CMAS Risk Assessment & Mitigation 2 — Questions and Answers
Question 1: A medical office discovers that an unlocked computer terminal was left unattended in a patient care area for 30 minutes. What is the PRIMARY risk this poses?
- Financial loss to the practice
- Unauthorized access to protected health information (Correct answer)
- Equipment damage or theft
- Violation of OSHA standards
Correct answer: Unauthorized access to protected health information
An unattended, unlocked terminal in a patient area creates the risk of unauthorized individuals viewing or accessing PHI, violating HIPAA Security Rule requirements.
Question 2: Which risk mitigation strategy BEST addresses the threat of ransomware attacks on a medical practice's electronic health records?
- Installing antivirus software only
- Regular encrypted offsite data backups combined with staff phishing training (Correct answer)
- Disabling internet access for all workstations
- Purchasing cybersecurity insurance alone
Correct answer: Regular encrypted offsite data backups combined with staff phishing training
Combining regular encrypted offsite backups with phishing awareness training addresses both recovery capability and the most common ransomware entry point.
Question 3: A patient slips and falls in the waiting room. Which document should be completed IMMEDIATELY after ensuring patient safety?
- A HIPAA breach notification form
- An incident/occurrence report (Correct answer)
- A Medicare Advantage claim form
- A OSHA 300 log entry
Correct answer: An incident/occurrence report
An incident or occurrence report must be completed immediately to document the event, preserve facts for risk management, and support potential liability defense.
Question 4: Under the doctrine of respondeat superior, a medical practice is MOST likely to be held liable for:
- Acts of independent contractors performing off-site services
- Negligent acts of employees committed within the scope of employment (Correct answer)
- Criminal acts committed by staff on personal time
- Errors made by medical staff at a separate unaffiliated facility
Correct answer: Negligent acts of employees committed within the scope of employment
Respondeat superior holds employers vicariously liable for employees' negligent acts performed within the scope of their employment duties.
Question 5: Which element is NOT required to prove medical negligence in a malpractice claim?
- Duty of care owed to the patient
- Proof of intentional harm by the provider (Correct answer)
- Breach of the standard of care
- Causation linking breach to patient injury
Correct answer: Proof of intentional harm by the provider
Medical negligence requires duty, breach, causation, and damages — intentional harm is not required; negligence involves failure to meet the standard of care, not intent.
Question 6: A practice manager wants to reduce the risk of fraudulent billing. Which internal control is MOST effective?
- Having the same employee enter charges and post payments
- Segregation of duties between billing and payment posting staff (Correct answer)
- Allowing physicians to approve their own coding
- Delaying accounts receivable reconciliation to monthly cycles
Correct answer: Segregation of duties between billing and payment posting staff
Segregating billing and payment posting duties prevents any single employee from both creating and concealing fraudulent transactions.
Question 7: What is the purpose of a healthcare organization's risk register?
- To record patient complaints for quality improvement only
- To document identified risks, their likelihood, impact, and mitigation strategies (Correct answer)
- To track employee disciplinary actions
- To maintain a log of all insurance claim denials
Correct answer: To document identified risks, their likelihood, impact, and mitigation strategies
A risk register is a centralized tool that catalogs identified risks along with their probability, potential impact, and the controls or actions in place to mitigate them.
A medical office discovers that an unlocked computer terminal was left unattended in a patient care area for 30 minutes.
What is the PRIMARY risk this poses?