HAC Regulatory Reporting & Data Governance 3 — Questions and Answers
Question 1: The Office of the National Coordinator (ONC) information blocking rule prohibits practices that interfere with access, exchange, or use of electronic health information (EHI). Which entity is NOT subject to this rule?
- Health IT developers of certified products
- Hospitals and clinician practices (actors)
- Health information networks and exchanges
- Pharmaceutical manufacturers without EHR products (Correct answer)
Correct answer: Pharmaceutical manufacturers without EHR products
The ONC information blocking rule applies to health IT developers, HIEs/HINs, and healthcare providers—not to pharmaceutical manufacturers that don't develop certified health IT.
Question 2: In a healthcare data warehouse, which design pattern best supports regulatory reporting by preserving historical snapshots of slowly changing dimensions?
- Star schema with Type 1 SCD (overwrite)
- Snowflake schema with no versioning
- Star schema with Type 2 SCD (add new row) (Correct answer)
- Flat file exports refreshed nightly
Correct answer: Star schema with Type 2 SCD (add new row)
Type 2 SCD adds a new row with effective dates when a dimension changes, preserving history needed for point-in-time regulatory reporting.
Question 3: CMS's Conditions of Participation (CoPs) for hospitals require medical records to be retained for a minimum of how many years from the date of discharge for adults?
- 3 years
- 5 years (Correct answer)
- 7 years
- 10 years
Correct answer: 5 years
CMS CoPs require hospitals to retain medical records for at least 5 years from the date of discharge, though state laws may require longer retention.
Question 4: A healthcare analytics team is building a dashboard to monitor hospital-acquired infection (HAI) rates for NHSN reporting. Which data quality dimension is most critical to validate first?
- Data timeliness
- Data completeness
- Data accuracy (Correct answer)
- Data accessibility
Correct answer: Data accuracy
Accuracy is paramount for HAI reporting because incorrectly coded infections directly affect public performance scores and regulatory compliance.
Question 5: Under the HITECH Act's Breach Notification Rule, covered entities must notify affected individuals of a PHI breach within:
- 30 days of discovery
- 60 days of discovery (Correct answer)
- 90 days of discovery
- 180 days of discovery
Correct answer: 60 days of discovery
The HIPAA Breach Notification Rule, strengthened by HITECH, requires individual notification without unreasonable delay and within 60 calendar days of discovery.
Question 6: Which metric is specifically required for ACO participation under the Medicare Shared Savings Program (MSSP)?
- Average length of stay per DRG
- Consumer Assessment of Healthcare Providers and Systems (CAHPS) survey scores (Correct answer)
- Medication error rate per 1,000 doses
- Door-to-balloon time for STEMI patients
Correct answer: Consumer Assessment of Healthcare Providers and Systems (CAHPS) survey scores
MSSP ACOs must report CAHPS survey results as part of their quality measure requirements for shared savings eligibility.
Question 7: A data governance policy assigns 'data ownership' to a specific executive role. What is the primary accountability of this data owner?
- Writing SQL queries for regulatory reports
- Authorizing access rights and accountable for data quality within their domain (Correct answer)
- Maintaining the physical database servers
- Conducting annual HIPAA Security Risk Analyses
Correct answer: Authorizing access rights and accountable for data quality within their domain
Data owners are accountable for the quality, integrity, and appropriate use of data in their business domain, including approving access.
The Office of the National Coordinator (ONC) information blocking rule prohibits practices that interfere with access, exchange, or use of electronic health information (EHI).
Which entity is NOT subject to this rule?