← All CHI Flashcard Decks

Quality Assurance & Compliance Flashcards

7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Quality Assurance & Compliance flashcards as text
  1. Which Joint Commission National Patient Safety Goal (NPSG) specifically addresses the accurate identification of patients to prevent errors such as wrong-patient medication administration?

    Answer: NPSG 01.01.01 — Use at least two patient identifiers

    NPSG 01.01.01 requires healthcare organizations to use at least two patient identifiers (e.g., name and date of birth) whenever providing care, treatment, or services to prevent wrong-patient errors.

  2. A health informatician is designing an audit trail for an EHR system. Which HIPAA Technical Safeguard standard requires this capability?

    Answer: Audit Controls (§164.312(b))

    The HIPAA Audit Controls standard (§164.312(b)) requires covered entities to implement hardware, software, and procedural mechanisms that record and examine activity in information systems containing ePHI.

  3. In healthcare quality measurement, which term describes a measure that captures a process known to be strongly correlated with a desired patient outcome, such as 'percentage of AMI patients receiving aspirin on arrival'?

    Answer: Process measure

    Process measures capture whether evidence-based care steps are performed; they are preferred when the link between the process and the outcome is well-established, as with aspirin administration in AMI.

  4. Under the Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)), which of the following arrangements is protected from prosecution by a safe harbor?

    Answer: Employment of a physician at fair market value for bona fide services

    The employment safe harbor protects remuneration paid by employers to employees for bona fide employment services at fair market value, provided all other safe harbor criteria are met.

  5. A health system is preparing for a HIPAA compliance audit. Which document BEST demonstrates that the organization has systematically identified and addressed risks to ePHI confidentiality, integrity, and availability?

    Answer: A completed and current HIPAA Security Risk Analysis with documented risk management plan

    The HIPAA Security Rule requires a comprehensive risk analysis identifying potential threats to ePHI and a risk management plan documenting how identified risks are reduced to reasonable and appropriate levels.

  6. Which data governance concept refers to the designated individual or group accountable for defining standards, ensuring quality, and managing the lifecycle of a specific data domain within a healthcare organization?

    Answer: Data steward

    A data steward is accountable for a specific data domain, responsible for defining business rules, maintaining data quality standards, and governing data throughout its lifecycle within the organization.

  7. A hospital quality director wants to determine whether a reduction in catheter-associated urinary tract infections (CAUTI) after a bundle intervention is statistically significant. Which approach is MOST appropriate?

    Answer: Apply a statistical process control (SPC) chart with appropriate control limits to assess special cause variation

    SPC charts are the recommended method in healthcare QI to determine whether a change represents true improvement (special cause variation) rather than normal random fluctuation in the process.