Quality Assurance & Compliance Flashcards
7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Quality Assurance & Compliance flashcards as text
A health informatician conducting a HIPAA Security Risk Analysis discovers an unencrypted laptop containing ePHI was used by a remote employee. Which risk response is MOST appropriate under HIPAA's required implementation specifications?
Answer: Implement encryption or document why encryption is not reasonable and appropriate as an equivalent alternative measure
Encryption for ePHI on portable devices is an addressable specification under HIPAA's Technical Safeguards, meaning the entity must either implement it or document an equivalent alternative measure.
Which quality improvement framework defines seven categories of organizational performance including Leadership, Strategy, Customers, Measurement, Workforce, Operations, and Results?
Answer: Malcolm Baldrige National Quality Award Criteria
The Malcolm Baldrige Performance Excellence Framework uses seven interconnected criteria categories to assess organizational quality and performance excellence in healthcare and other sectors.
Under CLIA (Clinical Laboratory Improvement Amendments), which certificate type is required for laboratories performing high-complexity testing such as molecular diagnostics?
Answer: Certificate of Accreditation or Certificate of Compliance
Laboratories performing high-complexity testing must obtain either a Certificate of Compliance (subject to CMS inspection) or Certificate of Accreditation (through an approved accreditation organization) under CLIA regulations.
A health system's compliance officer identifies that physicians are routinely up-coding evaluation and management services. This MOST directly violates which federal statute?
Answer: The False Claims Act (31 U.S.C. § 3729)
Submitting inflated claims to Medicare or Medicaid through up-coding constitutes a false claim under the False Claims Act, which imposes civil penalties of up to three times the amount of each fraudulent claim plus statutory per-claim penalties.
In health informatics, which concept refers to the ability of different information systems to exchange, interpret, and use data in a coordinated manner without special effort from the user?
Answer: Semantic interoperability
Semantic interoperability goes beyond syntactic data exchange to ensure that the meaning of information is preserved and understood consistently across different systems, enabling accurate interpretation of shared data.
Which tool is used during the 'Measure' phase of a Six Sigma DMAIC project to quantify how well a process meets specification limits relative to its actual variation?
Answer: Process Capability Index (Cp/Cpk)
The Process Capability Index (Cp and Cpk) statistically measures whether a process can consistently produce output within specification limits relative to the process's natural variation.
The ONC's information blocking rule prohibits covered actors from practices that interfere with access, exchange, or use of electronic health information (EHI). Which entity is NOT defined as a 'covered actor' under this rule?
Answer: Individual patients seeking their own records
The information blocking rule applies to health IT developers, HIEs/HINs, and healthcare providers — individual patients seeking their own records are not covered actors but are beneficiaries of the rule's protections.