NHA Certified Electronic Health Records Specialist (CEHRS) Exam — Questions and Answers
Question 1: A patient presents with a foreign name that has multiple acceptable spellings. What is the best practice when registering this patient in the EHR?
- Ask the patient to spell their name and enter it exactly as they provide it (Correct answer)
- Enter the most common spelling and note alternatives in a comments field
- Select the spelling that matches the insurance card
- Use the spelling from the referring physician's fax
Correct answer: Ask the patient to spell their name and enter it exactly as they provide it
Patient-provided spelling ensures the name is recorded as the patient intends, reducing identity errors.
Question 2: Which HCPCS level covers supplies, equipment, and services not classified under CPT codes?
- HCPCS Level I
- HCPCS Level II (Correct answer)
- HCPCS Level III
- HCPCS Level IV
Correct answer: HCPCS Level II
HCPCS Level II codes (alphanumeric, beginning with letters A-V) cover supplies, durable medical equipment, ambulance services, and other non-physician services.
Question 3: A provider documents a patient's tobacco use status in the EHR. Under Meaningful Use (now Promoting Interoperability), recording this is an example of:
- Documenting a social history element (Correct answer)
- Entering an immunization record
- Recording a vital sign
- A required core clinical quality measure
Correct answer: Documenting a social history element
Tobacco use status is classified as a social history element and was a Meaningful Use core objective because it informs preventive care and risk assessment.
Question 4: Under HIPAA, which of the following is NOT considered a covered entity?
- Health insurance company
- Pharmacy chain
- Life insurance company (Correct answer)
- Hospital billing department
Correct answer: Life insurance company
Life insurance companies are not covered entities under HIPAA because they do not conduct electronic healthcare transactions covered by the rule.
Question 5: Which of the following is a primary reason for collecting detailed patient demographic data in an EHR system?
- To sell aggregated, de-identified data to pharmaceutical companies.
- To create marketing campaigns for the healthcare facility.
- To ensure compliance with local zoning and building codes.
- To report on community health trends and for research purposes. (Correct answer)
Correct answer: To report on community health trends and for research purposes.
Detailed demographic data such as age, gender, ethnicity, and location is vital for public health research and identifying health trends within a community. This information, when de-identified, can be used to track disease prevalence, evaluate treatment outcomes, and plan public health initiatives.
Question 6: A clinic is implementing a new EHR module. Which step should occur before go-live?
- Immediately deploy to the production environment
- Archive all existing records
- Conduct user acceptance testing (UAT) in a test environment (Correct answer)
- Notify patients of the change
Correct answer: Conduct user acceptance testing (UAT) in a test environment
UAT verifies that the new module functions correctly for real-world workflows before it affects live patient care.
Question 7: Under the 21st Century Cures Act, which practice is prohibited when health IT vendors or providers restrict access, exchange, or use of EHR data?
- Selective disclosure
- Consent revocation
- Data minimization
- Information blocking (Correct answer)
Correct answer: Information blocking
The 21st Century Cures Act explicitly prohibits 'information blocking'—practices that interfere with the access, exchange, or use of electronic health information.
Question 8: Which document establishes the legal relationship between a covered entity and a vendor that handles PHI on its behalf?
- Data Use Agreement (DUA)
- Memorandum of Understanding (MOU)
- Notice of Privacy Practices (NPP)
- Business Associate Agreement (BAA) (Correct answer)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement contractually requires the vendor to protect PHI and comply with HIPAA obligations on behalf of the covered entity.
Question 9: What is the primary purpose of a Direct Secure Messaging system in healthcare?
- To send encrypted health information securely between trusted providers (Correct answer)
- To enable patient-to-physician video consultations
- To process and submit insurance claims electronically
- To store laboratory results in a centralized database
Correct answer: To send encrypted health information securely between trusted providers
Direct Secure Messaging provides a simple, secure, standards-based way for providers to send authenticated encrypted health information directly to known recipients.
Question 10: Which factor is most important when determining the training approach for clinical staff during EHR implementation?
- The total number of licenses purchased from the vendor
- The organization's hardware refresh schedule
- Role-specific workflows and the users' varying levels of technical proficiency (Correct answer)
- The availability of the vendor's online help documentation
Correct answer: Role-specific workflows and the users' varying levels of technical proficiency
Training must be tailored to each role's specific workflows and adapted to users' varying technical skill levels to ensure effective learning and adoption.
Question 11: When entering a specialist referral appointment in the EHR, which piece of information is MOST critical to capture accurately?
- The patient's preferred appointment time of day
- The specialist's personal mobile phone number
- The patient's most recent insurance card expiration date
- The referring provider's NPI number and the clinical reason for referral (Correct answer)
Correct answer: The referring provider's NPI number and the clinical reason for referral
The referring provider's NPI is required for insurance authorization and billing, and the clinical reason for referral drives medical necessity determinations. Without these, the referral may be denied or the specialist may lack the context to prepare for the visit.
Question 12: A physician performs a new patient office visit and also administers a vaccine during the same encounter. To bill both services correctly, which modifier should be appended to the E&M code?
- -59
- -25 (Correct answer)
- -57
- -51
Correct answer: -25
Modifier -25 indicates that a significant, separately identifiable E&M service was performed by the same physician on the same day as a procedure or other service.
Question 13: When a patient's legal guardian requests access to a minor's psychiatric records, the facility should:
- Release only the billing records
- Release all records immediately upon written request
- Consult state law, as minors may have privacy rights for certain sensitive records (Correct answer)
- Deny the request since guardians have no rights to medical records
Correct answer: Consult state law, as minors may have privacy rights for certain sensitive records
State laws often grant minors the right to consent to and control access to certain sensitive records such as mental health, substance abuse, and reproductive health.
Question 14: Which modifier is appended to a CPT code to indicate that a procedure was performed bilaterally?
- -51
- -59
- -50 (Correct answer)
- -76
Correct answer: -50
Modifier -50 indicates that the same procedure was performed on both sides of the body during the same operative session.
Question 15: Which federal initiative established the framework for nationwide health information exchange in the US?
- Health Insurance Portability and Accountability Act (HIPAA)
- Nationwide Health Information Network (NwHIN) (Correct answer)
- Medicare Access and CHIP Reauthorization Act (MACRA)
- Consolidated Omnibus Budget Reconciliation Act (COBRA)
Correct answer: Nationwide Health Information Network (NwHIN)
The Nationwide Health Information Network (NwHIN) was established to create standards and services for secure health information exchange across the US.
Question 16: During medication reconciliation, a discrepancy is found between a patient's home medications and the hospital admission orders. What is the correct first step?
- Document the discrepancy and wait for shift change
- Delete the conflicting entry from the EHR
- Administer the ordered medication immediately
- Notify the prescribing provider to resolve the discrepancy (Correct answer)
Correct answer: Notify the prescribing provider to resolve the discrepancy
Medication reconciliation discrepancies must be promptly communicated to the prescribing provider for clinical review and resolution before medications are administered.
Question 17: A physician documents a patient's diagnosis as 'Type 2 diabetes mellitus with hyperglycemia' and the procedure as a 'comprehensive metabolic panel'. Within the EHR, what is the MOST critical relationship the CEHRS must ensure is established for proper claim submission?
- The CPT code for the procedure is from the most recent publication year.
- The patient's insurance information is verified and active.
- The ICD-10-CM code for the diagnosis demonstrates medical necessity for the CPT code of the service provided. (Correct answer)
- The physician's digital signature is applied within 24 hours of the patient encounter.
Correct answer: The ICD-10-CM code for the diagnosis demonstrates medical necessity for the CPT code of the service provided.
For a claim to be paid, the diagnosis code (ICD-10-CM) must justify the reason a procedure or service (CPT) was performed. This relationship is called 'medical necessity'. An EHR helps facilitate this by allowing the linkage of diagnosis codes to procedure codes, but the CEHRS must understand this principle to ensure accurate claims are generated.
Question 18: What does the term 'upcoding' mean in the context of medical billing?
- Assigning a higher-level code than the documentation supports to receive greater reimbursement (Correct answer)
- Updating codes to the newest edition
- Using an unlisted code when no specific code exists
- Correcting a previously submitted claim
Correct answer: Assigning a higher-level code than the documentation supports to receive greater reimbursement
Upcoding is a form of fraud in which a provider bills a higher-level or more complex code than the services actually rendered.
Question 19: What is the maximum civil monetary penalty per violation category for HIPAA violations caused by willful neglect that is not corrected?
- $1,500,000 per year (Correct answer)
- $50,000
- $100,000
- $10,000
Correct answer: $1,500,000 per year
Willful neglect violations that are not corrected carry penalties of up to $50,000 per violation with a $1.5 million annual cap per violation category.
Question 20: Which data standard is used to transmit radiology images between systems and facilities?
- HL7 v2
- DICOM (Correct answer)
- X12 278
- CCD
Correct answer: DICOM
DICOM (Digital Imaging and Communications in Medicine) is the universal standard for storing and transmitting medical imaging data such as X-rays and MRIs.
Question 21: Which element is required in a valid authorization for release of protected health information under HIPAA?
- Insurance company verification
- Treating physician approval
- Expiration date or event (Correct answer)
- Witness signature
Correct answer: Expiration date or event
A valid HIPAA authorization must include an expiration date or expiration event that relates to the individual or the purpose of the use or disclosure.
Question 22: Which revenue cycle step involves reviewing claims before submission to identify errors that could cause denial?
- Eligibility verification
- Payment posting
- Charge capture
- Claim scrubbing (Correct answer)
Correct answer: Claim scrubbing
Claim scrubbing is an automated or manual review process that checks claims for errors, missing data, and coding inconsistencies before submission.
Question 23: A portal sends an automated appointment reminder to a patient's email. The patient replies that it is the wrong email address. What is the first action?
- Verify the patient's identity, correct the email in the EHR, and resend the invitation (Correct answer)
- Delete the patient's portal account and start over
- Ignore the reply since automated messages are one-way
- Disable all portal notifications for the patient
Correct answer: Verify the patient's identity, correct the email in the EHR, and resend the invitation
Correcting demographic data in the EHR after identity verification ensures future communications reach the patient and maintains record accuracy.
Question 24: Which workflow describes the correct sequence for processing a new patient referral in an EHR?
- Document clinical details → schedule → receive referral → verify insurance
- Schedule appointment → receive referral → verify insurance → document clinical reason
- Bill payer → receive referral → schedule → document
- Receive referral → verify insurance/authorization → schedule appointment → document clinical details (Correct answer)
Correct answer: Receive referral → verify insurance/authorization → schedule appointment → document clinical details
Best practice requires receiving the referral, verifying insurance eligibility and authorization, then scheduling the appointment, and finally documenting the clinical reason for the referral.
Question 25: Which 7th character is used in ICD-10-CM to indicate an initial encounter for an acute fracture?
- S
- A (Correct answer)
- G
- D
Correct answer: A
The 7th character 'A' designates the initial encounter, meaning the patient is receiving active treatment for the fracture.
Question 26: What does 'query-based exchange' allow in a health information exchange network?
- Lab systems to automatically send results to referring physicians
- Providers to request and retrieve patient records from other organizations as needed (Correct answer)
- Administrators to search all EHR systems for billing errors
- Patients to query their insurance coverage status in real time
Correct answer: Providers to request and retrieve patient records from other organizations as needed
Query-based exchange enables a provider to search for and retrieve patient information from other organizations at the point of care when needed.
Question 27: Which coding system is primarily used for procedures performed in outpatient hospital settings and physician offices in the US?
- ICD-10-PCS
- ICD-10-CM
- SNOMED CT
- CPT (Current Procedural Terminology) (Correct answer)
Correct answer: CPT (Current Procedural Terminology)
CPT codes are used to report medical, surgical, and diagnostic procedures in outpatient and physician office settings.
