CHI Quality Assurance & Compliance 3 — Questions and Answers
Question 1: A covered entity experiences a ransomware attack that encrypts ePHI. Under HIPAA Breach Notification Rule, what is the initial presumption regarding this incident?
- It is automatically classified as a minor security incident requiring only internal logging
- It is presumed to be a breach unless the entity can demonstrate low probability of PHI compromise (Correct answer)
- It requires immediate criminal referral to the DOJ before notifying patients
- It is exempt from breach notification if the data was encrypted prior to the attack
Correct answer: It is presumed to be a breach unless the entity can demonstrate low probability of PHI compromise
HHS guidance states that ransomware encrypting ePHI is presumed a breach under HIPAA unless the covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 2: Which statistical process control tool is MOST useful for visualizing whether a healthcare quality metric remains within expected variation limits over time?
- Pareto Chart
- Scatter Diagram
- Control Chart (Shewhart Chart) (Correct answer)
- Histogram
Correct answer: Control Chart (Shewhart Chart)
Control charts display a metric over time with upper and lower control limits, distinguishing common cause (random) variation from special cause variation that requires investigation.
Question 3: Under 21 CFR Part 11, what is required for electronic signatures used in FDA-regulated healthcare software systems to be considered legally binding?
- They must use RSA-2048 encryption only
- Each signature component must be unique to an individual and cannot be reused or reassigned (Correct answer)
- They must be witnessed by a notary public
- They must be printed and retained as paper records
Correct answer: Each signature component must be unique to an individual and cannot be reused or reassigned
21 CFR Part 11 requires that each electronic signature be unique to one individual, not reused or reassigned to anyone else, and that it include at least two distinct components such as an ID code and password.
Question 4: A health system is implementing a new quality measure that requires chart abstraction. Which approach BEST ensures inter-rater reliability among abstractors?
- Allowing each abstractor to use personal clinical judgment to fill data gaps
- Training abstractors together and conducting double-abstraction on a sample with kappa statistics (Correct answer)
- Assigning a single senior abstractor to review all records
- Using ICD-10 codes as a proxy for all measure numerators without manual review
Correct answer: Training abstractors together and conducting double-abstraction on a sample with kappa statistics
Inter-rater reliability is established through standardized training, followed by double-abstraction of a sample and calculating Cohen's kappa to measure agreement beyond chance.
Question 5: Which element is NOT required in a HIPAA-compliant Business Associate Agreement (BAA)?
- Permitted uses and disclosures of PHI by the business associate
- The business associate's obligation to report breaches to the covered entity
- A guarantee that the business associate will never experience a data breach (Correct answer)
- Requirement that the business associate use appropriate safeguards to protect PHI
Correct answer: A guarantee that the business associate will never experience a data breach
HIPAA does not require business associates to guarantee breach-free operations; BAAs must address permitted uses, safeguards, breach reporting, and return/destruction of PHI, but absolute security guarantees are not required or legally meaningful.
Question 6: In the context of clinical data quality, which term describes data captured in one system that contradicts data for the same patient in another system within the same organization?
- Incompleteness
- Inconsistency (Correct answer)
- Inaccuracy
- Untimeliness
Correct answer: Inconsistency
Inconsistency refers to data about the same entity that conflicts across systems, fields, or time points, representing a core data integrity problem in health information management.
Question 7: Which CMS quality reporting program specifically applies to eligible clinicians in outpatient settings and includes four performance categories: Quality, Promoting Interoperability, Improvement Activities, and Cost?
- Hospital Value-Based Purchasing
- Merit-based Incentive Payment System (MIPS) (Correct answer)
- HEDIS reporting
- Hospital Readmissions Reduction Program
Correct answer: Merit-based Incentive Payment System (MIPS)
MIPS is the CMS quality payment program for eligible clinicians in Medicare Part B, scoring performance across Quality, Promoting Interoperability, Improvement Activities, and Cost to adjust Medicare payments.
A covered entity experiences a ransomware attack that encrypts ePHI.
Under HIPAA Breach Notification Rule, what is the initial presumption regarding this incident?