AHIMA Registered Health Information Administrator Exam — Questions and Answers
Question 1: Which document serves as the foundation for CDI query standards in the US?
- Joint Commission Accreditation Standards
- CMS Conditions of Participation
- OIG Work Plan
- AHIMA/ACDIS CDI Query Practice Brief (Correct answer)
Correct answer: AHIMA/ACDIS CDI Query Practice Brief
The AHIMA/ACDIS CDI Query Practice Brief provides industry-standard guidelines for compliant, ethical, and clinically appropriate physician queries.
Question 2: Which of the following best describes the 'qui tam' provision of the False Claims Act?
- It permits private individuals to file suits on behalf of the government and share in recovered funds (Correct answer)
- It authorizes HHS to exclude providers from Medicare without a hearing
- It allows providers to voluntarily disclose fraud and avoid penalties
- It defines the statute of limitations for healthcare fraud
Correct answer: It permits private individuals to file suits on behalf of the government and share in recovered funds
The qui tam provision allows private citizens (relators) to file False Claims Act suits on behalf of the U.S. government and receive a portion of any recovered funds as a reward.
Question 3: Under HIPAA, a patient's authorization for use or disclosure of PHI must include which of the following elements?
- Signature of the treating physician
- Approval from the covered entity's privacy officer
- An expiration date or event (Correct answer)
- The patient's insurance policy number
Correct answer: An expiration date or event
A valid HIPAA authorization must include an expiration date or expiration event after which the authorization is no longer valid.
Question 4: Which governance concept requires that the person requesting access to health information be the person they claim to be?
- Authorization
- Authentication (Correct answer)
- Accounting
- Auditing
Correct answer: Authentication
Authentication is the process of verifying the identity of a user before granting access to protected health information or systems.
Question 5: Logistic regression is the appropriate predictive model when the outcome variable is:
- A binary outcome such as hospital readmission (yes or no) (Correct answer)
- A continuous measurement such as average length of stay
- An ordinal ranked outcome such as patient satisfaction tier
- A count outcome such as number of emergency department visits per year
Correct answer: A binary outcome such as hospital readmission (yes or no)
Logistic regression models the log-odds of a binary outcome, making it ideal for yes/no predictions like readmission, mortality, or infection occurrence.
Question 6: Which KPI measures the average number of days to collect payment after service delivery?
- Net Collection Rate
- Denial Rate
- Clean Claim Rate
- Days in Accounts Receivable (AR) (Correct answer)
Correct answer: Days in Accounts Receivable (AR)
Days in AR measures the average elapsed time between service delivery and receipt of payment, indicating collection efficiency.
Question 7: A clerical employee describes an event in which the clerk felt the first-line supervisor discriminated against her because of her gender. The greatest step for you to take now is to:
- inquire with other clerical personnel whether they have had similar issues.
- consult the first-line supervisor to discover what occurred.
- tell the clerk to give objective proof of the discrimination.
- thoroughly explore the situation and record your findings. (Correct answer)
Correct answer: thoroughly explore the situation and record your findings.
When an employee reports discrimination, the most appropriate initial step for a manager is to conduct a thorough and objective investigation. This involves gathering all relevant facts, interviewing involved parties, and meticulously documenting the findings. This comprehensive approach ensures fairness, helps determine the validity of the claim, and provides a basis for any necessary subsequent actions.
Question 8: Which CPT code modifier indicates that only the professional component of a service was provided?
- -59
- -TC
- -52
- -26 (Correct answer)
Correct answer: -26
Modifier -26 indicates the professional (physician interpretation) component of a diagnostic service, separate from the technical component.
Question 9: Which HIPAA civil monetary penalty tier applies to violations where the covered entity was unaware and could not have known of the violation even with reasonable diligence?
- Tier 1 — $100 to $50,000 per violation (Correct answer)
- Tier 2 — $1,000 to $50,000 per violation
- Tier 3 — $10,000 to $50,000 per violation
- Tier 4 — $50,000 per violation
Correct answer: Tier 1 — $100 to $50,000 per violation
Tier 1 penalties ($100–$50,000 per violation) apply when the entity did not know and, with reasonable diligence, could not have known of the HIPAA violation.
Question 10: Which federal program publicly reports hospital quality measure performance data online as a condition of participation in Medicare?
- Medicare Advantage quality ratings
- HITECH Act attestation reporting
- HIPAA Privacy Rule reporting requirements
- Hospital Compare / Care Compare (Correct answer)
Correct answer: Hospital Compare / Care Compare
CMS's Care Compare (formerly Hospital Compare) website publicly reports hospital performance on quality measures, enabling consumers to compare hospitals and incentivizing transparency.
Question 11: Failure Mode and Effects Analysis (FMEA) differs from root cause analysis (RCA) primarily because FMEA is:
- Conducted only after a sentinel event has already occurred
- Used exclusively for medication error prevention programs
- Mandated by CMS for all Medicare-participating hospitals annually
- A proactive tool that identifies potential failures before they cause harm (Correct answer)
Correct answer: A proactive tool that identifies potential failures before they cause harm
FMEA is a prospective risk assessment tool that systematically evaluates processes to identify where and how they might fail before an actual adverse event occurs.
Question 12: A focused coding audit is MOST commonly triggered by:
- Routine monthly productivity reporting
- Completion of annual staff performance evaluations
- New employee onboarding orientation requirements
- Significant variation from expected coding patterns or elevated payer denials (Correct answer)
Correct answer: Significant variation from expected coding patterns or elevated payer denials
Focused audits are initiated when data analysis reveals unusual coding patterns, high denial rates, or OIG Work Plan risk areas that warrant targeted review.
Question 13: The Joint Commission uses 'tracer methodology' during accreditation surveys primarily to:
- Inspect facility physical plant and life safety systems
- Follow a patient's care experience across departments to evaluate system performance (Correct answer)
- Review hospital financial records and billing compliance documentation
- Audit medical record completeness and deficiency statistics
Correct answer: Follow a patient's care experience across departments to evaluate system performance
Tracer methodology follows the care journey of selected patients through the organization to identify potential vulnerabilities in care processes, communication, and documentation.
Question 14: A strong succession plan in an HIM department should primarily focus on:
- Hiring all replacements exclusively from outside the organization
- Proactively identifying and developing future leaders from within the department (Correct answer)
- Reactively replacing staff only after they resign or retire
- Eliminating mid-level positions through automation
Correct answer: Proactively identifying and developing future leaders from within the department
Succession planning involves proactively identifying and preparing internal candidates for future leadership roles to ensure continuity of operations.
Question 15: How many CEHs must an RHIT credential holder complete per two-year renewal cycle?
- 10 CEHs
- 36 CEHs
- 30 CEHs
- 20 CEHs (Correct answer)
Correct answer: 20 CEHs
RHIT credential holders are required to earn 20 CEHs every two years to maintain active status.
Question 16: The FHIR standard uses which architectural approach as its primary data exchange mechanism?
- RESTful APIs exchanging JSON or XML resources (Correct answer)
- EDI 837/835 transaction file sets
- SOAP web services with XML message envelopes
- Batch SFTP file transfers with pipe-delimited data
Correct answer: RESTful APIs exchanging JSON or XML resources
FHIR is built on REST architecture, using standard HTTP methods (GET, POST, PUT) and JSON or XML payloads organized as 'resources' for lightweight, interoperable data exchange.
Question 17: The Stark Law (Physician Self-Referral Law) primarily prohibits:
- Physicians referring Medicare/Medicaid patients for designated health services to entities in which they have a financial relationship (Correct answer)
- Billing for services personally performed by the physician without proper documentation
- Physicians accepting gifts from pharmaceutical or device representatives
- Entering into gainsharing arrangements with non-physician staff
Correct answer: Physicians referring Medicare/Medicaid patients for designated health services to entities in which they have a financial relationship
Stark Law prohibits physicians from referring patients to entities for designated health services when the physician or an immediate family member has a financial interest in that entity.
Question 18: What is a 'concurrent' CDI review?
- Review performed after the patient is discharged
- Review performed only on surgical cases
- Review performed by an external auditor
- Review performed while the patient is still admitted (Correct answer)
Correct answer: Review performed while the patient is still admitted
Concurrent CDI review occurs while the patient is still hospitalized, allowing queries to be answered before discharge and the record is coded.
Question 19: Which sampling method gives every member of a patient population an equal and independent probability of being selected?
- Convenience sampling
- Purposive sampling
- Simple random sampling (Correct answer)
- Stratified random sampling
Correct answer: Simple random sampling
Simple random sampling assigns each individual in a population an equal, independent chance of selection, eliminating systematic selection bias.
Question 20: Natural Language Processing (NLP) is most commonly applied in clinical analytics to:
- Calculate risk-adjusted capitation payment rates
- Extract structured information from free-text clinical documentation (Correct answer)
- Generate automated appointment reminders for patients
- Synchronize patient records across hospital networks
Correct answer: Extract structured information from free-text clinical documentation
NLP enables computers to interpret and extract structured data elements from unstructured sources such as clinical notes, discharge summaries, and radiology reports.
Question 21: What is record retention policy?
- Guidelines specifying how long different types of health records must be kept before destruction (Correct answer)
- Keeping all records forever
- Retention is optional
- Destroying records immediately after discharge
Correct answer: Guidelines specifying how long different types of health records must be kept before destruction
Retention policies specify minimum retention periods based on federal/state law, accreditation requirements, and organizational needs, varying by record type and patient age.
Question 22: Which chart type is BEST suited for displaying a trend in monthly hospital admission rates over a two-year period?
- Box plot
- Line chart (Correct answer)
- Pie chart
- Scatter plot
Correct answer: Line chart
Line charts are designed to display continuous data trends over time, making changes and patterns in monthly admission rates easy to identify and interpret.
Question 23: An HIE receives a laboratory result but cannot match it to the correct patient. Which master data management tool is used to link patient records across systems?
- Clinical data repository
- Health information portal
- Data warehouse
- Enterprise Master Patient Index (EMPI) (Correct answer)
Correct answer: Enterprise Master Patient Index (EMPI)
An Enterprise Master Patient Index (EMPI) links patient identities across disparate systems using probabilistic or deterministic matching algorithms.
Question 24: A hospital's compliance officer discovers that a coder has been upcoding DRGs for six months. Under the False Claims Act, which penalty could the hospital face per false claim?
- $1,000–$5,000
- $50,000–$100,000
- $500–$1,000
- $13,946–$27,894 (adjusted annually) (Correct answer)
Correct answer: $13,946–$27,894 (adjusted annually)
The False Claims Act imposes civil penalties per false claim; as of recent adjustments these range approximately $13,946 to $27,894 per claim plus treble damages.
Question 25: What additional federal protections apply to substance use disorder treatment records beyond standard HIPAA requirements?
- The Mental Health Parity Act
- CMS Conditions of Participation
- Joint Commission accreditation standards
- 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) (Correct answer)
Correct answer: 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records)
42 CFR Part 2 imposes stricter confidentiality requirements on records of patients treated for substance use disorders at federally assisted programs, requiring specific patient consent for most disclosures.
Question 26: Which of the following best describes 'upcoding' in medical billing?
- Assigning a code for a higher-reimbursed service than actually performed (Correct answer)
- Assigning a code for a lesser service than documented
- Using an outdated code set
- Bundling multiple codes into one
Correct answer: Assigning a code for a higher-reimbursed service than actually performed
Upcoding is a form of fraud in which a provider bills for a more expensive service than was actually rendered.
Question 27: Which term describes the process of ensuring that a health record accurately reflects the patient's actual condition and the care provided?
- Concurrent review
- Prospective review
- Quantitative analysis
- Qualitative analysis (Correct answer)
Correct answer: Qualitative analysis
Qualitative analysis evaluates whether the clinical content of the record is complete, accurate, and consistent with the patient's condition and care.
Question 28: Population health management analytics is designed primarily to:
- Automate clinical documentation entry within the electronic health record
- Optimize scheduling efficiency for outpatient appointment booking systems
- Streamline hospital billing and revenue cycle processing workflows
- Proactively identify health risks and manage outcomes for defined patient groups (Correct answer)
Correct answer: Proactively identify health risks and manage outcomes for defined patient groups
Population health management uses data analytics to stratify risk, coordinate care, and implement targeted interventions that improve outcomes and reduce costs across defined patient populations.
Question 29: In outpatient facility coding, when should POA (Present on Admission) indicators be reported?
- For all diagnosis codes on inpatient acute care claims (Correct answer)
- Only for Medicaid claims
- Only for principal diagnoses
- For all diagnosis codes on all claim types
Correct answer: For all diagnosis codes on inpatient acute care claims
POA indicators are required for all diagnosis codes on inpatient acute care hospital claims submitted to Medicare.
Question 30: In health informatics, a 'data lake' differs from a 'data warehouse' primarily in that a data lake:
- Stores raw data in native format without pre-defined schema (Correct answer)
- Only stores structured relational data
- Is limited to real-time streaming data
- Requires ETL processing before data ingestion
Correct answer: Stores raw data in native format without pre-defined schema
A data lake stores raw, unprocessed data in its native format with schema applied on read, unlike a data warehouse which enforces schema on write.
Question 31: A control chart in healthcare quality improvement is primarily used to:
- Calculate cost-per-case values adjusted for patient diagnosis complexity
- Compare 30-day readmission rates between hospital departments
- Rank facilities by performance on HEDIS quality measures
- Identify whether observed process variation is due to common cause or special cause (Correct answer)
Correct answer: Identify whether observed process variation is due to common cause or special cause
Control charts (Shewhart charts) plot quality metrics over time with statistical control limits to distinguish normal common-cause variation from unusual special-cause variation that warrants investigation.
Question 32: A hospital compares its surgical site infection rate against national rates published in the CDC's NHSN database. This is an example of:
- External benchmarking (Correct answer)
- Internal benchmarking
- Process benchmarking
- Functional benchmarking
Correct answer: External benchmarking
External benchmarking compares an organization's performance data to national databases, peer groups, or industry leaders outside the organization.
Question 33: What is accounts receivable in healthcare?
- Money owed to the healthcare organization for services already provided (Correct answer)
- Money in the bank
- Prepaid insurance premiums
- Government grants received
Correct answer: Money owed to the healthcare organization for services already provided
Accounts receivable represents outstanding payments for services rendered, tracked by age (30, 60, 90+ days) to monitor collection efficiency.
Question 34: Which element is NOT required in a Business Associate Agreement (BAA)?
- Obligation to safeguard PHI
- Requirement to report breaches to the covered entity
- Description of permitted uses of PHI
- A flat fee schedule for services rendered (Correct answer)
Correct answer: A flat fee schedule for services rendered
A BAA must address permitted PHI uses, safeguarding obligations, and breach reporting, but pricing or fee arrangements are contractual business terms, not HIPAA-required BAA elements.
Question 35: Which regulation specifically governs the privacy and security of substance use disorder treatment records?
- HITECH Act
- 42 CFR Part 2 (Correct answer)
- HIPAA Privacy Rule
- CMS Conditions of Participation
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides stricter federal protections for records related to substance use disorder treatment programs.
Question 36: A patient calls to request copies of their medical records. Under HIPAA, the covered entity must provide access within:
- 60 calendar days, with no extensions allowed
- 30 calendar days, with one 30-day extension if needed (Correct answer)
- 72 hours for all requests regardless of complexity
- 15 calendar days, with one 15-day extension if needed
Correct answer: 30 calendar days, with one 30-day extension if needed
HIPAA requires covered entities to act on access requests within 30 calendar days, with one 30-day extension allowed if the entity notifies the individual.
Question 37: The Institute for Healthcare Improvement's 'Triple Aim' framework focuses on simultaneously improving which three dimensions?
- Cost, quality, and patient safety
- Access, efficiency, and staff satisfaction
- Population health, patient experience, and per capita cost (Correct answer)
- Clinical outcomes, documentation accuracy, and coding quality
Correct answer: Population health, patient experience, and per capita cost
The Triple Aim targets better health for populations, better care experiences for individuals, and lower per capita costs for healthcare systems.
Question 38: Which AHIMA credential is specifically designed for professionals specializing in clinical documentation improvement (CDI)?
- CDIP (Correct answer)
- CCS-P
- CHDA
- CHPS
Correct answer: CDIP
The Certified Documentation Improvement Practitioner (CDIP) credential targets professionals who work to improve the quality and accuracy of clinical documentation.
Question 39: What is the Medicare timely filing limit for initial claim submission?
- 6 months from date of service
- 12 months (1 year) from date of service (Correct answer)
- 90 days from date of service
- 24 months from date of service
Correct answer: 12 months (1 year) from date of service
Medicare requires claims to be filed within one calendar year (12 months) from the date of service.
Question 40: A hospital implements a Clinical Decision Support (CDS) system that fires an alert every time a nurse documents vitals. This is an example of which CDS problem?
- Data normalization failure
- Workflow bypass
- Alert fatigue (Correct answer)
- Lack of interoperability
Correct answer: Alert fatigue
Alert fatigue occurs when excessive or low-specificity alerts cause clinicians to override or ignore warnings, reducing the safety benefit of CDS.
Question 41: Which data quality characteristic ensures that health data collected is the same whether captured once or multiple times?
- Consistency (Correct answer)
- Currency
- Comprehensiveness
- Accessibility
Correct answer: Consistency
Consistency means that the same data collected in different places or at different times yields the same results, ensuring reliability across the record.
Question 42: A denial with CARC code CO-4 typically indicates:
- The claim was submitted after the timely filing limit
- The procedure code is inconsistent with the modifier used (Correct answer)
- The patient was not eligible on the date of service
- The service is not covered under the patient's plan
Correct answer: The procedure code is inconsistent with the modifier used
CO-4 means the procedure code is inconsistent with the modifier used, or a required modifier is absent.
Question 43: What is a subpoena for health records?
- A referral to a specialist
- A prescription request
- A legal order requiring the production of specified health records for legal proceedings (Correct answer)
- An insurance authorization
Correct answer: A legal order requiring the production of specified health records for legal proceedings
A subpoena legally compels the release of specified records, but proper authorization and HIPAA compliance must still be verified.
Question 44: A p-value of 0.03 in a healthcare outcome study indicates:
- There is a 3% probability that the treatment was effective
- The finding has strong clinical significance
- The result is statistically significant at the 0.05 alpha level (Correct answer)
- The sample size was too small for valid conclusions
Correct answer: The result is statistically significant at the 0.05 alpha level
A p-value of 0.03 falls below the conventional 0.05 significance threshold, indicating the result is statistically significant, though this does not automatically imply clinical significance.
Question 45: Which legal doctrine holds that a patient's medical record created during treatment is the property of the healthcare facility?
- Stare decisis
- Custodial ownership doctrine (Correct answer)
- Respondeat superior
- Res ipsa loquitur
Correct answer: Custodial ownership doctrine
The custodial ownership doctrine establishes that while the physical medical record belongs to the healthcare facility, the patient retains the right to access the information contained within it.
Question 46: What is a Business Associate Agreement (BAA)?
- A contract between a covered entity and a vendor that ensures PHI protection when shared (Correct answer)
- A patient consent form
- An insurance agreement
- A partnership between hospitals
Correct answer: A contract between a covered entity and a vendor that ensures PHI protection when shared
BAAs legally require business associates (vendors handling PHI) to implement appropriate safeguards and comply with HIPAA regulations.
