NHA Certified Electronic Health Records Specialist (CEHRS) Exam β Questions and Answers
Question 1: A user cannot access a specific patient's chart despite having the correct role. What should the EHR specialist check first?
- Network bandwidth
- Server disk space
- Patient-level access restrictions or break-the-glass policies (Correct answer)
- EHR license count
Correct answer: Patient-level access restrictions or break-the-glass policies
Patient-level restrictions such as VIP flags or break-the-glass policies can block access independent of user roles.
Question 2: A CEHRS notices that a provider frequently uses a pre-populated EHR template for documenting patient visits for 'chronic hypertension'. The template automatically includes extensive review of systems and physical exam details, often leading to a higher-level E/M code being suggested by the EHR. This practice poses a significant compliance risk related to:
- Inaccurate patient demographic data.
- HIPAA privacy violations.
- Failure to obtain informed consent.
- Lack of medical necessity. (Correct answer)
Correct answer: Lack of medical necessity.
While EHR templates can improve efficiency, using them to auto-populate extensive documentation that doesn't reflect the actual, specific service performed for that visit can lead to upcoding. Billing is based on the medical necessity of the services provided, not just the volume of documentation generated by an EHR. Payers can deny these claims and audit the provider for potential fraud if the documentation doesn't accurately support the level of service billed.
Question 3: Which metric is most commonly used to evaluate patient portal adoption rates?
- Average time to respond to a portal message
- Percentage of active patients who have logged into the portal at least once (Correct answer)
- Total number of portal pages viewed per month
- Number of lab results released per day
Correct answer: Percentage of active patients who have logged into the portal at least once
Portal adoption is standardly measured as the proportion of the patient population that has activated and logged into their portal account.
Question 4: A covered entity experiences a breach affecting 600 individuals in one state. Under HIPAA's Breach Notification Rule, who must be notified?
- Affected individuals and the state's attorney general only
- Affected individuals, HHS, and prominent media outlets in the state
- Affected individuals and HHS only (Correct answer)
- HHS and the state health department only
Correct answer: Affected individuals and HHS only
Breaches affecting fewer than 500 individuals require notification to affected individuals and HHS (logged annually); media notification is only required for breaches affecting 500 or more in a state or jurisdiction.
Question 5: Which metric best measures EHR system availability?
- Number of support tickets submitted
- Average screen load time
- System uptime percentage over a defined period (Correct answer)
- Number of active user licenses
Correct answer: System uptime percentage over a defined period
Uptime percentage directly reflects how reliably the EHR is accessible to users during scheduled operating hours.
Question 6: Which federal agency is responsible for enforcing HIPAA Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) (Correct answer)
- Office of the Inspector General (OIG)
- National Institutes of Health (NIH)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for investigating complaints and enforcing compliance with the HIPAA Privacy and Security Rules.
Question 7: Which of the following is an example of 'unbundling' in medical billing?
- Reporting a comprehensive procedure code when only components were performed
- Submitting the same claim to two different payers
- Adding a modifier to indicate a reduced service
- Billing each component of a surgical package separately instead of using the global code (Correct answer)
Correct answer: Billing each component of a surgical package separately instead of using the global code
Unbundling is the improper practice of billing multiple procedure codes for components that should be reported under a single comprehensive code.
Question 8: What is the purpose of a post-implementation review following an EHR go-live?
- To train new staff hired after the implementation
- To archive all paper records that predate the EHR
- To evaluate whether project objectives were met and identify lessons learned (Correct answer)
- To renegotiate the vendor contract based on system performance
Correct answer: To evaluate whether project objectives were met and identify lessons learned
A post-implementation review assesses whether the project met its goals, documents lessons learned, and identifies areas for ongoing optimization.
Question 9: Which type of clinical note summarizes a patient's hospital stay and is required before discharge in most accreditation standards?
- History and physical
- Discharge summary (Correct answer)
- Operative report
- Progress note
Correct answer: Discharge summary
The discharge summary provides a comprehensive overview of the patient's hospital course and must typically be completed within 30 days of discharge.
Question 10: Which CPT code range covers Evaluation and Management (E/M) services for office or outpatient visits?
- 99281β99288
- 99241β99255
- 99201β99215 (Correct answer)
- 99221β99236
Correct answer: 99201β99215
CPT codes 99202β99215 (new and established patients) represent E/M services provided in office or outpatient settings.
Question 11: A CEHRS specialist notices that a patient's problem list in the EHR has not been updated in 18 months despite multiple recent visits. This represents a deficiency in:
- Revenue cycle management
- Clinical documentation integrity (Correct answer)
- Insurance verification
- Financial reporting accuracy
Correct answer: Clinical documentation integrity
Maintaining an accurate and current problem list is a core element of clinical documentation integrity in EHR management.
Question 12: A researcher wants to access an EHR database without patient authorization for a study on diabetes outcomes. Under HIPAA, which option allows this?
- A verbal agreement with the hospital's CMO
- Accessing only records of deceased patients
- De-identified data under the Safe Harbor or Expert Determination method (Correct answer)
- Using a limited data set with no Data Use Agreement
Correct answer: De-identified data under the Safe Harbor or Expert Determination method
Using properly de-identified data via Safe Harbor or Expert Determination removes HIPAA protections, allowing research without patient authorization or a DUA.
Question 13: What is the primary purpose of a workflow redesign during an EHR implementation?
- To align clinical and administrative processes with new system capabilities (Correct answer)
- To reduce the number of staff needed for administrative tasks
- To establish a backup plan for system downtime
- To ensure all paper records are scanned into the system
Correct answer: To align clinical and administrative processes with new system capabilities
Workflow redesign aligns existing clinical and administrative processes with the capabilities and structure of the new EHR system to optimize efficiency.
Question 14: Which of the following is an example of a 'patient-mediated' health information exchange?
- A hospital query to an HIE for ED records
- A lab sending HL7 results to an EHR
- A patient using Apple Health to aggregate and share records (Correct answer)
- A provider sending a Direct message referral
Correct answer: A patient using Apple Health to aggregate and share records
Consumer- or patient-mediated exchange puts the patient in control of aggregating and sharing their own health data through apps or personal health records.
Question 15: What does 'role-based access control' (RBAC) mean in the context of EHR systems?
- Requiring multi-factor authentication for all users
- Assigning system permissions based on a user's job function (Correct answer)
- Encrypting data based on the user's department
- Granting access based on a user's physical location
Correct answer: Assigning system permissions based on a user's job function
RBAC restricts EHR access to the functions and data necessary for each user's defined role.
Question 16: A patient's allergy to penicillin is documented in the EHR. A provider orders amoxicillin. Which system should alert the provider?
- Revenue cycle management system
- Clinical decision support with allergy checking (Correct answer)
- Scheduling module
- Laboratory information system
Correct answer: Clinical decision support with allergy checking
Clinical decision support with allergy-checking functionality cross-references active orders against documented allergies and issues an alert for cross-reactive drugs like amoxicillin.
Question 17: Which SNOMED CT concept domain would be most appropriate for documenting a clinical finding such as 'pain in right knee' in an EHR?
- Pharmaceutical domain
- Body structure domain
- Clinical finding domain (Correct answer)
- Procedure domain
Correct answer: Clinical finding domain
SNOMED CT's clinical finding domain encompasses signs, symptoms, and diagnoses observed or reported during patient care.
Question 18: Which organization enforces the HIPAA Privacy and Security Rules for most covered entities?
- Joint Commission on Accreditation of Healthcare Organizations
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
- Drug Enforcement Administration (DEA)
Correct answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services investigates HIPAA complaints and enforces civil monetary penalties.
Question 19: Which of the following statements about the HIPAA Privacy Rule and minors is CORRECT?
- Parents always have full access to all medical records of their minor children
- HIPAA overrides all state laws regarding minor patient privacy
- In some cases, minors may have the right to control their own PHI, such as when state law permits them to consent to certain care (Correct answer)
- Covered entities must always provide a minor's records to both parents regardless of custody arrangements
Correct answer: In some cases, minors may have the right to control their own PHI, such as when state law permits them to consent to certain care
When a minor is legally permitted to consent to their own care under state law (e.g., substance abuse, reproductive health), they may also control access to related PHI.
Question 20: A patient calls the clinic stating they cannot see their recent lab results on the patient portal, though their provider said the results would be available. What is the MOST likely reason for this issue that a CEHRS should investigate first?
- The lab interface to the EHR is malfunctioning for all patients.
- The patient is looking in the wrong section of the portal.
- The patient's portal account has been temporarily deactivated due to inactivity.
- The lab results have not yet been reviewed and electronically released by the provider. (Correct answer)
Correct answer: The lab results have not yet been reviewed and electronically released by the provider.
Many EHR systems have a default workflow where diagnostic results are held in a provider's inbox for review before being released to the patient portal. This is a safety measure to ensure a provider can add context or contact the patient about sensitive results. It is the most common and logical first place for a CEHRS to check.
Question 21: A patient moves from one state to another and their new provider cannot access prior records. Which HIE model would BEST address this gap?
- Consumer-mediated exchange
- Query-based exchange (Correct answer)
- Consolidated-CDA only sharing
- Directed exchange
Correct answer: Query-based exchange
Query-based exchange allows providers to search and retrieve patient records from other providers on demand, ideal for accessing records across geographic boundaries.
Question 22: Which federal law established the Medicare and Medicaid programs and introduced the Conditions of Participation for healthcare facilities?
- Social Security Act of 1965 (Correct answer)
- HIPAA of 1996
- HITECH Act of 2009
- Affordable Care Act of 2010
Correct answer: Social Security Act of 1965
The Social Security Act of 1965 created Medicare and Medicaid and established Conditions of Participation that facilities must meet to receive federal reimbursement.
Question 23: What is a common barrier to effective health information exchange in the US?
- Absence of patient demographic information in EHRs
- Lack of standardized data formats and vendor interoperability (Correct answer)
- Insufficient number of certified EHR systems available
- Limited access to internet connectivity in urban areas
Correct answer: Lack of standardized data formats and vendor interoperability
One of the most significant barriers to HIE is the use of proprietary data formats and lack of standardization that makes it difficult for different EHR systems to communicate.
Question 24: Which term refers to a standardized summary document that can be created and exchanged between EHR systems to share a patient's health information?
- Explanation of Benefits (EOB)
- Superbill
- Admission, Discharge, Transfer (ADT) message
- Continuity of Care Document (CCD) (Correct answer)
Correct answer: Continuity of Care Document (CCD)
A Continuity of Care Document (CCD) is an HL7 C-CDA formatted XML document that summarizes a patient's key clinical data for sharing across systems.
Question 25: A claim is submitted with CPT code 99213 but the documentation supports only CPT 99212. What is the most appropriate action?
- Void the claim and do not bill for the service
- Correct the code to 99212 and resubmit to reflect accurate documentation (Correct answer)
- Submit the claim as coded to maximize reimbursement
- Add a modifier to justify the higher-level code
Correct answer: Correct the code to 99212 and resubmit to reflect accurate documentation
Coding must accurately reflect documented services; upcoding to a higher level than documentation supports constitutes fraud and must be corrected.
Question 26: Which process involves systematically reviewing EHR audit logs to identify unauthorized access to patient records?
- System performance monitoring
- Patch management
- Access audit review (Correct answer)
- Downtime recovery drill
Correct answer: Access audit review
Access audit reviews analyze EHR audit logs to detect unusual or unauthorized access patterns, which is required under the HIPAA Security Rule.