Question 28: The HIPAA Security Rule's 'addressable' implementation specifications mean that a covered entity must:
- Implement them only if the cost is under $10,000
- Ignore them if a smaller organization cannot afford them
- Implement them within 180 days regardless of circumstances
- Assess whether they are reasonable and appropriate and document the decision (Correct answer)
Correct answer: Assess whether they are reasonable and appropriate and document the decision
Addressable specifications require covered entities to evaluate whether implementation is reasonable and appropriate given their size, capabilities, and risk, and document that analysis.
Question 29: A nurse documents a patient's fall in the EHR after the incident occurred. Which documentation practice is being demonstrated?
- Interval documentation
- Late entry documentation (Correct answer)
- Addendum entry
- Prospective documentation
Correct answer: Late entry documentation
Late entry documentation refers to recording clinical information after the event occurred, and it should be clearly labeled as such with the reason for the delay.
Question 30: What is the primary function of the National Correct Coding Initiative (NCCI) edits?
- To standardize EHR documentation templates
- To prevent improper payment of procedures that should not be billed together (Correct answer)
- To assign DRG weights for inpatient stays
- To establish fee schedules for Medicare
Correct answer: To prevent improper payment of procedures that should not be billed together
NCCI edits are CMS-developed guidelines that identify pairs of codes that cannot be billed together because one is considered bundled into the other.
Question 31: A patient refuses to provide their Social Security Number during registration. What is the appropriate response?
- Document the refusal and proceed with registration using other identifiers (Correct answer)
- Deny registration until the SSN is provided
- Contact the patient's insurer to obtain the SSN directly
- Assign a temporary SSN for system entry
Correct answer: Document the refusal and proceed with registration using other identifiers
Patients have the right to decline providing their SSN; registration can continue using other required demographic identifiers.
Question 32: An EHR specialist suspects a patient has two separate MRNs in the system. What is the FIRST step that should be taken?
- Immediately merge the two records in the EHR to eliminate the duplicate
- Notify the patient of the error and ask them to confirm which record to keep
- Delete the record with the older registration date
- Verify through demographic and clinical data review that both records belong to the same patient before initiating any action (Correct answer)
Correct answer: Verify through demographic and clinical data review that both records belong to the same patient before initiating any action
Merging records without verification is dangerous — two patients could share similar demographics, and a premature merge would create a record overlay. The correct first step is to carefully verify identity through multiple demographic identifiers and, if available, photo ID or clinical evidence before any merge is initiated.
Question 33: A business associate agreement (BAA) must be established when a covered entity shares PHI with a vendor. Which vendor would NOT require a BAA?
- A transcription service handling dictated notes
- A cloud storage provider hosting ePHI
- A billing company that processes claims
- A janitorial company that cleans exam rooms (Correct answer)
Correct answer: A janitorial company that cleans exam rooms
A janitorial company that cleans exam rooms does not create, receive, maintain, or transmit PHI, so no BAA is required.
Question 34: Which regulatory body's Conditions of Participation (CoPs) govern medical record requirements for Medicare-certified hospitals?
- The Joint Commission
- Office for Civil Rights (OCR)
- Centers for Medicare and Medicaid Services (CMS) (Correct answer)
- American Health Information Management Association (AHIMA)
Correct answer: Centers for Medicare and Medicaid Services (CMS)
CMS Conditions of Participation define the standards hospitals must meet to participate in Medicare and Medicaid, including medical record requirements.
Question 35: A new medication is added to the formulary but does not appear in the EHR drug database. What is the correct support action?
- Disable drug interaction checking temporarily
- Submit a drug database update request or update the formulary table in the EHR (Correct answer)
- Remove the drug from the formulary
- Instruct providers to manually type the drug name
Correct answer: Submit a drug database update request or update the formulary table in the EHR
The EHR formulary or drug database must be updated so the new medication is available for order entry and interaction checking.
Question 36: An EHR specialist is reviewing a claim that was denied. The denial code indicates 'Claim is missing information.' Which of the following is the most likely cause for this denial?
- A duplicate claim was submitted for the same service.
- The patient's policy number was entered incorrectly. (Correct answer)
- The claim was not filed within the payer's time limit.
- The service provided was not a covered benefit.
Correct answer: The patient's policy number was entered incorrectly.
A denial for 'missing information' is most often due to data entry errors such as an incorrect or incomplete patient identifier, like a misspelled name or an invalid policy number. While other options are reasons for denials, they correspond to different denial categories such as non-covered services, duplicate submission, or timely filing limits.
Question 37: A patient calls asking for their lab results to be faxed directly to their employer. What should the EHR specialist do?
- Refuse the request entirely as employer disclosures are prohibited
- Consult the attending physician before taking any action
- Obtain a valid written authorization from the patient before releasing (Correct answer)
- Fax the results immediately since the patient requested it
Correct answer: Obtain a valid written authorization from the patient before releasing
Releasing PHI to an employer requires a valid patient authorization because employers are not covered entities and this disclosure exceeds standard TPO purposes.
Question 38: When a healthcare organization's compliance officer discovers a potential HIPAA violation, which action should occur FIRST?
- Notify all affected patients
- Conduct an internal investigation to determine scope and facts (Correct answer)
- Report immediately to OCR
- Terminate the employee involved
Correct answer: Conduct an internal investigation to determine scope and facts
The first step upon discovering a potential HIPAA violation is to conduct an internal investigation to determine the nature, scope, and whether a reportable breach occurred.
Question 39: A patient portal displays lab results immediately upon release without clinician review. What is the primary risk of this configuration?
- Lab results may be lost in transmission
- Results will not meet HIPAA standards
- The EHR vendor may charge additional fees
- Patients may see abnormal or critical results before being contacted by their provider, causing anxiety or confusion (Correct answer)
Correct answer: Patients may see abnormal or critical results before being contacted by their provider, causing anxiety or confusion
Immediate release without provider notification can lead to patient distress if results are abnormal and no clinical context or follow-up has been arranged.
Question 40: Which of the following is a common challenge when implementing Electronic Health Records (EHR) into clinical workflows?
- EHR systems are universally compatible with all healthcare provider tools
- There can be resistance from healthcare providers due to changes in workflow (Correct answer)
- EHRs typically require minimal training for staff
- EHR systems are only used for administrative tasks
Correct answer: There can be resistance from healthcare providers due to changes in workflow
A common challenge when implementing EHRs is resistance from healthcare providers, as the adoption of electronic systems often requires changes in established workflows and additional training. This transition can be met with some reluctance, especially if the system is perceived as difficult or time-consuming.
Question 41: A patient education document in the portal is written at a 14th-grade reading level. Why is this a concern?
- It violates HIPAA privacy rules
- It exceeds the recommended 6th–8th grade reading level, reducing patient comprehension (Correct answer)
- It is too short to be useful
- High reading levels are preferred for legal compliance
Correct answer: It exceeds the recommended 6th–8th grade reading level, reducing patient comprehension
Health literacy best practices recommend patient education materials be written at a 6th–8th grade reading level to maximize understanding across diverse populations.
Question 42: What is the purpose of a 'downtime procedure' in EHR support?
- To delete outdated patient records
- To permanently migrate data to a new system
- To train new staff on the EHR
- To maintain patient care workflows when the EHR is unavailable (Correct answer)
Correct answer: To maintain patient care workflows when the EHR is unavailable
Downtime procedures ensure clinical operations continue safely when the EHR system is offline.
Question 43: Which of the following best describes a 'closed-loop' medication management process in an EHR?
- The pharmacist reviews and manually transcribes all physician orders
- Patients self-report medication use to the billing department
- An integrated workflow from electronic ordering through pharmacy verification to administration documentation (Correct answer)
- Medications are ordered, dispensed, and documented without any electronic verification
Correct answer: An integrated workflow from electronic ordering through pharmacy verification to administration documentation
Closed-loop medication management integrates CPOE, pharmacy dispensing, and eMAR so that every step from order to administration is electronically tracked and verified.
Question 44: Which regulation requires that patients be provided with access to their electronic health information without special effort, and penalizes information blocking with civil monetary penalties?
- Meaningful Use Stage 3
- 21st Century Cures Act Final Rule (ONC) (Correct answer)
- HIPAA Privacy Rule
- HITECH Breach Notification Rule
Correct answer: 21st Century Cures Act Final Rule (ONC)
The ONC's 21st Century Cures Act Final Rule (2020) established information blocking prohibitions and mandated FHIR-based patient access APIs.
Question 45: What is a common barrier to effective health information exchange in the US?
- Absence of patient demographic information in EHRs
- Limited access to internet connectivity in urban areas
- Lack of standardized data formats and vendor interoperability (Correct answer)
- Insufficient number of certified EHR systems available
Correct answer: Lack of standardized data formats and vendor interoperability
One of the most significant barriers to HIE is the use of proprietary data formats and lack of standardization that makes it difficult for different EHR systems to communicate.
Question 46: Which federal regulation specifically governs the security of electronic protected health information (ePHI) in the United States?
- HIPAA Privacy Rule
- HITECH Act
- Meaningful Use Rule
- HIPAA Security Rule (Correct answer)
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities.
Question 47: Which of the following is an example of a quality assurance measure in the context of electronic health records?
- All of the above (Correct answer)
- Monitoring EHR usage to ensure that only authorized individuals access patient data
- Regularly updating the software to fix bugs and improve functionality
- Implementing encryption protocols for data security
Correct answer: All of the above
Quality assurance in EHR systems involves ensuring that the system operates efficiently, securely, and in compliance with regulations. This includes implementing encryption protocols, regular software updates, and monitoring access to prevent unauthorized data breaches.
Question 48: During registration, a patient lists two insurance plans. Which plan is typically billed first according to coordination of benefits rules?
- The plan associated with the patient's employer
- The plan with the highest premium
- The most recently obtained plan
- The primary insurance plan (Correct answer)
Correct answer: The primary insurance plan
Coordination of benefits (COB) rules require the primary insurer to be billed first, with any remainder sent to the secondary insurer.
Question 49: A primary benefit of using the EHR to deliver patient-specific educational materials through the patient portal is that it:
- allows for automated, timely delivery of information directly relevant to the patient's diagnosis. (Correct answer)
- eliminates the need for the provider to verbally discuss the condition with the patient.
- satisfies a core requirement for all private insurance payer contracts.
- guarantees that the patient will read and fully comprehend the material.
Correct answer: allows for automated, timely delivery of information directly relevant to the patient's diagnosis.
EHRs can be configured to use patient data, such as a new diagnosis code, to automatically suggest or send relevant educational materials. This ensures the education is highly specific to the patient's current condition and is delivered in a timely manner, enhancing the care provided.
Question 50: A patient's demographic record shows their sex as 'male' but they identify as a transgender woman. What is the best practice for documenting this in the EHR?
- Record both the administrative sex and the gender identity in separate designated fields (Correct answer)
- Do not change any fields to avoid system errors
- Add a free-text note only, leaving structured fields unchanged
- Override the field to 'female' without documentation of the change
Correct answer: Record both the administrative sex and the gender identity in separate designated fields
Modern EHRs include separate fields for administrative sex (used for billing/clinical defaults) and gender identity, supporting accurate and respectful care.
Question 51: When a provider bills a higher-complexity service than was actually performed, this is known as:
- Downcoding
- Balance billing
- Upcoding (Correct answer)
- Unbundling
Correct answer: Upcoding
Upcoding is the fraudulent practice of billing for a more expensive service than was rendered, inflating reimbursement.
Question 52: A patient who is a minor requests access to their own reproductive health records, which they paid for privately. The parent also requests the same records. What should the EHR specialist do?
- Deny both requests until a court order is obtained
- Provide records to whoever requests first
- Follow state law, which may grant the minor control over these records (Correct answer)
- Provide records to the parent as the legal guardian without question
Correct answer: Follow state law, which may grant the minor control over these records
HIPAA defers to state law on minors' rights; many states grant minors the right to control records for services they can consent to independently, such as reproductive health.
Question 53: Which of the following best describes "structured data" in an Electronic Health Record?
- Unorganized data that requires manual interpretation
- Free-text descriptions written by the healthcare provider
- Visual data such as x-rays or MRIs
- Data that is organized into predefined fields for easier analysis and retrieval (Correct answer)
Correct answer: Data that is organized into predefined fields for easier analysis and retrieval
Structured data in EHRs is information that is entered into predefined fields (e.g., patient name, medication list, lab results). This type of data is easier to analyze, search, and retrieve compared to unstructured data, such as handwritten notes.
Question 54: Which of the following is an example of 'unbundling' in medical billing?
- Billing each component of a procedure separately when a single comprehensive code exists (Correct answer)
- Billing a comprehensive code when only a component service was performed
- Submitting a claim with both CPT and HCPCS codes
- Using two modifiers on a single claim line
Correct answer: Billing each component of a procedure separately when a single comprehensive code exists
Unbundling occurs when a coder bills individual components of a procedure separately rather than using the single comprehensive CPT code that covers all components.
Question 55: During patient registration, a CEHRS notices that a patient's last name is spelled differently on their insurance card compared to their driver's license. Which of the following actions should the CEHRS take?
- Use the spelling from the driver's license as it is a legal document.
- Enter both spellings in the patient's record.
- Politely ask the patient to clarify the correct legal spelling of their last name. (Correct answer)
- Use the spelling from the insurance card to ensure payment.
Correct answer: Politely ask the patient to clarify the correct legal spelling of their last name.
When there are discrepancies in patient demographic information, the best practice is to ask the patient for clarification to ensure the legal name is captured correctly. This helps to avoid creating duplicate records or causing billing and insurance claim issues down the line. Using one version over the other without confirmation could lead to errors.
Question 56: Which of the following is an example of a 'patient-mediated' health information exchange?
- A hospital query to an HIE for ED records
- A provider sending a Direct message referral
- A patient using Apple Health to aggregate and share records (Correct answer)
- A lab sending HL7 results to an EHR
Correct answer: A patient using Apple Health to aggregate and share records
Consumer- or patient-mediated exchange puts the patient in control of aggregating and sharing their own health data through apps or personal health records.
Question 57: In population health reporting, which data element would be most useful for identifying patients overdue for colorectal cancer screening?
- Current medication list
- Most recent A1C level
- Most recent blood pressure reading
- Date of last colonoscopy or FOBT (Correct answer)
Correct answer: Date of last colonoscopy or FOBT
Tracking the date of last colonoscopy or fecal occult blood test (FOBT) allows identification of patients due for colorectal cancer screening based on age and screening intervals.
Question 58: A registration form asks for the patient's 'race' and 'ethnicity' as separate data elements. Why are these collected separately?
- Because insurance companies require both fields for eligibility verification
- Because race and ethnicity are distinct categories required by federal reporting standards such as OMB and Meaningful Use (Correct answer)
- To determine the patient's preferred language for clinical communication
- To comply with state-level billing requirements only
Correct answer: Because race and ethnicity are distinct categories required by federal reporting standards such as OMB and Meaningful Use
Federal standards (OMB, CMS Meaningful Use/MIPS) require race and ethnicity to be captured as separate fields to support health disparity analysis and reporting.
Question 59: Which document formally authorizes a project manager to use organizational resources for an EHR implementation?
- Statement of work
- Project charter (Correct answer)
- Implementation timeline
- Memorandum of understanding
Correct answer: Project charter
The project charter is the formal document that authorizes the project and grants the project manager authority to allocate resources.
Question 60: Which FHIR element is used to uniquely identify a patient resource across different healthcare systems?
- Endpoint
- Subject
- Identifier (Correct answer)
- Reference
Correct answer: Identifier
The Identifier element in FHIR is used to hold business identifiers such as MRN or SSN that uniquely identify a patient across different systems.
Question 61: What action should an EHR specialist take when they suspect unauthorized access to patient records?
- Notify the affected patient directly before reporting internally
- Delete the audit log entries related to the incident
- Report the incident to the privacy/security officer immediately (Correct answer)
- Reset the affected user's password and monitor the account
Correct answer: Report the incident to the privacy/security officer immediately
Suspected unauthorized access must be reported immediately to the organization's privacy or security officer, who will investigate and determine if a breach notification is required.
Question 62: Which of the following is a primary function of the 'secure messaging' feature within a patient portal?
- To allow patients to communicate with their insurance company about claims.
- To provide a platform for emergency medical communication with on-call providers.
- To facilitate social networking between patients who have similar health conditions.
- To enable HIPAA-compliant, non-urgent communication between the patient and the care team. (Correct answer)
Correct answer: To enable HIPAA-compliant, non-urgent communication between the patient and the care team.
Secure messaging is designed as a HIPAA-compliant tool for non-urgent communication, such as asking follow-up questions, requesting prescription refills, or clarifying instructions. Portals explicitly state that this feature should not be used for medical emergencies.
Question 63: Under the 21st Century Cures Act, what is information blocking?
- Any practice that interferes with the access, exchange, or use of electronic health information (Correct answer)
- Restricting EHR access to unauthorized users only
- Limiting provider access to non-essential patient data
- Encrypting patient data to prevent external breaches
Correct answer: Any practice that interferes with the access, exchange, or use of electronic health information
The 21st Century Cures Act defines information blocking as practices that unreasonably restrict the access, exchange, or use of electronic health information.
Question 64: In an EHR, what does 'hard stop' mean in the context of clinical decision support?
- A billing hold placed on the account for unpaid balances
- A mandatory alert that prevents the clinician from proceeding without acknowledging or resolving an issue (Correct answer)
- A system error that crashes the EHR application
- A scheduled maintenance shutdown of the system
Correct answer: A mandatory alert that prevents the clinician from proceeding without acknowledging or resolving an issue
A hard stop is a non-bypassable CDS alert that requires the clinician to take a specified action—such as documenting a contraindication override—before the workflow can continue.
