โ† All CMAA Flashcard Decks

Electronic Health Records and Health Information Technology Flashcards

7 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Electronic Health Records and Health Information Technology flashcards as text
  1. Which type of access control ensures healthcare workers can only view EHR information relevant to their specific job duties?

    Answer: Role-based access control (RBAC)

    Role-based access control (RBAC) restricts EHR access based on a user's defined role, ensuring staff can only view information necessary for their job responsibilities.

  2. What is an 'audit trail' in an EHR system?

    Answer: A chronological log of all user activities and changes made within the system

    An audit trail is a chronological, tamper-evident record of user logins, data access, and all changes made within an EHR, used to monitor compliance and detect unauthorized access.

  3. Which of the following best describes a PHI breach in an EHR context?

    Answer: Unauthorized access, use, or disclosure of patient health information

    A PHI breach occurs when protected health information is accessed, used, or disclosed in a manner not permitted under HIPAA, potentially compromising patient privacy.

  4. What should a medical administrative assistant do first upon suspecting an EHR security breach?

    Answer: Immediately report it to the appropriate supervisor or IT security team

    Suspected security breaches must be reported immediately to a supervisor or IT security team so that the incident can be properly investigated and contained per HIPAA breach notification rules.

  5. What is 'two-factor authentication' (2FA) in EHR security?

    Answer: Using two separate forms of identification to verify a user's identity before granting access

    Two-factor authentication requires users to provide two distinct types of credentials (e.g., a password plus a code sent to a mobile device), significantly reducing unauthorized access risk.

  6. Which of the following is considered best practice for EHR password management?

    Answer: Creating strong, unique passwords and updating them on a regular schedule

    Best practice requires strong, unique passwords that are changed regularly; sharing credentials or writing them down violates HIPAA security standards and increases breach risk.

  7. What is the primary purpose of data backup procedures in an EHR system?

    Answer: To ensure patient data can be recovered in the event of system failure or data loss

    Regular data backups ensure that patient information can be restored if the primary system experiences a failure, cyberattack, or accidental data loss, supporting continuity of care.