CMM Healthcare Information Systems 3 — Questions and Answers
Question 1: A clinical decision support (CDS) system alerts a physician when a prescribed medication may cause a harmful interaction with a current medication. This is an example of:
- Drug formulary management
- Drug-drug interaction checking (Correct answer)
- Pharmacy benefit management
- Medication reconciliation
Correct answer: Drug-drug interaction checking
Drug-drug interaction checking is a key CDS function that identifies potentially harmful combinations of medications at the point of prescribing.
Question 2: Under the HIPAA Security Rule, which category addresses policies and procedures to manage the selection and implementation of security measures?
- Physical safeguards
- Technical safeguards
- Administrative safeguards (Correct answer)
- Organizational requirements
Correct answer: Administrative safeguards
Administrative safeguards under HIPAA include policies, procedures, and training programs that manage workforce conduct and security program implementation.
Question 3: Which data standard is used to represent clinical concepts such as diagnoses, procedures, and observations in a machine-readable format?
- HL7 v2
- DICOM
- SNOMED CT (Correct answer)
- X12 270
Correct answer: SNOMED CT
SNOMED CT (Systematized Nomenclature of Medicine–Clinical Terms) is a comprehensive clinical terminology used to encode clinical concepts for interoperability.
Question 4: A practice manager notices that patient appointment data was inadvertently disclosed to a third-party vendor without a signed Business Associate Agreement (BAA). Under HIPAA, this constitutes a:
- Minor compliance gap requiring internal review only
- Breach requiring notification under the Breach Notification Rule (Correct answer)
- Technical violation with no reporting obligation
- Standard vendor transaction under safe harbor
Correct answer: Breach requiring notification under the Breach Notification Rule
Disclosing PHI to a vendor without a BAA is an unauthorized disclosure that triggers HIPAA's Breach Notification Rule obligations.
Question 5: Which of the following is a key advantage of a cloud-based EHR system compared to an on-premise system?
- Greater direct control over server hardware
- Reduced need for internet connectivity
- Lower upfront capital investment (Correct answer)
- Elimination of all HIPAA obligations
Correct answer: Lower upfront capital investment
Cloud-based EHRs typically use a subscription model (SaaS) which reduces large upfront infrastructure costs compared to on-premise deployments.
Question 6: In healthcare IT, 'data governance' refers to:
- Government regulation of EHR vendors
- Policies and standards ensuring data quality, consistency, and accountability (Correct answer)
- The technical process of backing up databases
- The patient's right to request data corrections
Correct answer: Policies and standards ensuring data quality, consistency, and accountability
Data governance encompasses the policies, roles, and standards an organization uses to manage the availability, integrity, and security of its data assets.
Question 7: Which metric is commonly used to evaluate the effectiveness of a practice management system's billing module?
- Mean time between failures (MTBF)
- Days in accounts receivable (A/R days) (Correct answer)
- Network uptime percentage
- User satisfaction score
Correct answer: Days in accounts receivable (A/R days)
Days in A/R measures the average number of days it takes to collect payment after a service is rendered, directly reflecting billing system effectiveness.
A clinical decision support (CDS) system alerts a physician when a prescribed medication may cause a harmful interaction with a current medication.
This is an example of: