EHR Regulatory Compliance & Standards 3 — Questions and Answers
Question 1: Which organization is responsible for certifying EHR technology under the ONC Health IT Certification Program?
- CMS
- Accredited Testing Laboratories (ATLs) and ONC-ACBs (Correct answer)
- The Joint Commission
- NIST alone
Correct answer: Accredited Testing Laboratories (ATLs) and ONC-ACBs
ONC-Authorized Certification Bodies (ONC-ACBs) working with ONC-Authorized Testing Laboratories (ATLs) perform EHR certification under the ONC program.
Question 2: A breach affecting 600 patients must be reported to HHS and patients within how many days under HIPAA?
- 30 days
- 45 days
- 60 days
- Within 60 days of discovery (Correct answer)
Correct answer: Within 60 days of discovery
HIPAA requires covered entities to notify affected individuals and HHS within 60 days of discovering a breach affecting 500 or more individuals, or fewer.
Question 3: The Minimum Necessary Standard under HIPAA requires covered entities to:
- Encrypt all PHI transmissions
- Limit PHI access and disclosure to the least amount needed for the intended purpose (Correct answer)
- Obtain written consent before every disclosure
- Train all staff on Privacy Rule annually
Correct answer: Limit PHI access and disclosure to the least amount needed for the intended purpose
The Minimum Necessary Standard requires that access to, use of, and disclosures of PHI be limited to the minimum amount necessary to accomplish the intended purpose.
Question 4: Which terminology standard is required by ONC for recording problems/diagnoses in a certified EHR?
- SNOMED CT
- ICD-10-CM (Correct answer)
- LOINC
- RxNorm
Correct answer: ICD-10-CM
ONC requires ICD-10-CM for recording patient diagnoses and problems in certified EHR technology for billing and clinical documentation purposes.
Question 5: Under HIPAA, a covered entity may share PHI with a public health authority without patient authorization for which purpose?
- Marketing campaigns
- Fundraising activities
- Disease surveillance and reporting (Correct answer)
- Employer wellness programs
Correct answer: Disease surveillance and reporting
HIPAA's public health activities exception permits disclosure of PHI to public health authorities for disease surveillance, reporting, and prevention without patient authorization.
Question 6: What is the primary purpose of a HIPAA Risk Analysis?
- To identify all employees who access EHR systems
- To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- To audit all third-party vendor contracts
- To create the organization's disaster recovery plan
Correct answer: To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
A HIPAA Risk Analysis identifies and assesses potential threats and vulnerabilities to ePHI to determine appropriate safeguards, as required by the Security Rule.
Question 7: Which of the following is a required implementation specification (not addressable) under the HIPAA Security Rule?
- Automatic logoff
- Encryption and decryption
- Audit controls
- Unique user identification (Correct answer)
Correct answer: Unique user identification
Unique user identification is a required implementation specification under the HIPAA Security Rule's Access Control standard, meaning it must be implemented.
Which organization is responsible for certifying EHR technology under the ONC Health IT Certification Program?