Electronic Health Records and Health Information Technology Flashcards
7 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Electronic Health Records and Health Information Technology flashcards as text
Which type of access control ensures healthcare workers can only view EHR information relevant to their specific job duties?
Answer: Role-based access control (RBAC)
Role-based access control (RBAC) restricts EHR access based on a user's defined role, ensuring staff can only view information necessary for their job responsibilities.
What is an 'audit trail' in an EHR system?
Answer: A chronological log of all user activities and changes made within the system
An audit trail is a chronological, tamper-evident record of user logins, data access, and all changes made within an EHR, used to monitor compliance and detect unauthorized access.
Which of the following best describes a PHI breach in an EHR context?
Answer: Unauthorized access, use, or disclosure of patient health information
A PHI breach occurs when protected health information is accessed, used, or disclosed in a manner not permitted under HIPAA, potentially compromising patient privacy.
What should a medical administrative assistant do first upon suspecting an EHR security breach?
Answer: Immediately report it to the appropriate supervisor or IT security team
Suspected security breaches must be reported immediately to a supervisor or IT security team so that the incident can be properly investigated and contained per HIPAA breach notification rules.
What is 'two-factor authentication' (2FA) in EHR security?
Answer: Using two separate forms of identification to verify a user's identity before granting access
Two-factor authentication requires users to provide two distinct types of credentials (e.g., a password plus a code sent to a mobile device), significantly reducing unauthorized access risk.
Which of the following is considered best practice for EHR password management?
Answer: Creating strong, unique passwords and updating them on a regular schedule
Best practice requires strong, unique passwords that are changed regularly; sharing credentials or writing them down violates HIPAA security standards and increases breach risk.
What is the primary purpose of data backup procedures in an EHR system?
Answer: To ensure patient data can be recovered in the event of system failure or data loss
Regular data backups ensure that patient information can be restored if the primary system experiences a failure, cyberattack, or accidental data loss, supporting continuity of care.