Question 27: A provider's template for a common visit type is missing required fields after an EHR update. Who should the EHR specialist involve to resolve this?
- The billing department only
- The patient scheduling team
- The clinical informatics or build team responsible for template configuration (Correct answer)
- The hardware vendor
Correct answer: The clinical informatics or build team responsible for template configuration
Template configuration is managed by the clinical informatics or build team, who can restore or update the required fields.
Question 28: What does the term 'revenue cycle management' (RCM) encompass in healthcare organizations?
- The entire financial process from patient scheduling and registration through coding, billing, payment, and collections (Correct answer)
- Solely the Medicare cost report preparation
- Managing the EHR software subscription costs
- Only the billing and collections process
Correct answer: The entire financial process from patient scheduling and registration through coding, billing, payment, and collections
RCM covers the complete lifecycle of a patient account, including eligibility verification, charge capture, coding, claim submission, payment posting, and denial management.
Question 29: Which EHR function tracks when each provider last reviewed a specific section of the patient's chart?
- Patient-reported outcomes tool
- Audit trail or access log (Correct answer)
- Version control module
- Clinical summary generator
Correct answer: Audit trail or access log
The audit trail (access log) records who accessed or modified each element of the EHR and when, supporting accountability, compliance monitoring, and breach investigation.
Question 30: A patient requests that a note documenting a sensitive mental health diagnosis be excluded from the portal. What is the appropriate response?
- Review applicable state law and HIPAA psychotherapy notes provisions, then restrict access if legally warranted (Correct answer)
- Delete the note from the EHR entirely
- Deny the request because all records must be visible
- Grant access to the note only to insurance companies
Correct answer: Review applicable state law and HIPAA psychotherapy notes provisions, then restrict access if legally warranted
Psychotherapy notes and certain sensitive records may be withheld under HIPAA and state law; staff must evaluate the specific legal basis before restricting portal display.
Question 31: What is the significance of recording a patient's 'preferred name' versus their 'legal name' in an EHR?
- Preferred name changes the patient's MRN in the MPI
- Preferred name replaces the legal name on all clinical and billing documents
- Preferred name is required by HIPAA for all patient interactions
- Preferred name is used for clinical communication while the legal name is retained for billing and legal records (Correct answer)
Correct answer: Preferred name is used for clinical communication while the legal name is retained for billing and legal records
Recording a preferred name improves patient experience and communication while the legal name remains for billing, insurance, and legal compliance.
Question 32: Which privacy principle requires that only the minimum necessary PHI be used or disclosed to accomplish the intended purpose?
- Minimum necessary standard (Correct answer)
- Proportionality doctrine
- Need-to-know basis rule
- Data integrity principle
Correct answer: Minimum necessary standard
The HIPAA minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use and disclosure to what is necessary for the intended purpose.
Question 33: A physician reports that clinical decision support alerts are firing too frequently and being ignored. What is the best corrective action?
- Upgrade the EHR server hardware
- Require physicians to document each alert dismissal
- Review and optimize alert thresholds to reduce alert fatigue (Correct answer)
- Disable all clinical decision support alerts
Correct answer: Review and optimize alert thresholds to reduce alert fatigue
Tuning alert thresholds reduces alert fatigue while preserving clinically meaningful notifications.
Question 34: Which quality improvement model uses Plan-Do-Study-Act (PDSA) cycles to test changes in healthcare processes?
- Root Cause Analysis
- Six Sigma
- Model for Improvement (Correct answer)
- Lean methodology
Correct answer: Model for Improvement
The Model for Improvement, developed by Associates in Process Improvement, uses PDSA cycles to iteratively test and refine process changes.
Question 35: Which of the following is a common challenge when implementing Electronic Health Records (EHR) into clinical workflows?
- There can be resistance from healthcare providers due to changes in workflow (Correct answer)
- EHR systems are universally compatible with all healthcare provider tools
- EHR systems are only used for administrative tasks
- EHRs typically require minimal training for staff
Correct answer: There can be resistance from healthcare providers due to changes in workflow
A common challenge when implementing EHRs is resistance from healthcare providers, as the adoption of electronic systems often requires changes in established workflows and additional training. This transition can be met with some reluctance, especially if the system is perceived as difficult or time-consuming.
Question 36: Which term describes the ability of an EHR system to continue processing transactions even when one component fails?
- Portability
- Fault tolerance (Correct answer)
- Modularity
- Scalability
Correct answer: Fault tolerance
Fault tolerance is the system's ability to maintain operations through redundant components so that a single failure does not cause a complete outage.
Question 37: Which of the following is an example of 'unbundling' in medical billing?
- Submitting a claim with both CPT and HCPCS codes
- Billing a comprehensive code when only a component service was performed
- Using two modifiers on a single claim line
- Billing each component of a procedure separately when a single comprehensive code exists (Correct answer)
Correct answer: Billing each component of a procedure separately when a single comprehensive code exists
Unbundling occurs when a coder bills individual components of a procedure separately rather than using the single comprehensive CPT code that covers all components.
Question 38: Under the 21st Century Cures Act, what is information blocking?
- Limiting provider access to non-essential patient data
- Encrypting patient data to prevent external breaches
- Any practice that interferes with the access, exchange, or use of electronic health information (Correct answer)
- Restricting EHR access to unauthorized users only
Correct answer: Any practice that interferes with the access, exchange, or use of electronic health information
The 21st Century Cures Act defines information blocking as practices that unreasonably restrict the access, exchange, or use of electronic health information.
Question 39: A 'record overlay' is the MOST dangerous MPI error because it means:
- A patient's chart is stored in a legacy system that cannot be migrated
- Two patients share the same appointment slot in the scheduling system
- One patient's clinical data is written into a different patient's medical record (Correct answer)
- A paper chart has been scanned and indexed under an incorrect document type
Correct answer: One patient's clinical data is written into a different patient's medical record
In a record overlay, Patient A's MRN is used to document care that actually belongs to Patient B β or vice versa. This is a critical patient safety event: providers may make clinical decisions (medications, surgery, transfusions) based on another person's allergies, blood type, or diagnoses. Overlays are far more dangerous than duplicates.
Question 40: Which HIPAA civil monetary penalty tier applies when a covered entity did not know and could not reasonably have known about the violation?
- $10,000β$50,000 per violation
- $50,000 or more per violation
- $100β$50,000 per violation (Tier 1 β unknowing) (Correct answer)
- Same as willful neglect corrected
Correct answer: $100β$50,000 per violation (Tier 1 β unknowing)
Tier 1 penalties of $100 to $50,000 per violation apply when the entity was unaware of the violation and exercised reasonable diligence.
Question 41: Which type of malware encrypts EHR data and demands payment for the decryption key?
- Rootkit
- Adware
- Ransomware (Correct answer)
- Spyware
Correct answer: Ransomware
Ransomware is malicious software that encrypts a victim's data and demands a ransom payment in exchange for the decryption key needed to restore access.
Question 42: Which accreditation standard requires hospitals to maintain a complete medical record for every patient and defines minimum content requirements?
- HITECH meaningful use
- URAC accreditation
- PCMH recognition
- CMS Conditions of Participation (Correct answer)
Correct answer: CMS Conditions of Participation
CMS Conditions of Participation (42 CFR 482.24) specify that hospitals must maintain a medical record for every patient with defined minimum content elements.
Question 43: An EHR specialist discovers that a coworker has been accessing patient records out of curiosity without a treatment need. This is best described as:
- Incidental disclosure
- A permissible use for healthcare operations
- A technical security incident only
- Insider threat and a HIPAA Privacy Rule violation (Correct answer)
Correct answer: Insider threat and a HIPAA Privacy Rule violation
Accessing PHI without a legitimate purpose violates the Minimum Necessary and need-to-know principles under the HIPAA Privacy Rule and constitutes an insider threat.
Question 44: When a patient pays out-of-pocket in full for a service, HIPAA gives them the right to:
- Have the covered entity delete the information from their records
- Receive a discount on services rendered
- Request that the covered entity not share that service's information with a health plan (Correct answer)
- Obtain a second opinion at no additional cost
Correct answer: Request that the covered entity not share that service's information with a health plan
Under the 2013 Omnibus Rule, patients who pay out-of-pocket in full may restrict disclosure of that specific service to a health plan, and covered entities must honor this restriction.
Question 45: A scheduling model in which multiple patients are booked at the beginning of each time block and then seen in order of arrival is called:
- Open-access scheduling
- Stream scheduling
- Modified wave scheduling
- Wave scheduling (Correct answer)
Correct answer: Wave scheduling
Wave scheduling places several patients at the start of each hour or block and serves them in arrival order, allowing flexibility for varying visit lengths. Modified wave scheduling staggers those arrivals slightly to reduce waiting room congestion while preserving flexibility.
Question 46: Which metric measures the percentage of submitted claims that are paid on the first submission without denial or rejection?
- Denial rate
- Net collection rate
- Days in accounts receivable
- First-pass resolution rate (FPRR) (Correct answer)
Correct answer: First-pass resolution rate (FPRR)
The first-pass resolution rate measures how often claims are adjudicated and paid correctly on initial submission, reflecting billing quality.
Question 47: A practice uses a separate billing system that must receive charges generated in the EHR. The link between these two systems is called a(n):
- Data warehouse query
- Audit trail
- Bi-directional interface (Correct answer)
- Downtime procedure
Correct answer: Bi-directional interface
A bi-directional interface allows data to flow in both directions between the EHR and billing system, ensuring charges and updates sync automatically.
Question 48: Which HIPAA rule specifically requires covered entities to implement technical, administrative, and physical safeguards for electronic PHI?
- Security Rule (Correct answer)
- Privacy Rule
- Enforcement Rule
- Breach Notification Rule
Correct answer: Security Rule
The HIPAA Security Rule requires covered entities and business associates to implement safeguards specifically to protect electronic PHI (ePHI).
Question 49: What is the purpose of a 'downtime procedure' in clinical workflow?
- Reducing the number of daily logins required by clinical staff
- Archiving old patient records to free up server space
- Shutting down the EHR for maintenance without affecting clinical operations
- Using paper-based backup processes to maintain care delivery when the EHR is unavailable (Correct answer)
Correct answer: Using paper-based backup processes to maintain care delivery when the EHR is unavailable
Downtime procedures are paper-based or offline protocols that ensure patient care and documentation can continue safely when the EHR system is temporarily unavailable.
Question 50: What is the primary purpose of a Direct Secure Messaging system in healthcare?
- To process and submit insurance claims electronically
- To enable patient-to-physician video consultations
- To send encrypted health information securely between trusted providers (Correct answer)
- To store laboratory results in a centralized database
Correct answer: To send encrypted health information securely between trusted providers
Direct Secure Messaging provides a simple, secure, standards-based way for providers to send authenticated encrypted health information directly to known recipients.
Question 51: Which federal initiative established the framework for nationwide health information exchange in the US?
- Health Insurance Portability and Accountability Act (HIPAA)
- Consolidated Omnibus Budget Reconciliation Act (COBRA)
- Medicare Access and CHIP Reauthorization Act (MACRA)
- Nationwide Health Information Network (NwHIN) (Correct answer)
Correct answer: Nationwide Health Information Network (NwHIN)
The Nationwide Health Information Network (NwHIN) was established to create standards and services for secure health information exchange across the US.
Question 52: Which factor is NOT part of the four-factor risk assessment used to determine if a breach of PHI requires notification?
- Likelihood that PHI was actually compromised
- The financial cost of the breach investigation (Correct answer)
- Who accessed or could have accessed the PHI
- Nature and extent of PHI involved
Correct answer: The financial cost of the breach investigation
The HIPAA breach risk assessment evaluates the type of PHI, who accessed it, whether it was actually acquired or viewed, and the extent of mitigation β not investigation costs.
Question 53: In EHR project management, the term 'scope creep' refers to:
- A gradual increase in system response time after go-live
- The tendency for end users to revert to paper-based workflows
- Uncontrolled expansion of project requirements beyond the original plan (Correct answer)
- Unauthorized access attempts that increase over the project lifecycle
Correct answer: Uncontrolled expansion of project requirements beyond the original plan
Scope creep occurs when additional features or requirements are added to a project without proper approval, leading to budget overruns and timeline delays.
Question 54: Which action should be taken when a terminated employee's EHR access has not been revoked?
- Immediately disable the account and document the action per policy (Correct answer)
- Move the employee to a read-only role
- Change the employee's password
- Send the employee an email reminder to stop logging in
Correct answer: Immediately disable the account and document the action per policy
Prompt account deactivation upon termination is a HIPAA security requirement to prevent unauthorized access.
Question 55: Which EHR scheduling feature is designed to proactively contact patients who are due for preventive screenings or follow-up care?
- Appointment conflict checker
- Recall or tickler system (Correct answer)
- Double-booking module
- Referral authorization tracker
Correct answer: Recall or tickler system
A recall (or tickler) system automatically generates reminders or outreach tasks for patients who are due for recurring care β such as annual wellness visits, mammograms, or diabetic follow-ups β helping practices close care gaps and improve preventive health metrics.
Question 56: Which of the following scenarios would trigger an overlap alert in the MPI?
- A patient changes their insurance between visits
- Two records share the same name, date of birth, and gender but have different MRNs (Correct answer)
- A patient is registered by two different registration clerks on the same day
- A patient is seen at two different departments in the same facility on the same day
Correct answer: Two records share the same name, date of birth, and gender but have different MRNs
An MPI overlap alert fires when demographic data strongly matches across two separate records, suggesting a duplicate patient identity.
Question 57: Under the 21st Century Cures Act, which practice is prohibited when health IT vendors or providers restrict access, exchange, or use of EHR data?
- Selective disclosure
- Data minimization
- Information blocking (Correct answer)
- Consent revocation
Correct answer: Information blocking
The 21st Century Cures Act explicitly prohibits 'information blocking'βpractices that interfere with the access, exchange, or use of electronic health information.
Question 58: Which of the following demographic fields is most important for calculating a patient's insurance eligibility and benefits?
- Preferred language
- Marital status
- Date of birth (Correct answer)
- Employer address
Correct answer: Date of birth
Date of birth is used by insurers to verify eligibility, determine age-specific benefits, and confirm subscriber identity.
Question 59: Which of the following best describes 'meaningful use' in the context of EHR reporting requirements?
- Scanning paper records into an electronic system
- Using certified EHR technology to improve quality, safety, and efficiency of care (Correct answer)
- Sharing patient data with pharmaceutical companies
- Using an EHR system for billing purposes only
Correct answer: Using certified EHR technology to improve quality, safety, and efficiency of care
Meaningful use requires healthcare providers to use certified EHR technology in ways that improve patient care quality, safety, and efficiency while meeting specific reporting objectives.
Question 60: In healthcare quality management, a control chart is primarily used to:
- Identify which staff members make the most errors
- Rank departments by error frequency
- Compare facility performance to national benchmarks
- Monitor process variation over time to distinguish common from special cause variation (Correct answer)
Correct answer: Monitor process variation over time to distinguish common from special cause variation
Control charts display process data over time with statistical control limits, helping distinguish normal variation (common cause) from unusual events (special cause).
Question 61: Which risk is most directly associated with migrating historical patient data to a new EHR system?
- Loss of network connectivity during peak usage hours
- Unauthorized access by external parties during migration
- Data corruption or incomplete transfer of clinical records (Correct answer)
- Increased licensing costs due to expanded data storage needs
Correct answer: Data corruption or incomplete transfer of clinical records
Data corruption or incomplete transfer is the primary risk during data migration, as errors can result in missing or inaccurate patient records that affect care quality.
Question 62: Medication reconciliation in an EHR is BEST defined as:
- Verifying that all prescribed medications were billed to the correct payer
- Calculating the correct weight-based dosage for pediatric patients
- Automatically refilling prescriptions that are within 7 days of expiration
- Comparing a patient's current medication orders to all medications the patient was previously taking to identify discrepancies (Correct answer)
Correct answer: Comparing a patient's current medication orders to all medications the patient was previously taking to identify discrepancies
Medication reconciliation is the clinical process of creating the most accurate possible list of all medications a patient is taking and comparing it to the provider's orders. This process is critical at care transitions (admission, discharge, transfers) to prevent omissions, duplications, and dosing errors.
Question 63: In medical coding, what does 'specificity' refer to?
- Using only three-digit category codes
- The speed at which codes are assigned
- Coding to the highest level of detail supported by documentation (Correct answer)
- Selecting the most common diagnosis code for a condition
Correct answer: Coding to the highest level of detail supported by documentation
Coding to the highest level of specificity means selecting the most detailed code available that is supported by the physician's documentation.
Question 64: What is the role of an 'interface engine' (such as Mirth Connect) in an EHR environment?
- It manages user authentication
- It translates and routes health data messages between different systems (Correct answer)
- It generates patient billing statements
- It stores scanned documents
Correct answer: It translates and routes health data messages between different systems
Interface engines transform and route HL7 or FHIR messages between systems that use different formats or protocols.
Question 65: Which term describes the process of replacing PHI identifiers with a code or token while retaining a mapping file that allows re-identification?