Question 65: A patient requests an amendment to their medical record because they believe information is incorrect. Under HIPAA, the covered entity may deny the request if:
- The record was not created by that covered entity (Correct answer)
- The amendment would extend the record
- The patient lacks medical knowledge to judge accuracy
- More than 30 days have passed since treatment
Correct answer: The record was not created by that covered entity
A covered entity may deny an amendment request if the information was not created by that entity, as the creator is best positioned to evaluate its accuracy.
Question 66: Which HIPAA Security Rule safeguard category includes policies and procedures for managing workforce access to ePHI?
- Technical safeguards
- Organizational safeguards
- Administrative safeguards (Correct answer)
- Physical safeguards
Correct answer: Administrative safeguards
Administrative safeguards include policies and procedures such as workforce training, access management, and security awareness that govern how ePHI is managed.
Question 67: A health system's interface engine receives an HL7 ADT A08 message. What event does this message type signal?
- Patient discharge
- Patient transfer
- Patient information update (Correct answer)
- Patient admission
Correct answer: Patient information update
The HL7 ADT A08 event type is 'Update Patient Information,' used when demographic or other patient details change without a status change.
Question 68: A verbal order given by a physician must be authenticated within what standard timeframe under most accreditation guidelines?
- Immediately upon giving the order
- Within 24 hours (Correct answer)
- Within 48 hours
- Within 30 days
Correct answer: Within 24 hours
Most accreditation standards, including TJC, require verbal orders to be authenticated by the ordering physician within 24 hours.
Question 69: A patient requests that a note documenting a sensitive mental health diagnosis be excluded from the portal. What is the appropriate response?
- Review applicable state law and HIPAA psychotherapy notes provisions, then restrict access if legally warranted (Correct answer)
- Delete the note from the EHR entirely
- Grant access to the note only to insurance companies
- Deny the request because all records must be visible
Correct answer: Review applicable state law and HIPAA psychotherapy notes provisions, then restrict access if legally warranted
Psychotherapy notes and certain sensitive records may be withheld under HIPAA and state law; staff must evaluate the specific legal basis before restricting portal display.
Question 70: Which SNOMED CT concept domain would be most appropriate for documenting a clinical finding such as 'pain in right knee' in an EHR?
- Pharmaceutical domain
- Procedure domain
- Clinical finding domain (Correct answer)
- Body structure domain
Correct answer: Clinical finding domain
SNOMED CT's clinical finding domain encompasses signs, symptoms, and diagnoses observed or reported during patient care.
Question 71: Which metric is most useful for evaluating user adoption of a newly implemented EHR system?
- Login frequency and documentation completion rates by users (Correct answer)
- Number of support tickets submitted to the vendor
- System uptime percentage
- Average hardware replacement cycle
Correct answer: Login frequency and documentation completion rates by users
Login frequency and documentation completion rates directly measure how consistently and effectively staff are using the new EHR system after go-live.
Question 72: In ICD-10-CM, what is the meaning of the placeholder character 'X' in certain code categories?
- It indicates an unknown etiology
- It indicates pediatric-only codes
- It holds a position to allow future expansion or to enable a 7th character extension (Correct answer)
- It marks codes that require additional digits
Correct answer: It holds a position to allow future expansion or to enable a 7th character extension
The placeholder X is used when a code requires a 7th character but has fewer than six characters; X fills the empty positions to reach the correct length.
Question 73: What is a Diagnosis-Related Group (DRG) primarily used for?
- Grouping inpatient cases for prospective payment to hospitals under Medicare (Correct answer)
- Organizing EHR problem lists by organ system
- Calculating physician fee-for-service payments
- Classifying outpatient visits by complexity
Correct answer: Grouping inpatient cases for prospective payment to hospitals under Medicare
DRGs are used by CMS under the Inpatient Prospective Payment System (IPPS) to pay hospitals a fixed amount based on the patient's diagnosis and procedures.
Question 74: Under the Medicare Physician Quality Reporting System (PQRS), what is the consequence for eligible professionals who do not satisfactorily report?
- Mandatory EHR system replacement
- Referral to the OIG for fraud investigation
- Immediate loss of Medicare billing privileges
- A payment adjustment (penalty) applied to Medicare reimbursements (Correct answer)
Correct answer: A payment adjustment (penalty) applied to Medicare reimbursements
Providers who fail to meet PQRS reporting requirements are subject to a negative payment adjustment on their Medicare reimbursements.
Question 75: Under HIPAA, when must a covered entity honor a patient's request to restrict disclosure of PHI to a health plan?
- Only when the restriction is for mental health information
- Only when approved by the covered entity's privacy officer
- Whenever the patient submits the request in writing
- When the PHI pertains to a service for which the patient paid out-of-pocket in full (Correct answer)
Correct answer: When the PHI pertains to a service for which the patient paid out-of-pocket in full
Under the Omnibus Rule, covered entities are required to honor a patient's restriction request when the service was paid for entirely out-of-pocket and the disclosure would be to a health plan.
Question 76: Which of the following is an example of a PHYSICAL safeguard required under the HIPAA Security Rule?
- Encrypting ePHI during transmission
- Implementing automatic logoff for workstations
- Conducting workforce security awareness training
- Using facility access controls to limit unauthorized entry (Correct answer)
Correct answer: Using facility access controls to limit unauthorized entry
Physical safeguards include facility access controls, workstation use policies, and device and media controls — measures that physically protect hardware and facilities.
Question 77: Under HIPAA, a covered entity must respond to a patient's request to access their PHI within how many days?
- 90 days
- 60 days (Correct answer)
- 15 days
- 30 days
Correct answer: 60 days
HIPAA requires covered entities to act on a patient's access request within 30 days, with a possible 30-day extension (60 days total).
Question 78: What does FHIR stand for in healthcare IT?
- Flexible Health Integration and Retrieval
- Federated Healthcare Interoperability Registry
- Fast Healthcare Interoperability Resources (Correct answer)
- Federal Health Information Repository
Correct answer: Fast Healthcare Interoperability Resources
FHIR stands for Fast Healthcare Interoperability Resources, a standard developed by HL7 for exchanging healthcare information electronically.
Question 79: A provider's order set is missing after an EHR system migration. What is the first step to resolve this?
- Ask the provider to use a different order set
- Recreate the order set from memory
- Check migration logs and restore the order set from the pre-migration backup (Correct answer)
- Submit a request to the EHR vendor for a new template
Correct answer: Check migration logs and restore the order set from the pre-migration backup
Migration logs identify whether the order set was skipped, and restoring from backup is the fastest recovery path.
Question 80: What is the HIPAA required timeframe for notifying individuals of a breach affecting their PHI?
- Within 10 business days of discovering the breach
- Within 60 days of discovering the breach (Correct answer)
- Within 30 days of discovering the breach
- Within 90 days of discovering the breach
Correct answer: Within 60 days of discovering the breach
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Question 81: Which privacy principle requires that only the minimum necessary PHI be used or disclosed to accomplish the intended purpose?
- Need-to-know basis rule
- Data integrity principle
- Minimum necessary standard (Correct answer)
- Proportionality doctrine
Correct answer: Minimum necessary standard
The HIPAA minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use and disclosure to what is necessary for the intended purpose.
Question 82: Under the Medicare Access and CHIP Reauthorization Act (MACRA), MIPS stands for:
- Managed Integrated Payment Structure
- Merit-based Incentive Payment System (Correct answer)
- Medicare Incentive for Provider Services
- Medical Information and Performance Standards
Correct answer: Merit-based Incentive Payment System
MIPS (Merit-based Incentive Payment System) is a value-based payment program under MACRA that adjusts Medicare payments based on quality, cost, and other performance categories.
Question 83: The Joint Commission's National Patient Safety Goals (NPSGs) require hospitals to use at least how many patient identifiers before providing care?
- Two (Correct answer)
- One
- Three
- Four
Correct answer: Two
The Joint Commission requires at least two patient identifiers (such as name and date of birth) to be used before providing care, treatment, or services.
Question 84: A patient submits a written request for a copy of their electronic health record to be sent to their personal email. According to the HIPAA Privacy Rule's Right of Access, what is the covered entity's obligation?
- To mail a paper copy to the patient's home address instead.
- To refuse the request, as email is not a secure method of transmission.
- To require the patient to come to the office and view the record on-screen only.
- To provide the record in the requested electronic format, after informing the patient of the risks. (Correct answer)
Correct answer: To provide the record in the requested electronic format, after informing the patient of the risks.
The HIPAA Privacy Rule's right of access requires a covered entity to provide individuals with access to their PHI in the form and format they request, if it is readily producible. If a patient requests their EHR be sent to an unsecure email, the provider must do so after warning the patient of the associated security risks.
Question 85: A 16-year-old patient requests portal access to their own record in a state where minors can consent to certain sensitive services. What is the correct approach?
- Require a court order before granting access
- Grant the minor their own portal account for services they legally consented to, separate from parental proxy access (Correct answer)
- Deny access until the patient turns 18
- Share all records with the parent automatically
Correct answer: Grant the minor their own portal account for services they legally consented to, separate from parental proxy access
Minor consent laws allow adolescents portal access limited to services they legally consented to, protecting sensitive information from parental view.
Question 86: A patient calls the clinic stating they cannot see their recent lab results on the patient portal, though their provider said the results would be available. What is the MOST likely reason for this issue that a CEHRS should investigate first?
- The lab interface to the EHR is malfunctioning for all patients.
- The patient is looking in the wrong section of the portal.
- The patient's portal account has been temporarily deactivated due to inactivity.
- The lab results have not yet been reviewed and electronically released by the provider. (Correct answer)
Correct answer: The lab results have not yet been reviewed and electronically released by the provider.
Many EHR systems have a default workflow where diagnostic results are held in a provider's inbox for review before being released to the patient portal. This is a safety measure to ensure a provider can add context or contact the patient about sensitive results. It is the most common and logical first place for a CEHRS to check.
Question 87: A CEHRS is assisting the billing manager in analyzing the practice's revenue cycle performance. Which of the following is a key performance indicator (KPI) that measures the average number of days it takes to collect payment after a service has been provided?
- Days in Accounts Receivable (A/R) (Correct answer)
- Clean Claim Rate
- Net Collection Rate
- Denial Rate
Correct answer: Days in Accounts Receivable (A/R)
'Days in A/R' is a critical KPI that measures the average time it takes for a practice to receive payment from payers and patients. A lower number indicates a more efficient revenue cycle, while a high number signals potential problems in the billing process.
Question 88: A practice manager asks a CEHRS to generate a report that categorizes outstanding balances by the length of time they have been due (e.g., 0-30 days, 31-60 days, 91+ days). Which financial report should the CEHRS create?
- Payer Mix Summary
- Accounts Receivable Aging Report (Correct answer)
- Daily Transaction Journal
- Revenue and Usage Report
Correct answer: Accounts Receivable Aging Report
The Accounts Receivable (A/R) Aging Report is specifically designed to show unpaid invoices and categorize them by the length of time they have been outstanding, which is crucial for managing collections and assessing the financial health of the practice.
Question 89: When a patient's address field contains a P.O. Box, what additional information is often required for proper registration?
- The ZIP+4 code for the P.O. Box
- A physical (street) address for clinical and legal correspondence (Correct answer)
- A secondary emergency contact address
- Proof of ownership of the P.O. Box
Correct answer: A physical (street) address for clinical and legal correspondence
A physical address is needed for certain legal notifications, ambulance dispatch, and some insurance requirements that do not accept P.O. Boxes.
Question 90: Which federal law established significant penalties for submitting false claims to Medicare and Medicaid?
- Anti-Kickback Statute
- False Claims Act (FCA) (Correct answer)
- Stark Law
- HIPAA
Correct answer: False Claims Act (FCA)
The False Claims Act imposes civil penalties and treble damages on entities that knowingly submit fraudulent claims to federal healthcare programs.
Question 91: What does 'proxy access' mean in the context of a patient portal?
- An encrypted backup of portal credentials
- A secondary login used only by clinical staff
- A firewall setting that hides patient data from external networks
- Permission granted to a designated person to view or manage another patient's portal account (Correct answer)
Correct answer: Permission granted to a designated person to view or manage another patient's portal account
Proxy access allows an authorized representative, such as a parent or caregiver, to access another patient's portal on their behalf.
Question 92: A limited data set under HIPAA may be used for research, public health, or health care operations. What must be removed from a limited data set?
- Insurance policy numbers and lab results
- Dates of service and geographic information smaller than a state
- Direct identifiers such as names, addresses, and social security numbers (Correct answer)
- Diagnosis codes and procedure codes
Correct answer: Direct identifiers such as names, addresses, and social security numbers
A limited data set removes direct identifiers like names, SSNs, and addresses, but may retain dates and geographic data at levels larger than a street address.
Question 93: An EHR specialist configures the system to automatically send a reminder to patients 48 hours before their appointment. This feature is part of:
- Release of information module
- Clinical decision support
- Patient engagement and outreach automation (Correct answer)
- Charge capture workflow
Correct answer: Patient engagement and outreach automation
Patient engagement automation tools within the EHR use scheduling data to trigger appointment reminders via phone, text, or email without manual intervention.
Question 94: Which metric best measures EHR system availability?
- Number of support tickets submitted
- System uptime percentage over a defined period (Correct answer)
- Number of active user licenses
- Average screen load time
Correct answer: System uptime percentage over a defined period
Uptime percentage directly reflects how reliably the EHR is accessible to users during scheduled operating hours.
Question 95: A patient discovers an error in their electronic health record and requests an amendment. According to HIPAA, what is the proper procedure for a CEHRS to follow?
- Delete the incorrect information and replace it with the corrected data.
- Inform the patient that the record cannot be changed once it is signed by the provider.
- Create a new, separate health record for the patient with the updated information.
- Append the correct information, note the date and time of the change, and link it to the original entry. (Correct answer)
Correct answer: Append the correct information, note the date and time of the change, and link it to the original entry.
According to the HIPAA Privacy Rule, a covered entity must append or link the corrected information to the original entry, not delete the original entry. This ensures a complete and accurate legal health record that reflects all changes. The original information should remain accessible. Denying a valid request or creating a duplicate record is improper procedure.
Question 96: A patient's EHR record shows a mismatch between their insurance ID on file and the number on their current insurance card. What is the appropriate action?
- Submit the claim using both ID numbers
- Bill using the number on file to maintain historical consistency
- Flag the record for fraud investigation
- Update the EHR with the current card number after verifying with the patient and/or insurer (Correct answer)
Correct answer: Update the EHR with the current card number after verifying with the patient and/or insurer
Updating the insurance ID after verification prevents claim rejections and ensures accurate billing to the correct payer.
Question 97: In EHR-based coding, what is the role of a 'code editor' or 'claims scrubber'?
- A person who manually reviews every claim before submission
- A tool that converts SNOMED CT codes to ICD-10
- Automated software that checks claims for coding errors and payer rule violations before submission (Correct answer)
- A compliance officer who audits past claims
Correct answer: Automated software that checks claims for coding errors and payer rule violations before submission
A claims scrubber automatically reviews claims for issues such as unbundling, missing modifiers, and payer-specific edits prior to submission to reduce denials.
Question 98: A patient's allergy to penicillin is documented in the EHR. A provider orders amoxicillin. Which system should alert the provider?
- Clinical decision support with allergy checking (Correct answer)
- Scheduling module
- Revenue cycle management system
- Laboratory information system
Correct answer: Clinical decision support with allergy checking
Clinical decision support with allergy-checking functionality cross-references active orders against documented allergies and issues an alert for cross-reactive drugs like amoxicillin.
Question 99: Which network topology connects all devices to a single central hub or switch?
- Mesh topology
- Bus topology
- Star topology (Correct answer)
- Ring topology
Correct answer: Star topology
In a star topology, every device connects to a central hub or switch, making it easy to isolate failures and manage traffic.
Question 100: While managing clinical documents, a CEHRS notices that a physician frequently uses the 'copy and paste' function to bring forward information from previous notes. This practice poses a significant risk to:
- Data integrity and patient safety. (Correct answer)
- Network speed and EHR performance.
- The storage capacity of the server.
- The provider's typing efficiency.
Correct answer: Data integrity and patient safety.
Copying and pasting, also known as 'cloning,' can introduce outdated or inaccurate information into the current record, which compromises data integrity and can lead to clinical errors, affecting patient safety. While it may seem efficient, it is a risky practice that can lead to cluttered and incorrect patient records.
Question 101: A practice uses a waitlist to fill appointment slots when cancellations occur. Which criterion should take HIGHEST priority when selecting the next patient from the waitlist?
- The patient whose clinical urgency or appointment type best matches the opening (Correct answer)
- The patient who has been waiting the longest on the list
- The patient who lives closest to the practice
- The patient with the highest outstanding balance
Correct answer: The patient whose clinical urgency or appointment type best matches the opening
While length of wait is a fairness consideration, matching the appointment slot (duration, visit type, provider) to the opening and the patient's clinical need ensures the slot is used appropriately and that the patient receives the correct level of care. Clinical appropriateness supersedes wait time.
NHA Certified Electronic Health Records Specialist (CEHRS) Exam
The NHA CEHRS examination certifies professionals who manage electronic health record systems, covering EHR software navigation, clinical and non-clinical documentation, revenue cycle operations, regulatory compliance including HIPAA, and healthcare reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds