CEHRS Practice Test – Electronic Health Records,
Health Information Management, Documentation,
Privacy and Security
1. A provider realizes they entered a diagnosis on the wrong patient’s electronic chart. Which
of the following is the correct procedure for correcting this error?
A. Delete the entry and restart the record.
B. Flag the entry as ‘erroneous’ and create an addendum with the correct information.
C. Use the strike-through function and add a correction note.
D. Contact the IT department to purge the data from the server.
Correct Answer: B
Explanation: In an EHR, original entries should never be deleted to maintain the audit trail
and legal integrity of the record. The correct process involves flagging or ‘soft-deleting’ the
error and appending an addendum that clarifies the mistake. This ensures that anyone
viewing the record understands the sequence of events and corrections, avoiding the trap
of thinking digital records are wiped like simple text files.
2. A patient requests a copy of their medical records via the patient portal. According to
HIPAA, what is the maximum timeframe for the facility to provide these records?
A. 15 days
B. 45 days
,C. 30 days
D. 60 days
Correct Answer: C
Explanation: HIPAA’s Privacy Rule generally requires covered entities to provide access to
PHI within 30 calendar days of the request. While some states have stricter laws (e.g., 15
days), the federal standard remains 30 days with a possible one-time 30-day extension. A
common mistake is confusing the federal 30-day limit with various state-specific
requirements or insurance reimbursement timelines.
3. Which of the following describes the ‘Minimum Necessary’ standard under HIPAA?
A. Providing only the information requested by the patient.
B. Restricting all data access to only one department in the hospital.
C. Ensuring only doctors can see a patient’s full medical history.
D. Limiting PHI access to the smallest amount of data needed to accomplish a specific task.
Correct Answer: D
Explanation: The Minimum Necessary standard requires covered entities to take
reasonable steps to limit the use or disclosure of PHI to the minimum amount necessary to
accomplish the intended purpose. This applies to internal access by employees and
external disclosures to third parties like insurance companies. It does not apply to
disclosures to healthcare providers for treatment purposes, which is a frequent point of
confusion on exams.
,4. A CEHRS is auditing an EHR and notices ‘cloned’ notes where a provider copied and pasted
the exact same physical exam for five different patients. Why is this a major compliance risk?
A. It saves too much time and reduces billable hours.
B. EHR systems do not support the copy-paste function for security reasons.
C. It suggests the records do not accurately reflect the specific care provided to each
individual.
D. It causes the patient portal to malfunction and display incorrect data.
Correct Answer: C
Explanation: Documentation ‘cloning’ or ‘copy-paste’ can lead to medical errors and
fraudulent billing because it may not represent the actual service provided during the
current encounter. Payers and auditors view this practice as a lack of documentation
integrity, as it suggests the provider did not perform a unique assessment. The trap here is
thinking that because the EHR allows the action, it is clinically and legally appropriate.
5. A patient calls the office to complain that their laboratory results were sent to their
employer without consent. Under which circumstance is this disclosure permitted under
HIPAA?
A. The employer pays for the patient’s health insurance.
B. The results are needed for a routine performance review.
C. The patient’s supervisor is listed as an emergency contact.
D. The results are related to a work-related injury or illness (Workers’ Compensation).
, Correct Answer: D
Explanation: Disclosures for Workers’ Compensation purposes are a specific exception to
the HIPAA requirement for individual authorization. Healthcare providers may disclose
PHI to the extent necessary to comply with laws relating to workers’ compensation or
similar programs. Students often mistakenly believe that an employer has a right to any
medical data if they pay the insurance premiums, which is incorrect.
6. A clinical decision support (CDS) tool in the EHR alerts a provider about a potential drug-
drug interaction. What is the primary purpose of this feature?
A. To increase the speed of the checkout process.
B. To improve patient safety and reduce medication errors.
C. To replace the provider’s clinical judgment with automated decisions.
D. To track the provider’s productivity for performance reviews.
Correct Answer: B
Explanation: CDS tools are designed to provide clinicians with person-specific, filtered
information at appropriate times to enhance health care. Drug-drug interaction alerts help
prevent adverse events by notifying the provider of risks they might otherwise overlook. A
common trap is viewing these alerts solely as administrative burdens rather than critical
safety interventions.
Health Information Management, Documentation,
Privacy and Security
1. A provider realizes they entered a diagnosis on the wrong patient’s electronic chart. Which
of the following is the correct procedure for correcting this error?
A. Delete the entry and restart the record.
B. Flag the entry as ‘erroneous’ and create an addendum with the correct information.
C. Use the strike-through function and add a correction note.
D. Contact the IT department to purge the data from the server.
Correct Answer: B
Explanation: In an EHR, original entries should never be deleted to maintain the audit trail
and legal integrity of the record. The correct process involves flagging or ‘soft-deleting’ the
error and appending an addendum that clarifies the mistake. This ensures that anyone
viewing the record understands the sequence of events and corrections, avoiding the trap
of thinking digital records are wiped like simple text files.
2. A patient requests a copy of their medical records via the patient portal. According to
HIPAA, what is the maximum timeframe for the facility to provide these records?
A. 15 days
B. 45 days
,C. 30 days
D. 60 days
Correct Answer: C
Explanation: HIPAA’s Privacy Rule generally requires covered entities to provide access to
PHI within 30 calendar days of the request. While some states have stricter laws (e.g., 15
days), the federal standard remains 30 days with a possible one-time 30-day extension. A
common mistake is confusing the federal 30-day limit with various state-specific
requirements or insurance reimbursement timelines.
3. Which of the following describes the ‘Minimum Necessary’ standard under HIPAA?
A. Providing only the information requested by the patient.
B. Restricting all data access to only one department in the hospital.
C. Ensuring only doctors can see a patient’s full medical history.
D. Limiting PHI access to the smallest amount of data needed to accomplish a specific task.
Correct Answer: D
Explanation: The Minimum Necessary standard requires covered entities to take
reasonable steps to limit the use or disclosure of PHI to the minimum amount necessary to
accomplish the intended purpose. This applies to internal access by employees and
external disclosures to third parties like insurance companies. It does not apply to
disclosures to healthcare providers for treatment purposes, which is a frequent point of
confusion on exams.
,4. A CEHRS is auditing an EHR and notices ‘cloned’ notes where a provider copied and pasted
the exact same physical exam for five different patients. Why is this a major compliance risk?
A. It saves too much time and reduces billable hours.
B. EHR systems do not support the copy-paste function for security reasons.
C. It suggests the records do not accurately reflect the specific care provided to each
individual.
D. It causes the patient portal to malfunction and display incorrect data.
Correct Answer: C
Explanation: Documentation ‘cloning’ or ‘copy-paste’ can lead to medical errors and
fraudulent billing because it may not represent the actual service provided during the
current encounter. Payers and auditors view this practice as a lack of documentation
integrity, as it suggests the provider did not perform a unique assessment. The trap here is
thinking that because the EHR allows the action, it is clinically and legally appropriate.
5. A patient calls the office to complain that their laboratory results were sent to their
employer without consent. Under which circumstance is this disclosure permitted under
HIPAA?
A. The employer pays for the patient’s health insurance.
B. The results are needed for a routine performance review.
C. The patient’s supervisor is listed as an emergency contact.
D. The results are related to a work-related injury or illness (Workers’ Compensation).
, Correct Answer: D
Explanation: Disclosures for Workers’ Compensation purposes are a specific exception to
the HIPAA requirement for individual authorization. Healthcare providers may disclose
PHI to the extent necessary to comply with laws relating to workers’ compensation or
similar programs. Students often mistakenly believe that an employer has a right to any
medical data if they pay the insurance premiums, which is incorrect.
6. A clinical decision support (CDS) tool in the EHR alerts a provider about a potential drug-
drug interaction. What is the primary purpose of this feature?
A. To increase the speed of the checkout process.
B. To improve patient safety and reduce medication errors.
C. To replace the provider’s clinical judgment with automated decisions.
D. To track the provider’s productivity for performance reviews.
Correct Answer: B
Explanation: CDS tools are designed to provide clinicians with person-specific, filtered
information at appropriate times to enhance health care. Drug-drug interaction alerts help
prevent adverse events by notifying the provider of risks they might otherwise overlook. A
common trap is viewing these alerts solely as administrative burdens rather than critical
safety interventions.