CCS Health Information Management & Data Accuracy 2 — Questions and Answers
Question 1: What is the primary purpose of the Master Patient Index (MPI)?
- To store all clinical documentation for a patient
- To uniquely identify each patient and link all their records across encounters (Correct answer)
- To list all physicians credentialed at a facility
- To track all insurance authorizations for scheduled procedures
Correct answer: To uniquely identify each patient and link all their records across encounters
The MPI is the permanent database that assigns a unique medical record number to each patient and links all their visits and records within a health system, ensuring record integrity.
The Master Patient Index (MPI) is one of the most critical databases in health information management. It assigns each patient a unique identifier (medical record number) and contains demographic data used to link all encounters and records for that patient. MPI integrity is essential - duplicates, overlays, or incorrect merges create patient safety risks and billing errors. The CCS must understand MPI because coding errors tied to wrong patient records are a serious compliance issue.
Question 2: Which data quality characteristic ensures that health information is available when needed by authorized users?
- Accuracy
- Timeliness
- Accessibility (Correct answer)
- Completeness
Correct answer: Accessibility
Accessibility refers to data being available and retrievable by authorized users when needed - a core characteristic of high-quality health information.
AHIMA defines multiple data quality characteristics including accuracy (correct), completeness (all required elements present), consistency (uniform across systems), timeliness (available when needed based on time standards), and accessibility (available to authorized users when required). Accessibility is specifically about system availability and appropriate access controls. All characteristics collectively define data quality in health information management.
Question 3: A hospital's inpatient coding is found to have a 12% query rate for physician clarification. What does this primarily indicate?
- The coders are undercoding diagnoses
- Clinical documentation is frequently insufficient to code accurately without clarification (Correct answer)
- The hospital has too few coders for its patient volume
- Physicians are routinely upcoding their documentation
Correct answer: Clinical documentation is frequently insufficient to code accurately without clarification
A high physician query rate indicates that clinical documentation lacks the specificity or completeness needed for accurate coding, requiring coders to ask physicians for clarification.
Clinical Documentation Improvement (CDI) programs exist because physician documentation often lacks the specificity needed for accurate ICD-10-CM/PCS coding and DRG assignment. Coders issue queries (written requests for clarification) when documentation is ambiguous, conflicting, or incomplete. A 12% query rate, while indicating documentation gaps, also reflects an active CDI effort. AHIMA provides query practice briefs defining appropriate vs. leading queries.
Question 4: Under HIPAA, what is the minimum necessary standard as it applies to health information access?
- Providers must share all patient information with any treating clinician
- Covered entities must make reasonable efforts to limit PHI access to the minimum needed for the intended purpose (Correct answer)
- Patients must authorize every single use of their protected health information
- Health plans can access complete medical records for all billing purposes
Correct answer: Covered entities must make reasonable efforts to limit PHI access to the minimum needed for the intended purpose
The minimum necessary standard requires covered entities to limit PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose.
The HIPAA Privacy Rule's minimum necessary standard (45 CFR 164.502(b)) requires covered entities to evaluate their practices and enhance safeguards to limit unnecessary or inappropriate access to PHI. For example, a coder reviewing a record for coding purposes should only access what is needed for that task. Exceptions include treatment purposes (where providers may share more freely) and patient-authorized disclosures. This standard does not apply to disclosures to the patient themselves.
Question 5: What does the Health Insurance Portability and Accountability Act (HIPAA) transaction code set standard mandate for claims submission?
- All claims must be submitted in paper format for Medicare
- Electronic healthcare transactions must use HIPAA-mandated standard formats (X12 transactions) (Correct answer)
- Providers must use a single universal claim form for all payers
- Only hospitals with more than 500 beds must submit electronic claims
Correct answer: Electronic healthcare transactions must use HIPAA-mandated standard formats (X12 transactions)
HIPAA's administrative simplification provisions mandate that covered entities use X12 standard electronic transaction formats (e.g., 837P, 837I) for electronic claims submission.
HIPAA's transaction and code set standards (45 CFR Part 162) require covered entities to use specific X12 electronic transaction formats for standard healthcare transactions. The 837I (institutional claim) and 837P (professional claim) are the HIPAA-standard formats replacing paper UB-04 and CMS-1500 for electronic submission. Other mandated transactions include the 835 (remittance advice), 270/271 (eligibility inquiry/response), and 276/277 (claim status). Standardization reduces administrative burden across payers.
Question 6: A health information manager discovers that 200 records have been accessed by an employee without a treatment, payment, or operations purpose. Under HIPAA, this constitutes:
- A minor policy violation requiring retraining only
- A breach requiring assessment under the Breach Notification Rule (Correct answer)
- A routine audit finding with no required action
- A HIPAA violation only if the records were shared externally
Correct answer: A breach requiring assessment under the Breach Notification Rule
Unauthorized access to PHI is a potential breach under HIPAA. The covered entity must conduct a breach risk assessment and may be required to notify affected individuals and HHS.
Under the HIPAA Breach Notification Rule (45 CFR 164.400), a breach is defined as an impermissible use or disclosure of PHI that compromises security or privacy. Unauthorized employee access without a legitimate purpose is presumed to be a breach unless a risk assessment demonstrates a low probability that PHI was compromised. If a breach is confirmed, affected individuals must be notified within 60 days, and breaches affecting 500 or more individuals require media notification and immediate HHS reporting.
What is the primary purpose of the Master Patient Index (MPI)?