Health Information Governance Flashcards
7 cards from real AHIMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Health Information Governance flashcards as text
An organization's information governance policy prohibits sending unencrypted PHI via email. An employee who does so has violated which governance element?
Answer: Information security policy
Sending unencrypted PHI via email violates the organization's information security policy, which requires safeguards to protect PHI in transit.
Which data quality dimension measures whether all required data fields in a health record have been completed?
Answer: Completeness
Completeness measures whether all required data elements are present and populated in the health record.
A governance policy requiring physicians to complete discharge summaries within 30 days supports which health record quality dimension?
Answer: Timeliness
Timeliness requires that health record entries be made promptly; completion deadlines are a governance mechanism to enforce this dimension.
Under the HIPAA Security Rule, which category of safeguards includes workforce training and access management policies?
Answer: Administrative safeguards
Administrative safeguards under the HIPAA Security Rule include policies and procedures governing workforce conduct, training, and access authorization.
A health system's governance framework includes a process for patients to request amendments to their records. This right stems from which regulation?
Answer: HIPAA Privacy Rule 45 CFR §164.526
45 CFR §164.526 of the HIPAA Privacy Rule grants individuals the right to request amendments to their protected health information held by covered entities.
Which of the following BEST describes 'information lifecycle management' in health information governance?
Answer: Governing data from creation through use, storage, archiving, and destruction
Information lifecycle management is the governance discipline that oversees data from the moment it is created through every stage until its authorized destruction.
A hospital must report a breach affecting 600 patients to which entities under the HIPAA Breach Notification Rule?
Answer: The affected patients, HHS, and prominent media outlets in the affected area
Breaches affecting 500 or more individuals require notification to affected individuals, HHS, and prominent media outlets serving the affected area.