CHI Quality Assurance & Compliance 2 — Questions and Answers
Question 1: Which federal regulation establishes the Security Rule requiring covered entities to implement administrative, physical, and technical safeguards for ePHI?
- HITECH Act
- HIPAA (Correct answer)
- Meaningful Use Rule
- 21st Century Cures Act
Correct answer: HIPAA
HIPAA's Security Rule (45 CFR Parts 160 and 164) requires covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards.
Question 2: A hospital's quality team discovers that medication error rates are 3x the national benchmark. Which QI methodology would BEST structure a root cause analysis and iterative improvement cycle?
- Six Sigma DMAIC
- Plan-Do-Study-Act (PDSA) (Correct answer)
- Lean 5S
- Failure Mode and Effects Analysis (FMEA)
Correct answer: Plan-Do-Study-Act (PDSA)
The PDSA cycle is designed for rapid, iterative improvement testing by planning a change, doing it on a small scale, studying results, and acting on findings.
Question 3: Under the CMS Conditions of Participation, which document must a hospital maintain to demonstrate ongoing quality monitoring of medical staff performance?
- Business Associate Agreement
- Notice of Privacy Practices
- Medical Staff Bylaws and Credentialing Files (Correct answer)
- HIPAA Risk Assessment
Correct answer: Medical Staff Bylaws and Credentialing Files
CMS Conditions of Participation require hospitals to maintain medical staff bylaws and credentialing files that document ongoing professional practice evaluation (OPPE) and focused professional practice evaluation (FPPE).
Question 4: Which accreditation standard requires hospitals to implement a proactive risk assessment to identify potential patient safety vulnerabilities before adverse events occur?
- The Joint Commission's FMEA requirement (Correct answer)
- CMS Meaningful Use Stage 3
- ONC Interoperability Rule
- CLIA proficiency testing standard
Correct answer: The Joint Commission's FMEA requirement
The Joint Commission requires accredited organizations to conduct at least one proactive risk assessment (Failure Mode and Effects Analysis) annually to identify and mitigate potential safety risks.
Question 5: A health informatics professional is auditing EHR access logs and finds a nurse accessed 200 patient records outside her unit in one week. This MOST likely triggers which compliance action?
- Filing a HIPAA breach notification with HHS
- Conducting a workforce sanction per the HIPAA Privacy Rule (Correct answer)
- Submitting a Sentinel Event report to The Joint Commission
- Issuing a corrective action plan to CMS
Correct answer: Conducting a workforce sanction per the HIPAA Privacy Rule
Inappropriate access to PHI by workforce members requires investigation and, if confirmed, imposition of sanctions consistent with the organization's HIPAA Privacy Rule policies.
Question 6: In healthcare data quality management, which dimension refers to the degree to which data correctly represents the real-world construct it is intended to measure?
- Completeness
- Timeliness
- Validity (Correct answer)
- Consistency
Correct answer: Validity
Validity (also called accuracy or conformity) measures whether data values correctly represent the real-world facts or conform to defined formats and constraints.
Question 7: Which CMS program ties hospital inpatient reimbursement penalties to publicly reported outcome measures including readmission rates and hospital-acquired conditions?
- Hospital Value-Based Purchasing (VBP) Program
- Hospital Readmissions Reduction Program (HRRP)
- Merit-based Incentive Payment System (MIPS)
- Hospital-Acquired Condition Reduction Program (HACRP) (Correct answer)
Correct answer: Hospital-Acquired Condition Reduction Program (HACRP)
The Hospital-Acquired Condition Reduction Program (HACRP) penalizes hospitals in the worst-performing quartile for rates of hospital-acquired infections and other conditions, reducing Medicare payments by 1%.
Which federal regulation establishes the Security Rule requiring covered entities to implement administrative, physical, and technical safeguards for ePHI?