← All Epic Skills Assessment Flashcard Decks

Patient Data Management Flashcards

30 cards from real Epic Skills Assessment practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Patient Data Management flashcards as text
  1. In an EHR, what is an 'Enterprise Master Patient Index' (EMPI)?

    Answer: A system that assigns and maintains a unique patient identifier across all facilities in a health system to prevent duplicate patient records

    An EMPI is the authoritative patient identity management system. It assigns a unique medical record number (MRN) to each patient across all sites, using matching algorithms to identify duplicates and maintain a single, accurate patient identity.

  2. What are the required HIPAA 'minimum necessary' principles for accessing patient information?

    Answer: Access only the minimum amount of PHI (protected health information) necessary to accomplish the intended purpose

    HIPAA's minimum necessary standard requires healthcare workers to access only the PHI required for their specific job function. This limits exposure of sensitive data and reduces the risk of unauthorized disclosure.

  3. What is a 'duplicate medical record,' and what risks does it create?

    Answer: Two or more records existing for the same patient, creating risk of incomplete medical history, medication errors, duplicate testing, and incorrect treatment

    Duplicate records split a patient's clinical history across two or more MRNs. Clinicians may not see the complete picture, leading to repeated tests, missed allergies, incorrect medication history, and treatment decisions based on incomplete information.

  4. What is the difference between 'demographic data' and 'clinical data' in a patient record?

    Answer: Demographic data identifies the patient (name, DOB, address, insurance); clinical data documents the patient's health (diagnoses, medications, labs, notes)

    Demographic data (administrative data) includes identifying and contact information used for registration, insurance, and communication. Clinical data encompasses all health-related information: diagnoses, medications, allergies, lab results, imaging, and notes.

  5. In EHR patient data management, what is 'data integrity'?

    Answer: The accuracy, completeness, and consistency of patient data throughout its lifecycle in the health record

    Data integrity ensures that clinical data is accurate, complete, consistent, and not corrupted. Poor data integrity (incorrect allergies, wrong dates, erroneous values) directly endangers patient safety and compromises clinical decision-making.

  6. What does an allergy/adverse reaction record in the EHR need to include for it to be clinically useful?

    Answer: The substance, the type of reaction (allergy vs. intolerance), the specific reaction documented (rash, anaphylaxis, nausea), and the severity

    A complete allergy record includes: substance name, reaction type (allergy vs. intolerance vs. side effect), specific reaction description (anaphylaxis, rash, GI upset), and severity. This information determines clinical decision support alerting thresholds.

  7. What is a 'patient portal,' and what types of data can patients typically access through it?

    Answer: A secure online platform where patients can access their health records, test results, medication lists, visit summaries, and communicate with their care team

    Patient portals (e.g., MyChart) give patients access to their health information: lab results, visit summaries, medication lists, immunization records, and after-visit summaries. They also enable secure messaging, appointment requests, and prescription refill requests.

  8. What is the purpose of 'data validation' in EHR patient data entry?

    Answer: To ensure that entered data is within acceptable ranges, in the correct format, and logically consistent before it is saved to the record

    Data validation rules prevent obvious errors: a heart rate of 5,000 bpm, a birth date in the future, or a medication dose of 0. Range checks, format validation, and required field enforcement maintain data quality at the point of entry.

  9. What is a 'data breach' in the healthcare context, and what are the required response actions under HIPAA?

    Answer: Unauthorized access or disclosure of PHI; requires notification to affected individuals (60 days), HHS, and possibly media for large breaches (>500)

    A HIPAA breach is impermissible use/disclosure of PHI that compromises its security. The Breach Notification Rule requires: individual notification within 60 days, HHS notification (annually for small breaches, immediate for >500 individuals), and media notice for breaches >500 in a state.

  10. What is the purpose of a 'longitudinal patient record'?

    Answer: To maintain a comprehensive, continuous health history across all encounters, providers, and time — supporting coordinated care and informed clinical decisions

    A longitudinal record accumulates the patient's complete health history over time and across care settings. It allows any provider to understand the full context of a patient's health: prior diagnoses, treatments, responses, and evolving conditions.

  11. In EHR data management, what is 'chart correction' and when is it appropriate?

    Answer: The process of amending or correcting documentation errors while maintaining the original entry visible — addenda are preferred; deletions are generally not allowed

    Chart corrections follow strict rules: original documentation must remain visible (no deleting). Corrections are made by addendum (additional note) or amendment, clearly dated and identified as a correction. Altering records to hide errors is illegal.

  12. What is 'data provenance' in a health record?

    Answer: The documented origin and history of data: who entered it, when, from what source, and whether it has been modified

    Data provenance tracks the lineage of each data element: who created it, when, from what source (manual entry vs. device import vs. external feed), and any subsequent changes. This is critical for assessing data trustworthiness.

  13. What does 'consent management' in an EHR involve?

    Answer: Documenting and enforcing patient consents and authorizations including general treatment consent, research participation, data sharing, and procedure-specific informed consents

    EHR consent management tracks: general treatment consent, HIPAA privacy acknowledgment, specific procedure informed consents, research participation consents, and data sharing authorizations. Some consents restrict which providers can view certain sensitive data.

  14. What is the purpose of a 'Master Facility Table' (MFT) in a health system's EHR?

    Answer: A reference table defining all locations, departments, rooms, and beds in the enterprise that the EHR uses for patient placement, reporting, and workflows

    The MFT is a foundational EHR configuration table that defines all organizational units: facilities, departments, rooms, beds, and clinics. It drives patient placement, worklists, reporting, ADT transactions, and facility-specific rules.

  15. What is 'real-time eligibility verification' in patient registration, and why is it performed?

    Answer: Automated checking of the patient's current insurance coverage status and benefits during registration to ensure accurate billing and identify patient financial responsibility

    Real-time eligibility (RTE) queries the insurance carrier's database at the time of scheduling or registration to confirm active coverage, verify benefits, identify copays/deductibles, and flag coverage gaps before the visit.

  16. In health information management, what is the 'legal health record' (LHR)?

    Answer: The subset of the complete health record that is released in response to legal requests, defined by the organization's HIM policies

    The LHR is the organization-defined subset of the health record that constitutes the official business record of patient care — what is released for legal requests, court orders, and subpoenas. Organizations define LHR content in policies.

  17. What is 'semantic interoperability' in health data exchange?

    Answer: The ability of systems to exchange data AND have the receiving system correctly interpret and use the meaning of that data

    Semantic interoperability goes beyond technical transmission: the receiving system understands what the data means and can use it clinically. This requires shared clinical terminologies (SNOMED CT, LOINC, RxNorm) so 'diabetes mellitus type 2' means the same thing in all systems.

  18. What does 'de-identification' of patient data mean under HIPAA?

    Answer: Removing or anonymizing the 18 specified PHI identifiers so the data cannot be linked to a specific individual, allowing use without patient authorization

    HIPAA de-identification removes 18 specific identifiers (name, DOB, zip code, MRN, etc.) so the data is no longer considered PHI. De-identified data can be used for research, analytics, and public health purposes without patient authorization.

  19. What is the purpose of 'data governance' in a healthcare organization?

    Answer: To establish policies, standards, and accountability for data quality, security, integrity, and proper use across the organization

    Data governance establishes the organizational framework for managing health data as a strategic asset: policies for data quality, standards for terminology and coding, stewardship roles, privacy/security rules, and processes for data lifecycle management.

  20. In an EHR, what is 'role-based access control' (RBAC)?

    Answer: A security model where users are granted EHR access permissions based on their job role, ensuring they can only access data and functions they need

    RBAC assigns access rights based on organizational roles (physician, nurse, receptionist, coder). A scheduler can access scheduling and demographics but not clinical notes; a nurse can document vitals but not prescribe medications. This enforces minimum necessary access.