CHL Documentation and Record Keeping 5 — Questions and Answers
Question 1: Under the HITECH Act, which entities are directly liable for HIPAA compliance in addition to covered entities?
- State health departments
- Business associates (Correct answer)
- Healthcare clearinghouses only
- Accreditation organizations
Correct answer: Business associates
The HITECH Act extended direct HIPAA liability to business associates, meaning they are now independently accountable for compliance with applicable Security and Privacy Rule requirements.
Question 2: What is the primary purpose of the Health Information Management (HIM) department in a hospital?
- Managing IT infrastructure and servers
- Overseeing the collection, analysis, and protection of patient health information (Correct answer)
- Credentialing medical staff
- Coordinating patient discharge planning
Correct answer: Overseeing the collection, analysis, and protection of patient health information
The HIM department is responsible for managing the integrity, accuracy, accessibility, and security of patient health information throughout its lifecycle.
Question 3: A 'verbal order' for medication in a hospital setting must typically be:
- Recorded by the ordering physician only
- Documented by the receiving nurse and countersigned by the physician within a defined timeframe (Correct answer)
- Held in a separate verbal order log and never placed in the medical record
- Approved by pharmacy before being recorded
Correct answer: Documented by the receiving nurse and countersigned by the physician within a defined timeframe
Verbal orders must be documented immediately by the licensed professional receiving them and authenticated by the ordering physician within the organization's defined timeframe, typically 24–48 hours.
Question 4: Which of the following best defines 'health record integrity'?
- The physical security of paper charts
- The accuracy, completeness, and trustworthiness of health information over its entire lifecycle (Correct answer)
- The speed at which records are retrieved for clinical use
- The number of providers who have accessed a record
Correct answer: The accuracy, completeness, and trustworthiness of health information over its entire lifecycle
Health record integrity refers to maintaining the accuracy, completeness, consistency, and trustworthiness of health information from creation through destruction.
Question 5: When releasing records in response to a court subpoena, a healthcare organization should:
- Release all records immediately without review
- Consult legal counsel and follow established protocols for responding to legal process (Correct answer)
- Deny the request until a formal court order is obtained
- Release only records from the past 12 months
Correct answer: Consult legal counsel and follow established protocols for responding to legal process
Responding to a subpoena requires legal review to determine whether it is valid, whether patient authorization is needed, and what information must or should be disclosed.
Question 6: Which documentation principle is violated when a provider backdates an entry to make it appear the care was documented at the time it was delivered?
- Minimum necessary principle
- Timeliness principle
- Authenticity and accuracy principle (Correct answer)
- Chain of custody principle
Correct answer: Authenticity and accuracy principle
Backdating an entry violates the authenticity and accuracy principle of documentation because it falsely represents when the entry was made, which can constitute fraud.
Question 7: A healthcare leader reviewing compliance with CMS Conditions of Participation (CoPs) would focus on medical record standards that require documentation to be:
- Completed only by physicians
- Accurate, legible, complete, and authenticated by the responsible practitioner (Correct answer)
- Written exclusively in narrative format
- Stored off-site within 30 days of discharge
Correct answer: Accurate, legible, complete, and authenticated by the responsible practitioner
CMS Conditions of Participation require that medical records be accurate, legible, complete, and authenticated by the responsible practitioner to ensure quality care and accountability.
Under the HITECH Act, which entities are directly liable for HIPAA compliance in addition to covered entities?