CMAA Electronic Health Records and Health Information Technology 2 — Questions and Answers
Question 1: Which type of access control ensures healthcare workers can only view EHR information relevant to their specific job duties?
- Universal access policy
- Role-based access control (RBAC) (Correct answer)
- Open network access
- Shared login protocols
Correct answer: Role-based access control (RBAC)
Role-based access control (RBAC) restricts EHR access based on a user's defined role, ensuring staff can only view information necessary for their job responsibilities.
Question 2: What is an 'audit trail' in an EHR system?
- A list of all medications prescribed to a patient
- A chronological log of all user activities and changes made within the system (Correct answer)
- A summary report of patient diagnoses by provider
- A billing report submitted to insurance companies
Correct answer: A chronological log of all user activities and changes made within the system
An audit trail is a chronological, tamper-evident record of user logins, data access, and all changes made within an EHR, used to monitor compliance and detect unauthorized access.
Question 3: Which of the following best describes a PHI breach in an EHR context?
- A scheduled system maintenance outage
- Unauthorized access, use, or disclosure of patient health information (Correct answer)
- A patient requesting and receiving copies of their own records
- A provider reviewing records of their own assigned patients
Correct answer: Unauthorized access, use, or disclosure of patient health information
A PHI breach occurs when protected health information is accessed, used, or disclosed in a manner not permitted under HIPAA, potentially compromising patient privacy.
Question 4: What should a medical administrative assistant do first upon suspecting an EHR security breach?
- Attempt to fix the issue independently before notifying anyone
- Monitor the situation and wait to see if it resolves on its own
- Immediately report it to the appropriate supervisor or IT security team (Correct answer)
- Delete the affected files to prevent further exposure
Correct answer: Immediately report it to the appropriate supervisor or IT security team
Suspected security breaches must be reported immediately to a supervisor or IT security team so that the incident can be properly investigated and contained per HIPAA breach notification rules.
Question 5: What is 'two-factor authentication' (2FA) in EHR security?
- Having two different supervisors approve each login session
- Using two separate forms of identification to verify a user's identity before granting access (Correct answer)
- Requiring a user to log in twice to confirm their identity
- Mandating that both a physician and nurse approve access to patient records
Correct answer: Using two separate forms of identification to verify a user's identity before granting access
Two-factor authentication requires users to provide two distinct types of credentials (e.g., a password plus a code sent to a mobile device), significantly reducing unauthorized access risk.
Question 6: Which of the following is considered best practice for EHR password management?
- Using the same password across all healthcare systems for convenience
- Sharing login credentials with a trusted colleague when unavailable
- Creating strong, unique passwords and updating them on a regular schedule (Correct answer)
- Writing passwords on a note kept near the workstation for quick reference
Correct answer: Creating strong, unique passwords and updating them on a regular schedule
Best practice requires strong, unique passwords that are changed regularly; sharing credentials or writing them down violates HIPAA security standards and increases breach risk.
Question 7: What is the primary purpose of data backup procedures in an EHR system?
- To archive records that are no longer needed into permanent storage
- To ensure patient data can be recovered in the event of system failure or data loss (Correct answer)
- To provide insurance companies with duplicate copies of patient information
- To convert electronic records back into paper format for long-term storage
Correct answer: To ensure patient data can be recovered in the event of system failure or data loss
Regular data backups ensure that patient information can be restored if the primary system experiences a failure, cyberattack, or accidental data loss, supporting continuity of care.
Which type of access control ensures healthcare workers can only view EHR information relevant to their specific job duties?