Question 47: What is data warehousing in healthcare?
- A physical storage facility for medical supplies
- A cold storage for vaccines
- A centralized repository storing integrated data from multiple sources for analysis and reporting (Correct answer)
- A pharmacy inventory system
Correct answer: A centralized repository storing integrated data from multiple sources for analysis and reporting
Data warehouses consolidate information from various clinical and administrative systems for comprehensive analysis and reporting.
Question 48: What is health information exchange (HIE)?
- The electronic sharing of health information between organizations according to national standards (Correct answer)
- Exchanging paper records between hospitals
- Email between doctors
- A type of insurance plan
Correct answer: The electronic sharing of health information between organizations according to national standards
HIE enables the electronic movement of health information among disparate healthcare organizations, improving care coordination and reducing duplicate testing.
Question 49: When a patient requests an amendment to their health record and the covered entity denies it, the entity must:
- Immediately report the denial to HHS
- Notify the patient's insurance company of the denial
- Allow the patient to submit a statement of disagreement (Correct answer)
- Delete the original record entry
Correct answer: Allow the patient to submit a statement of disagreement
If a covered entity denies an amendment request, the patient has the right to submit a statement of disagreement that must be appended to their record.
Question 50: Which element is a required component of an effective compliance plan per OIG guidance?
- Unlimited appeals budget for all denied Medicare claims
- A guarantee of zero claim denials within the fiscal year
- Written standards of conduct with internal monitoring and auditing processes (Correct answer)
- Delegation of all billing responsibilities to a contracted payer
Correct answer: Written standards of conduct with internal monitoring and auditing processes
The OIG identifies seven elements of an effective compliance program, including written policies, training, internal auditing, and corrective action procedures.
Question 51: In organizing an instructional session for your team about adopting a benchmarking program, you inform your staff that when an organization employs benchmarking, it is crucial to compare your facility's results to __________________.
- nationally known facilities.
- facilities within your corporation.
- facilities with superior performance. (Correct answer)
- larger facilities.
Correct answer: facilities with superior performance.
Benchmarking is a strategic process where an organization compares its performance metrics, processes, and practices to those of the best performers in its industry or other industries. The goal is to identify areas for improvement and adopt 'best practices' from those who excel. Therefore, comparing results to facilities with superior performance provides the most valuable insights for enhancing efficiency and quality.
Question 52: The concept of 'incidental disclosure' under HIPAA refers to:
- An accidental mailing of records to the wrong address
- A secondary disclosure that cannot reasonably be prevented and is limited in nature (Correct answer)
- Any unauthorized breach of PHI
- A disclosure made without the patient's knowledge
Correct answer: A secondary disclosure that cannot reasonably be prevented and is limited in nature
An incidental disclosure is a by-product of an otherwise permissible disclosure that is limited and cannot reasonably be prevented, such as overhearing staff discuss a patient in a hallway.
Question 53: A revenue cycle system automatically applies the correct ICD-10-PCS code based on documentation in the operative note. This functionality is an example of:
- Optical character recognition
- Natural language processing (NLP) computer-assisted coding (Correct answer)
- Rules-based clinical decision support
- Robotic process automation
Correct answer: Natural language processing (NLP) computer-assisted coding
NLP-powered computer-assisted coding (CAC) analyzes free-text clinical documentation to suggest or assign procedure and diagnosis codes automatically.
Question 54: What is an EOB (Explanation of Benefits)?
- A medical diagnosis summary
- A prescription refill notice
- A statement from an insurer showing what was billed, what insurance paid, and what the patient owes (Correct answer)
- A hospital discharge summary
Correct answer: A statement from an insurer showing what was billed, what insurance paid, and what the patient owes
The EOB details the claim processing results: services billed, amounts allowed, insurance payment, adjustments, and the patient's remaining financial responsibility.
Question 55: A healthcare organization implements a zero-tolerance policy against retaliation toward employees who report compliance concerns. This reflects which OIG compliance program element?
- Open lines of communication (Correct answer)
- Implementing disciplinary standards
- Conducting internal monitoring and auditing
- Responding to detected offenses
Correct answer: Open lines of communication
Non-retaliation policies encourage employees to report concerns through open communication channels, a core element of OIG's seven-component compliance program framework.
Question 56: A patient's psychotherapy notes receive special protection under HIPAA because:
- They must be stored in a separate facility from other records
- They require a specific authorization separate from general PHI authorization (Correct answer)
- They are automatically shared with insurers under coordination of benefits
- They are not considered part of the legal health record
Correct answer: They require a specific authorization separate from general PHI authorization
Psychotherapy notes (process notes) receive heightened HIPAA protection and require a specific, separate patient authorization for disclosure — they cannot be released under a general PHI authorization.
Question 57: An HIM director is asked to testify as a fact witness about the hospital's record retention practices. In this role, the director should:
- Provide only statistical summaries rather than specific facts
- Offer expert opinions about how other hospitals handle retention
- Testify only about the facts of the facility's specific practices without offering opinions (Correct answer)
- Decline to testify because HIM directors are protected by peer review privilege
Correct answer: Testify only about the facts of the facility's specific practices without offering opinions
A fact witness testifies only about what they directly know or observed, not opinions or generalizations about industry standards.
Question 58: In FHIR-based HIE, which resource is used to document a patient's consent for or against the sharing of their health information?
- RelatedPerson
- Provenance
- Consent (Correct answer)
- AuditEvent
Correct answer: Consent
The FHIR Consent resource records a patient's agreement or refusal related to the use or disclosure of their health information within an HIE.
Question 59: Which federal law specifically prohibits offering or accepting remuneration to induce referrals for services covered by Medicare or Medicaid?
- EMTALA
- False Claims Act
- Stark Law
- Anti-Kickback Statute (Correct answer)
Correct answer: Anti-Kickback Statute
The Anti-Kickback Statute (42 USC 1320a-7b) prohibits knowingly offering, paying, soliciting, or receiving anything of value to induce or reward referrals of federal healthcare program business.
Question 60: What is prior authorization?
- A doctor's license verification
- A patient's signature on a consent form
- Approval from an insurance company required before certain services are provided (Correct answer)
- A hospital's accreditation
Correct answer: Approval from an insurance company required before certain services are provided
Prior authorization requires providers to obtain insurance company approval before delivering specific services, ensuring medical necessity and coverage.
Question 61: What is the purpose of obtaining prior authorization before providing a service?
- To collect the patient's copay before treatment begins
- To verify that the provider is in-network for the patient's plan
- To confirm that the payer will cover a specific service before it is rendered (Correct answer)
- To document medical necessity after a claim has been denied
Correct answer: To confirm that the payer will cover a specific service before it is rendered
Prior authorization is the payer's advance approval that a service will be covered, reducing the risk of a medical necessity or non-covered service denial.
Question 62: Which law grants patients born after August 1975 the right to inspect their own federal education records, but is often confused with healthcare privacy rules?
- HIPAA
- HITECH
- COPPA
- FERPA (Correct answer)
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) governs educational records, not health records, though student health records at schools may fall under its scope.
Question 63: Which release of information scenario requires a valid written authorization from the patient?
- Providing records to law enforcement for a gunshot wound report
- Sending records to a public health authority for disease reporting
- Releasing records to the patient's employer for occupational health purposes (Correct answer)
- Disclosing records to a treating specialist for continuing care
Correct answer: Releasing records to the patient's employer for occupational health purposes
Disclosure to an employer generally requires written patient authorization because it falls outside the permitted uses for treatment, payment, and operations.
Question 64: Which health record component serves as the primary tool for communicating a patient's ongoing care plan among members of the interdisciplinary care team?
- Face sheet (patient registration form)
- Discharge summary
- Master patient index
- Physician's orders (Correct answer)
Correct answer: Physician's orders
Physician's orders are the primary mechanism through which care instructions are communicated to all members of the interdisciplinary team responsible for carrying out patient care.
Question 65: Which of the following is NOT considered Protected Health Information (PHI) under HIPAA?
- A patient's date of birth linked to a diagnosis
- An MRI scan with the patient's name
- De-identified statistical health data (Correct answer)
- A patient's name combined with their prescription information
Correct answer: De-identified statistical health data
De-identified health information that has had all 18 identifying elements removed does not meet the definition of PHI and is not protected under HIPAA.
Question 66: Denial management analysis in a health information quality program is BEST used to:
- Measure coder attendance and individual productivity metrics
- Schedule concurrent record reviews during patient admissions
- Generate project timelines and Gantt charts for HIM leadership
- Identify patterns in claim denials linked to coding or documentation deficiencies (Correct answer)
Correct answer: Identify patterns in claim denials linked to coding or documentation deficiencies
Analyzing denial patterns by payer, DRG, or denial reason helps identify systemic coding or documentation issues that can be corrected to improve clean claim rates.
Question 67: A telehealth platform must ensure video sessions are encrypted and patient privacy is protected. Which technical safeguard is MOST critical?
- Role-based access to scheduling
- Automatic logoff after inactivity
- End-to-end encryption of media streams (Correct answer)
- Audit logs of login attempts
Correct answer: End-to-end encryption of media streams
End-to-end encryption ensures that telehealth video and audio data cannot be intercepted or accessed by unauthorized parties during transmission.
Question 68: What is the purpose of a health record?
- To track employee schedules
- For marketing purposes only
- To document patient care, support clinical decisions, and serve as a legal document (Correct answer)
- Only for billing purposes
Correct answer: To document patient care, support clinical decisions, and serve as a legal document
Health records serve multiple functions: documenting care, supporting clinical decisions, providing legal evidence, enabling research, and facilitating billing.
Question 69: What is meaningful use of EHR?
- Any use of electronic records
- Federal criteria for using certified EHR technology to improve quality, safety, and efficiency (Correct answer)
- Using computers meaningfully
- A type of health insurance
Correct answer: Federal criteria for using certified EHR technology to improve quality, safety, and efficiency
Meaningful use (now Promoting Interoperability) sets specific criteria for using EHR technology to improve care quality and earn incentive payments.
Question 70: What is interoperability in healthcare IT?
- The ability of different health IT systems to exchange and use information meaningfully (Correct answer)
- All hospitals using the same software
- Having multiple computer monitors
- Connecting to the internet
Correct answer: The ability of different health IT systems to exchange and use information meaningfully
Interoperability enables different healthcare systems to share data in ways that can be understood and used, supporting coordinated care across organizations.
Question 71: In healthcare quality terminology, a 'never event' is defined as:
- A serious, largely preventable patient safety incident that should never occur in a well-run system (Correct answer)
- A billing error identified during a payer compliance audit
- An undocumented complication discovered during retrospective record review
- An adverse event that is statistically rare but clinically possible
Correct answer: A serious, largely preventable patient safety incident that should never occur in a well-run system
Never events, as defined by the NQF, are serious reportable events that are clearly identifiable, measurable, largely preventable, and signal a need for immediate investigation.
Question 72: What is the HIPAA-compliant fee limit concept for providing patients electronic access to their PHI in a readily producible format?
- A flat fee of $6.50 per record regardless of length
- Only a reasonable, cost-based fee limited to labor for copying and supplies; no retrieval or overhead fees allowed for patient access requests (Correct answer)
- The same rate charged to attorneys for legal records
- Standard copy fees set by state law only
Correct answer: Only a reasonable, cost-based fee limited to labor for copying and supplies; no retrieval or overhead fees allowed for patient access requests
For patient access requests, HHS guidance limits fees to the actual cost of labor for copying and supplies; facilities cannot charge retrieval, overhead, or other add-on fees.
Question 73: As a new CTR, you want to identify all reportable cancer cases from the preceding year. A crucial resource will be the facility's _____________.
- disease index (Correct answer)
- patient index
- physicians’ index
- number control index
Correct answer: disease index
A disease index is a crucial resource for a Certified Tumor Registrar (CTR) because it organizes patient records by diagnosis, including specific cancer codes. By consulting the disease index, the CTR can efficiently identify and track all patients who have been diagnosed and treated for reportable cancer cases within the facility during a given period. This ensures comprehensive case finding for cancer registries.
Question 74: Which CPT code range covers Evaluation and Management (E/M) services?
- 00100–01999
- 10000–69999
- 70010–79999
- 99202–99499 (Correct answer)
Correct answer: 99202–99499
E/M services in CPT are found in the range 99202–99499 and cover office visits, hospital care, and consultations.
Question 75: What is HIPAA?
- A type of health insurance
- The Health Insurance Portability and Accountability Act — federal law protecting patient health information privacy (Correct answer)
- A medical procedure
- A coding system
Correct answer: The Health Insurance Portability and Accountability Act — federal law protecting patient health information privacy
HIPAA establishes national standards for protecting sensitive patient health information from being disclosed without consent.
Question 76: An organization maps its information governance program against the Generally Accepted Recordkeeping Principles® (GARP®). What organization developed GARP®?
- AHIMA
- The Joint Commission
- ARMA International (Correct answer)
- The American Medical Association
Correct answer: ARMA International
ARMA International developed the Generally Accepted Recordkeeping Principles® (GARP®) as a global framework for records and information management.
Question 77: Which condition must be documented by the physician for a CDI specialist to query for 'malnutrition' to affect MS-DRG assignment?
- Clinical indicators such as poor intake, weight loss, or muscle wasting documented alongside a clinical diagnosis (Correct answer)
- Low albumin level only
- BMI below 18.5
- Any mention of dietary restrictions
Correct answer: Clinical indicators such as poor intake, weight loss, or muscle wasting documented alongside a clinical diagnosis
Malnutrition requires a physician's clinical diagnosis supported by documented indicators; lab values alone are insufficient for coding purposes.
Question 78: Which of the following is considered a leading indicator in healthcare quality analytics?
- Average length of stay
- Patient mortality rate
- 30-day readmission rate
- Hand hygiene compliance rate (Correct answer)
Correct answer: Hand hygiene compliance rate
Hand hygiene compliance is a process (leading) indicator that predicts future outcomes like infection rates, unlike readmission or mortality, which are lagging outcome measures.
Question 79: Which retention schedule should a hospital apply when state law requires records to be kept 7 years but HIPAA mandates 6 years?
- Use whichever is shorter to reduce storage costs
- Follow the state law's 7-year requirement (Correct answer)
- Consult the Joint Commission for a ruling
- Follow HIPAA's 6-year requirement as the federal standard
Correct answer: Follow the state law's 7-year requirement
When state law imposes a longer retention period than HIPAA, facilities must comply with the more stringent state requirement.
Question 80: A hospital's record retention policy must account for which special population that may require extended retention beyond standard adult periods?
- Patients who paid out-of-pocket
- Patients over age 65
- Minor patients, whose records are often retained until they reach the age of majority plus the standard retention period (Correct answer)
- Patients with chronic conditions
Correct answer: Minor patients, whose records are often retained until they reach the age of majority plus the standard retention period
Records for minors are typically retained until the patient reaches the age of majority plus the standard retention period, to preserve their future rights.
Question 81: Under the HITECH Act, which incentive program accelerated the adoption of electronic health records and, by extension, Health Information Exchange?
- Meaningful Use (now Promoting Interoperability) (Correct answer)
- MACRA Quality Payment Program
- Medicare Advantage
- Stark Law Safe Harbors
Correct answer: Meaningful Use (now Promoting Interoperability)
The Meaningful Use program, established under HITECH, provided financial incentives for EHR adoption and required electronic exchange of clinical information as a core measure.
Question 82: A covered entity discovers a laptop containing unencrypted ePHI was stolen. Under the Breach Notification Rule, this event is:
- Exempt if the laptop was password-protected
- Not a breach because laptops are small breaches
- Presumed to be a breach unless the covered entity demonstrates a low probability of compromise (Correct answer)
- Not reportable if fewer than 10 patients are affected
Correct answer: Presumed to be a breach unless the covered entity demonstrates a low probability of compromise
Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless a four-factor risk assessment demonstrates a low probability that PHI was compromised.
Question 83: Under the HIPAA Privacy Rule, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Annually regardless of patient contact
- Only when PHI is disclosed to a third party
- Only upon written request
- At first service delivery and upon request thereafter (Correct answer)
Correct answer: At first service delivery and upon request thereafter
Covered entities must provide the NPP to patients at the first point of service delivery and make it available upon request at any time.
Question 84: In ICD-10-PCS, how many characters does every procedure code contain?
- 8
- 7 (Correct answer)
- 5
- 6
Correct answer: 7
Every ICD-10-PCS code is exactly 7 alphanumeric characters, with each character representing a specific axis of classification.
Question 85: What is an audit trail in health information?
- A hiking path through a hospital
- A patient walking route
- A financial spreadsheet
- A chronological record showing who accessed, modified, or deleted data and when (Correct answer)
Correct answer: A chronological record showing who accessed, modified, or deleted data and when
Audit trails create accountability by tracking all interactions with health data.
Question 86: Which step in the revenue cycle involves recording payer payments and adjustments to individual patient accounts?
- Utilization management
- Payment posting (Correct answer)
- Charge capture
- Claim submission
Correct answer: Payment posting
Payment posting is the process of entering payments, contractual adjustments, and denials received via ERA or paper remittance into the practice management system.
Question 87: A governance policy requiring physicians to complete discharge summaries within 30 days supports which health record quality dimension?
- Timeliness (Correct answer)
- Currency
- Accuracy
- Granularity
Correct answer: Timeliness
Timeliness requires that health record entries be made promptly; completion deadlines are a governance mechanism to enforce this dimension.
Question 88: Which database model is best suited for storing and querying highly variable, unstructured patient-generated health data from wearables?
- Network model
- Relational (SQL)
- NoSQL document store (Correct answer)
- Hierarchical
Correct answer: NoSQL document store
NoSQL document stores like MongoDB handle schema-flexible, unstructured data efficiently, making them well suited for variable wearable device outputs.
Question 89: Which standard defines the structure and content of electronic health records to support longitudinal patient care across multiple providers?
- IEEE 11073
- ISO/TR 20514 (Correct answer)
- HL7 FHIR
- ASTM E1384
Correct answer: ISO/TR 20514
ISO/TR 20514 defines the electronic health record architecture and content requirements to support continuity of care across settings and time.
Question 90: What is the correct action when an error is discovered in a paper-based medical record?
- Delete the entry and write 'error' in the margin
- Remove the page and rewrite it accurately
- Draw a single line through the error, date, and initial it (Correct answer)
- Use correction fluid (white-out) to cover the error neatly
Correct answer: Draw a single line through the error, date, and initial it
The correct method is to draw a single line through the error, add the date and initials, and write the correct information—never obliterate the original entry.
Question 91: What is HL7 in health IT?
- A drug classification
- Health Level Seven — a set of international standards for sharing electronic health information (Correct answer)
- A hospital floor designation
- A vital sign measurement
Correct answer: Health Level Seven — a set of international standards for sharing electronic health information
HL7 standards enable different health IT systems to communicate by defining how data is formatted, transmitted, and interpreted.
Question 92: When a covered entity uses or discloses PHI for marketing purposes, HIPAA generally requires:
- Only that an opt-out notice be provided to the patient
- Approval from HHS before any marketing disclosure
- A business associate agreement with the marketing vendor but no authorization
- Patient authorization unless it is a face-to-face communication or a promotional gift of nominal value (Correct answer)
Correct answer: Patient authorization unless it is a face-to-face communication or a promotional gift of nominal value
HIPAA requires patient authorization for marketing uses of PHI, with narrow exceptions for face-to-face communications and promotional gifts of nominal value.