- Anonymization
- Aggregation
- Pseudonymization (Correct answer)
- De-identification
Correct answer: Pseudonymization
Pseudonymization replaces direct identifiers with surrogate values but retains a key to reverse the process, unlike true de-identification which destroys the link.
Question 66: A patient's demographic record shows their sex as 'male' but they identify as a transgender woman. What is the best practice for documenting this in the EHR?
- Do not change any fields to avoid system errors
- Record both the administrative sex and the gender identity in separate designated fields (Correct answer)
- Add a free-text note only, leaving structured fields unchanged
- Override the field to 'female' without documentation of the change
Correct answer: Record both the administrative sex and the gender identity in separate designated fields
Modern EHRs include separate fields for administrative sex (used for billing/clinical defaults) and gender identity, supporting accurate and respectful care.
Question 67: A breach of unsecured PHI affecting 600 patients requires notification to which entities under the HIPAA Breach Notification Rule?
- HHS and the state attorney general only
- Affected individuals and HHS only
- Affected individuals only
- Affected individuals, HHS, and prominent local media outlets (Correct answer)
Correct answer: Affected individuals, HHS, and prominent local media outlets
Breaches affecting 500 or more individuals in a state require notification to affected individuals, HHS, and prominent media outlets in that state.
Question 68: A patient's psychotherapy notes are held to a stricter standard than general medical records under HIPAA because they:
- Are excluded from the EHR system entirely
- Must be destroyed after five years by federal law
- Can only be accessed by psychiatrists, not psychologists
- Are always stored separately and require specific authorization for most disclosures (Correct answer)
Correct answer: Are always stored separately and require specific authorization for most disclosures
Psychotherapy notes are specifically protected under HIPAA and generally require patient authorization for disclosure even for TPO purposes, unlike most other PHI.
Question 69: Which government program uses the Inpatient Prospective Payment System (IPPS) to reimburse hospitals based on Diagnosis-Related Groups (DRGs)?
- TRICARE Prime
- Medicare Part B
- Medicare Part A (Correct answer)
- Medicaid fee-for-service
Correct answer: Medicare Part A
Medicare Part A uses the IPPS with DRG-based reimbursement for inpatient hospital services, paying a fixed amount per diagnosis regardless of actual costs.
Question 70: In ICD-10-CM, what is the meaning of the placeholder character 'X' in certain code categories?
- It indicates an unknown etiology
- It marks codes that require additional digits
- It holds a position to allow future expansion or to enable a 7th character extension (Correct answer)
- It indicates pediatric-only codes
Correct answer: It holds a position to allow future expansion or to enable a 7th character extension
The placeholder X is used when a code requires a 7th character but has fewer than six characters; X fills the empty positions to reach the correct length.
Question 71: An Advance Beneficiary Notice (ABN) must be given to a Medicare patient when:
- The provider believes Medicare may deny the service as not medically necessary (Correct answer)
- The patient owes a co-payment
- The claim exceeds the annual deductible
- The patient has a secondary insurance
Correct answer: The provider believes Medicare may deny the service as not medically necessary
An ABN informs Medicare beneficiaries that Medicare may not pay for a service and allows them to decide whether to proceed and accept financial responsibility.
Question 72: Which type of HIE governance model is characterized by a central organization that stores and manages all participating members' patient data?
- Centralized model (Correct answer)
- Peer-to-peer model
- Hybrid model
- Federated model
Correct answer: Centralized model
In a centralized HIE model, a single repository stores data from all participants, enabling fast queries but requiring strong governance and data stewardship.
Question 73: A CEHRS receives a high-priority help desk ticket stating that a physician cannot electronically sign a patient's prescription order due to a system error. This issue prevents the pharmacy from dispensing a critical medication. According to standard help desk ticket prioritization, what is the MOST critical factor that defines this as a high-priority issue?
- The time of day the ticket was submitted.
- The seniority of the user reporting the problem.
- The direct impact on patient care and safety. (Correct answer)
- The number of users affected by the same issue.
Correct answer: The direct impact on patient care and safety.
In a healthcare setting, help desk tickets are prioritized based on their impact and urgency, with the highest priority given to issues that directly affect patient care, safety, or critical clinical workflows. An inability to prescribe medication is a direct threat to patient care.
Question 74: When entering a specialist referral appointment in the EHR, which piece of information is MOST critical to capture accurately?
- The patient's preferred appointment time of day
- The referring provider's NPI number and the clinical reason for referral (Correct answer)
- The patient's most recent insurance card expiration date
- The specialist's personal mobile phone number
Correct answer: The referring provider's NPI number and the clinical reason for referral
The referring provider's NPI is required for insurance authorization and billing, and the clinical reason for referral drives medical necessity determinations. Without these, the referral may be denied or the specialist may lack the context to prepare for the visit.
Question 75: Which of the following best describes a 'closed-loop' medication management process in an EHR?
- An integrated workflow from electronic ordering through pharmacy verification to administration documentation (Correct answer)
- The pharmacist reviews and manually transcribes all physician orders
- Patients self-report medication use to the billing department
- Medications are ordered, dispensed, and documented without any electronic verification
Correct answer: An integrated workflow from electronic ordering through pharmacy verification to administration documentation
Closed-loop medication management integrates CPOE, pharmacy dispensing, and eMAR so that every step from order to administration is electronically tracked and verified.
Question 76: An EHR system automatically populates a note with information from a previous visit without clinician review. This practice is called:
- Concurrent coding
- Prospective documentation
- Copy forward or cloning (Correct answer)
- Auto-authentication
Correct answer: Copy forward or cloning
Copy forward or cloning can compromise documentation integrity if outdated or inaccurate information is carried forward without review.
Question 77: When a CEHRS is enrolling a new patient for portal access at the clinic, which step is MOST critical for authenticating the patient's identity and protecting their health information?
- Sending a confirmation link to the patient's provided email address.
