CBCS Electronic Health Records 1 — Questions and Answers
Question 1: Which federal law mandated the adoption of electronic health records by eligible healthcare professionals?
- HIPAA
- HITECH Act (Correct answer)
- ACA
- ARRA only
Correct answer: HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act mandated EHR adoption and incentivized meaningful use.
The HITECH Act, enacted as part of the American Recovery and Reinvestment Act of 2009, established programs to incentivize the adoption and meaningful use of certified EHR technology. It created the Medicare and Medicaid EHR Incentive Programs (later renamed the Promoting Interoperability Programs) and also strengthened HIPAA privacy and security enforcement.
Question 2: What does 'meaningful use' of an EHR require?
- Using an EHR system at least once per week
- Using certified EHR technology in ways that improve quality, safety, and efficiency (Correct answer)
- Using EHRs only for billing and coding purposes
- Adopting an EHR approved by the state government
Correct answer: Using certified EHR technology in ways that improve quality, safety, and efficiency
Meaningful use requires healthcare providers to use certified EHR technology in specific, measurable ways to improve patient care.
Meaningful use (now called Promoting Interoperability) required eligible professionals and hospitals to use certified EHR technology in ways that are meaningful to the patient care process. This included recording patient demographics, maintaining active medication lists, recording smoking status, generating patient lists by condition, and exchanging health information electronically. Meeting these criteria was required to receive EHR incentive payments.
Question 3: Under HIPAA, which of the following is a covered entity?
- A marketing firm that analyzes patient data for a hospital
- A health plan that pays for medical services (Correct answer)
- A software company that builds EHR systems
- An employer who sponsors a health plan
Correct answer: A health plan that pays for medical services
Health plans are covered entities under HIPAA, along with healthcare providers and healthcare clearinghouses.
Under HIPAA, covered entities are: (1) health plans (including health insurance companies, HMOs, company health plans, and Medicare/Medicaid), (2) healthcare clearinghouses (entities that process nonstandard health information into standard formats), and (3) healthcare providers who transmit health information electronically. Business associates (companies that work with covered entities and handle PHI) must also comply with HIPAA but through Business Associate Agreements.
Question 4: What is interoperability in the context of electronic health records?
- The ability of an EHR system to prevent data breaches
- The ability of different EHR systems to exchange and use health information (Correct answer)
- The process of converting paper records to electronic format
- The ability to perform billing functions within an EHR
Correct answer: The ability of different EHR systems to exchange and use health information
Interoperability refers to the ability of different EHR systems to communicate, exchange, and use health information seamlessly.
Interoperability in health information technology means that different EHR systems and health IT systems can connect, exchange data, and use that data without special effort from the user. True interoperability enables a patient's health information to follow them across care settings (hospital, specialist, pharmacy) regardless of which EHR system each provider uses. The 21st Century Cures Act and HL7 FHIR standards are driving improved interoperability.
Question 5: Which HIPAA standard governs the electronic transmission of healthcare claims?
- 837 transaction standard (Correct answer)
- 835 transaction standard
- 270/271 transaction standard
- 834 transaction standard
Correct answer: 837 transaction standard
The HIPAA 837 transaction standard governs the electronic submission of healthcare claims (837P for professional, 837I for institutional).
HIPAA mandates standard transaction formats for electronic data interchange (EDI) in healthcare. The 837P (professional) and 837I (institutional) transactions are the standard electronic formats for submitting healthcare claims. The 835 is used for electronic remittance advice (ERAs/payment), 270/271 for eligibility verification, 276/277 for claim status inquiry, and 834 for benefits enrollment.
Question 6: What is a key difference between an Electronic Medical Record (EMR) and an Electronic Health Record (EHR)?
- EMRs are legally required; EHRs are optional
- EHRs are designed to share information across organizations; EMRs are practice-specific (Correct answer)
- EMRs contain more detailed information than EHRs
- EHRs are used only for billing; EMRs are used for clinical care
Correct answer: EHRs are designed to share information across organizations; EMRs are practice-specific
EHRs are designed to share patient information across multiple healthcare organizations, while EMRs are typically limited to a single practice.
An Electronic Medical Record (EMR) is a digital version of a patient chart used within a single practice or organization. An Electronic Health Record (EHR) is a more comprehensive system designed to be shared across multiple healthcare organizations, specialists, hospitals, and other care settings. EHRs support care coordination, data portability, and population health management in ways that practice-limited EMRs do not.
Question 7: Which security safeguard under HIPAA requires healthcare facilities to limit access to systems containing PHI based on job role?
- Encryption
- Role-based access control (Correct answer)
- Two-factor authentication
- Audit control
Correct answer: Role-based access control
Role-based access control (RBAC) restricts access to PHI based on a user's job function, ensuring minimum necessary access.
HIPAA's Security Rule requires covered entities to implement technical safeguards to protect electronic PHI (ePHI). Role-based access control (RBAC) is a method of restricting system access so that users can only access the minimum information necessary to perform their job functions. This aligns with HIPAA's minimum necessary standard and helps prevent unauthorized disclosure of ePHI by limiting exposure based on role or job title.
Question 8: What is the purpose of an audit trail in an EHR system?
- To automatically correct coding errors
- To track who accessed or modified a patient record and when (Correct answer)
- To generate billing reports for payers
- To back up patient data to a remote server
Correct answer: To track who accessed or modified a patient record and when
An audit trail records all accesses, modifications, and transactions within an EHR to support security and compliance monitoring.
An audit trail (also called an audit log) in an EHR system automatically records every instance of access to patient records — who logged in, what records were viewed, what changes were made, and when each action occurred. This is a required HIPAA administrative safeguard that enables organizations to detect unauthorized access, investigate potential breaches, and demonstrate compliance. Regular review of audit logs is part of a comprehensive HIPAA compliance program.
Which federal law mandated the adoption of electronic health records by eligible healthcare professionals?