CBCS Electronic Health Records 2 — Questions and Answers
Question 1: What does HL7 FHIR stand for in health IT?
- Health Level 7 Fast Interoperability Resources
- Health Level 7 Fast Healthcare Interoperability Resources (Correct answer)
- Health Linking 7 Federal Health Integration Records
- Health Level 7 Federal Interoperability Requirements
Correct answer: Health Level 7 Fast Healthcare Interoperability Resources
FHIR stands for Fast Healthcare Interoperability Resources, a standard for exchanging healthcare information electronically.
HL7 FHIR (Fast Healthcare Interoperability Resources) is a standard developed by Health Level Seven International (HL7) for exchanging electronic health information. FHIR uses modern web technologies (REST APIs, JSON, XML) to enable secure, standardized data exchange between EHR systems and applications. The 21st Century Cures Act and CMS Interoperability Rule require FHIR-based APIs to support patient data access.
Question 2: Which HIPAA rule establishes requirements for protecting the privacy of individually identifiable health information?
- Security Rule
- Privacy Rule (Correct answer)
- Breach Notification Rule
- Enforcement Rule
Correct answer: Privacy Rule
The HIPAA Privacy Rule establishes standards for protecting individually identifiable health information (PHI).
The HIPAA Privacy Rule (45 CFR Parts 160 and 164) establishes national standards to protect individuals' medical records and other personal health information (PHI). It gives patients rights over their health information, sets limits on uses and disclosures without patient authorization, and requires covered entities to implement safeguards to protect PHI. The Privacy Rule applies to PHI in any form (electronic, paper, oral).
Question 3: A nurse in the billing department accesses a patient record out of curiosity without a work-related need. This is a violation of which principle?
- Data portability
- Minimum necessary standard (Correct answer)
- Chain of trust
- Workforce clearance
Correct answer: Minimum necessary standard
The minimum necessary standard requires that access to PHI be limited to only what is needed to perform a job function.
HIPAA's minimum necessary standard requires covered entities to make reasonable efforts to limit access to PHI to only what is necessary to accomplish the intended purpose. Accessing a patient record without a legitimate job-related reason — even by an authorized user — violates this standard. Healthcare organizations must implement policies and access controls that enforce the minimum necessary principle and train staff accordingly.
Question 4: What is the maximum penalty per violation category for willful neglect of HIPAA with no correction?
- $10,000
- $50,000
- $100,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
HIPAA penalties for willful neglect that is not corrected can reach up to $1,900,000 per violation category per year.
HIPAA civil monetary penalties are tiered based on culpability: (1) Did not know: $100-$50,000 per violation; (2) Reasonable cause: $1,000-$50,000; (3) Willful neglect, corrected: $10,000-$50,000; (4) Willful neglect, not corrected: $50,000-$1,900,000 per violation category per year. The maximum has been updated by inflation adjustments. Criminal penalties and OCR investigations can result in additional consequences.
Question 5: In EHR documentation, which practice ensures accuracy and prevents falsification?
- Backdating entries when a note was missed
- Late entries documented as such with date/time of actual entry (Correct answer)
- Deleting errors and rewriting the note correctly
- Amending notes without indicating what was changed
Correct answer: Late entries documented as such with date/time of actual entry
Late entries should be clearly labeled as late entries with the actual date and time they were written, not the date of the encounter.
Proper EHR documentation requires that all entries be accurate, timely, and legible. When a note is not entered at the time of service, it must be clearly marked as a late entry, with the actual date and time of documentation — not the date of the encounter. Backdating entries, deleting errors without a correction trail, or altering documentation constitutes falsification of medical records, which is illegal and unethical.
Question 6: What is a Business Associate Agreement (BAA) under HIPAA?
- An agreement between a physician and a billing company outlining service fees
- A contract requiring a business associate to protect PHI it receives from a covered entity (Correct answer)
- An authorization form signed by patients before sharing their records
- A government-issued certificate for HIPAA-compliant EHR vendors
Correct answer: A contract requiring a business associate to protect PHI it receives from a covered entity
A BAA is a required contract between a covered entity and a business associate that ensures PHI is protected by both parties.
A Business Associate Agreement (BAA) is a required HIPAA contract between a covered entity (e.g., a hospital or physician practice) and a business associate (e.g., a billing company, EHR vendor, or IT contractor) that creates or maintains PHI on the covered entity's behalf. The BAA establishes the permitted uses and disclosures of PHI, requires the business associate to implement appropriate safeguards, and outlines reporting requirements for breaches.
Question 7: Which of the following is NOT one of the 18 HIPAA identifiers that make health information individually identifiable?
- Geographic data smaller than state
- Account numbers
- Full-face photographs
- General diagnosis category (Correct answer)
Correct answer: General diagnosis category
A general diagnosis category is not one of the 18 HIPAA identifiers; the actual diagnosis combined with other data could identify someone, but the category alone is not listed.
HIPAA's 18 identifiers that make health information 'individually identifiable' include: names, geographic data smaller than state, dates (except year), phone numbers, fax numbers, email, SSN, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, VIN/serial numbers, device identifiers, URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifying numbers. A general diagnosis category (like 'cardiovascular disease') is not itself one of the 18 identifiers.
Question 8: What is the primary purpose of the HIPAA Security Rule?
- To protect paper health records from physical damage
- To establish safeguards for electronic protected health information (ePHI) (Correct answer)
- To regulate the transfer of health records between states
- To set standards for patient consent in clinical research
Correct answer: To establish safeguards for electronic protected health information (ePHI)
The HIPAA Security Rule establishes national standards to protect electronic PHI (ePHI) through administrative, physical, and technical safeguards.
The HIPAA Security Rule (45 CFR Parts 160 and 164) requires covered entities and their business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information (ePHI). Unlike the Privacy Rule (which covers PHI in any form), the Security Rule applies only to ePHI. Safeguards include access controls, encryption, audit controls, transmission security, and workforce training.
What does HL7 FHIR stand for in health IT?