AHIMA Health Information Governance 2 — Questions and Answers
Question 1: Which governance framework principle requires that health information be available to authorized users when needed?
- Integrity
- Availability (Correct answer)
- Confidentiality
- Accountability
Correct answer: Availability
Availability ensures that health information and systems are accessible to authorized users at the time they need them.
Question 2: An HIM director is developing a data governance charter. Which element is MOST critical to include first?
- List of approved software tools
- Defined roles and responsibilities for data stewardship (Correct answer)
- Employee training schedules
- Vendor contract summaries
Correct answer: Defined roles and responsibilities for data stewardship
A data governance charter must first establish clear roles and responsibilities so accountability for data assets is unambiguous.
Question 3: What is the primary purpose of a data dictionary in health information governance?
- To store patient demographic information
- To define standard meanings and formats for data elements (Correct answer)
- To track employee access logs
- To manage release of information requests
Correct answer: To define standard meanings and formats for data elements
A data dictionary provides standardized definitions, formats, and acceptable values for data elements to ensure consistent interpretation across the organization.
Question 4: Under HIPAA, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon written request
- No later than the first service delivery date (Correct answer)
- Annually on January 1st
- Only when a breach has occurred
Correct answer: No later than the first service delivery date
HIPAA requires covered entities to provide the NPP no later than the date of first service delivery to the individual.
Question 5: Which type of health information governance policy addresses the length of time records must be retained?
- Access control policy
- Retention and destruction policy (Correct answer)
- Minimum necessary policy
- Audit log policy
Correct answer: Retention and destruction policy
A retention and destruction policy governs how long health records must be kept and the approved methods for their disposal.
Question 6: A hospital's governance committee discovers that two departments use different codes for the same diagnosis. This is an example of a failure in:
- Information security
- Data quality — consistency (Correct answer)
- Release of information
- Record completion
Correct answer: Data quality — consistency
Data consistency means the same data element has the same value across all systems and departments; differing codes for the same diagnosis violates this dimension.
Question 7: Which body provides the official guidelines for ICD-10-CM coding that HIM governance policies must align with?
- The Joint Commission
- The American Medical Association
- The ICD-10-CM Official Guidelines Cooperating Parties (Correct answer)
- The Office of the National Coordinator
Correct answer: The ICD-10-CM Official Guidelines Cooperating Parties
The Cooperating Parties — AHA, AHIMA, CMS, and NCHS — jointly publish the official ICD-10-CM coding guidelines that govern coding practice.
Which governance framework principle requires that health information be available to authorized users when needed?