← All CMAS Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CMAS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. A medical office discovers that an unlocked computer terminal was left unattended in a patient care area for 30 minutes. What is the PRIMARY risk this poses?

    Answer: Unauthorized access to protected health information

    An unattended, unlocked terminal in a patient area creates the risk of unauthorized individuals viewing or accessing PHI, violating HIPAA Security Rule requirements.

  2. Which risk mitigation strategy BEST addresses the threat of ransomware attacks on a medical practice's electronic health records?

    Answer: Regular encrypted offsite data backups combined with staff phishing training

    Combining regular encrypted offsite backups with phishing awareness training addresses both recovery capability and the most common ransomware entry point.

  3. A patient slips and falls in the waiting room. Which document should be completed IMMEDIATELY after ensuring patient safety?

    Answer: An incident/occurrence report

    An incident or occurrence report must be completed immediately to document the event, preserve facts for risk management, and support potential liability defense.

  4. Under the doctrine of respondeat superior, a medical practice is MOST likely to be held liable for:

    Answer: Negligent acts of employees committed within the scope of employment

    Respondeat superior holds employers vicariously liable for employees' negligent acts performed within the scope of their employment duties.

  5. Which element is NOT required to prove medical negligence in a malpractice claim?

    Answer: Proof of intentional harm by the provider

    Medical negligence requires duty, breach, causation, and damages — intentional harm is not required; negligence involves failure to meet the standard of care, not intent.

  6. A practice manager wants to reduce the risk of fraudulent billing. Which internal control is MOST effective?

    Answer: Segregation of duties between billing and payment posting staff

    Segregating billing and payment posting duties prevents any single employee from both creating and concealing fraudulent transactions.

  7. What is the purpose of a healthcare organization's risk register?

    Answer: To document identified risks, their likelihood, impact, and mitigation strategies

    A risk register is a centralized tool that catalogs identified risks along with their probability, potential impact, and the controls or actions in place to mitigate them.