HAC Regulatory Reporting & Data Governance 2 — Questions and Answers
Question 1: Under the CMS Promoting Interoperability Program, which standard is required for certified EHR technology to support patient data access via APIs?
- HL7 FHIR R4 (Correct answer)
- HL7 v2.5.1
- X12 EDI 837
- DICOM 3.0
Correct answer: HL7 FHIR R4
CMS mandates HL7 FHIR R4 for patient-facing API access under the Promoting Interoperability Program.
Question 2: A hospital's data governance committee discovers that the same patient metric is defined differently across three departments. Which governance artifact should be created to resolve this?
- A master data management policy
- A business glossary entry with agreed-upon definition (Correct answer)
- An audit trail log
- A data retention schedule
Correct answer: A business glossary entry with agreed-upon definition
A business glossary establishes authoritative, organization-wide definitions to eliminate metric inconsistencies.
Question 3: Which regulation specifically governs the privacy and security of substance use disorder patient records in the US?
- HIPAA Privacy Rule
- 42 CFR Part 2 (Correct answer)
- 21st Century Cures Act
- HITECH Act
Correct answer: 42 CFR Part 2
42 CFR Part 2 imposes stricter confidentiality protections on substance use disorder treatment records than HIPAA.
Question 4: In healthcare data governance, what is the primary role of a data steward?
- Approving capital expenditures for IT infrastructure
- Managing day-to-day data quality and policy compliance within a domain (Correct answer)
- Performing external regulatory audits
- Setting organizational strategy for data monetization
Correct answer: Managing day-to-day data quality and policy compliance within a domain
Data stewards are responsible for maintaining data quality, definitions, and adherence to governance policies within their assigned domain.
Question 5: When submitting the CMS Hospital Inpatient Quality Reporting (IQR) measures, what is the consequence of missing the annual deadline?
- A criminal referral to the OIG
- A 2-percentage-point reduction in the annual market basket update (Correct answer)
- Immediate decertification from Medicare
- A mandatory corrective action plan with CMS
Correct answer: A 2-percentage-point reduction in the annual market basket update
Hospitals that fail to meet IQR submission requirements receive a 2-percentage-point reduction in their annual payment update.
Question 6: A data lineage map in healthcare analytics is primarily used to:
- Track the physical location of servers storing patient data
- Document the origin, movement, and transformation of data from source to report (Correct answer)
- Schedule routine database maintenance windows
- Assign role-based access control permissions
Correct answer: Document the origin, movement, and transformation of data from source to report
Data lineage maps trace how data moves and changes from its source systems through transformations to final analytical outputs.
Question 7: Which of the following is an example of a 'minimum necessary' standard violation under the HIPAA Privacy Rule?
- A physician accessing only their own patients' records for treatment
- A billing clerk downloading the entire patient database to process one claim (Correct answer)
- A covered entity sharing a complete medical record with another treating provider
- An HIE transmitting a continuity of care document upon patient request
Correct answer: A billing clerk downloading the entire patient database to process one claim
Accessing more PHI than needed for the specific task—such as downloading an entire database to process one claim—violates the minimum necessary standard.
Under the CMS Promoting Interoperability Program, which standard is required for certified EHR technology to support patient data access via APIs?