RMA Electronic Health Records 3 — Questions and Answers
Question 1: Under HIPAA, how long must a patient's medical records generally be retained (per most state and federal guidance)?
- At least 6 years (Correct answer)
- 30 days
- 1 year
- Indefinitely with no exceptions
Correct answer: At least 6 years
HIPAA requires records be retained at least 6 years, though many states require longer.
Question 2: What is 'Meaningful Use' (now Promoting Interoperability) designed to encourage?
- Effective use of certified EHR technology to improve care (Correct answer)
- Reducing the number of patients seen
- Eliminating paper for billing only
- Faster internet speeds in clinics
Correct answer: Effective use of certified EHR technology to improve care
The program incentivizes providers to use certified EHRs in ways that improve quality and outcomes.
Question 3: A patient portal primarily allows patients to do which of the following?
- View results, request refills, and message their provider (Correct answer)
- Edit physician progress notes
- Access other patients' records
- Change billing codes
Correct answer: View results, request refills, and message their provider
Patient portals give patients secure access to their own information and communication tools.
Question 4: What should a medical assistant do immediately if they suspect a data breach of EHR information?
- Report it to the privacy officer or supervisor (Correct answer)
- Delete the affected records
- Ignore it if no harm is obvious
- Email the patients themselves first
Correct answer: Report it to the privacy officer or supervisor
Suspected breaches must be promptly reported per facility policy and HIPAA breach rules.
Question 5: Which term describes a brief electronic summary of a patient's health used during transitions of care?
- Continuity of Care Document (CCD) (Correct answer)
- Superbill
- Encounter form
- Remittance advice
Correct answer: Continuity of Care Document (CCD)
A CCD is a standardized summary supporting care continuity when patients move between providers.
Question 6: Why is automatic logoff an important EHR security feature?
- It prevents unauthorized access from unattended workstations (Correct answer)
- It speeds up data entry
- It increases screen brightness
- It backs up records
Correct answer: It prevents unauthorized access from unattended workstations
Automatic logoff protects records when a user leaves a workstation unattended.
Question 7: What is the role of a unique user login and password in an EHR?
- To attribute actions to specific individuals for accountability (Correct answer)
- To share access among the whole team
- To speed up the system
- To bypass audit logging
Correct answer: To attribute actions to specific individuals for accountability
Unique credentials ensure each action is traceable to one identifiable user.
Under HIPAA, how long must a patient's medical records generally be retained (per most state and federal guidance)?