Question 93: What is revenue cycle management in healthcare?
- Setting doctor salaries
- The financial process tracking patient service from registration through final payment (Correct answer)
- Counting daily patient visits
- Managing hospital revenue only from grants
Correct answer: The financial process tracking patient service from registration through final payment
RCM encompasses the entire financial lifecycle: patient registration, insurance verification, coding, claim submission, payment posting, and collections.
Question 94: Which federal regulation requires healthcare providers to give patients electronic access to their health information within 30 days of request?
- 21st Century Cures Act (Correct answer)
- HITECH Act
- Medicare Modernization Act
- Affordable Care Act
Correct answer: 21st Century Cures Act
The 21st Century Cures Act mandates timely patient access to electronic health information and prohibits information blocking by covered actors.
Question 95: The legal health record (LHR) differs from the designated record set (DRS) in that the LHR:
- Must encompass all data used to make patient care decisions
- Is determined solely by HIPAA regulations
- Includes administrative financial data used for payment decisions
- Is defined by the organization for business and legal purposes (Correct answer)
Correct answer: Is defined by the organization for business and legal purposes
The LHR is defined by each organization to identify records disclosed for legal proceedings, while the DRS is a broader HIPAA concept covering records used in care or payment decisions.
Question 96: Which HL7 FHIR operation allows a client to retrieve all resources related to a specific patient in a single request?
- $everything (Correct answer)
- $validate
- $expand
- $lookup
Correct answer: $everything
The FHIR $everything operation on the Patient resource returns all resources associated with that patient in a single bundle response.
Question 97: What is data integrity in health information?
- The accuracy, completeness, consistency, and reliability of data throughout its lifecycle (Correct answer)
- Having a large database
- Backing up files
- Data encryption only
Correct answer: The accuracy, completeness, consistency, and reliability of data throughout its lifecycle
Data integrity ensures health information is accurate, complete, consistently formatted, and reliable from creation through storage and retrieval.
Question 98: A covered entity that experiences a breach affecting more than 500 residents of a state must notify the media within:
- 60 days of discovery (Correct answer)
- 90 days of discovery
- Within 30 days and simultaneously with HHS notification
- 30 days of discovery
Correct answer: 60 days of discovery
For breaches affecting more than 500 residents of a state or jurisdiction, covered entities must notify prominent media outlets in addition to individuals, within 60 days of discovery.
Question 99: Under HIPAA, what right does a patient have regarding amendments to their health record?
- The right to request amendment of PHI they believe is inaccurate or incomplete (Correct answer)
- The right to require the covered entity to add their version within 7 days
- The right to delete any information they dislike
- The right to rewrite the physician's notes
Correct answer: The right to request amendment of PHI they believe is inaccurate or incomplete
HIPAA gives patients the right to request an amendment to their PHI; the covered entity may deny the request if the information is accurate and complete, but must document the denial.
Question 100: In healthcare compliance, a 'corporate integrity agreement' (CIA) is typically entered into between a provider and:
- State Medicaid agency
- The Joint Commission
- The Office of Inspector General (OIG) (Correct answer)
- CMS
Correct answer: The Office of Inspector General (OIG)
Corporate Integrity Agreements are negotiated between the OIG and providers as an alternative to exclusion from federal healthcare programs following fraud or abuse settlements.
Question 101: A patient requests amendment of their medical record, claiming a diagnosis is incorrect. The covered entity may deny the request if:
- The record was created more than one year ago
- The diagnosis was entered by a licensed physician
- The information was created by another provider and is accurate and complete (Correct answer)
- The patient did not submit the request in writing
Correct answer: The information was created by another provider and is accurate and complete
A covered entity may deny an amendment request if the PHI was not created by the entity and it believes the originating provider is better positioned to assess accuracy.
Question 102: How many continuing education hours (CEHs) must an RHIA credential holder complete per two-year renewal cycle?
- 30 CEHs (Correct answer)
- 20 CEHs
- 36 CEHs
- 40 CEHs
Correct answer: 30 CEHs
RHIA credential holders must complete 30 CEHs every two years to maintain active credential status.
Question 103: Which role is MOST accountable for the overall strategic direction of health information governance across an enterprise?
- Chief Information Governance Officer (CIGO) or equivalent executive (Correct answer)
- Data steward
- Release of information specialist
- Medical records technician
Correct answer: Chief Information Governance Officer (CIGO) or equivalent executive
A CIGO or equivalent executive-level role holds enterprise-wide accountability for the strategic direction, policies, and culture of information governance.
Question 104: A hospital's governance committee discovers that two departments use different codes for the same diagnosis. This is an example of a failure in:
- Release of information
- Record completion
- Data quality — consistency (Correct answer)
- Information security
Correct answer: Data quality — consistency
Data consistency means the same data element has the same value across all systems and departments; differing codes for the same diagnosis violates this dimension.
Question 105: Under HIPAA, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- No later than the first service delivery date (Correct answer)
- Annually on January 1st
- Only upon written request
- Only when a breach has occurred
Correct answer: No later than the first service delivery date
HIPAA requires covered entities to provide the NPP no later than the date of first service delivery to the individual.
Question 106: What is HCPCS?
- A health insurance plan
- A patient identifier
- Healthcare Common Procedure Coding System — codes for services, equipment, and supplies not in CPT (Correct answer)
- A hospital management system
Correct answer: Healthcare Common Procedure Coding System — codes for services, equipment, and supplies not in CPT
HCPCS codes cover items and services not included in CPT, such as durable medical equipment, prosthetics, ambulance services, and certain drugs.
Question 107: A hospital's IT team uses a CMDB (Configuration Management Database) to track all hardware and software assets. This practice belongs to which IT management framework?
- ITIL (Correct answer)
- COBIT
- Six Sigma
- Lean Healthcare
Correct answer: ITIL
A CMDB is a core component of ITIL's Service Asset and Configuration Management process, tracking IT assets and their relationships.
Question 108: A hospital must report a breach affecting 600 patients to which entities under the HIPAA Breach Notification Rule?
- Only HHS, as patients are notified at next visit
- The affected patients, HHS, and prominent media outlets in the affected area (Correct answer)
- Only the affected patients
- The affected patients and HHS; media notification is not required below 500 in the same state
Correct answer: The affected patients, HHS, and prominent media outlets in the affected area
Breaches affecting 500 or more individuals require notification to affected individuals, HHS, and prominent media outlets serving the affected area.
Question 109: What distinguishes a problem-oriented medical record (POMR) from a source-oriented medical record (SOMR)?
- POMR organizes information by clinical problem; SOMR organizes by department or source of information (Correct answer)
- POMR uses ICD codes; SOMR uses CPT codes
- POMR is used only in outpatient settings; SOMR is used only in hospitals
- POMR requires electronic format; SOMR allows paper only
Correct answer: POMR organizes information by clinical problem; SOMR organizes by department or source of information
The POMR organizes entries around numbered patient problems, while the SOMR groups information by the type or source of service (e.g., lab, radiology, nursing).
Question 110: Which type of consent authorizes a healthcare facility to provide routine treatment and is typically obtained upon admission?
- Advance directive
- Informed consent
- Implied consent
- General consent (Correct answer)
Correct answer: General consent
General consent covers routine hospital care and administrative processes, while informed consent is procedure-specific and requires disclosure of risks, benefits, and alternatives.
Question 111: Which organization jointly developed the Official Guidelines for Coding and Reporting used with ICD-10-CM in the US?
- CMS, NCHS, AHA, and AHIMA (Correct answer)
- AMA and AHA only
- WHO and CMS
- CMS and AMA only
Correct answer: CMS, NCHS, AHA, and AHIMA
The Official Guidelines are a cooperative effort of four organizations: CMS, NCHS, AHA, and AHIMA.
Question 112: Which HIPAA transaction set is used to transmit an electronic remittance advice (ERA)?
- HIPAA 835 (Correct answer)
- HIPAA 270/271
- HIPAA 837P
- HIPAA 276/277
Correct answer: HIPAA 835
The HIPAA 835 transaction is the electronic remittance advice used by payers to communicate payment details and adjustments to providers.
Question 113: What does the term 'authentication' mean in the context of health records?
- Encrypting a record so only authorized users can view it
- Verifying the author's identity and confirming they are responsible for an entry (Correct answer)
- Converting a paper record into electronic format
- Auditing a record for compliance with coding guidelines
Correct answer: Verifying the author's identity and confirming they are responsible for an entry
Authentication is the process by which an author verifies their identity and accepts responsibility for the content of a health record entry.
Question 114: Which of the following activities qualifies as an AHIMA-approved continuing education activity for credential renewal?
- Volunteering at a community health fair
- Reading a journal article with no associated assessment
- Reviewing personal health records for accuracy
- Attending an AHIMA-approved educational seminar or webinar (Correct answer)
Correct answer: Attending an AHIMA-approved educational seminar or webinar
Attending AHIMA-approved educational programs with defined learning objectives is a recognized CEH-earning activity.
Question 115: Benchmarking in healthcare quality improvement is BEST described as:
- Comparing organizational performance against best practices or peer organizations (Correct answer)
- Conducting unannounced audits of departmental processes and workflows
- Setting internal performance targets based solely on prior-year organizational data
- Reviewing patient satisfaction surveys on a quarterly basis
Correct answer: Comparing organizational performance against best practices or peer organizations
Benchmarking uses external reference points — industry best practices or comparable organizations — to set meaningful performance targets and identify improvement gaps.
Question 116: Which system architecture pattern separates data access logic into a distinct layer, making it easier to swap underlying database technologies in a health IT application?
- Publish-subscribe
- Repository pattern (Correct answer)
- Service mesh
- Event sourcing
Correct answer: Repository pattern
The repository pattern abstracts data access behind an interface, allowing the persistence layer to be replaced without changing business logic.
Question 117: What is master patient index (MPI)?
- A list of the best patients
- A database that assigns a unique identifier to each patient and cross-references all their records (Correct answer)
- An insurance company database
- A hospital's main telephone directory
Correct answer: A database that assigns a unique identifier to each patient and cross-references all their records
The MPI ensures each patient has one unique identifier across all systems, preventing duplicate records and enabling accurate record retrieval.
Question 118: Which scenario describes a valid 'incidental disclosure' that does not violate HIPAA?
- A patient overhearing their name called in a waiting room despite reasonable safeguards being in place (Correct answer)
- Faxing a full medical record to a wrong number
- Emailing unencrypted PHI to the wrong provider
- Posting a patient's diagnosis on a public bulletin board by mistake
Correct answer: A patient overhearing their name called in a waiting room despite reasonable safeguards being in place
Incidental disclosures that occur as a by-product of a permissible disclosure and despite reasonable safeguards do not violate HIPAA, such as calling a patient's name in a waiting room.
Question 119: Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of a breach within:
- 30 days of discovery
- 24 hours of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
Correct answer: 60 days of discovery
Covered entities must provide breach notifications to affected individuals without unreasonable delay and no later than 60 days following discovery of the breach.
Question 120: Under ICD-10-CM/PCS guidelines, when is it appropriate to code a condition as 'present on admission' (POA)?
- When the condition develops within 24 hours of admission
- When the condition is documented on the face sheet
- When the condition exists at the time the order for inpatient admission occurs (Correct answer)
- When the attending physician designates it as pre-existing
Correct answer: When the condition exists at the time the order for inpatient admission occurs
POA is defined as a condition present at the time the order for inpatient admission is made, including conditions that develop during an outpatient encounter that results in admission.
Question 121: The Joint Commission's ORYX initiative requires accredited hospitals to collect and report data on:
- Financial performance metrics and operating costs
- Staff credentialing and licensure status
- Core performance measures linked to accreditation standards (Correct answer)
- Facility infrastructure and safety inspections
Correct answer: Core performance measures linked to accreditation standards
ORYX integrates performance measurement data into the accreditation process, requiring hospitals to report on standardized core measures such as sepsis care, VTE prophylaxis, and perinatal care.
Question 122: What does the term 'upcoding' mean in medical billing?
- Coding a service that was never rendered
- Using outdated code sets for claim submission
- Assigning a higher-level code than documented to increase reimbursement (Correct answer)
- Assigning a lower-level code than documented to reduce patient costs
Correct answer: Assigning a higher-level code than documented to increase reimbursement
Upcoding is assigning a billing code for a more expensive or complex service than what was actually documented or performed, constituting fraud.
Question 123: The use of personal signature stamps to authenticate entries in a paper-based record necessitates additional precautions to prevent delegated stamp usage. In a totally computerized patient record system, comparable techniques may be applied to regulate the usage of _____________________.
- voice recognition systems
- expert systems
- fingerprint signatures
- electronic signatures (Correct answer)
Correct answer: electronic signatures
In a paper-based system, signature stamps require strict controls to prevent unauthorized use. Similarly, in a fully computerized patient record system, electronic signatures serve the same authentication purpose, verifying the identity of the person making an entry. Therefore, comparable stringent techniques and controls are necessary to regulate the usage of electronic signatures to ensure their integrity, security, and prevent unauthorized access or use.
Question 124: Which claim form is required for professional/physician billing to Medicare?
- CMS-1500 (Correct answer)
- HIPAA 837I
- UB-04
- ADA Dental Claim Form
Correct answer: CMS-1500
The CMS-1500 is the standard claim form used by non-institutional providers, including physicians, for professional billing to Medicare.
Question 125: What federal law primarily governs the release of protected health information (PHI) by covered entities in the US?
- The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (Correct answer)
- The Freedom of Information Act (FOIA)
- The Health Information Technology for Economic and Clinical Health (HITECH) Act only
- The Americans with Disabilities Act (ADA)
Correct answer: The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule
The HIPAA Privacy Rule (45 CFR Parts 160 and 164) is the primary federal regulation governing disclosure of PHI by covered entities and business associates.
Question 126: Which data quality characteristic refers to whether data values fall within an expected or acceptable range for a given data element?
- Completeness
- Consistency
- Timeliness
- Validity (Correct answer)
Correct answer: Validity
Data validity means the data conforms to an expected format, range, or set of permissible values — for example, a patient age of 250 would fail a validity check.
Question 127: Under HIPAA's Minimum Necessary Standard, a covered entity must:
- Disclose only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Disclose complete records whenever requested by any provider
- Obtain separate authorizations for each data field disclosed
- Redact all demographic information before any disclosure
Correct answer: Disclose only the minimum amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires that covered entities make reasonable efforts to limit PHI disclosed to the smallest amount necessary to accomplish the intended purpose.
Question 128: Which CMS program adjusts hospital inpatient payments based on performance on quality, safety, and patient experience measures?
- Meaningful Use Incentive Program
- Promoting Interoperability Program
- Hospital Value-Based Purchasing (VBP) (Correct answer)
- Physician Quality Reporting System (PQRS)
Correct answer: Hospital Value-Based Purchasing (VBP)
The Hospital VBP program withholds a percentage of base operating DRG payments and redistributes them based on hospital performance across clinical outcomes, safety, and patient experience domains.
Question 129: When a health system implements a new EHR, which governance document guides the mapping of legacy data fields to the new system's data elements?
- Business associate agreement
- Data migration crosswalk or mapping document (Correct answer)
- Release of information log
- Minimum necessary matrix
Correct answer: Data migration crosswalk or mapping document
A data migration crosswalk or mapping document aligns legacy data fields with corresponding elements in the new system to ensure accurate data transfer.
Question 130: Which coding quality activity involves reviewing a statistically valid random sample of discharged records to assess overall coder performance across the department?
- Deficiency analysis
- Case mix monitoring
- Random retrospective coding audit (Correct answer)
- Concurrent prospective review
Correct answer: Random retrospective coding audit
A random retrospective coding audit samples discharged records across coders and payers to evaluate accuracy and identify education needs without targeting a specific issue.
Question 131: Which of the following represents a permissible disclosure of PHI without patient authorization under HIPAA?
- Disclosing PHI to a marketing company for targeted ads
- Sharing PHI with an employer for performance review
- Reporting communicable disease information to a public health authority (Correct answer)
- Selling PHI to a pharmaceutical company for research
Correct answer: Reporting communicable disease information to a public health authority
HIPAA permits disclosure of PHI to public health authorities for disease surveillance and reporting without patient authorization.
Question 132: What is the primary objective of a Clinical Documentation Improvement (CDI) program?
- To reduce the total volume of medical records stored on-site
- To transition facilities from paper to electronic health records
- To ensure documentation accurately reflects patient severity, complexity, and resource use (Correct answer)
- To accelerate medical record coding turnaround time
Correct answer: To ensure documentation accurately reflects patient severity, complexity, and resource use
CDI programs work concurrently with clinicians to clarify ambiguous or incomplete documentation so coded data accurately represents the patient's true clinical picture.
Question 133: In a healthcare data governance program, a data steward is primarily responsible for:
- Ensuring data quality, integrity, and appropriate use within an assigned data domain (Correct answer)
- Managing IT infrastructure and hardware for enterprise data storage
- Designing and maintaining the physical database schema
- Writing optimized SQL queries for analytics and reporting
Correct answer: Ensuring data quality, integrity, and appropriate use within an assigned data domain
A data steward acts as a subject matter expert who defines data quality rules, resolves data issues, and ensures data within their domain is accurate, consistent, and used appropriately.
Question 134: Which approach to data normalization in HIE ensures that clinical concepts from different code systems (e.g., SNOMED CT, ICD-10, LOINC) are correctly translated to a common meaning?
- Syntactic interoperability
- Organizational interoperability
- Foundational interoperability
- Semantic interoperability through terminology mapping (Correct answer)
Correct answer: Semantic interoperability through terminology mapping
Semantic interoperability achieved through terminology mapping (e.g., mapping SNOMED CT to ICD-10) ensures that concepts shared between systems carry the same meaning.
Question 135: Mentorship programs in the HIM profession primarily serve to:
- Substitute for required continuing education credits
- Transfer institutional knowledge and support career growth for newer professionals (Correct answer)
- Replace formal education and credentialing requirements
- Guarantee promotions for mentees within two years
Correct answer: Transfer institutional knowledge and support career growth for newer professionals
HIM mentorship programs connect experienced practitioners with newer professionals to transfer knowledge and guide career development.
Question 136: What is the timeframe a covered entity has to provide a patient access to their own PHI under the HIPAA Access Rule?
- 7 business days
- 14 calendar days
- 60 calendar days
- 30 calendar days, with one 30-day extension if needed (Correct answer)
Correct answer: 30 calendar days, with one 30-day extension if needed
HIPAA requires covered entities to provide patient access to PHI within 30 calendar days of the request, with the option of a single 30-day extension with written notice.
Question 137: A hospital's case mix index (CMI) increased from 1.4 to 1.7. This most likely indicates that the hospital:
- Discharged more patients with lower acuity and fewer resource requirements
- Treated a higher proportion of complex or resource-intensive patients (Correct answer)
- Experienced a decline in coding accuracy leading to systematic undercoding
- Had a significant decrease in total patient discharge volume during the period
Correct answer: Treated a higher proportion of complex or resource-intensive patients
A higher CMI reflects a shift in patient mix toward more complex, resource-intensive cases, which typically increases Medicare MS-DRG reimbursement rates.
Question 138: Which of the following illustrates prospective utilization management?
- Patient's medical claims are denied.
- The patient's care is evaluated to assess if the degree of treatment is suitable.
- Surgical treatments require preauthorization from your insurance company. (Correct answer)
- As the patient's condition improves, their care is transferred from the ICU to the cardiac unit.
Correct answer: Surgical treatments require preauthorization from your insurance company.
Prospective utilization management involves evaluating the medical necessity and appropriateness of healthcare services *before* they are rendered. Requiring preauthorization from an insurance company for surgical treatments is a prime example of this. This process ensures that services are justified and meet coverage criteria prior to the patient receiving care, helping to control costs and ensure appropriate utilization.
Question 139: Which type of PHI disclosure does NOT require a patient's authorization under HIPAA?
- Release for treatment, payment, or healthcare operations (TPO) (Correct answer)
- Release to a marketing firm
- Release to the patient's employer for personnel decisions
- Release to a life insurance company
Correct answer: Release for treatment, payment, or healthcare operations (TPO)
HIPAA permits covered entities to disclose PHI without patient authorization for treatment, payment, and healthcare operations purposes.
Question 140: Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?
- Transmission security
- Facility access controls
- Workstation use policies
- Security management process (Correct answer)
Correct answer: Security management process
The security management process is a required administrative safeguard that includes risk analysis, risk management, sanction policy, and information system activity review.
Question 141: Which interoperability framework published by the Office of the National Coordinator (ONC) defines the four domains of interoperability—foundational, structural, semantic, and organizational?
- FHIR Implementation Guide
- CommonWell Health Alliance Charter
- Interoperability Standards Advisory (ISA)
- TEFCA (Trusted Exchange Framework and Common Agreement) (Correct answer)
Correct answer: TEFCA (Trusted Exchange Framework and Common Agreement)
TEFCA establishes the Trusted Exchange Framework defining governance, technical, and legal requirements, and references the four interoperability domains across its structure.
Question 142: What is 'severity of illness' (SOI) in the context of clinical documentation and reimbursement?
- The number of diagnoses assigned to a case
- A measure of the extent of physiologic decompensation or organ system loss of function (Correct answer)
- A Medicare billing modifier
- The patient's pain scale score
Correct answer: A measure of the extent of physiologic decompensation or organ system loss of function
Severity of illness reflects the degree of physiologic decompensation and is used in all-patient refined DRG (APR-DRG) systems to assess resource needs.
Question 143: Which of the following best describes 'workforce' under HIPAA?
- Only licensed healthcare professionals
- Contractors who sign a BAA
- Employees, volunteers, trainees, and others under the direct control of the covered entity (Correct answer)
- Only full-time employees of a covered entity
Correct answer: Employees, volunteers, trainees, and others under the direct control of the covered entity
HIPAA defines workforce broadly to include all persons whose conduct is under the direct control of the covered entity, whether or not they are paid.
Question 144: Which of the following is TRUE about the HIPAA 'Right to Restrict' disclosures?
- Covered entities must always honor all patient restriction requests
- Covered entities can never restrict disclosures to health plans
- Covered entities must honor a restriction if the patient pays out-of-pocket in full for a service (Correct answer)
- Restriction requests must be approved by the covered entity's medical director
Correct answer: Covered entities must honor a restriction if the patient pays out-of-pocket in full for a service
Under the 2013 Omnibus Rule, covered entities must honor a patient's request to restrict disclosure to a health plan when the patient pays out-of-pocket in full for the service.
Question 145: What does the prefix "99" indicate in the tumor registry accession number "99-0001"?
- the total number of primary cancers recorded for that patient
- the year the case was put into the registry's database (Correct answer)
- the case's sequence number
- the tumor's stage according to the TNM staging method
Correct answer: the year the case was put into the registry's database
In tumor registry accession numbers, the initial digits typically indicate the year the case was entered into the registry's database. Therefore, in the accession number '99-0001', the prefix '99' signifies that the case was accessioned or added to the registry in the year 1999. The subsequent numbers usually represent the sequence of cases for that year.
Question 146: What are clinical quality measures?
- Financial performance indicators
- Standardized metrics assessing healthcare processes, outcomes, and patient experience (Correct answer)
- Patient satisfaction surveys only
- Hospital decoration standards
Correct answer: Standardized metrics assessing healthcare processes, outcomes, and patient experience
Clinical quality measures evaluate whether healthcare services are effective, safe, efficient, patient-centered, equitable, and timely.
Question 147: 'Data provenance' in healthcare analytics refers to:
- Legal ownership rights over patient-generated health data
- The documented history of a dataset's origin, movement, and transformation over time (Correct answer)
- The geographic region where patient data was originally collected
- Regulatory requirements governing minimum health data retention periods
Correct answer: The documented history of a dataset's origin, movement, and transformation over time
Data provenance tracks where data came from, how it was collected, who modified it, and what transformations it underwent—essential for audit trails and trusting analytical results.
Question 148: A data steward's PRIMARY responsibility in health information governance is to:
- Oversee clinical staff credentialing
- Ensure data quality and appropriate use within an assigned domain (Correct answer)
- Approve IT infrastructure purchases
- Negotiate payer contracts
Correct answer: Ensure data quality and appropriate use within an assigned domain
Data stewards are accountable for the quality, integrity, and appropriate use of data elements within their assigned subject area or domain.
Question 149: Which SQL aggregate function would an analyst use to calculate the average length of stay for patients in a specific DRG?
- MAX()
- SUM()
- AVG() (Correct answer)
- COUNT()
Correct answer: AVG()
The AVG() function returns the arithmetic mean of a numeric column, which directly computes the average length of stay across a group of patient records.
Question 150: A health system's governance policy allows de-identified data to be shared freely for research. Which de-identification method removes 18 specific identifiers listed in the HIPAA Privacy Rule?
- Safe Harbor method (Correct answer)
- Statistical sampling method
- Limited data set method
- Expert determination method
Correct answer: Safe Harbor method
The Safe Harbor method requires removal of all 18 specific categories of identifiers listed in the HIPAA Privacy Rule before data is considered de-identified.
Question 151: What is the role of the Case Mix Index (CMI) trend in assessing CDI program effectiveness?
- A rising CMI always indicates fraud
- An increasing CMI after CDI implementation may suggest improved documentation capture of patient complexity (Correct answer)
- CMI measures only surgical case complexity
- CMI is unrelated to CDI outcomes
Correct answer: An increasing CMI after CDI implementation may suggest improved documentation capture of patient complexity
An upward trend in CMI following CDI program implementation often reflects better documentation of patient severity, not necessarily sicker patients.
Question 152: Which federal certification program ensures that EHR products meet technical standards required for Promoting Interoperability programs?
- CMS Conditions of Participation
- Joint Commission EHR Accreditation
- ONC Health IT Certification Program (Correct answer)
- HITRUST Certification
Correct answer: ONC Health IT Certification Program
The ONC Health IT Certification Program tests and certifies EHR technology to ensure it meets standards required for CMS incentive programs.
Question 153: A health information manager notices that the same clinical concept is coded differently across two merged health systems. This is a problem of:
- Data redundancy
- Syntactic mismatch
- Semantic interoperability (Correct answer)
- Record duplication
Correct answer: Semantic interoperability
Semantic interoperability requires that data shared between systems has a consistent, agreed-upon meaning — inconsistent coding breaks this.
Question 154: Which statistical measure is most resistant to outliers when analyzing patient length-of-stay data?
- Mean
- Median (Correct answer)
- Variance
- Standard deviation
Correct answer: Median
The median is the middle value of an ordered dataset and is unaffected by extreme outliers, making it more reliable than the mean for skewed distributions like length of stay.
Question 155: Which of the following is an example of a HIPAA technical safeguard?
- Training employees on privacy policies
- Installing locks on server room doors
- Conducting annual risk assessments
- Implementing automatic logoff for workstations after a period of inactivity (Correct answer)
Correct answer: Implementing automatic logoff for workstations after a period of inactivity
Automatic logoff is a technical safeguard that terminates an electronic session after a predetermined period of inactivity to prevent unauthorized access.
Question 156: Which FHIR resource type is used to represent a patient's longitudinal clinical record summary, including problems, medications, and allergies?
- Encounter
- CarePlan
- DocumentReference
- Composition (used in CCD/C-CDA) (Correct answer)
Correct answer: Composition (used in CCD/C-CDA)
The FHIR Composition resource assembles a set of clinical resources into a coherent document, and is the basis for the Consolidated CDA (C-CDA) mapped in FHIR, representing a summary record.
Question 157: In CDI, what is the 'case mix index' (CMI)?
- The percentage of cases with MCCs
- The average relative weight of all MS-DRGs for a given period (Correct answer)
- The average length of stay for all patients
- The ratio of surgical to medical cases
Correct answer: The average relative weight of all MS-DRGs for a given period
The case mix index is the average relative weight of MS-DRGs for a hospital's patient population, reflecting the complexity and resource intensity of cases treated.
Question 158: Which of the following is an addressable implementation specification under the HIPAA Security Rule?
- Encryption and decryption of ePHI at rest (Correct answer)
- Unique user identification
- Risk analysis
- Sanction policy
Correct answer: Encryption and decryption of ePHI at rest
Encryption of ePHI at rest is an addressable specification, meaning covered entities must implement it or document why an equivalent alternative measure is sufficient.
Question 159: An HIM professional who misrepresents their credentials on a job application has violated which core principle of the AHIMA Code of Ethics?
- Honesty and integrity in professional conduct (Correct answer)
- Compliance with ICD-10 coding guidelines
- Advocacy for patient rights
- Confidentiality of protected health information
Correct answer: Honesty and integrity in professional conduct
Falsifying or misrepresenting credentials violates the honesty and integrity principle of the AHIMA Code of Ethics.
Question 160: Which body provides the official guidelines for ICD-10-CM coding that HIM governance policies must align with?
- The Joint Commission
- The ICD-10-CM Official Guidelines Cooperating Parties (Correct answer)
- The Office of the National Coordinator
- The American Medical Association
Correct answer: The ICD-10-CM Official Guidelines Cooperating Parties
The Cooperating Parties — AHA, AHIMA, CMS, and NCHS — jointly publish the official ICD-10-CM coding guidelines that govern coding practice.
Question 161: What is the correct process when a patient revokes a previously signed HIPAA authorization?
- The covered entity must immediately stop all disclosures, with no exceptions
- The revocation must be notarized to be valid
- Revocation applies only to electronic records
- Disclosures that already occurred in reliance on the authorization are not affected, but future disclosures must stop (Correct answer)
Correct answer: Disclosures that already occurred in reliance on the authorization are not affected, but future disclosures must stop
A patient may revoke a HIPAA authorization in writing at any time, but the revocation does not affect disclosures already made in reliance on the authorization.
Question 162: In the United States, the ICD-10-CM diagnosis coding system used for quality reporting and reimbursement is officially maintained by:
- AHRQ and The Joint Commission
- CMS and the CDC's National Center for Health Statistics (NCHS) (Correct answer)
- AHIMA and the AHA jointly through the Cooperating Parties
- The American Medical Association (AMA)
Correct answer: CMS and the CDC's National Center for Health Statistics (NCHS)
ICD-10-CM is maintained cooperatively by CMS and the NCHS/CDC in the US, with annual updates coordinated through the ICD-10 Coordination and Maintenance Committee.
Question 163: What is the purpose of medical coding?
- To translate diagnoses, procedures, and services into universal alphanumeric codes for billing and data analysis (Correct answer)
- To create passwords
- To encrypt patient records
- To organize medical supplies
Correct answer: To translate diagnoses, procedures, and services into universal alphanumeric codes for billing and data analysis
Medical coding converts clinical documentation into standardized codes that support billing, research, public health monitoring, and quality measurement.
Question 164: What does the acronym 'NEC' mean when encountered in the ICD-10-CM Tabular List?
- Not Entirely Coded
- No External Cause
- Non-Essential Condition
- Not Elsewhere Classifiable (Correct answer)
Correct answer: Not Elsewhere Classifiable
NEC stands for 'Not Elsewhere Classifiable' and is used when the available codes do not fully describe a specific condition.
Question 165: In the context of health information governance, 'data provenance' refers to:
- The geographic origin of the patient
- The documented history of data origin, movement, and transformation (Correct answer)
- The encryption algorithm used to secure data
- The cost associated with data storage
Correct answer: The documented history of data origin, movement, and transformation
Data provenance tracks the origin, custody, and transformation history of data so users can assess its reliability and trustworthiness.
Question 166: Which of the following conditions would be coded as a 'manifestation' rather than an 'etiology' in ICD-10-CM?
- Essential hypertension
- Diabetic peripheral neuropathy (the neuropathy) (Correct answer)
- Type 2 diabetes mellitus
- Hypertension causing chronic kidney disease
Correct answer: Diabetic peripheral neuropathy (the neuropathy)
Diabetic peripheral neuropathy is a manifestation of diabetes; the neuropathy code is sequenced second after the diabetes (etiology) code.
Question 167: What must a covered entity include in its Notice of Privacy Practices (NPP)?
- A description of how PHI may be used and disclosed, patient rights, and how to file a complaint with HHS (Correct answer)
- A list of all patients' names and diagnoses
- Employee access log policies only
- The facility's billing codes and fee schedule
Correct answer: A description of how PHI may be used and disclosed, patient rights, and how to file a complaint with HHS
The NPP must describe the covered entity's uses and disclosures of PHI, patient rights (access, amendment, accounting), how to exercise those rights, and how to file a complaint with HHS OCR.
Question 168: What is data mapping in health information?
- Drawing maps of hospital departments
- The process of connecting data fields between different systems to enable information exchange (Correct answer)
- Creating geographic databases
- Mapping patient locations
Correct answer: The process of connecting data fields between different systems to enable information exchange
Data mapping establishes correspondences between data elements in different systems, enabling meaningful information exchange and system interoperability.
Question 169: HCPCS Level II codes are primarily used to report:
- Inpatient principal diagnosis codes
- Evaluation and management services
- Surgical procedures performed in the operating room
- Durable medical equipment, supplies, and non-physician services (Correct answer)
Correct answer: Durable medical equipment, supplies, and non-physician services
HCPCS Level II alpha-numeric codes cover items such as DME, ambulance services, orthotics, prosthetics, and drugs not classified within CPT.
Question 170: Which right does HIPAA give patients regarding their health records?
- The right to access and obtain a copy of their PHI (Correct answer)
- The right to alter clinical notes without provider consent
- The right to demand deletion of all their PHI
- The right to prohibit any disclosure including for treatment
Correct answer: The right to access and obtain a copy of their PHI
HIPAA's Privacy Rule grants individuals the right to access, inspect, and receive copies of their PHI held by a covered entity.
Question 171: Which scenario best exemplifies 'secondary use' of health data?
- A researcher analyzing de-identified EHR data to study diabetes outcomes (Correct answer)
- A clinician accessing records during an emergency department visit
- A nurse documenting vital signs during an inpatient encounter
- A physician reviewing a patient's chart before a scheduled appointment
Correct answer: A researcher analyzing de-identified EHR data to study diabetes outcomes
Secondary use occurs when health data originally collected for patient care is subsequently used for research, quality improvement, or public health purposes outside the original encounter.
Question 172: What is data governance in health information?
- Policies and procedures ensuring data quality, security, availability, and proper use across an organization (Correct answer)
- Keeping data on government servers
- A type of encryption
- Deleting old data
Correct answer: Policies and procedures ensuring data quality, security, availability, and proper use across an organization
Data governance establishes the framework for data management including quality standards, access policies, security measures, and accountability structures.
Question 173: A patient requests amendment of their medical record because they believe a diagnosis is incorrect. Under HIPAA, the covered entity may deny the request if:
- The information was not created by the covered entity (Correct answer)
- The record was created more than 6 months ago
- The patient has previously requested an amendment
- The provider who created the record is no longer employed there
Correct answer: The information was not created by the covered entity
HIPAA permits denial of an amendment request if the covered entity did not create the information and the originating source is still available.
Question 174: Which federal regulation establishes the minimum necessary standard for sharing protected health information (PHI)?
- CMS Conditions of Participation
- Joint Commission Standards
- HITECH Act
- HIPAA Privacy Rule (Correct answer)
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule requires that only the minimum necessary amount of PHI be used or disclosed to accomplish the intended purpose.
Question 175: The Anti-Kickback Statute (AKS) prohibits:
- Physicians billing for services provided by unqualified staff
- Offering, paying, soliciting, or receiving anything of value to induce referrals for federally reimbursed services (Correct answer)
- Submitting claims without complete supporting documentation
- Billing Medicare as primary payer when a commercial payer is primary
Correct answer: Offering, paying, soliciting, or receiving anything of value to induce referrals for federally reimbursed services
The AKS prohibits any remuneration exchanged to induce or reward referrals of items or services covered by federal healthcare programs.
Question 176: Which federal rule, effective in 2022, prohibits healthcare organizations from blocking patients' access to their own electronic health information?
- Affordable Care Act Section 3001
- HIPAA Omnibus Rule
- Medicare Access and CHIP Reauthorization Act (MACRA)
- 21st Century Cures Act Information Blocking Rule (Correct answer)
Correct answer: 21st Century Cures Act Information Blocking Rule
The Information Blocking Rule under the 21st Century Cures Act prohibits practices that unreasonably restrict access, exchange, or use of electronic health information (EHI) without a recognized exception.
Question 177: What is the legal health record?
- The patient's personal health journal
- Only the billing records
- The documentation of healthcare services maintained by an organization that serves as its business and legal record (Correct answer)
- Any notes a doctor writes
Correct answer: The documentation of healthcare services maintained by an organization that serves as its business and legal record
The legal health record is the subset of all patient data that the organization defines as its official business record, used for legal proceedings, patient requests, and audits.
Question 178: What elements are required in a valid HIPAA authorization for release of PHI?
- Physician signature and facility stamp
- Patient name and date only
- Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke (Correct answer)
- Insurance ID number and diagnosis code
Correct answer: Description of information, purpose, recipient, expiration, patient signature with date, and right to revoke
A valid HIPAA authorization must include core elements such as a description of the PHI, the purpose of disclosure, the recipient, an expiration date/event, patient signature, and notice of the right to revoke.
Question 179: What is health information governance?
- An electronic health record vendor
- An organization-wide framework for managing the integrity, confidentiality, and availability of health data (Correct answer)
- A type of medical license
- A government agency overseeing hospitals
Correct answer: An organization-wide framework for managing the integrity, confidentiality, and availability of health data
HIG provides the strategic framework for policies, procedures, and oversight ensuring health information is managed properly across the organization.
Question 180: Which HIPAA rule specifically governs the administrative, physical, and technical safeguards for ePHI?
- Breach Notification Rule
- Privacy Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule establishes national standards for protecting electronic protected health information through administrative, physical, and technical safeguards.
AHIMA Registered Health Information Administrator Exam
The AHIMA (American Health Information Management Association) administers credentials including the RHIA (Registered Health Information Administrator) and RHIT (Registered Health Information Technician). The exams cover health records management, medical coding and classification, HIPAA privacy and security, healthcare data analytics, revenue cycle management, health information governance, quality improvement, compliance and legal standards, health IT systems, clinical documentation improvement, and release of information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds