Epic Skills Assessment Patient Data Management 1 — Questions and Answers
Question 1: In an EHR, what is an 'Enterprise Master Patient Index' (EMPI)?
- A system that assigns and maintains a unique patient identifier across all facilities in a health system to prevent duplicate patient records (Correct answer)
- A list of the hospital's most critical patients requiring enterprise-level care
- The master billing record for all patients in the system
- A centralized medication database for all patients
Correct answer: A system that assigns and maintains a unique patient identifier across all facilities in a health system to prevent duplicate patient records
An EMPI is the authoritative patient identity management system. It assigns a unique medical record number (MRN) to each patient across all sites, using matching algorithms to identify duplicates and maintain a single, accurate patient identity.
Question 2: What are the required HIPAA 'minimum necessary' principles for accessing patient information?
- Access only the minimum amount of PHI (protected health information) necessary to accomplish the intended purpose (Correct answer)
- Access all patient information as long as the user is a healthcare worker
- Access patient information only for billing purposes
- Restrict all PHI access to physicians only
Correct answer: Access only the minimum amount of PHI (protected health information) necessary to accomplish the intended purpose
HIPAA's minimum necessary standard requires healthcare workers to access only the PHI required for their specific job function. This limits exposure of sensitive data and reduces the risk of unauthorized disclosure.
Question 3: What is a 'duplicate medical record,' and what risks does it create?
- Two or more records existing for the same patient, creating risk of incomplete medical history, medication errors, duplicate testing, and incorrect treatment (Correct answer)
- Two copies of the same record filed in different locations for backup purposes
- A record containing duplicate medication orders
- Two patient records with identical demographics but different conditions
Correct answer: Two or more records existing for the same patient, creating risk of incomplete medical history, medication errors, duplicate testing, and incorrect treatment
Duplicate records split a patient's clinical history across two or more MRNs. Clinicians may not see the complete picture, leading to repeated tests, missed allergies, incorrect medication history, and treatment decisions based on incomplete information.
Question 4: What is the difference between 'demographic data' and 'clinical data' in a patient record?
- Demographic data identifies the patient (name, DOB, address, insurance); clinical data documents the patient's health (diagnoses, medications, labs, notes) (Correct answer)
- Demographic data includes lab results; clinical data includes billing information
- Demographic data is stored in the EHR; clinical data is on paper
- They are interchangeable terms for patient information
Correct answer: Demographic data identifies the patient (name, DOB, address, insurance); clinical data documents the patient's health (diagnoses, medications, labs, notes)
Demographic data (administrative data) includes identifying and contact information used for registration, insurance, and communication. Clinical data encompasses all health-related information: diagnoses, medications, allergies, lab results, imaging, and notes.
Question 5: In EHR patient data management, what is 'data integrity'?
- The accuracy, completeness, and consistency of patient data throughout its lifecycle in the health record (Correct answer)
- The speed at which data is entered into the EHR
- The security encryption protecting patient data from hackers
- The number of fields completed in the patient record
Correct answer: The accuracy, completeness, and consistency of patient data throughout its lifecycle in the health record
Data integrity ensures that clinical data is accurate, complete, consistent, and not corrupted. Poor data integrity (incorrect allergies, wrong dates, erroneous values) directly endangers patient safety and compromises clinical decision-making.
Question 6: What does an allergy/adverse reaction record in the EHR need to include for it to be clinically useful?
- The substance, the type of reaction (allergy vs. intolerance), the specific reaction documented (rash, anaphylaxis, nausea), and the severity (Correct answer)
- Just the name of the allergen
- The medication lot number and dispensing pharmacy
- Only confirmed allergies with positive skin test results
Correct answer: The substance, the type of reaction (allergy vs. intolerance), the specific reaction documented (rash, anaphylaxis, nausea), and the severity
A complete allergy record includes: substance name, reaction type (allergy vs. intolerance vs. side effect), specific reaction description (anaphylaxis, rash, GI upset), and severity. This information determines clinical decision support alerting thresholds.
Question 7: What is a 'patient portal,' and what types of data can patients typically access through it?
- A secure online platform where patients can access their health records, test results, medication lists, visit summaries, and communicate with their care team (Correct answer)
- An internal staff portal for accessing patient records remotely
- A billing portal for patients to pay medical bills only
- A scheduling system for hospital procedures
Correct answer: A secure online platform where patients can access their health records, test results, medication lists, visit summaries, and communicate with their care team
Patient portals (e.g., MyChart) give patients access to their health information: lab results, visit summaries, medication lists, immunization records, and after-visit summaries. They also enable secure messaging, appointment requests, and prescription refill requests.
Question 8: What is the purpose of 'data validation' in EHR patient data entry?
- To ensure that entered data is within acceptable ranges, in the correct format, and logically consistent before it is saved to the record (Correct answer)
- To validate the user's identity before allowing data entry
- To confirm that data has been backed up to the server
- To verify that billing codes match clinical documentation
Correct answer: To ensure that entered data is within acceptable ranges, in the correct format, and logically consistent before it is saved to the record
Data validation rules prevent obvious errors: a heart rate of 5,000 bpm, a birth date in the future, or a medication dose of 0. Range checks, format validation, and required field enforcement maintain data quality at the point of entry.
Question 9: What is a 'data breach' in the healthcare context, and what are the required response actions under HIPAA?
- Unauthorized access or disclosure of PHI; requires notification to affected individuals (60 days), HHS, and possibly media for large breaches (>500) (Correct answer)
- Any time a patient requests their records; routine procedure
- Loss of paper records stored offsite; internal documentation only
- Shared login credentials; resolved by password reset without reporting
Correct answer: Unauthorized access or disclosure of PHI; requires notification to affected individuals (60 days), HHS, and possibly media for large breaches (>500)
A HIPAA breach is impermissible use/disclosure of PHI that compromises its security. The Breach Notification Rule requires: individual notification within 60 days, HHS notification (annually for small breaches, immediate for >500 individuals), and media notice for breaches >500 in a state.
Question 10: What is the purpose of a 'longitudinal patient record'?
- To maintain a comprehensive, continuous health history across all encounters, providers, and time — supporting coordinated care and informed clinical decisions (Correct answer)
- To record only the most recent 3 years of a patient's history
- To document a patient's condition at a single point in time only
- To store only surgical and procedural history
Correct answer: To maintain a comprehensive, continuous health history across all encounters, providers, and time — supporting coordinated care and informed clinical decisions
A longitudinal record accumulates the patient's complete health history over time and across care settings. It allows any provider to understand the full context of a patient's health: prior diagnoses, treatments, responses, and evolving conditions.
Question 11: In EHR data management, what is 'chart correction' and when is it appropriate?
- The process of amending or correcting documentation errors while maintaining the original entry visible — addenda are preferred; deletions are generally not allowed (Correct answer)
- Deleting incorrect information from the record to prevent confusion
- Changing a diagnosis code after billing to improve reimbursement
- Re-writing a patient note to improve its appearance for legal review
Correct answer: The process of amending or correcting documentation errors while maintaining the original entry visible — addenda are preferred; deletions are generally not allowed
Chart corrections follow strict rules: original documentation must remain visible (no deleting). Corrections are made by addendum (additional note) or amendment, clearly dated and identified as a correction. Altering records to hide errors is illegal.
Question 12: What is 'data provenance' in a health record?
- The documented origin and history of data: who entered it, when, from what source, and whether it has been modified (Correct answer)
- The physical location of data storage servers
- The financial source for purchasing the EHR system
- The regulatory authority that governs data standards
Correct answer: The documented origin and history of data: who entered it, when, from what source, and whether it has been modified
Data provenance tracks the lineage of each data element: who created it, when, from what source (manual entry vs. device import vs. external feed), and any subsequent changes. This is critical for assessing data trustworthiness.
Question 13: What does 'consent management' in an EHR involve?
- Documenting and enforcing patient consents and authorizations including general treatment consent, research participation, data sharing, and procedure-specific informed consents (Correct answer)
- Managing physician privileges and system access consents
- The insurance authorization process for procedures
- The legal consent for minors to be treated without parental approval
Correct answer: Documenting and enforcing patient consents and authorizations including general treatment consent, research participation, data sharing, and procedure-specific informed consents
EHR consent management tracks: general treatment consent, HIPAA privacy acknowledgment, specific procedure informed consents, research participation consents, and data sharing authorizations. Some consents restrict which providers can view certain sensitive data.
Question 14: What is the purpose of a 'Master Facility Table' (MFT) in a health system's EHR?
- A reference table defining all locations, departments, rooms, and beds in the enterprise that the EHR uses for patient placement, reporting, and workflows (Correct answer)
- A table listing all medical staff privileges by facility
- A financial table of facility charges and fees
- A table of emergency contacts for each facility
Correct answer: A reference table defining all locations, departments, rooms, and beds in the enterprise that the EHR uses for patient placement, reporting, and workflows
The MFT is a foundational EHR configuration table that defines all organizational units: facilities, departments, rooms, beds, and clinics. It drives patient placement, worklists, reporting, ADT transactions, and facility-specific rules.
Question 15: What is 'real-time eligibility verification' in patient registration, and why is it performed?
- Automated checking of the patient's current insurance coverage status and benefits during registration to ensure accurate billing and identify patient financial responsibility (Correct answer)
- Verifying a patient's identity with a government ID in real time
- Confirming a patient's medical history is up to date at registration
- Checking if the patient has outstanding balances in real time
Correct answer: Automated checking of the patient's current insurance coverage status and benefits during registration to ensure accurate billing and identify patient financial responsibility
Real-time eligibility (RTE) queries the insurance carrier's database at the time of scheduling or registration to confirm active coverage, verify benefits, identify copays/deductibles, and flag coverage gaps before the visit.
Question 16: In health information management, what is the 'legal health record' (LHR)?
- The subset of the complete health record that is released in response to legal requests, defined by the organization's HIM policies (Correct answer)
- Only the paper records kept before EHR implementation
- The complete EHR including all system logs and metadata
- Records required to be kept for legal disputes only
Correct answer: The subset of the complete health record that is released in response to legal requests, defined by the organization's HIM policies
The LHR is the organization-defined subset of the health record that constitutes the official business record of patient care — what is released for legal requests, court orders, and subpoenas. Organizations define LHR content in policies.
Question 17: What is 'semantic interoperability' in health data exchange?
- The ability of systems to exchange data AND have the receiving system correctly interpret and use the meaning of that data (Correct answer)
- The technical ability to transmit data between systems regardless of meaning
- The use of a common human language in clinical notes
- The standardization of user interfaces across EHR platforms
Correct answer: The ability of systems to exchange data AND have the receiving system correctly interpret and use the meaning of that data
Semantic interoperability goes beyond technical transmission: the receiving system understands what the data means and can use it clinically. This requires shared clinical terminologies (SNOMED CT, LOINC, RxNorm) so 'diabetes mellitus type 2' means the same thing in all systems.
Question 18: What does 'de-identification' of patient data mean under HIPAA?
- Removing or anonymizing the 18 specified PHI identifiers so the data cannot be linked to a specific individual, allowing use without patient authorization (Correct answer)
- Encoding patient data so only authorized users can decode it
- Assigning a pseudonym to replace the patient's name in research records
- Deleting all patient data after it is no longer needed
Correct answer: Removing or anonymizing the 18 specified PHI identifiers so the data cannot be linked to a specific individual, allowing use without patient authorization
HIPAA de-identification removes 18 specific identifiers (name, DOB, zip code, MRN, etc.) so the data is no longer considered PHI. De-identified data can be used for research, analytics, and public health purposes without patient authorization.
Question 19: What is the purpose of 'data governance' in a healthcare organization?
- To establish policies, standards, and accountability for data quality, security, integrity, and proper use across the organization (Correct answer)
- To govern which software vendors provide data services
- To manage patient data requests and release processes only
- To control access to financial data in the EHR
Correct answer: To establish policies, standards, and accountability for data quality, security, integrity, and proper use across the organization
Data governance establishes the organizational framework for managing health data as a strategic asset: policies for data quality, standards for terminology and coding, stewardship roles, privacy/security rules, and processes for data lifecycle management.
Question 20: In an EHR, what is 'role-based access control' (RBAC)?
- A security model where users are granted EHR access permissions based on their job role, ensuring they can only access data and functions they need (Correct answer)
- A control that allows patients to decide who can access their records
- An audit system that tracks access based on user roles
- A feature where supervisors can override any access restriction
Correct answer: A security model where users are granted EHR access permissions based on their job role, ensuring they can only access data and functions they need
RBAC assigns access rights based on organizational roles (physician, nurse, receptionist, coder). A scheduler can access scheduling and demographics but not clinical notes; a nurse can document vitals but not prescribe medications. This enforces minimum necessary access.
Question 21: What is a 'health information exchange' (HIE), and how does it benefit patient care?
- A network enabling secure sharing of patient health information across different healthcare organizations, reducing duplicate testing and improving care coordination (Correct answer)
- An exchange where hospitals trade staff for educational purposes
- A billing clearinghouse that processes insurance claims
- A pharmacy network that shares medication dispensing data
Correct answer: A network enabling secure sharing of patient health information across different healthcare organizations, reducing duplicate testing and improving care coordination
An HIE allows hospitals, clinics, labs, and pharmacies to electronically share patient information. When an ED physician can access records from another hospital, they avoid duplicate imaging, know the patient's medications and allergies, and make better-informed decisions.
Question 22: What does the term 'FHIR' (Fast Healthcare Interoperability Resources) describe?
- A modern HL7 standard for sharing healthcare information via web-based APIs, enabling real-time data exchange between applications (Correct answer)
- A fire safety standard for data center server rooms
- A financial reporting standard for healthcare organizations
- A clinical documentation standard for nursing notes
Correct answer: A modern HL7 standard for sharing healthcare information via web-based APIs, enabling real-time data exchange between applications
FHIR (HL7 FHIR) uses web technologies (REST APIs, JSON, XML) to enable real-time, granular health data exchange. Patient apps, population health tools, and clinical decision support tools increasingly use FHIR to access EHR data.
Question 23: What is a 'patient matching algorithm,' and why is accuracy critical?
- Software that identifies when multiple records belong to the same patient; errors cause either dangerous merges (wrong patient gets wrong record) or duplicates (missing history) (Correct answer)
- An algorithm that matches patients to clinical trials
- A formula for calculating patient acuity scores
- A scheduling tool matching patients to available providers
Correct answer: Software that identifies when multiple records belong to the same patient; errors cause either dangerous merges (wrong patient gets wrong record) or duplicates (missing history)
Patient matching uses demographic attributes (name, DOB, address, SSN) to determine if records represent the same individual. False merges (linking two different patients) can cause wrong-patient errors; false splits (not linking same patient) create duplicate records.
Question 24: In EHR data management, what is the difference between 'data archival' and 'data backup'?
- Archival moves inactive data to long-term storage for compliance while remaining accessible; backup creates copies of current data for disaster recovery (Correct answer)
- They are identical processes performed at different times
- Backup is permanent; archival is temporary storage
- Archival deletes old data; backup prevents all data from being deleted
Correct answer: Archival moves inactive data to long-term storage for compliance while remaining accessible; backup creates copies of current data for disaster recovery
Data backup creates restorable copies for disaster recovery (system failure, ransomware). Data archival moves inactive data (old records, closed encounters) to less expensive storage where it remains accessible for compliance and legal requirements.
Question 25: What is a 'transition of care document' (C-CDA) and when is it transmitted?
- A standardized, structured clinical document (HL7 C-CDA format) containing essential patient information transmitted when care transitions between settings or providers (Correct answer)
- A form signed by the patient when transitioning to a different insurance plan
- A progress note template used during patient transfers between hospital units
- A billing document generated when patients change providers
Correct answer: A standardized, structured clinical document (HL7 C-CDA format) containing essential patient information transmitted when care transitions between settings or providers
The Consolidated Clinical Document Architecture (C-CDA) is a structured XML document containing key patient data (problems, medications, allergies, results, notes). It is transmitted at transitions of care (discharge, referral, care summary) to support continuity.
Question 26: What does 'patient matching' at registration prevent?
- Registering a returning patient as a new patient (creating a duplicate) or linking one patient's registration to a different patient's existing record (wrong patient merge) (Correct answer)
- Scheduling conflicts when multiple patients share the same appointment time
- Insurance fraud by patients using false identities
- Duplicate billing charges for the same service
Correct answer: Registering a returning patient as a new patient (creating a duplicate) or linking one patient's registration to a different patient's existing record (wrong patient merge)
Accurate patient matching at registration is the first line of defense against duplicates and overlays. Staff must verify the patient against existing records using multiple identifiers (name, DOB, address, SSN) before creating a new MRN.
Question 27: What is the 'Release of Information' (ROI) process in health information management?
- The formal process of fulfilling authorized requests for copies of patient health records, following HIPAA authorization requirements and applicable state laws (Correct answer)
- The process of releasing new EHR software updates to end users
- The automatic sharing of patient data with any requesting provider
- The process of discarding outdated patient records
Correct answer: The formal process of fulfilling authorized requests for copies of patient health records, following HIPAA authorization requirements and applicable state laws
ROI involves verifying the requester's authorization, confirming the correct patient, identifying the applicable record, applying any applicable restrictions (sensitive data, minor records), and releasing records in the approved format within required timeframes.
Question 28: What are 'sensitivity flags' on patient records in an EHR?
- Restrictions on access to specific sensitive information (behavioral health, substance abuse, HIV status) beyond standard access controls, often per specific federal or state law (Correct answer)
- Flags indicating a patient poses a safety risk to staff
- Indicators that a record has not been reviewed recently and needs updating
- Tags marking patients with rare diagnoses for research inclusion
Correct answer: Restrictions on access to specific sensitive information (behavioral health, substance abuse, HIV status) beyond standard access controls, often per specific federal or state law
Sensitivity restrictions protect information governed by specific laws: 42 CFR Part 2 (substance abuse treatment), HIV/AIDS confidentiality laws, mental health records, and others require extra consent or legal authorization beyond general HIPAA for disclosure.
Question 29: In healthcare analytics, what is the difference between 'operational reporting' and 'clinical analytics'?
- Operational reporting tracks business metrics (patient volume, wait times, revenue); clinical analytics examines clinical outcomes, quality measures, and population health trends (Correct answer)
- They are the same type of analysis applied to different datasets
- Operational reporting is real-time; clinical analytics is always retrospective
- Clinical analytics is done by physicians; operational reporting by administrators
Correct answer: Operational reporting tracks business metrics (patient volume, wait times, revenue); clinical analytics examines clinical outcomes, quality measures, and population health trends
Operational (administrative) reporting focuses on efficiency and financial metrics: volumes, throughput, revenue cycle, staffing. Clinical analytics examines outcomes: readmission rates, mortality, quality measure performance, and population health trends to improve care.
Question 30: What is 'chain of custody' in health information management?
- Documentation of every person or system that handles a patient record, maintaining accountability and evidence integrity especially for legal and forensic purposes (Correct answer)
- The sequence of providers in a patient's care team
- The process of transferring records between hospital departments
- The approval chain for releasing records to external parties
Correct answer: Documentation of every person or system that handles a patient record, maintaining accountability and evidence integrity especially for legal and forensic purposes
Chain of custody documents each transfer of health record custody: who received it, when, for what purpose, and what was done with it. This is critical when records are used for litigation, insurance investigations, or regulatory audits.
In an EHR, what is an 'Enterprise Master Patient Index' (EMPI)?