EHR Regulatory Compliance & Standards 5 β Questions and Answers
Question 1: Which law established the Medicare and Medicaid EHR Incentive Programs (Meaningful Use) and appropriated funding for health IT adoption?
- HIPAA (1996)
- HITECH Act within ARRA (2009) (Correct answer)
- ACA (2010)
- 21st Century Cures Act (2016)
Correct answer: HITECH Act within ARRA (2009)
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act (ARRA) in 2009, established the EHR Incentive Programs.
Question 2: A patient requests an amendment to their medical record. Under HIPAA, the covered entity may deny the request if:
- The patient is no longer receiving care at the facility
- The information was not created by the covered entity (Correct answer)
- The amendment would exceed one page in length
- More than 60 days have passed since the original entry
Correct answer: The information was not created by the covered entity
A covered entity may deny an amendment request if it did not create the information, as the originating entity is better positioned to assess its accuracy.
Question 3: Under the HIPAA Security Rule, which category of safeguards includes workstation use policies and device and media controls?
- Administrative safeguards
- Physical safeguards (Correct answer)
- Technical safeguards
- Organizational safeguards
Correct answer: Physical safeguards
Physical safeguards under the HIPAA Security Rule include facility access controls, workstation use policies, and device and media controls.
Question 4: When a hospital's EHR is subpoenaed for records, the hospital should release PHI:
- Immediately upon receiving the subpoena
- Only after obtaining a qualified protective order or patient authorization (Correct answer)
- Only if the judge personally signs the order
- After notifying HHS within 24 hours
Correct answer: Only after obtaining a qualified protective order or patient authorization
HIPAA requires a satisfactory assurance (typically a qualified protective order or patient authorization) before releasing PHI in response to a subpoena not accompanied by a court order.
Question 5: Which interoperability standard, adopted by ONC for the Cures Act API requirements, enables third-party apps to securely access EHR data using OAuth 2.0?
- HL7 v2.x
- SMART on FHIR (Correct answer)
- DICOM Web
- IHE XDS.b
Correct answer: SMART on FHIR
SMART on FHIR (Substitutable Medical Applications, Reusable Technologies) uses OAuth 2.0 and OpenID Connect to enable secure, standardized app access to EHR data.
Question 6: State breach notification laws in relation to HIPAA are best described as:
- Preempted entirely by HIPAA in all cases
- Applicable only when they are more protective than HIPAA (Correct answer)
- Irrelevant once federal compliance is achieved
- Required to match HIPAA's 60-day notification window exactly
Correct answer: Applicable only when they are more protective than HIPAA
HIPAA establishes a federal floor, and state laws that provide greater privacy protections or shorter notification timeframes are not preempted and must also be followed.
Question 7: The Promoting Interoperability (PI) category in MIPS replaced which earlier program?
- PQRS
- Meaningful Use (EHR Incentive Program) (Correct answer)
- Value-Based Purchasing
- Physician Quality Reporting Initiative
Correct answer: Meaningful Use (EHR Incentive Program)
The Promoting Interoperability category in MIPS directly replaced the Meaningful Use EHR Incentive Program, retaining its focus on certified EHR use and health data exchange.
Which law established the Medicare and Medicaid EHR Incentive Programs (Meaningful Use) and appropriated funding for health IT adoption?