CPHQ Regulatory and Accreditation 3 — Questions and Answers
Question 1: An organization discovers a vendor's software breach exposed 600 patient records. Under HIPAA's Breach Notification Rule, notification to affected individuals must occur within:
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
- 180 days of discovery
Correct answer: 60 days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach.
Question 2: Which Joint Commission chapter specifically addresses the organization's obligation to manage risks associated with the physical environment?
- Human Resources (HR)
- Environment of Care (EC) (Correct answer)
- Life Safety (LS)
- Emergency Management (EM)
Correct answer: Environment of Care (EC)
The Environment of Care chapter requires organizations to manage safety, security, hazardous materials, fire safety, medical equipment, and utilities.
Question 3: CMS requires hospitals to perform a medical screening examination (MSE) for any individual who presents to the emergency department. This requirement derives from:
- HIPAA Security Rule
- EMTALA (Correct answer)
- Stark Law
- Anti-Kickback Statute
Correct answer: EMTALA
EMTALA (Emergency Medical Treatment and Labor Act) mandates that hospitals provide a medical screening exam and stabilizing treatment regardless of ability to pay.
Question 4: During a tracer activity, a Joint Commission surveyor follows a patient's care experience through the organization. The PRIMARY purpose of this methodology is to:
- Review only medical staff credentials
- Evaluate systems and processes across multiple departments as experienced by the patient (Correct answer)
- Audit billing and coding accuracy
- Inspect physical plant conditions
Correct answer: Evaluate systems and processes across multiple departments as experienced by the patient
The tracer methodology evaluates how well an organization's systems work together by following an individual patient's care journey.
Question 5: A hospital's quality professional is reviewing the organization's compliance with the CMS Hospital Inpatient Quality Reporting (IQR) Program. This program primarily impacts the hospital by:
- Determining accreditation status
- Affecting Medicare payment updates for failure to report (Correct answer)
- Setting state licensure requirements
- Establishing HIPAA compliance benchmarks
Correct answer: Affecting Medicare payment updates for failure to report
Hospitals that fail to report required quality measures under IQR face a reduction in their annual Medicare payment update.
Question 6: Which term describes the process by which an accreditation organization is itself evaluated to ensure its standards meet or exceed federal requirements?
- Deemed status approval
- Validation surveying
- Deeming authority recognition (Correct answer)
- Comparative benchmarking
Correct answer: Deeming authority recognition
Deeming authority recognition (also called deemed status approval) is the CMS process of approving accreditation organizations whose standards are equivalent to or exceed federal Conditions of Participation.
Question 7: The Occupational Safety and Health Administration (OSHA) Bloodborne Pathogens Standard requires healthcare employers to:
- Conduct annual HIPAA audits
- Provide hepatitis B vaccination at no cost to at-risk employees (Correct answer)
- Submit sentinel event reports to CMS
- Obtain Joint Commission accreditation
Correct answer: Provide hepatitis B vaccination at no cost to at-risk employees
OSHA's Bloodborne Pathogens Standard (29 CFR 1910.1030) requires employers to offer hepatitis B vaccination to all at-risk employees at no cost.
An organization discovers a vendor's software breach exposed 600 patient records.
Under HIPAA's Breach Notification Rule, notification to affected individuals must occur within: