EHR Regulatory Compliance & Standards 2 — Questions and Answers
Question 1: Under the HITECH Act, which entity type became directly liable for HIPAA compliance for the first time?
- Covered entities
- Business associates (Correct answer)
- State health departments
- Health information exchanges
Correct answer: Business associates
HITECH (2009) extended direct HIPAA liability to business associates, who were previously only bound through contracts with covered entities.
Question 2: Which CMS program requires eligible professionals to report quality measures through an EHR to avoid a payment adjustment?
- Meaningful Use Stage 1
- MACRA/MIPS (Correct answer)
- ICD-10 transition program
- HIPAA Security Rule
Correct answer: MACRA/MIPS
MACRA established MIPS, which requires clinicians to report quality, cost, and improvement activity data—often through certified EHRs—to avoid negative Medicare payment adjustments.
Question 3: A hospital shares de-identified patient data with a research university. Under HIPAA, which standard must the data meet to be considered truly de-identified?
- Removal of only name and SSN
- Expert determination or Safe Harbor method (Correct answer)
- Encryption of all data fields
- IRB approval alone
Correct answer: Expert determination or Safe Harbor method
HIPAA recognizes two de-identification methods: the Expert Determination method and the Safe Harbor method, which requires removal of 18 specific identifiers.
Question 4: Which federal regulation mandates that EHR systems support electronic prescribing of controlled substances (EPCS)?
- HIPAA Privacy Rule
- DEA 21 CFR Part 1311 (Correct answer)
- HITECH Act Section 3004
- ONC 2015 Edition Certification
Correct answer: DEA 21 CFR Part 1311
The DEA's 21 CFR Part 1311 (2010) established the federal framework permitting and regulating electronic prescribing of controlled substances.
Question 5: What is the maximum penalty per violation category per year under HIPAA's tiered civil monetary penalty structure?
- $10,000
- $50,000
- $1,500,000 (Correct answer)
- $5,000,000
Correct answer: $1,500,000
HIPAA's tiered penalty structure caps annual penalties at $1,500,000 per violation category, regardless of the number of individual violations in that category.
Question 6: Which standard governs the electronic exchange of clinical documents, including discharge summaries and progress notes, in a structured format?
- HL7 v2.x
- HL7 CDA (Clinical Document Architecture) (Correct answer)
- X12 EDI 837
- DICOM
Correct answer: HL7 CDA (Clinical Document Architecture)
HL7 Clinical Document Architecture (CDA) is the XML-based standard for structuring and exchanging clinical documents such as discharge summaries.
Question 7: Under the 21st Century Cures Act's information blocking rules, which actor is NOT subject to information blocking prohibitions?
- Health IT developers of certified EHRs
- Health information networks
- Individual clinicians not using certified EHRs (Correct answer)
- Hospitals participating in Medicare
Correct answer: Individual clinicians not using certified EHRs
The information blocking rule applies to health IT developers, HIEs/HINs, and healthcare providers—individual clinicians using non-certified systems are not enumerated actors under the rule.
Under the HITECH Act, which entity type became directly liable for HIPAA compliance for the first time?