MHA Information Technology 2 — Questions and Answers
Question 1: Which federal law specifically governs the privacy and security of individually identifiable health information maintained by covered entities?
- HITECH Act
- HIPAA (Correct answer)
- Affordable Care Act
- MACRA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes the Privacy Rule and Security Rule governing protected health information (PHI).
Question 2: A hospital CIO wants to ensure patient data remains available during a ransomware attack. Which strategy provides the BEST protection?
- Encrypting all data at rest
- Maintaining air-gapped offline backups (Correct answer)
- Installing the latest antivirus software
- Implementing multi-factor authentication
Correct answer: Maintaining air-gapped offline backups
Air-gapped offline backups cannot be encrypted by ransomware since they are physically disconnected from the network.
Question 3: Which data exchange standard is the modern replacement for HL7 v2 and enables RESTful APIs for health data interoperability?
- DICOM
- FHIR (Correct answer)
- CCD
- X12 EDI
Correct answer: FHIR
HL7 FHIR (Fast Healthcare Interoperability Resources) uses RESTful APIs and JSON/XML formats for modern health data exchange.
Question 4: Under the HIPAA Security Rule, which of the following is classified as a physical safeguard?
- Audit controls
- Facility access controls (Correct answer)
- Transmission security
- Integrity controls
Correct answer: Facility access controls
Physical safeguards under HIPAA include facility access controls, workstation use policies, and device and media controls.
Question 5: A health system is selecting a cloud vendor to store PHI. Which contractual requirement is MANDATORY under HIPAA?
- Service Level Agreement
- Business Associate Agreement (Correct answer)
- Non-Disclosure Agreement
- Data Use Agreement
Correct answer: Business Associate Agreement
A Business Associate Agreement (BAA) is legally required before a covered entity can share PHI with any vendor or business associate.
Question 6: Which clinical decision support feature is MOST likely to cause alert fatigue in physicians?
- Drug-allergy checking
- High-frequency low-severity drug interaction alerts (Correct answer)
- Sepsis early warning scores
- Critical lab value notifications
Correct answer: High-frequency low-severity drug interaction alerts
High-frequency low-severity alerts cause physicians to habitually override warnings, reducing the effectiveness of truly critical alerts.
Question 7: The 21st Century Cures Act information blocking rule prohibits which actor from unreasonably restricting access to electronic health information?
- Patients only
- Health IT developers, HIEs, and healthcare providers (Correct answer)
- Insurance companies only
- Federal agencies only
Correct answer: Health IT developers, HIEs, and healthcare providers
The information blocking rule applies to health IT developers, health information exchanges (HIEs), and healthcare providers as the three defined actor categories.
Which federal law specifically governs the privacy and security of individually identifiable health information maintained by covered entities?