CHL Documentation and Record Keeping 3 — Questions and Answers
Question 1: A patient requests access to their medical records. Under HIPAA, how many days does a covered entity typically have to provide access?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
HIPAA requires covered entities to provide patients access to their records within 30 days of the request, with one 30-day extension allowed if the entity notifies the patient.
Question 2: Which element is LEAST likely to be found in a legally defensible clinical note?
- Date and time of entry
- Author's signature or authentication
- Personal opinions about the patient's lifestyle (Correct answer)
- Objective findings and clinical observations
Correct answer: Personal opinions about the patient's lifestyle
Personal opinions about a patient's lifestyle are inappropriate in clinical documentation; legally defensible records contain objective, factual, and clinically relevant information.
Question 3: The Joint Commission requires that medical records be completed within how many days following patient discharge?
- 15 days
- 30 days (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days
The Joint Commission standard requires that medical records be completed, including all signatures and discharge summaries, within 30 days of patient discharge.
Question 4: What is the primary purpose of a discharge summary in inpatient documentation?
- To authorize insurance billing
- To provide a concise overview of the hospital stay for continuity of care (Correct answer)
- To document nursing shift handoffs
- To record patient satisfaction scores
Correct answer: To provide a concise overview of the hospital stay for continuity of care
The discharge summary synthesizes the hospital course, diagnoses, treatments, and follow-up plan to ensure continuity of care as the patient transitions to the next care setting.
Question 5: Under the 'minimum necessary' standard in HIPAA, covered entities should:
- Share all patient information with any requesting provider
- Disclose only the amount of PHI needed to accomplish the intended purpose (Correct answer)
- Provide complete records for all quality improvement requests
- Obtain written consent before sharing records internally
Correct answer: Disclose only the amount of PHI needed to accomplish the intended purpose
The HIPAA minimum necessary standard requires that disclosures of protected health information be limited to the least amount needed to fulfill the specific request or purpose.
Question 6: Which type of audit specifically examines whether documentation supports the codes billed for services?
- Clinical audit
- Coding compliance audit (Correct answer)
- Peer review audit
- Sentinel event review
Correct answer: Coding compliance audit
A coding compliance audit cross-references clinical documentation with submitted billing codes to ensure accuracy and reduce fraud and abuse risk.
Question 7: When a healthcare organization transitions from paper to electronic health records (EHR), which of the following is the most critical governance concern?
- Selecting the vendor with the lowest licensing cost
- Ensuring data integrity, security, and access control policies are established (Correct answer)
- Converting all paper records to electronic format immediately
- Eliminating all paper forms on the go-live date
Correct answer: Ensuring data integrity, security, and access control policies are established
Data integrity, security, and access controls are the most critical governance concerns during an EHR transition to protect patient information and maintain regulatory compliance.
A patient requests access to their medical records.
Under HIPAA, how many days does a covered entity typically have to provide access?