Question 46: Which of the following scenarios qualifies as a 'use' of PHI under HIPAA (rather than a 'disclosure')?
- A nurse reviewing a patient's chart within the same covered entity (Correct answer)
- Faxing a lab result to another hospital
- Sending patient records to a specialist outside the covered entity
- Sharing immunization records with a school
Correct answer: A nurse reviewing a patient's chart within the same covered entity
A 'use' occurs when PHI is shared, employed, or applied within the same covered entity; a 'disclosure' involves sharing outside the entity.
Question 47: A hospital's case mix index (CMI) increased from 1.4 to 1.7. This most likely indicates that the hospital:
- Discharged more patients with lower acuity and fewer resource requirements
- Had a significant decrease in total patient discharge volume during the period
- Treated a higher proportion of complex or resource-intensive patients (Correct answer)
- Experienced a decline in coding accuracy leading to systematic undercoding
Correct answer: Treated a higher proportion of complex or resource-intensive patients
A higher CMI reflects a shift in patient mix toward more complex, resource-intensive cases, which typically increases Medicare MS-DRG reimbursement rates.
Question 48: Which quality improvement tool displays process variation over time and distinguishes between common-cause and special-cause variation?
- Scatter diagram
- Histogram
- Control chart (Correct answer)
- Pareto chart
Correct answer: Control chart
A control chart plots data points over time with upper and lower control limits, helping identify whether variation is inherent to the process or caused by an unusual event.
Question 49: A covered entity participates in an HIE and shares patient data with network participants. Which agreement ensures that the HIE itself complies with HIPAA as a business associate?
- Data Sharing Compact
- Memorandum of Understanding (MOU)
- Participation Agreement
- Business Associate Agreement (BAA) (Correct answer)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement is required when a covered entity shares protected health information with an HIE, as the HIE qualifies as a business associate under HIPAA.
Question 50: A covered entity discovers a laptop containing unencrypted ePHI was stolen. Under the Breach Notification Rule, this event is:
- Not a breach because laptops are small breaches
- Not reportable if fewer than 10 patients are affected
- Exempt if the laptop was password-protected
- Presumed to be a breach unless the covered entity demonstrates a low probability of compromise (Correct answer)
Correct answer: Presumed to be a breach unless the covered entity demonstrates a low probability of compromise
Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless a four-factor risk assessment demonstrates a low probability that PHI was compromised.
Question 51: Under HIPAA's Minimum Necessary Standard, a covered entity must:
- Disclose only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Disclose complete records whenever requested by any provider
- Obtain separate authorizations for each data field disclosed
- Redact all demographic information before any disclosure
Correct answer: Disclose only the minimum amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires that covered entities make reasonable efforts to limit PHI disclosed to the smallest amount necessary to accomplish the intended purpose.
Question 52: Which CMS program penalizes hospitals for excess readmissions and relies on accurate clinical documentation?
- Medicare Shared Savings Program
- Bundled Payments for Care Improvement (BPCI)
- Hospital Readmissions Reduction Program (HRRP) (Correct answer)
- Merit-based Incentive Payment System (MIPS)
Correct answer: Hospital Readmissions Reduction Program (HRRP)
The Hospital Readmissions Reduction Program penalizes hospitals with higher-than-expected readmission rates for specific conditions, making accurate documentation of comorbidities essential.
Question 53: In organizing an instructional session for your team about adopting a benchmarking program, you inform your staff that when an organization employs benchmarking, it is crucial to compare your facility's results to __________________.
- facilities with superior performance. (Correct answer)
- nationally known facilities.
- larger facilities.
- facilities within your corporation.
Correct answer: facilities with superior performance.
Benchmarking is a strategic process where an organization compares its performance metrics, processes, and practices to those of the best performers in its industry or other industries. The goal is to identify areas for improvement and adopt 'best practices' from those who excel. Therefore, comparing results to facilities with superior performance provides the most valuable insights for enhancing efficiency and quality.
Question 54: A covered entity experiences a breach affecting 600 individuals. Under HIPAA Breach Notification Rule, notification to the Secretary of HHS must occur within:
- 60 days of discovery (Correct answer)
- 45 days of discovery
- 60 days of year-end
- 30 days of discovery
Correct answer: 60 days of discovery
For breaches affecting fewer than 500 individuals, covered entities must notify HHS within 60 days of the end of the calendar year in which the breach was discovered, but breaches over 500 require notification within 60 days of discovery.
Question 55: What is the function of the National Correct Coding Initiative (NCCI) edits?
- To validate ICD-10-CM code sequencing
- To prevent improper unbundling of CPT codes (Correct answer)
- To determine medical necessity for procedures
- To assign MS-DRGs for inpatient stays
Correct answer: To prevent improper unbundling of CPT codes
NCCI edits are CMS-developed bundling edits that prevent unbundling of procedures that should be billed together.
Question 56: The primary purpose of a Receiver Operating Characteristic (ROC) curve in clinical predictive modeling is to:
- Compare geographic distribution of diagnosis codes across regions
- Visualize time trends in the prevalence of a chronic disease
- Evaluate the trade-off between sensitivity and specificity across multiple decision thresholds (Correct answer)
- Measure inter-rater reliability for coded clinical documentation
Correct answer: Evaluate the trade-off between sensitivity and specificity across multiple decision thresholds
The ROC curve plots sensitivity against 1−specificity at all possible classification thresholds; the area under the curve (AUC) summarizes the model's overall ability to discriminate between outcomes.
Question 57: A data steward's PRIMARY responsibility in health information governance is to:
- Oversee clinical staff credentialing
- Approve IT infrastructure purchases
- Negotiate payer contracts
- Ensure data quality and appropriate use within an assigned domain (Correct answer)
Correct answer: Ensure data quality and appropriate use within an assigned domain
Data stewards are accountable for the quality, integrity, and appropriate use of data elements within their assigned subject area or domain.
Question 58: An HIM professional whose credential has lapsed into inactive status can restore it by:
- Retaking the full credentialing examination from scratch
- Completing outstanding CEH requirements and paying applicable reinstatement fees (Correct answer)
- Submitting a written appeal directly to CMS
- Waiting one year for automatic reactivation
Correct answer: Completing outstanding CEH requirements and paying applicable reinstatement fees
Inactive credentials can typically be restored by fulfilling the required CEHs and paying applicable fees within the allowed timeframe.
Question 59: Natural Language Processing (NLP) is most commonly applied in clinical analytics to:
- Calculate risk-adjusted capitation payment rates
- Extract structured information from free-text clinical documentation (Correct answer)
- Synchronize patient records across hospital networks
- Generate automated appointment reminders for patients
Correct answer: Extract structured information from free-text clinical documentation
NLP enables computers to interpret and extract structured data elements from unstructured sources such as clinical notes, discharge summaries, and radiology reports.
Question 60: Under HIPAA, which entity is primarily responsible for enforcement and imposing civil money penalties?
- Office for Civil Rights (OCR) within HHS (Correct answer)
- The Joint Commission
- Centers for Medicare & Medicaid Services (CMS)
- The American Health Information Management Association
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing HIPAA's Privacy, Security, and Breach Notification Rules.
Question 61: Which HIPAA transaction set is used to transmit an electronic remittance advice (ERA)?
- HIPAA 835 (Correct answer)
- HIPAA 270/271
- HIPAA 837P
- HIPAA 276/277
Correct answer: HIPAA 835
The HIPAA 835 transaction is the electronic remittance advice used by payers to communicate payment details and adjustments to providers.
Question 62: What is a key performance indicator (KPI) in healthcare?
- A measurable value demonstrating how effectively an organization achieves its operational and clinical objectives (Correct answer)
- A billing category
- A patient identification code
- A type of medical device
Correct answer: A measurable value demonstrating how effectively an organization achieves its operational and clinical objectives
KPIs track progress toward specific goals like readmission rates, patient satisfaction, or coding accuracy.
Question 63: Which chart type is BEST suited for displaying a trend in monthly hospital admission rates over a two-year period?
- Pie chart
- Box plot
- Scatter plot
- Line chart (Correct answer)
Correct answer: Line chart
Line charts are designed to display continuous data trends over time, making changes and patterns in monthly admission rates easy to identify and interpret.
Question 64: What is a Business Associate Agreement (BAA)?
- A patient consent form
- An insurance agreement
- A partnership between hospitals
- A contract between a covered entity and a vendor that ensures PHI protection when shared (Correct answer)
Correct answer: A contract between a covered entity and a vendor that ensures PHI protection when shared
BAAs legally require business associates (vendors handling PHI) to implement appropriate safeguards and comply with HIPAA regulations.
Question 65: Under HIPAA, which of the following is considered a permissible disclosure without patient authorization?
- Disclosing PHI to public health authorities for disease surveillance (Correct answer)
- Marketing a health plan's products
- Selling PHI to a pharmaceutical company
- Sharing PHI with an employer about an employee's diagnosis
Correct answer: Disclosing PHI to public health authorities for disease surveillance
HIPAA permits disclosure of PHI to public health authorities for activities such as disease surveillance, investigation, and intervention without patient authorization.
Question 66: Which data quality characteristic refers to whether data values fall within an expected or acceptable range for a given data element?
- Validity (Correct answer)
- Consistency
- Completeness
- Timeliness
Correct answer: Validity
Data validity means the data conforms to an expected format, range, or set of permissible values — for example, a patient age of 250 would fail a validity check.
Question 67: Under the HIPAA Security Rule, which of the following is classified as a required implementation specification?
- Assigned security responsibility (Correct answer)
- Encryption of data in transit
- Workforce security training
- Automatic logoff
Correct answer: Assigned security responsibility
Assigning a security official (security responsibility) is a required implementation specification under the HIPAA Security Rule's administrative safeguards.
Question 68: Which federal program publicly reports hospital quality measure performance data online as a condition of participation in Medicare?
- HITECH Act attestation reporting
- Hospital Compare / Care Compare (Correct answer)
- HIPAA Privacy Rule reporting requirements
- Medicare Advantage quality ratings
Correct answer: Hospital Compare / Care Compare
CMS's Care Compare (formerly Hospital Compare) website publicly reports hospital performance on quality measures, enabling consumers to compare hospitals and incentivizing transparency.
Question 69: What is the purpose of a 'physician advisor' in a CDI program?
- To perform utilization management reviews only
- To replace CDI specialists for all queries
- To review complex clinical documentation issues and support query escalations (Correct answer)
- To assign final MS-DRGs after discharge
Correct answer: To review complex clinical documentation issues and support query escalations
A physician advisor supports CDI programs by reviewing clinically complex cases, educating physicians, and resolving disputes between CDI specialists and attending physicians.
Question 70: Which federal regulation requires healthcare providers to give patients electronic access to their health information within 30 days of request?
- 21st Century Cures Act (Correct answer)
- Medicare Modernization Act
- HITECH Act
- Affordable Care Act
Correct answer: 21st Century Cures Act
The 21st Century Cures Act mandates timely patient access to electronic health information and prohibits information blocking by covered actors.
Question 71: What does the ICD-10-CM placeholder 'X' serve to do in a code?
- Denote an external cause
- Allow for future expansion and fill required character positions (Correct answer)
- Indicate an unspecified laterality
- Mark a manifestation code
Correct answer: Allow for future expansion and fill required character positions
The placeholder X is used in ICD-10-CM to fill required character positions and allow for future code expansion.
Question 72: Which FHIR resource type is used to represent a patient's longitudinal clinical record summary, including problems, medications, and allergies?
- DocumentReference
- CarePlan
- Composition (used in CCD/C-CDA) (Correct answer)
- Encounter
Correct answer: Composition (used in CCD/C-CDA)
The FHIR Composition resource assembles a set of clinical resources into a coherent document, and is the basis for the Consolidated CDA (C-CDA) mapped in FHIR, representing a summary record.
Question 73: Which challenge in HIE specifically refers to the difficulty of correctly linking records belonging to the same patient across different systems?
- Semantic interoperability
- Patient identity matching / record linkage (Correct answer)
- Consent management
- Data normalization
Correct answer: Patient identity matching / record linkage
Patient identity matching (record linkage) is the process of determining whether records from different systems refer to the same individual, a core challenge in HIE due to inconsistent identifiers.
Question 74: In ICD-10-PCS, how many characters does every procedure code contain?
- 7 (Correct answer)
- 6
- 5
- 8
Correct answer: 7
Every ICD-10-PCS code is exactly 7 alphanumeric characters, with each character representing a specific axis of classification.
Question 75: A covered entity must provide patients with a Notice of Privacy Practices (NPP):
- Annually to all patients on file
- Only when there has been a breach
- At first service delivery and upon request thereafter (Correct answer)
- Only at initial treatment, never again
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP no later than the first date of service and must make it available upon request at any subsequent time.
Question 76: The AHIMA Information Governance Adoption Model (IGAM) is structured around how many core competency areas?
- 12
- 16
- 4
- 8 (Correct answer)
Correct answer: 8
The AHIMA IGAM is organized around 8 core information governance competency areas that organizations use to assess and advance their IG maturity.
Question 77: The Case Mix Index (CMI) in hospital quality and financial management is BEST defined as:
- The average patient satisfaction score across all hospital service lines
- The percentage of total cases billed to government payers
- A measure of the relative complexity and resource intensity of a facility's patient mix (Correct answer)
- The ratio of Medicare to Medicaid patients treated by a facility
Correct answer: A measure of the relative complexity and resource intensity of a facility's patient mix
CMI is the average relative weight of all Medicare DRGs assigned to a hospital's patients, reflecting the complexity and resource demands of its overall case mix.
Question 78: Under HIPAA, what right does a patient have regarding amendments to their health record?
- The right to rewrite the physician's notes
- The right to request amendment of PHI they believe is inaccurate or incomplete (Correct answer)
- The right to delete any information they dislike
- The right to require the covered entity to add their version within 7 days
Correct answer: The right to request amendment of PHI they believe is inaccurate or incomplete
HIPAA gives patients the right to request an amendment to their PHI; the covered entity may deny the request if the information is accurate and complete, but must document the denial.
Question 79: Which release of information scenario requires a valid written authorization from the patient?
- Releasing records to the patient's employer for occupational health purposes (Correct answer)
- Disclosing records to a treating specialist for continuing care
- Sending records to a public health authority for disease reporting
- Providing records to law enforcement for a gunshot wound report
Correct answer: Releasing records to the patient's employer for occupational health purposes
Disclosure to an employer generally requires written patient authorization because it falls outside the permitted uses for treatment, payment, and operations.
Question 80: Which data quality dimension measures whether all required data fields in a health record have been completed?
- Timeliness
- Accuracy
- Completeness (Correct answer)
- Consistency
Correct answer: Completeness
Completeness measures whether all required data elements are present and populated in the health record.
Question 81: Which right does HIPAA give patients regarding their health records?
- The right to demand deletion of all their PHI
- The right to prohibit any disclosure including for treatment
- The right to access and obtain a copy of their PHI (Correct answer)
- The right to alter clinical notes without provider consent
Correct answer: The right to access and obtain a copy of their PHI
HIPAA's Privacy Rule grants individuals the right to access, inspect, and receive copies of their PHI held by a covered entity.
Question 82: What is the difference between EHR and EMR?
- EMR is a digital version of a single practice's chart; EHR is designed to share information across organizations (Correct answer)
- EHR is only for hospitals
- EMR is newer technology
- They are exactly the same
Correct answer: EMR is a digital version of a single practice's chart; EHR is designed to share information across organizations
EMRs are digital records within one practice, while EHRs are designed for interoperability, allowing information sharing across healthcare organizations.
Question 83: A patient portal allows patients to view their records but uses only username and password. To meet NIST AAL2 guidelines, what should be added?
- Single sign-on
- Audit logging
- Role-based access control
- Multi-factor authentication (Correct answer)
Correct answer: Multi-factor authentication
NIST AAL2 (Authenticator Assurance Level 2) requires multi-factor authentication using two different authentication factors.
Question 84: A patient has a fracture documented as 'closed, initial encounter.' Which 7th character should be appended to the ICD-10-CM fracture code?
- A (Correct answer)
- S
- D
- G
Correct answer: A
The 7th character 'A' denotes an initial encounter for a fracture receiving active treatment.
Question 85: What is the primary objective of a Clinical Documentation Improvement (CDI) program?
- To accelerate medical record coding turnaround time
- To ensure documentation accurately reflects patient severity, complexity, and resource use (Correct answer)
- To transition facilities from paper to electronic health records
- To reduce the total volume of medical records stored on-site
Correct answer: To ensure documentation accurately reflects patient severity, complexity, and resource use
CDI programs work concurrently with clinicians to clarify ambiguous or incomplete documentation so coded data accurately represents the patient's true clinical picture.
Question 86: Which scenario describes a valid 'incidental disclosure' that does not violate HIPAA?
- Emailing unencrypted PHI to the wrong provider
- Faxing a full medical record to a wrong number
- A patient overhearing their name called in a waiting room despite reasonable safeguards being in place (Correct answer)
- Posting a patient's diagnosis on a public bulletin board by mistake
Correct answer: A patient overhearing their name called in a waiting room despite reasonable safeguards being in place
Incidental disclosures that occur as a by-product of a permissible disclosure and despite reasonable safeguards do not violate HIPAA, such as calling a patient's name in a waiting room.
Question 87: Which data quality characteristic ensures that health data collected is the same whether captured once or multiple times?
- Accessibility
- Comprehensiveness
- Consistency (Correct answer)
- Currency
Correct answer: Consistency
Consistency means that the same data collected in different places or at different times yields the same results, ensuring reliability across the record.
Question 88: A health information manager discovers that a physician has been documenting patient encounters using copy-paste from previous visits without updating clinical findings. This practice primarily raises concern related to:
- EMTALA non-compliance
- Violation of state licensing standards only
- HIPAA minimum necessary violations
- Healthcare fraud, documentation integrity, and potential false claims liability (Correct answer)
Correct answer: Healthcare fraud, documentation integrity, and potential false claims liability
Cloning or copy-paste documentation without clinical verification constitutes fraudulent documentation, threatens record integrity, and can create false claims liability under the False Claims Act.
Question 89: What is 'severity of illness' (SOI) in the context of clinical documentation and reimbursement?
- A measure of the extent of physiologic decompensation or organ system loss of function (Correct answer)
- The patient's pain scale score
- A Medicare billing modifier
- The number of diagnoses assigned to a case
Correct answer: A measure of the extent of physiologic decompensation or organ system loss of function
Severity of illness reflects the degree of physiologic decompensation and is used in all-patient refined DRG (APR-DRG) systems to assess resource needs.
Question 90: During an EHR system selection, an organization uses a weighted scoring matrix to evaluate vendors. This approach is part of which phase of the system development life cycle?
- Implementation
- Design
- Analysis (Correct answer)
- Planning
Correct answer: Analysis
Vendor evaluation using weighted scoring criteria occurs during the Analysis phase, when requirements are assessed and solutions are compared.
Question 91: Under the Information Blocking Rule, which of the following is a recognized exception that permits an actor to restrict EHI access?
- Revenue Protection Exception
- Privacy Exception (Correct answer)
- Competitor Exception
- Staffing Limitation Exception
Correct answer: Privacy Exception
The Privacy Exception allows actors to restrict access to EHI when required to protect patient privacy under applicable law, such as when a patient restricts disclosure.
Question 92: What is a subpoena for health records?
- An insurance authorization
- A referral to a specialist
- A legal order requiring the production of specified health records for legal proceedings (Correct answer)
- A prescription request
Correct answer: A legal order requiring the production of specified health records for legal proceedings
A subpoena legally compels the release of specified records, but proper authorization and HIPAA compliance must still be verified.
Question 93: Which AHIMA publication provides members with peer-reviewed articles, research, and industry updates to support continuous professional learning?
- The Journal of AHIMA (JAHIMA) (Correct answer)
- ICD-10-CM Official Guidelines for Coding and Reporting
- The CMS Federal Register coding supplement
- AHIMA's internal billing compliance newsletter
Correct answer: The Journal of AHIMA (JAHIMA)
The Journal of AHIMA (JAHIMA) is AHIMA's peer-reviewed publication covering research, practice trends, and policy relevant to HIM professionals.
Question 94: The concept of 'incidental disclosure' under HIPAA refers to:
- A secondary disclosure that cannot reasonably be prevented and is limited in nature (Correct answer)
- A disclosure made without the patient's knowledge
- An accidental mailing of records to the wrong address
- Any unauthorized breach of PHI
Correct answer: A secondary disclosure that cannot reasonably be prevented and is limited in nature
An incidental disclosure is a by-product of an otherwise permissible disclosure that is limited and cannot reasonably be prevented, such as overhearing staff discuss a patient in a hallway.
Question 95: The AHIMA House of Delegates primarily serves to:
- Approve individual credentialing exam applications
- Conduct coding audits for member organizations
- Manage the finances of state component associations
- Provide governance and set policy direction for AHIMA as an association (Correct answer)
Correct answer: Provide governance and set policy direction for AHIMA as an association
The House of Delegates is AHIMA's governance body, responsible for setting association policy and strategic direction.
Question 96: The legal health record (LHR) differs from the designated record set (DRS) in that the LHR:
- Must encompass all data used to make patient care decisions
- Is determined solely by HIPAA regulations
- Is defined by the organization for business and legal purposes (Correct answer)
- Includes administrative financial data used for payment decisions
Correct answer: Is defined by the organization for business and legal purposes
The LHR is defined by each organization to identify records disclosed for legal proceedings, while the DRS is a broader HIPAA concept covering records used in care or payment decisions.
Question 97: Which query type asks a physician to clarify documentation without suggesting a specific diagnosis?
- Closed query
- Non-leading query (Correct answer)
- Leading query
- Retrospective query
Correct answer: Non-leading query
A non-leading query presents clinical indicators and asks the physician to provide their clinical interpretation without suggesting an answer.
Question 98: In health informatics, a 'data lake' differs from a 'data warehouse' primarily in that a data lake:
- Requires ETL processing before data ingestion
- Is limited to real-time streaming data
- Stores raw data in native format without pre-defined schema (Correct answer)
- Only stores structured relational data
Correct answer: Stores raw data in native format without pre-defined schema
A data lake stores raw, unprocessed data in its native format with schema applied on read, unlike a data warehouse which enforces schema on write.
Question 99: What is a release of information (ROI) process?
- Releasing new software
- The procedure for disclosing patient health information in response to authorized requests (Correct answer)
- Announcing hospital policies
- Publishing medical research
Correct answer: The procedure for disclosing patient health information in response to authorized requests
ROI involves verifying authorization, identifying requested records, reviewing for compliance, and disclosing only the minimum necessary information.
Question 100: A health system's governance policy allows de-identified data to be shared freely for research. Which de-identification method removes 18 specific identifiers listed in the HIPAA Privacy Rule?
- Safe Harbor method (Correct answer)
- Expert determination method
- Statistical sampling method
- Limited data set method
Correct answer: Safe Harbor method
The Safe Harbor method requires removal of all 18 specific categories of identifiers listed in the HIPAA Privacy Rule before data is considered de-identified.
Question 101: Which interoperability framework published by the Office of the National Coordinator (ONC) defines the four domains of interoperability—foundational, structural, semantic, and organizational?
- CommonWell Health Alliance Charter
- FHIR Implementation Guide
- TEFCA (Trusted Exchange Framework and Common Agreement) (Correct answer)
- Interoperability Standards Advisory (ISA)
Correct answer: TEFCA (Trusted Exchange Framework and Common Agreement)
TEFCA establishes the Trusted Exchange Framework defining governance, technical, and legal requirements, and references the four interoperability domains across its structure.
Question 102: What is data integrity in health information?
- Backing up files
- Data encryption only
- Having a large database
- The accuracy, completeness, consistency, and reliability of data throughout its lifecycle (Correct answer)
Correct answer: The accuracy, completeness, consistency, and reliability of data throughout its lifecycle
Data integrity ensures health information is accurate, complete, consistently formatted, and reliable from creation through storage and retrieval.
Question 103: Which CPT code modifier indicates that only the professional component of a service was provided?
- -52
- -TC
- -59
- -26 (Correct answer)
Correct answer: -26
Modifier -26 indicates the professional (physician interpretation) component of a diagnostic service, separate from the technical component.
Question 104: Which emerging area of competency is increasingly emphasized in AHIMA workforce development for future HIM professionals?
- Health data analytics, AI governance, and interoperability (Correct answer)
- Fee-for-service claims processing systems only
- Manual transcription and paper chart assembly
- Microfilm management and physical record archival
Correct answer: Health data analytics, AI governance, and interoperability
AHIMA workforce studies identify data analytics, AI governance, and interoperability as critical future competencies for the evolving HIM profession.
Question 105: What is record retention policy?
- Destroying records immediately after discharge
- Keeping all records forever
- Guidelines specifying how long different types of health records must be kept before destruction (Correct answer)
- Retention is optional
Correct answer: Guidelines specifying how long different types of health records must be kept before destruction
Retention policies specify minimum retention periods based on federal/state law, accreditation requirements, and organizational needs, varying by record type and patient age.
Question 106: Which health IT governance framework defines controls for IT services aligned to business needs and is widely used by healthcare CIOs?
- HITRUST CSF
- COBIT (Correct answer)
- NIST SP 800-66
- ISO 27001
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is an IT governance framework that aligns IT management with organizational goals.
Question 107: Which of the following best describes the concept of 'Integrity' in the context of the HIPAA Security Rule?
- Ensuring ePHI is not altered or destroyed in an unauthorized manner (Correct answer)
- Ensuring ePHI is accessible only to authorized users
- Ensuring ePHI is available when needed by authorized persons
- Ensuring all ePHI is encrypted at rest and in transit
Correct answer: Ensuring ePHI is not altered or destroyed in an unauthorized manner
Under HIPAA's Security Rule, integrity means that ePHI is not altered or destroyed in an unauthorized manner, preserving its accuracy and completeness.
Question 108: HIPAA's 'Minimum Necessary' standard does NOT apply to disclosures made:
- To a business associate for billing purposes
- For public health reporting to authorities
- To law enforcement under a valid court order
- To the individual who is the subject of the PHI (Correct answer)
Correct answer: To the individual who is the subject of the PHI
The minimum necessary standard does not apply when disclosures are made to the individual who is the subject of the PHI, for treatment purposes, or pursuant to an authorization.
Question 109: What is clinical decision support (CDS)?
- A patient self-diagnosis tool
- A management consulting firm
- An insurance approval system
- Technology providing clinicians with knowledge and person-specific information to enhance decision-making (Correct answer)
Correct answer: Technology providing clinicians with knowledge and person-specific information to enhance decision-making
CDS systems provide alerts, reminders, evidence-based guidelines, and diagnostic support to improve clinical decisions.
Question 110: Under HIPAA, what is a 'business associate'?
- Any vendor that sells products to a hospital
- A person or entity that performs functions or activities on behalf of a covered entity involving PHI (Correct answer)
- A health plan member
- An employee of the covered entity
Correct answer: A person or entity that performs functions or activities on behalf of a covered entity involving PHI
A business associate is a person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a function or service.
Question 111: What is the correct process when a patient revokes a previously signed HIPAA authorization?
- Disclosures that already occurred in reliance on the authorization are not affected, but future disclosures must stop (Correct answer)
- The revocation must be notarized to be valid
- Revocation applies only to electronic records
- The covered entity must immediately stop all disclosures, with no exceptions
Correct answer: Disclosures that already occurred in reliance on the authorization are not affected, but future disclosures must stop
A patient may revoke a HIPAA authorization in writing at any time, but the revocation does not affect disclosures already made in reliance on the authorization.
Question 112: Which law grants patients born after August 1975 the right to inspect their own federal education records, but is often confused with healthcare privacy rules?
- FERPA (Correct answer)
- COPPA
- HITECH
- HIPAA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) governs educational records, not health records, though student health records at schools may fall under its scope.
Question 113: What is the legal health record?
- The documentation of healthcare services maintained by an organization that serves as its business and legal record (Correct answer)
- Any notes a doctor writes
- Only the billing records
- The patient's personal health journal
Correct answer: The documentation of healthcare services maintained by an organization that serves as its business and legal record
The legal health record is the subset of all patient data that the organization defines as its official business record, used for legal proceedings, patient requests, and audits.
Question 114: When a hospital merges with another facility, which HIM function is critical to prevent duplicate medical record numbers from causing patient safety issues?
- Master Patient Index (MPI) reconciliation (Correct answer)
- Chart deficiency analysis
- Coding compliance review
- Release of information audit
Correct answer: Master Patient Index (MPI) reconciliation
MPI reconciliation identifies and resolves duplicate or overlapping patient identifiers across merged systems to ensure patient safety and data integrity.
Question 115: In a healthcare data governance program, a data steward is primarily responsible for:
- Ensuring data quality, integrity, and appropriate use within an assigned data domain (Correct answer)
- Designing and maintaining the physical database schema
- Writing optimized SQL queries for analytics and reporting
- Managing IT infrastructure and hardware for enterprise data storage
Correct answer: Ensuring data quality, integrity, and appropriate use within an assigned data domain
A data steward acts as a subject matter expert who defines data quality rules, resolves data issues, and ensures data within their domain is accurate, consistent, and used appropriately.
Question 116: Which of the following activities qualifies as an AHIMA-approved continuing education activity for credential renewal?
- Reviewing personal health records for accuracy
- Volunteering at a community health fair
- Reading a journal article with no associated assessment
- Attending an AHIMA-approved educational seminar or webinar (Correct answer)
Correct answer: Attending an AHIMA-approved educational seminar or webinar
Attending AHIMA-approved educational programs with defined learning objectives is a recognized CEH-earning activity.
Question 117: What is data warehousing in healthcare?
- A physical storage facility for medical supplies
- A cold storage for vaccines
- A pharmacy inventory system
- A centralized repository storing integrated data from multiple sources for analysis and reporting (Correct answer)
Correct answer: A centralized repository storing integrated data from multiple sources for analysis and reporting
Data warehouses consolidate information from various clinical and administrative systems for comprehensive analysis and reporting.
Question 118: What is the key difference between ICD-10-CM and ICD-10-PCS?
- They are interchangeable and cover the same content
- ICD-10-CM is for diagnoses; ICD-10-PCS is for inpatient procedures (Correct answer)
- ICD-10-PCS is used in outpatient settings only
- ICD-10-CM is for procedures; ICD-10-PCS is for diagnoses
Correct answer: ICD-10-CM is for diagnoses; ICD-10-PCS is for inpatient procedures
ICD-10-CM classifies diagnoses used across all settings, while ICD-10-PCS classifies inpatient hospital procedures.
Question 119: A Pareto chart is MOST useful for:
- Tracking performance trends across multiple time periods
- Identifying the vital few causes that account for most problems (Correct answer)
- Showing the correlation between two variables
- Displaying the frequency distribution of a single variable
Correct answer: Identifying the vital few causes that account for most problems
Based on the 80/20 rule, a Pareto chart ranks causes by frequency so teams can focus on the few factors responsible for the majority of problems.
Question 120: What is HIPAA?
- A coding system
- The Health Insurance Portability and Accountability Act — federal law protecting patient health information privacy (Correct answer)
- A medical procedure
- A type of health insurance
Correct answer: The Health Insurance Portability and Accountability Act — federal law protecting patient health information privacy
HIPAA establishes national standards for protecting sensitive patient health information from being disclosed without consent.
Question 121: What are clinical quality measures?
- Financial performance indicators
- Hospital decoration standards
- Patient satisfaction surveys only
- Standardized metrics assessing healthcare processes, outcomes, and patient experience (Correct answer)
Correct answer: Standardized metrics assessing healthcare processes, outcomes, and patient experience
Clinical quality measures evaluate whether healthcare services are effective, safe, efficient, patient-centered, equitable, and timely.
Question 122: A good opening step toward maintaining the security of data included in a health information computer system would be ______________________.
- offer remote terminals for easier access to the records.
- create a good tracking system.
- define security levels for various sorts of information based on their sensitivity. (Correct answer)
- offer online access to facility records.
Correct answer: define security levels for various sorts of information based on their sensitivity.
A crucial initial step in maintaining the security of data in a health information computer system is to define security levels based on the sensitivity of various types of information. This allows for the implementation of appropriate access controls and safeguards tailored to the risk associated with different data, ensuring that highly sensitive information receives the strongest protection and preventing unauthorized access.
Question 123: Under HIPAA, what is the 'minimum necessary' standard for release of information?
- Limiting PHI disclosures to the least amount necessary to accomplish the intended purpose (Correct answer)
- Providing only the discharge summary for all requests
- Releasing only data from the past 12 months
- Releasing only the first and last page of the record
Correct answer: Limiting PHI disclosures to the least amount necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI disclosure to what is needed for the specific purpose of the request.
Question 124: Which HIPAA civil monetary penalty tier applies to violations where the covered entity was unaware and could not have known of the violation even with reasonable diligence?
- Tier 1 — $100 to $50,000 per violation (Correct answer)
- Tier 4 — $50,000 per violation
- Tier 3 — $10,000 to $50,000 per violation
- Tier 2 — $1,000 to $50,000 per violation
Correct answer: Tier 1 — $100 to $50,000 per violation
Tier 1 penalties ($100–$50,000 per violation) apply when the entity did not know and, with reasonable diligence, could not have known of the HIPAA violation.
Question 125: Which step in the revenue cycle involves recording payer payments and adjustments to individual patient accounts?
- Claim submission
- Charge capture
- Payment posting (Correct answer)
- Utilization management
Correct answer: Payment posting
Payment posting is the process of entering payments, contractual adjustments, and denials received via ERA or paper remittance into the practice management system.
Question 126: Which standard messaging protocol is most commonly used to exchange clinical data such as lab results, ADT notifications, and radiology reports in Health Information Exchange?
- NCPDP SCRIPT
- DICOM
- HL7 v2.x (Correct answer)
- X12 EDI
Correct answer: HL7 v2.x
HL7 version 2.x is the dominant messaging standard for exchanging clinical data like ADT events, lab results, and radiology reports between healthcare systems.
Question 127: Which model of care coordination is most directly supported by HIE's ability to send real-time ADT notifications to care managers when high-risk patients are admitted to a hospital?
- Prospective Payment System auditing
- Utilization Management
- Population Health Reporting
- Transitions of Care / Care Coordination (Correct answer)
Correct answer: Transitions of Care / Care Coordination
Real-time ADT notifications enable care managers to intervene promptly during transitions of care, reducing readmissions and improving coordination for high-risk patients.
Question 128: What is a 'concurrent' CDI review?
- Review performed by an external auditor
- Review performed only on surgical cases
- Review performed after the patient is discharged
- Review performed while the patient is still admitted (Correct answer)
Correct answer: Review performed while the patient is still admitted
Concurrent CDI review occurs while the patient is still hospitalized, allowing queries to be answered before discharge and the record is coded.
Question 129: The Anti-Kickback Statute (AKS) prohibits:
- Physicians billing for services provided by unqualified staff
- Billing Medicare as primary payer when a commercial payer is primary
- Offering, paying, soliciting, or receiving anything of value to induce referrals for federally reimbursed services (Correct answer)
- Submitting claims without complete supporting documentation
Correct answer: Offering, paying, soliciting, or receiving anything of value to induce referrals for federally reimbursed services
The AKS prohibits any remuneration exchanged to induce or reward referrals of items or services covered by federal healthcare programs.
Question 130: A covered entity retains records for seven years from the date of service. A patient requests records from nine years ago. What should the HIM professional do?
- Provide the records immediately
- Request a court order before responding
- Inform the patient the records have been destroyed per policy (Correct answer)
- Transfer the request to the billing department
Correct answer: Inform the patient the records have been destroyed per policy
If records have been lawfully destroyed according to the organization's retention and destruction policy, the patient should be informed they no longer exist.
Question 131: What distinguishes a problem-oriented medical record (POMR) from a source-oriented medical record (SOMR)?
- POMR uses ICD codes; SOMR uses CPT codes
- POMR is used only in outpatient settings; SOMR is used only in hospitals
- POMR requires electronic format; SOMR allows paper only
- POMR organizes information by clinical problem; SOMR organizes by department or source of information (Correct answer)
Correct answer: POMR organizes information by clinical problem; SOMR organizes by department or source of information
The POMR organizes entries around numbered patient problems, while the SOMR groups information by the type or source of service (e.g., lab, radiology, nursing).
Question 132: Under the HIPAA Privacy Rule, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon written request
- Annually regardless of patient contact
- At first service delivery and upon request thereafter (Correct answer)
- Only when PHI is disclosed to a third party
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP to patients at the first point of service delivery and make it available upon request at any time.
Question 133: Which type of consent authorizes a healthcare facility to provide routine treatment and is typically obtained upon admission?
- Informed consent
- Implied consent
- General consent (Correct answer)
- Advance directive
Correct answer: General consent
General consent covers routine hospital care and administrative processes, while informed consent is procedure-specific and requires disclosure of risks, benefits, and alternatives.
Question 134: What is Protected Health Information (PHI)?
- Only insurance information
- Only billing records
- Only a patient's name
- Any individually identifiable health information including demographics, diagnoses, and treatment records (Correct answer)
Correct answer: Any individually identifiable health information including demographics, diagnoses, and treatment records
PHI includes any information that can identify an individual and relates to their health condition, care, or payment, in any form (paper, electronic, oral).
Question 135: Which coding guideline applies when a definitive diagnosis has NOT been established at the time of an outpatient visit?
- Use the most recent inpatient diagnosis
- Code the condition to the highest degree of certainty using signs and symptoms (Correct answer)
- Code the suspected diagnosis
- Leave the diagnosis field blank
Correct answer: Code the condition to the highest degree of certainty using signs and symptoms
For outpatient visits, coders report signs and symptoms rather than unconfirmed or suspected diagnoses.
Question 136: What is a DRG (Diagnosis-Related Group)?
- A type of drug
- A diagnostic test
- A patient classification system that groups similar clinical conditions for hospital payment purposes (Correct answer)
- A department within a hospital
Correct answer: A patient classification system that groups similar clinical conditions for hospital payment purposes
DRGs classify hospital inpatients into groups based on diagnosis, procedures, age, and complications, determining the hospital's Medicare payment for each case.
Question 137: What is the purpose of an Encoder in health information management?
- To calculate patient billing totals
- To physically store health records
- To electronically assign and validate diagnosis and procedure codes (Correct answer)
- To manage patient scheduling
Correct answer: To electronically assign and validate diagnosis and procedure codes
An encoder is software that assists coders in selecting and validating ICD, CPT, and HCPCS codes.
Question 138: What is the ICD-10-CM code category for Type 2 diabetes mellitus?
- E11 (Correct answer)
- E10
- E12
- E13
Correct answer: E11
E11 is the ICD-10-CM category for Type 2 diabetes mellitus, including all its manifestations and complications.
Question 139: Which body provides the official guidelines for ICD-10-CM coding that HIM governance policies must align with?
- The American Medical Association
- The ICD-10-CM Official Guidelines Cooperating Parties (Correct answer)
- The Joint Commission
- The Office of the National Coordinator
Correct answer: The ICD-10-CM Official Guidelines Cooperating Parties
The Cooperating Parties — AHA, AHIMA, CMS, and NCHS — jointly publish the official ICD-10-CM coding guidelines that govern coding practice.
Question 140: In healthcare analytics, 'data granularity' refers to:
- The level of detail at which data is captured or stored (Correct answer)
- The security classification level assigned to a dataset
- The number of data sources feeding into a data warehouse
- The frequency at which scheduled data backups occur
Correct answer: The level of detail at which data is captured or stored
Data granularity describes how detailed the data is—patient-level data has higher granularity than aggregated facility-level summaries.
Question 141: What is patient safety culture?
- A nursing philosophy
- An organizational culture that prioritizes safety through open reporting, learning from errors, and systems thinking (Correct answer)
- A patient education program
- Hospital decoration standards
Correct answer: An organizational culture that prioritizes safety through open reporting, learning from errors, and systems thinking
A strong safety culture encourages error reporting without blame, learns from mistakes, and continuously improves systems.
Question 142: Which of the following is an addressable implementation specification under the HIPAA Security Rule?
- Encryption and decryption of ePHI at rest (Correct answer)
- Risk analysis
- Sanction policy
- Unique user identification
Correct answer: Encryption and decryption of ePHI at rest
Encryption of ePHI at rest is an addressable specification, meaning covered entities must implement it or document why an equivalent alternative measure is sufficient.
Question 143: Which element is a required component of an effective compliance plan per OIG guidance?
- Delegation of all billing responsibilities to a contracted payer
- A guarantee of zero claim denials within the fiscal year
- Written standards of conduct with internal monitoring and auditing processes (Correct answer)
- Unlimited appeals budget for all denied Medicare claims
Correct answer: Written standards of conduct with internal monitoring and auditing processes
The OIG identifies seven elements of an effective compliance program, including written policies, training, internal auditing, and corrective action procedures.
Question 144: Which of the following is NOT considered Protected Health Information (PHI) under HIPAA?
- A patient's name combined with their prescription information
- An MRI scan with the patient's name
- A patient's date of birth linked to a diagnosis
- De-identified statistical health data (Correct answer)
Correct answer: De-identified statistical health data
De-identified health information that has had all 18 identifying elements removed does not meet the definition of PHI and is not protected under HIPAA.
Question 145: Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of a breach within:
- 60 days of discovery (Correct answer)
- 90 days of discovery
- 24 hours of discovery
- 30 days of discovery
Correct answer: 60 days of discovery
Covered entities must provide breach notifications to affected individuals without unreasonable delay and no later than 60 days following discovery of the breach.
Question 146: The healthcare quality measurement framework of 'structure, process, and outcome' was developed by which pioneer?
- Philip Crosby
- W. Edwards Deming
- Avedis Donabedian (Correct answer)
- Joseph Juran
Correct answer: Avedis Donabedian
Avedis Donabedian proposed this three-part framework for evaluating healthcare quality, where structure enables process and process influences outcomes.
Question 147: Which sampling method gives every member of a patient population an equal and independent probability of being selected?
- Stratified random sampling
- Purposive sampling
- Simple random sampling (Correct answer)
- Convenience sampling
Correct answer: Simple random sampling
Simple random sampling assigns each individual in a population an equal, independent chance of selection, eliminating systematic selection bias.
Question 148: What is HCPCS?
- A hospital management system
- A health insurance plan
- A patient identifier
- Healthcare Common Procedure Coding System — codes for services, equipment, and supplies not in CPT (Correct answer)
Correct answer: Healthcare Common Procedure Coding System — codes for services, equipment, and supplies not in CPT
HCPCS codes cover items and services not included in CPT, such as durable medical equipment, prosthetics, ambulance services, and certain drugs.
Question 149: A patient who was treated under a pseudonym for confidentiality reasons (e.g., a public figure) is discharged. The HIM department should:
- Report the alias use to the state health department
- Merge the alias record with the permanent MPI record under the real name using a secure linkage process (Correct answer)
- File the record under the alias permanently
- Destroy the record to prevent identification
Correct answer: Merge the alias record with the permanent MPI record under the real name using a secure linkage process
The alias record must be properly linked to the patient's true identity in the MPI through a controlled process to ensure care continuity and accurate records.
Question 150: In the context of health information governance, 'data provenance' refers to:
- The encryption algorithm used to secure data
- The geographic origin of the patient
- The cost associated with data storage
- The documented history of data origin, movement, and transformation (Correct answer)
Correct answer: The documented history of data origin, movement, and transformation
Data provenance tracks the origin, custody, and transformation history of data so users can assess its reliability and trustworthiness.
Question 151: What elements are required in a valid HIPAA authorization for release of PHI?
- Insurance ID number and diagnosis code
- Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke (Correct answer)
- Physician signature and facility stamp
- Patient name and date only
Correct answer: Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke
A valid HIPAA authorization must include core elements such as a description of the PHI, the purpose of disclosure, the recipient, an expiration date/event, patient signature, and notice of the right to revoke.
Question 152: What is the primary purpose of a Remittance Advice (RA)?
- To document medical necessity for a claim
- To notify patients of their outstanding balance
- To explain payments and adjustments made by the payer (Correct answer)
- To pre-authorize services before treatment
Correct answer: To explain payments and adjustments made by the payer
A Remittance Advice details how a payer processed and paid (or denied) a claim, including adjustment reason codes and payment amounts.
Question 153: What is master patient index (MPI)?
- A list of the best patients
- A hospital's main telephone directory
- A database that assigns a unique identifier to each patient and cross-references all their records (Correct answer)
- An insurance company database
Correct answer: A database that assigns a unique identifier to each patient and cross-references all their records
The MPI ensures each patient has one unique identifier across all systems, preventing duplicate records and enabling accurate record retrieval.
Question 154: Which term describes the process of ensuring that a health record accurately reflects the patient's actual condition and the care provided?
- Quantitative analysis
- Prospective review
- Concurrent review
- Qualitative analysis (Correct answer)
Correct answer: Qualitative analysis
Qualitative analysis evaluates whether the clinical content of the record is complete, accurate, and consistent with the patient's condition and care.
Question 155: A focused coding audit is MOST commonly triggered by:
- Routine monthly productivity reporting
- New employee onboarding orientation requirements
- Completion of annual staff performance evaluations
- Significant variation from expected coding patterns or elevated payer denials (Correct answer)
Correct answer: Significant variation from expected coding patterns or elevated payer denials
Focused audits are initiated when data analysis reveals unusual coding patterns, high denial rates, or OIG Work Plan risk areas that warrant targeted review.
Question 156: What is the purpose of the National Correct Coding Initiative (NCCI) edits?
- To identify high-risk claims for pre-payment audit
- To prevent improper payment of procedure code combinations that should not be billed together (Correct answer)
- To establish the Medicare Physician Fee Schedule
- To assign relative weights to inpatient DRG categories
Correct answer: To prevent improper payment of procedure code combinations that should not be billed together
NCCI edits are CMS code-pair tables that identify procedure combinations where one code is bundled into another, preventing improper unbundling.
Question 157: What is the chargemaster?
- A government price list
- A comprehensive listing of all billable items and their prices used by a healthcare facility (Correct answer)
- A hospital employee who manages billing
- A patient's itemized bill
Correct answer: A comprehensive listing of all billable items and their prices used by a healthcare facility
The chargemaster (charge description master) is a hospital's master price list for all services, procedures, supplies, and drugs used for billing purposes.
Question 158: Which of the following best describes the 'qui tam' provision of the False Claims Act?
- It permits private individuals to file suits on behalf of the government and share in recovered funds (Correct answer)
- It allows providers to voluntarily disclose fraud and avoid penalties
- It authorizes HHS to exclude providers from Medicare without a hearing
- It defines the statute of limitations for healthcare fraud
Correct answer: It permits private individuals to file suits on behalf of the government and share in recovered funds
The qui tam provision allows private citizens (relators) to file False Claims Act suits on behalf of the U.S. government and receive a portion of any recovered funds as a reward.
Question 159: What is the primary role of patient access in the revenue cycle?
- Reducing the volume of prior authorizations required by payers
- Maximizing the number of patient appointments scheduled per day
- Capturing accurate demographic and insurance information to support clean claim submission (Correct answer)
- Eliminating patient financial responsibility at the point of registration
Correct answer: Capturing accurate demographic and insurance information to support clean claim submission
Patient access is the front end of the revenue cycle; accurate registration and eligibility data gathered here directly determines downstream billing accuracy.
Question 160: The primary purpose of a data dictionary in a health information system is to:
- Control patient access permissions in the EHR
- Store encryption keys for protected health information
- Define the structure, format, and meaning of each data element (Correct answer)
- Manage physical database server configurations
Correct answer: Define the structure, format, and meaning of each data element
A data dictionary is a metadata repository that documents the definition, format, source, and relationships of each data element to ensure consistent interpretation and use.
Question 161: What is the primary function of a Recovery Audit Contractor (RAC) in Medicare?
- Processing Medicare claims and issuing initial payments to providers
- Identifying and recovering improper Medicare payments through post-payment audits (Correct answer)
- Verifying provider enrollment and credentialing in the Medicare program
- Conducting pre-payment medical necessity reviews on high-risk claims
Correct answer: Identifying and recovering improper Medicare payments through post-payment audits
RACs are CMS-contracted entities that perform post-payment audits to identify overpayments and underpayments in the Medicare program.
Question 162: What is the role of a Health Information Management (HIM) professional?
- Only managing hospital IT systems
- Only filing paper records
- Managing patient health information systems, ensuring data quality, privacy compliance, and proper coding (Correct answer)
- Only answering phone calls
Correct answer: Managing patient health information systems, ensuring data quality, privacy compliance, and proper coding
HIM professionals oversee health information collection, maintenance, and access, ensuring quality, privacy compliance, and supporting the healthcare organization's data needs.
Question 163: Which of the following is considered a leading indicator in healthcare quality analytics?
- 30-day readmission rate
- Hand hygiene compliance rate (Correct answer)
- Average length of stay
- Patient mortality rate
Correct answer: Hand hygiene compliance rate
Hand hygiene compliance is a process (leading) indicator that predicts future outcomes like infection rates, unlike readmission or mortality, which are lagging outcome measures.
Question 164: What is meaningful use of EHR?
- Using computers meaningfully
- Federal criteria for using certified EHR technology to improve quality, safety, and efficiency (Correct answer)
- A type of health insurance
- Any use of electronic records
Correct answer: Federal criteria for using certified EHR technology to improve quality, safety, and efficiency
Meaningful use (now Promoting Interoperability) sets specific criteria for using EHR technology to improve care quality and earn incentive payments.
Question 165: Which CMS program adjusts hospital inpatient payments based on performance on quality, safety, and patient experience measures?
- Meaningful Use Incentive Program
- Physician Quality Reporting System (PQRS)
- Hospital Value-Based Purchasing (VBP) (Correct answer)
- Promoting Interoperability Program
Correct answer: Hospital Value-Based Purchasing (VBP)
The Hospital VBP program withholds a percentage of base operating DRG payments and redistributes them based on hospital performance across clinical outcomes, safety, and patient experience domains.
Question 166: Which MS-DRG complication or comorbidity (CC) level carries the highest relative weight and reimbursement impact?
- CC (Complication or Comorbidity)
- No CC/MCC
- MCC (Major Complication or Comorbidity) (Correct answer)
- Secondary CC
Correct answer: MCC (Major Complication or Comorbidity)
MCCs (Major Complications or Comorbidities) carry the highest relative weight in MS-DRG grouping, reflecting greater resource utilization.
Question 167: Which type of PHI disclosure does NOT require a patient's authorization under HIPAA?
- Release to the patient's employer for personnel decisions
- Release for treatment, payment, or healthcare operations (TPO) (Correct answer)
- Release to a life insurance company
- Release to a marketing firm
Correct answer: Release for treatment, payment, or healthcare operations (TPO)
HIPAA permits covered entities to disclose PHI without patient authorization for treatment, payment, and healthcare operations purposes.
Question 168: What is the purpose of medical coding?
- To encrypt patient records
- To translate diagnoses, procedures, and services into universal alphanumeric codes for billing and data analysis (Correct answer)
- To create passwords
- To organize medical supplies
Correct answer: To translate diagnoses, procedures, and services into universal alphanumeric codes for billing and data analysis
Medical coding converts clinical documentation into standardized codes that support billing, research, public health monitoring, and quality measurement.
Question 169: What is the Medicare timely filing limit for initial claim submission?
- 12 months (1 year) from date of service (Correct answer)
- 6 months from date of service
- 90 days from date of service
- 24 months from date of service
Correct answer: 12 months (1 year) from date of service
Medicare requires claims to be filed within one calendar year (12 months) from the date of service.
Question 170: Which type of health IT system is specifically designed to support public health surveillance and outbreak detection at the population level?
- Personal health record (PHR)
- Population health management platform
- Practice management system
- Syndromic surveillance system (Correct answer)
Correct answer: Syndromic surveillance system
Syndromic surveillance systems aggregate real-time data from emergency departments and other sources to detect disease outbreaks before diagnoses are confirmed.
Question 171: A patient requests amendment of their medical record, claiming a diagnosis is incorrect. The covered entity may deny the request if:
- The patient did not submit the request in writing
- The information was created by another provider and is accurate and complete (Correct answer)
- The record was created more than one year ago
- The diagnosis was entered by a licensed physician
Correct answer: The information was created by another provider and is accurate and complete
A covered entity may deny an amendment request if the PHI was not created by the entity and it believes the originating provider is better positioned to assess accuracy.
Question 172: What is a HIPAA breach notification?
- Required notification to affected individuals and HHS when unsecured PHI is improperly accessed or disclosed (Correct answer)
- A system error report
- A patient complaint form
- An optional courtesy notification
Correct answer: Required notification to affected individuals and HHS when unsecured PHI is improperly accessed or disclosed
Breach notification rules require covered entities to notify affected individuals, HHS, and sometimes media when a breach of unsecured PHI occurs.
Question 173: What are accreditation requirements for health records?
- Parking regulations
- Employee dress codes
- Building codes
- Standards set by organizations like The Joint Commission governing record content, timeliness, and completeness (Correct answer)
Correct answer: Standards set by organizations like The Joint Commission governing record content, timeliness, and completeness
Accrediting bodies set minimum standards for documentation quality, completeness, and accessibility.
Question 174: Which of the following illustrates prospective utilization management?
- As the patient's condition improves, their care is transferred from the ICU to the cardiac unit.
- The patient's care is evaluated to assess if the degree of treatment is suitable.
- Surgical treatments require preauthorization from your insurance company. (Correct answer)
- Patient's medical claims are denied.
Correct answer: Surgical treatments require preauthorization from your insurance company.
Prospective utilization management involves evaluating the medical necessity and appropriateness of healthcare services *before* they are rendered. Requiring preauthorization from an insurance company for surgical treatments is a prime example of this. This process ensures that services are justified and meet coverage criteria prior to the patient receiving care, helping to control costs and ensure appropriate utilization.
Question 175: What is the False Claims Act?
- A law about food labeling
- A federal law imposing liability on those who submit fraudulent claims to government healthcare programs (Correct answer)
- A law about identity theft
- A law about false advertising
Correct answer: A federal law imposing liability on those who submit fraudulent claims to government healthcare programs
The False Claims Act penalizes submitting knowingly false or fraudulent claims for payment to federal programs like Medicare.
Question 176: Failure Mode and Effects Analysis (FMEA) differs from root cause analysis (RCA) primarily because FMEA is:
- A proactive tool that identifies potential failures before they cause harm (Correct answer)
- Conducted only after a sentinel event has already occurred
- Mandated by CMS for all Medicare-participating hospitals annually
- Used exclusively for medication error prevention programs
Correct answer: A proactive tool that identifies potential failures before they cause harm
FMEA is a prospective risk assessment tool that systematically evaluates processes to identify where and how they might fail before an actual adverse event occurs.
Question 177: What is the purpose of a health record?
- For marketing purposes only
- To document patient care, support clinical decisions, and serve as a legal document (Correct answer)
- To track employee schedules
- Only for billing purposes
Correct answer: To document patient care, support clinical decisions, and serve as a legal document
Health records serve multiple functions: documenting care, supporting clinical decisions, providing legal evidence, enabling research, and facilitating billing.
Question 178: What is the primary purpose of a deficiency analysis in health information management?
- To evaluate physician credentialing compliance
- To track incomplete or missing documentation in medical records (Correct answer)
- To audit coding accuracy for DRG assignment
- To identify billing errors before claim submission
Correct answer: To track incomplete or missing documentation in medical records
Deficiency analysis identifies incomplete, missing, or unsigned documentation so that records can be completed within required timeframes.
Question 179: A 'small breach' affecting fewer than 500 individuals in a state must be reported to HHS:
- Within 30 days and simultaneously to local media
- Within 60 days of the breach
- Annually, no later than 60 days after the end of the calendar year (Correct answer)
- Only if the patient requests it
Correct answer: Annually, no later than 60 days after the end of the calendar year
Breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, within 60 days of the end of the calendar year.
Question 180: What is the purpose of a HIPAA Risk Analysis?
- To assess potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- To identify all employees who have accessed PHI
- To determine the financial penalties for a breach
- To create a list of all business associates
Correct answer: To assess potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI
A risk analysis identifies and evaluates potential threats and vulnerabilities to ePHI to determine the likelihood and impact of potential risks.
AHIMA Registered Health Information Administrator Exam
The AHIMA (American Health Information Management Association) administers credentials including the RHIA (Registered Health Information Administrator) and RHIT (Registered Health Information Technician). The exams cover health records management, medical coding and classification, HIPAA privacy and security, healthcare data analytics, revenue cycle management, health information governance, quality improvement, compliance and legal standards, health IT systems, clinical documentation improvement, and release of information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds