18 Templates, Data Exchange & Telehealth Practice Questions & Answers
Every Templates, Data Exchange & Telehealth practice question from the CEHRS Electronic Health Records Specialist Practice Test, with the correct answer and a short explanation.
Start practice test →1. A clinic asks an EHR specialist to build a template for diabetes follow-up visits. What is the primary reason the template captures foot exam, eye exam referral, and blood pressure in discrete coded fields rather than in a free-text narrative box?
- A.Discrete fields can be counted and retrieved by the system for reporting and exchange✓ Answer
- B.Discrete fields carry more legal weight in a malpractice proceeding than narrative
- C.Discrete fields let the specialist complete the clinical assessment for the provider
- D.Discrete fields remove the need for the provider to review and sign the note
Structured (discrete) data is machine-readable, so it can be aggregated for quality measures, decision support, and interoperable exchange. Free-text narrative may be richer clinically but cannot be reliably computed on. Discrete capture changes nothing about legal weight, provider responsibility, or the requirement that the author review and sign the entry.
Source: NHA CEHRS Test Plan, Clinical Operations — clinical templates for data captureReport a problem with this question
2. Under the HIPAA Security Rule technical safeguards, how is encryption of electronic protected health information classified?
- A.Addressable, so it is assessed and implemented or documented otherwise✓ Answer
- B.Required, so it must be implemented on every system without any assessment
- C.Optional, so a covered entity may decline it without any documentation
- D.Required only for data at rest, and addressable for data in transit
Encryption appears as an addressable implementation specification under both access control and transmission security in 45 CFR 164.312. Addressable does not mean optional: the entity must assess whether the measure is reasonable and appropriate, implement it if so, or document why not and adopt an equivalent alternative safeguard.
Source: HIPAA Security Rule, 45 CFR 164.312 — addressable implementation specificationsReport a problem with this question
3. An emergency department receives an unresponsive patient with no family present and no records on file. Staff use the health information exchange to search outside organizations for that patient's history. Which type of exchange is this?
- A.Query-based exchange✓ Answer
- B.Organizational exchange
- C.Consumer-mediated exchange
- D.Directed exchange
Query-based exchange lets a provider search for and pull records on an unfamiliar patient, which is why it is the typical model for emergency and unplanned care. Directed exchange is a push from a known sender to a named receiver; consumer-mediated exchange puts the patient in control of moving the data; organizational is a level of interoperability, not an exchange architecture.
Source: ONC health information exchange models — directed, query-based, and consumer-mediated exchangeReport a problem with this question
4. A physician sends a referral note directly to a named cardiologist's secure address, and the message is encrypted and routed using certificates through a health information service provider. What is this an example of?
- A.Public health reporting to a state registry
- B.Directed exchange between a defined sender and receiver✓ Answer
- C.Consumer-mediated exchange controlled by the patient
- D.Query-based exchange initiated by the receiving specialist
Directed exchange is a push from a known sender to a known recipient, typically over encrypted, certificate-based secure messaging routed by a health information service provider, and it is the standard method for referrals, transitions of care, and lab result delivery. A query pulls records rather than pushing them, and consumer-mediated exchange requires the patient to move the data.
Source: ONC health information exchange models — directed exchange and secure messagingReport a problem with this question
5. An EHR specialist notices that a provider's templated progress notes repeatedly contain a complete review of systems that the provider did not perform, because the template pre-checks every finding as normal. What is the correct characterization of this practice?
- A.A template defect that only matters if the payer requests records
- B.A documentation integrity failure that misrepresents the encounter✓ Answer
- C.An efficiency feature that is acceptable if the provider signs the note
- D.A charting shortcut permitted when the patient has no complaints
A template must never auto-populate findings that were not actually obtained, because the record then describes an encounter that did not happen. Pre-checked normals and pull-forward macros are a recognized upcoding and false-claims risk regardless of signature, patient complaint, or whether records are ever requested.
Source: NHA CEHRS Test Plan, Clinical Operations — clinical template content and documentation integrityReport a problem with this question
6. Which set of purposes allows a practice to disclose protected health information to another provider without first obtaining the patient's written authorization?
- A.Employment screening, insurance underwriting, and litigation
- B.Marketing, fundraising, and research recruitment
- C.Treatment, payment, and health care operations✓ Answer
- D.Psychotherapy note review, research, and public advertising
The HIPAA Privacy Rule permits disclosure for treatment, payment, and health care operations without patient authorization, which is what makes continuity-of-care exchange possible. Marketing, most research uses, and psychotherapy notes generally require a valid authorization, and employment or underwriting disclosures are not treatment purposes.
Source: HIPAA Privacy Rule, 45 CFR 164.506 — uses and disclosures for treatment, payment, and health care operationsReport a problem with this question
7. A clinic wants to release a data set of patient records to an outside analytics group studying readmission patterns. Which handling of the data keeps the release outside the reach of HIPAA entirely?
- A.Encrypt the file and transmit it through a secure channel
- B.Send a limited data set governed by a data use agreement
- C.Restrict the file to the minimum necessary data elements
- D.De-identify the records by removing each identifier type✓ Answer
Health information that has been de-identified under the Privacy Rule is no longer protected health information, so HIPAA does not apply to it. A limited data set still contains identifiers and remains regulated under a data use agreement, and encryption or minimum necessary are protections applied to data that is still PHI.
Source: HIPAA Privacy Rule, 45 CFR 164.514 — de-identification of protected health informationReport a problem with this question
8. A practice contracts with a telehealth video platform, a cloud-hosted EHR, and an electronic fax service, all of which handle patient data. What must be in place with each of these vendors?
- A.A software licensing agreement listing the certified product version
- B.A notice of privacy practices posted on each vendor's public website
- C.A signed business associate agreement covering the handling of PHI✓ Answer
- D.A signed patient authorization naming each vendor by company name
Any vendor that creates, receives, maintains, or transmits protected health information on the practice's behalf is a business associate and must sign a business associate agreement obligating it to safeguard that information. Patient authorization is not what permits a vendor relationship, and a privacy notice or license agreement does not create the required safeguard obligations.
Source: HIPAA Privacy and Security Rules, 45 CFR 164 — business associate contractsReport a problem with this question
9. An EHR specialist discovers that a discharge summary was faxed to a wrong number belonging to an unrelated business. What is the appropriate action?
- A.Refax the summary to the correct number and close the matter there
- B.Delete the fax confirmation log so the record shows no transmission
- C.Call the recipient business and ask them to shred the pages received
- D.Report the incident to the privacy or security officer✓ Answer
A misdirected transmission is an impermissible disclosure that is presumed to be a breach unless a risk assessment shows a low probability of compromise, and only the privacy or security officer can make that determination. Informal retrieval, altering the transmission log, or simply resending leaves the disclosure unassessed and unreported.
Source: HIPAA Breach Notification Rule, 45 CFR 164.402 — presumption of breach and risk assessmentReport a problem with this question
10. During a scheduled video visit, the provider asks the EHR specialist what must appear in the encounter documentation that would not be needed for an in-person visit. What is the correct answer?
- A.The device manufacturer and the network bandwidth during the session
- B.The modality used and the locations of the patient and the provider✓ Answer
- C.The provider's license number and the date of the last credentialing review
- D.The patient's insurance card image and the copayment amount collected
A telehealth encounter must record that it was conducted by telehealth, the modality used, and where the patient and the practitioner each were, because the originating and distant sites determine coverage and licensure. Insurance images, device details, and credentialing data are handled elsewhere and are not encounter documentation elements unique to telehealth.
Source: NHA CEHRS Test Plan, Clinical Operations — telehealth and telemedicine workflowsReport a problem with this question
11. A dermatology practice has patients photograph a skin lesion and upload it through the portal for the physician to review the following day. Which telehealth modality is this?
- A.Remote patient monitoring
- B.Consumer-mediated record transfer
- C.Asynchronous store-and-forward✓ Answer
- D.Synchronous two-way audio and video
Store-and-forward telehealth captures images or data at one time and transmits them for review later, so the patient and provider are never connected at the same moment. Synchronous care requires a live connection, remote patient monitoring uses devices that transmit physiologic data, and consumer-mediated transfer describes the patient moving records between organizations.
Source: NHA CEHRS Test Plan, Clinical Operations — telehealth modalitiesReport a problem with this question
12. When a patient is at home and the treating physician is at the clinic during a video visit, how are the two sites correctly named?
- A.Both are distant sites because neither party is physically together
- B.The patient is at the distant site and the physician at the originating site
- C.The patient is at the originating site and the physician at the distant site✓ Answer
- D.Both are originating sites because two locations are connected
By convention the originating site is where the patient is located and the distant site is where the practitioner delivering the service is located. The terms are defined from the patient's position, which is why they do not change based on who initiated the call or how many locations are connected.
Source: NHA CEHRS Test Plan, Clinical Operations — originating and distant sites in telehealthReport a problem with this question
13. A patient asks to have her telehealth appointment conducted over a public livestreaming platform because it is easier for her to use. How should the practice respond?
- A.Allow it if the provider turns off the recording and comment features
- B.Allow it once the patient signs a waiver accepting the privacy risk
- C.Offer standard email instead, since a written exchange is lower risk
- D.Offer the practice's compliant platform instead✓ Answer
Public-facing platforms expose the encounter to an undefined audience and can never satisfy the Security Rule, so telehealth must run on a compliant, non-public platform covered by a business associate agreement. A patient waiver does not relieve the covered entity of its own safeguard obligations, and unencrypted standard email is likewise not a secure channel.
Source: HIPAA Security Rule, 45 CFR 164.312 — transmission security for telehealth technologiesReport a problem with this question
14. A hospital sends a patient's discharge information to the primary care office as a standardized clinical document so the next provider sees problems, medications, and allergies. What is the purpose of this summary-of-care document?
- A.To serve as the billing claim for the hospital admission
- B.To carry a common set of clinical data across a transition of care✓ Answer
- C.To replace the receiving practice's own legal medical record
- D.To satisfy the patient's right to an accounting of disclosures
A summary-of-care document packages an agreed core set of clinical data in a standard structure so the receiving system can file it into the right fields at a transition of care, which reduces the risk of unknown allergies or duplicated therapy. It supplements rather than replaces the receiving record, and it is neither a claim nor an accounting of disclosures.
Source: NHA CEHRS Test Plan, Clinical Operations — exchange of patient data for continuity of careReport a problem with this question
15. Two organizations exchange lab results successfully, but one system files potassium results under a locally invented code that the other cannot interpret. Which level of interoperability has failed?
- A.Foundational interoperability, which depends on secure connectivity
- B.Semantic interoperability, which depends on shared standard vocabularies✓ Answer
- C.Structural interoperability, which depends on message format and syntax
- D.Organizational interoperability, which depends on governance and trust
Semantic interoperability is the level at which both systems attach the same meaning to the data, which requires standard vocabularies such as those used for laboratory observations rather than locally invented codes. The message arrived and parsed correctly, so connectivity and format were not the point of failure.
Source: ONC interoperability levels — foundational, structural, semantic, and organizationalReport a problem with this question
16. An EHR specialist prepares to transmit records in response to a request from another provider treating the same patient. Which consideration governs how much information is sent?
- A.The minimum necessary standard does not restrict disclosures made for treatment✓ Answer
- B.The minimum necessary standard requires the entire designated record set be sent
- C.The minimum necessary standard bars any disclosure without written authorization
- D.The minimum necessary standard limits the disclosure to a problem list only
The minimum necessary standard expressly does not apply to disclosures to or requests by a health care provider for treatment, because withholding clinical detail from a treating provider would endanger the patient. It also does not apply to disclosures to the individual or those made under a valid authorization.
Source: HIPAA Privacy Rule, 45 CFR 164.502 — minimum necessary standard and its exceptionsReport a problem with this question
17. Under the HIPAA Security Rule technical safeguards for access control, which implementation specification is classified as required rather than addressable?
- A.Integrity controls verifying that transmitted data was not altered
- B.Unique user identification for each person with system access✓ Answer
- C.Encryption and decryption of stored electronic health information
- D.Automatic logoff after a defined period of inactivity
Unique user identification is a required specification because audit controls and accountability collapse if two people share one login and activity cannot be traced to an individual. Automatic logoff, encryption and decryption, and transmission integrity controls are all addressable specifications that must be assessed and either implemented or replaced by a documented equivalent.
Source: HIPAA Security Rule, 45 CFR 164.312 — access control and transmission security specificationsReport a problem with this question
18. A specialty clinic asks for a template covering a specific procedure. Which description best fits the EHR specialist's role in building it?
- A.Decide which procedure steps are clinically necessary to document
- B.Write the clinical findings language that providers will select from
- C.Approve the finished template and release it without further review
- D.Configure the required fields and route the design for provider approval✓ Answer
The EHR specialist builds and maintains the template structure and verifies that required fields exist, while clinicians supply and approve the clinical content, since deciding what is clinically necessary or how findings are worded is outside the specialist's scope of practice. Template designs also move through the organization's change and approval process before release.
Source: NHA CEHRS Test Plan, Clinical Operations — developing clinical templates and EHR specialist scope of practiceReport a problem with this question
Practice questions based on the NHA CEHRS Test Plan, the HIPAA Privacy and Security Rules (45 CFR Part 164), and the HITECH Act. This site is not affiliated with or endorsed by the National Healthcareer Association. Every electronic health record system arranges its own screens and menus, so workflows here are described in general terms — follow your own system's documentation and your facility's policies. Record-retention periods, permissible abbreviations, and many release-of-information details are set by state law and facility policy rather than federally, and penalty amounts are adjusted over time; verify all of these against current sources rather than against a practice test. Confirm current eligibility and exam requirements with NHA before you test. About the CEHRS certification →