- Providing the patient with a brochure on the portal's security features.
- Asking the patient to create a security question they can remember.
- Verifying the patient's identity using a government-issued photo ID. (Correct answer)
Correct answer: Verifying the patient's identity using a government-issued photo ID.
Before granting access to sensitive ePHI, HIPAA's Person or Entity Authentication standard requires the covered entity to verify that the individual is who they claim to be. Using a government-issued photo ID is a standard and reliable method for identity proofing in person.
Question 78: When entering a patient's address, the EHR system flags it as undeliverable. What is the best next step?
- Leave the address field blank to avoid errors
- Use the address from the previous visit without asking
- Verify the address with the patient and correct it if needed (Correct answer)
- Enter the address exactly as typed and ignore the flag
Correct answer: Verify the address with the patient and correct it if needed
Address verification with the patient ensures accurate contact information for billing, correspondence, and care coordination.
Question 79: What does the term 'interoperability' mean in the context of EHR systems?
- The ability of different EHR systems to exchange and use shared information (Correct answer)
- The encryption of patient data during transmission
- The ability to access EHR data from any mobile device
- The process of converting paper records to digital format
Correct answer: The ability of different EHR systems to exchange and use shared information
Interoperability refers to the ability of different EHR systems to communicate, exchange data, and use the information that has been exchanged.
Question 80: The process of verifying a patient's insurance eligibility BEFORE the date of service is called:
- Pre-certification
- Pre-adjudication
- Pre-authorization
- Pre-verification (Correct answer)
Correct answer: Pre-verification
Pre-verification (eligibility verification) confirms coverage, co-pays, and deductibles before the patient arrives for care.
Question 81: What is a Diagnosis-Related Group (DRG) primarily used for?
- Calculating physician fee-for-service payments
- Organizing EHR problem lists by organ system
- Classifying outpatient visits by complexity
- Grouping inpatient cases for prospective payment to hospitals under Medicare (Correct answer)
Correct answer: Grouping inpatient cases for prospective payment to hospitals under Medicare
DRGs are used by CMS under the Inpatient Prospective Payment System (IPPS) to pay hospitals a fixed amount based on the patient's diagnosis and procedures.
Question 82: When a provider bills a higher-complexity service than was actually performed, this is known as:
- Unbundling
- Upcoding (Correct answer)
- Downcoding
- Balance billing
Correct answer: Upcoding
Upcoding is the fraudulent practice of billing for a more expensive service than was rendered, inflating reimbursement.
Question 83: What is the role of a Master Patient Index (MPI) in health information exchange?
- To store all clinical notes in a searchable database
- To match and link patient records across different healthcare organizations (Correct answer)
- To authorize insurance claims between payers
- To generate patient billing statements automatically
Correct answer: To match and link patient records across different healthcare organizations
A Master Patient Index (MPI) serves as the authoritative source for patient identification, linking records for the same patient across multiple facilities.
Question 84: What is the purpose of an Advance Beneficiary Notice (ABN) in medical coding?
- To authorize surgery in advance
- To pre-approve inpatient admissions
- To notify Medicare patients that a service may not be covered so they can accept financial responsibility (Correct answer)
- To document a patient's advanced directive
Correct answer: To notify Medicare patients that a service may not be covered so they can accept financial responsibility
An ABN informs Medicare beneficiaries that a service may be denied as not medically necessary, giving them the choice to proceed and accept responsibility for payment.
Question 85: Under HIPAA, what is the maximum number of days a covered entity has to respond to a patient's request to access their own medical records before an extension may be invoked?
- 15 days
- 30 days (Correct answer)
- 90 days
- 60 days
Correct answer: 30 days
HIPAA's Privacy Rule (45 CFR Β§164.524) requires a covered entity to act on a patient's access request within 30 days. One 30-day extension is permitted if the entity notifies the patient in writing of the reason for the delay.
Question 86: A patient refuses to provide their Social Security Number during registration. What is the appropriate response?
- Contact the patient's insurer to obtain the SSN directly
- Deny registration until the SSN is provided
- Document the refusal and proceed with registration using other identifiers (Correct answer)
- Assign a temporary SSN for system entry
Correct answer: Document the refusal and proceed with registration using other identifiers
Patients have the right to decline providing their SSN; registration can continue using other required demographic identifiers.
Question 87: A hospital's HIM department notices that electronic records are being accessed by clinical staff outside their care team. Which HIPAA safeguard addresses this issue?
- Physical safeguards β workstation security
- Organizational safeguards β business associate agreements
- Technical safeguards β audit controls (Correct answer)
- Administrative safeguards β workforce training
Correct answer: Technical safeguards β audit controls
Technical safeguard audit controls (45 CFR 164.312(b)) require covered entities to implement hardware, software, and procedural mechanisms to record and examine EHR access activity.
Question 88: Which regulatory authority issued the foundational rule that established legal standards for electronic prescribing of controlled substances (EPCS)?
- The Joint Commission
- The Drug Enforcement Administration (DEA) (Correct answer)
- The Office of the National Coordinator for Health IT (ONC)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Drug Enforcement Administration (DEA)
The DEA published its Interim Final Rule on Electronic Prescriptions for Controlled Substances in 2010, establishing the technical and identity-proofing requirements that prescribers and software vendors must meet to transmit Schedule IIβV controlled substance prescriptions electronically.
Question 89: When planning an EHR implementation budget, which cost category is most commonly underestimated?
- Training and ongoing support (Correct answer)
- Hardware procurement
- Software licensing fees
- Network infrastructure upgrades
Correct answer: Training and ongoing support
Training and ongoing support are frequently underestimated because the true cost extends beyond initial go-live to include refresher training, support desk staffing, and optimization.
Question 90: Which format is most commonly used for structuring clinical notes, particularly in physician documentation?
- STAR (Situation, Task, Action, Result)
- DARE (Diagnosis, Assessment, Response, Evaluation)
- SOAP (Subjective, Objective, Assessment, Plan) (Correct answer)
- CARE (Chief complaint, Assessment, Referral, Education)
Correct answer: SOAP (Subjective, Objective, Assessment, Plan)
The SOAP format is the standard structure for clinical notes, organizing documentation into subjective findings, objective data, assessment, and plan.
Question 91: What is the primary purpose of an electronic prior authorization (ePA) workflow integrated into the EHR?
- To replace the pharmacy dispensing system
- To automatically approve all high-cost medications without payer review
- To document patient consent for procedures
- To streamline the submission and tracking of insurance authorization requests directly from the clinical workflow (Correct answer)
Correct answer: To streamline the submission and tracking of insurance authorization requests directly from the clinical workflow
An ePA workflow allows providers to initiate, submit, and track prior authorization requests to payers without leaving the EHR, reducing delays and administrative burden.
Question 92: A business associate agreement (BAA) is REQUIRED when a covered entity shares ePHI with a vendor that:
- Is another covered entity
- Performs functions involving PHI on behalf of the covered entity (Correct answer)
- Accesses aggregate statistical data only
- Only stores de-identified data
Correct answer: Performs functions involving PHI on behalf of the covered entity
A BAA is required whenever a covered entity engages a business associate to perform services that involve creating, receiving, maintaining, or transmitting PHI.
Question 93: A physician documents a patient's diagnosis as 'Type 2 diabetes mellitus with hyperglycemia' and the procedure as a 'comprehensive metabolic panel'. Within the EHR, what is the MOST critical relationship the CEHRS must ensure is established for proper claim submission?
- The patient's insurance information is verified and active.
- The CPT code for the procedure is from the most recent publication year.
- The physician's digital signature is applied within 24 hours of the patient encounter.
- The ICD-10-CM code for the diagnosis demonstrates medical necessity for the CPT code of the service provided. (Correct answer)
Correct answer: The ICD-10-CM code for the diagnosis demonstrates medical necessity for the CPT code of the service provided.
For a claim to be paid, the diagnosis code (ICD-10-CM) must justify the reason a procedure or service (CPT) was performed. This relationship is called 'medical necessity'. An EHR helps facilitate this by allowing the linkage of diagnosis codes to procedure codes, but the CEHRS must understand this principle to ensure accurate claims are generated.
Question 94: In a RACI matrix used during EHR implementation, 'A' stands for:
- Available
- Accountable (Correct answer)
- Authorized
- Assigned
Correct answer: Accountable
In a RACI matrix, 'A' stands for Accountable β the person ultimately answerable for the task's completion and who approves the work.
Question 95: Which report would a CEHRS specialist run to identify claims that were submitted but have not yet received a response from the payer?
- Day sheet
- Denial management report
- Claims status/pending claims report (Correct answer)
- Remittance advice summary
Correct answer: Claims status/pending claims report
A pending claims report tracks submitted claims that are still awaiting adjudication or response from the insurance payer.
Question 96: What is the purpose of a 'downtime procedure' in EHR support?
- To train new staff on the EHR
- To maintain patient care workflows when the EHR is unavailable (Correct answer)
- To permanently migrate data to a new system
- To delete outdated patient records
Correct answer: To maintain patient care workflows when the EHR is unavailable
Downtime procedures ensure clinical operations continue safely when the EHR system is offline.
Question 97: Which of the following is an example of using the patient portal to support population health management?
- Posting the clinic's holiday hours on the portal home page
- Sending automated preventive care reminders (e.g., flu shot, mammogram) to eligible patient cohorts through the portal (Correct answer)
- Allowing patients to change their username
- Enabling patients to download their billing invoices
Correct answer: Sending automated preventive care reminders (e.g., flu shot, mammogram) to eligible patient cohorts through the portal
Automated portal outreach to cohorts based on clinical criteria (age, diagnosis, last visit) is a key population health management strategy.
Question 98: A patient requests an amendment to their medical record. The covered entity may deny the request if:
- The amendment would improve clarity
- The information is older than five years
- The patient does not provide a written reason
- The record was not created by the covered entity (Correct answer)
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if it did not create the record and is not the appropriate custodian to amend it.
Question 99: Which portal functionality helps reduce no-show rates by allowing patients to confirm or cancel appointments online?
- Appointment reminder and confirmation with self-service cancellation or rescheduling (Correct answer)
- Online bill payment
- Medication refill requests
- Lab result viewing
Correct answer: Appointment reminder and confirmation with self-service cancellation or rescheduling
Interactive appointment reminders that allow patients to confirm or cancel online reduce no-shows by prompting timely responses and freeing slots for other patients.
Question 100: Which standard message format is most commonly used to transmit lab results, ADT notifications, and order information between hospital systems?
- X12 EDI 837
- HL7 v2.x (Correct answer)
- DICOM
- FHIR R4
Correct answer: HL7 v2.x
HL7 v2.x remains the most widely deployed standard for real-time clinical messaging including ADT, ORM, ORU, and other transaction types.
Question 101: In healthcare financial reporting, the term 'bad debt' specifically refers to:
- Overpayments returned to payers
- Patient balances deemed uncollectible after reasonable collection efforts (Correct answer)
- Claims denied by insurance for coding errors
- Contractual adjustments written off per payer contracts
Correct answer: Patient balances deemed uncollectible after reasonable collection efforts
Bad debt represents patient balances that a practice has made reasonable efforts to collect but has determined are uncollectible.
NHA Certified Electronic Health Records Specialist (CEHRS) Exam
The NHA CEHRS examination certifies professionals who manage electronic health record systems, covering EHR software navigation, clinical and non-clinical documentation, revenue cycle operations, regulatory compliance including HIPAA, and healthcare reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds