Click Study Flashcards above to open the flashcard hub — hundreds of RHIA cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official AHIMA knowledge domains, so you study exactly what the administrator exam tests.[2] Pair them with our free practice test and study guide.
RHIA Flashcard Study Modes
Flip mode lets you work through a domain card by card and check yourself on sight. Match turns terms and definitions into a timed pairing game. Type gives you the definition and asks you to produce the term, so a front like MS-DRG has to come from memory. Quiz builds multiple choice from the same 303 cards for a final check.

Why Flashcards Work for the RHIA
Compliance: Access, Use & Disclosure of PHI carries the heaviest official weight at 26%, and its 62 cards drill the privacy and security vocabulary that shows up everywhere on the RHIA. You get statutory anchors such as HIPAA, the HITECH Act and 42 CFR Part 2, role terms like Covered entity, and the incident language of Snooping, Mitigation and Encryption that separates a breach response from routine safeguards.
Data Analytics & Informatics is next at 24% with 66 cards, the largest block after leadership. The cards mix standards and statistics: interoperability terms like HL7 and FHIR sit beside computation terms such as Rate, Census and Morbidity, and presentation terms such as Dashboard and Bar chart. Registry appears here too, so you can separate data sources from data displays.
Information Governance holds 19% and 43 cards, the smallest stack but a dense one. The fronts cluster around stewardship and data quality, including Data governance, Data steward, Data integrity and Data definition, plus lineage and structure terms like Data mapping, Data lineage, Metadata and Structured data that are easy to confuse under time pressure.
Revenue Cycle Management sits at 16% with 64 cards covering claims, coding integrity and payment rules. Expect Claim, Clean claim and CMS-1500 on the processing side, MS-DRG and Appeal on the reimbursement side, and fraud and abuse fronts such as Upcoding, Unbundling and Stark Law.
Management & Leadership rounds out the deck at 15% with 68 cards on process improvement, budgeting and supervision. Quality methods appear as Lean, Six Sigma, DMAIC and the PDSA cycle, while project and staffing terms include Budget, Milestone, Delegation and Licensure.
The RHIA is dense with terminology — HIPAA privacy and security rules, healthcare statistics, the MPI, the revenue cycle and CDI, and management concepts.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
RHIA Flashcards by Domain
The cards are organized by the five official AHIMA domains. Drill the highest-weighted ones first — PHI Compliance and Data Analytics are half the exam:[2]
| Domain | Exam weight |
|---|---|
| Compliance: Access, Use & Disclosure of PHI | 26% |
| Data Analytics & Informatics | 24% |
| Information Governance | 19% |
| Revenue Management | 16% |
| Management & Leadership | 15% |
How to Get the Most Out of These Flashcards
- Start with compliance. Compliance: Access, Use & Disclosure of PHI is the heaviest domain at 26% and 62 cards, so build that vocabulary first and let the other domains reinforce it.
- Type-drill the exact names. Statutes and forms lose points when they are half-remembered, so run 42 CFR Part 2 and CMS-1500 in Type until you can spell them without a prompt.
- Use Match for the short terms. The quality-method and display fronts, such as DMAIC and Bar chart, pair fast and reveal which definitions you only half recognize.
- Move to the practice test once recall holds. When Quiz stops surprising you across all five domains, switch to the practice test for question-length reasoning and use the study guide to fill gaps.
- Rotate rather than cram. With 303 cards, take one domain per session, review the prior domain in Flip first, and finish each session with a short Quiz on the mixed deck.
RHIA Flashcards FAQ
Hundreds of free RHIA flashcards, organized across all five AHIMA knowledge domains — Information Governance, PHI Compliance, Data Analytics & Informatics, Revenue Management, and Management & Leadership. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the RHIA's heavy terminology in HIPAA, statistics, the revenue cycle, and management.
All five content-outline domains: Information Governance (data integrity, the data dictionary), PHI Compliance (HIPAA, ROI, breach, retention), Data Analytics & Informatics (statistics, the MPI, EHR/HIE), Revenue Management (revenue cycle, CDI, value-based care), and Management & Leadership (strategy, HR, budgets, accreditation).
Lead with the heaviest domains — PHI Compliance (26%) and Data Analytics (24%) — then drill Information Governance, Revenue Management, and Management & Leadership. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the AHIMA RHIA Exam Content Outline effective March 1, 2021 — the five current domains and their weights.
RHIA flashcard bank
All 303 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Information Governance (43)
- Information governance (IG)
Show answerHide answer
An organization-wide framework of accountability, policies, and decision rights for managing information as a strategic asset across its lifecycle.
- Data governance
Show answerHide answer
A subset of information governance focused specifically on the management, quality, and integrity of the organization's data.
- Data integrity
Show answerHide answer
The accuracy, completeness, consistency, and reliability of data throughout its lifecycle — data is unchanged from source and fit for its purpose.
- Data dictionary
Show answerHide answer
A documented set of standard definitions for every data element — name, format, allowable values, and meaning — that enforces consistency across systems.
- Data standardization
Show answerHide answer
Applying uniform definitions, formats, and value sets (a data dictionary) so the same element means the same thing everywhere it is collected or reported.
- Master Patient Index (MPI)
Show answerHide answer
The permanent database that links every medical record number a patient has across an organization to one unique enterprise identifier.
- Enterprise Master Patient Index (EMPI)
Show answerHide answer
An MPI that links a patient's identifiers across multiple facilities or systems within a health system or HIE.
- AHIMA IG Adoption Model (IGAM)
Show answerHide answer
AHIMA's maturity model describing how an organization advances information governance across competency areas over staged levels.
- Information lifecycle
Show answerHide answer
The stages information passes through — creation/capture, use, storage/maintenance, archival, and destruction — each governed by IG policy.
- Data quality (AHIMA DQM)
Show answerHide answer
AHIMA's data-quality model: data should be accurate, complete, consistent, timely, relevant, and accessible (among other characteristics).
- Data steward
Show answerHide answer
A person accountable for the quality, definition, and appropriate use of a specific set of data elements under the IG framework.
- Structured data
Show answerHide answer
Data captured in discrete, defined fields (e.g., coded values, lab results) that can be queried and analyzed directly.
- Unstructured data
Show answerHide answer
Free-text or narrative data (e.g., dictated notes) that is not in defined fields and is harder to query without processing.
- Metadata
Show answerHide answer
Data about data — descriptive details (author, date, source, format) that give context and support retrieval, audit, and governance.
- Health record content
Show answerHide answer
The clinical and administrative documentation an organization must capture and maintain, governed by regulatory, accreditation, and organizational policy.
- Legal health record (LHR)
Show answerHide answer
The formally defined subset of records an organization will disclose as its official business record in response to a legal request.
- Designated record set (DRS)
Show answerHide answer
Under HIPAA, the records a covered entity uses to make decisions about an individual — what a patient has a right to access and amend.
- Data mapping
Show answerHide answer
Linking data elements from one system or code set to another (e.g., a crosswalk) so information moves accurately between systems.
- Data governance committee
Show answerHide answer
A cross-functional body that sets data policies, resolves data-definition conflicts, and oversees data quality enterprise-wide.
- Quality reporting data
Show answerHide answer
Required clinical data elements abstracted and submitted for quality programs and to facility committees and payers.
- Data normalization
Show answerHide answer
Mapping local terms and values to a common standard or terminology so data from different sources can be aggregated and compared.
- Single source of truth
Show answerHide answer
The principle that one authoritative, governed copy of a data element exists, so reports and decisions rely on consistent data.
- Information governance vs records management
Show answerHide answer
Records management handles documents/retention; IG is the broader strategic framework governing all information, including data and analytics.
- Data dictionary standardization policy
Show answerHide answer
An organizational policy requiring all systems to use approved element definitions and value sets to prevent inconsistent or duplicate data.
- Health Information Management (HIM)
Show answerHide answer
The discipline of acquiring, analyzing, protecting, and governing digital and traditional health information to support quality care and operations.
- Charge description master (CDM) — IG view
Show answerHide answer
A governed master file of billable items, codes, and prices; its integrity is an information-governance and revenue concern.
- Trustworthy data
Show answerHide answer
Data that stakeholders can rely on for decisions because its quality and integrity are governed, documented, and auditable.
- Policy and procedure (P&P)
Show answerHide answer
A documented organizational rule (policy) and the step-by-step method to carry it out (procedure) — the backbone of IG and compliance.
- Data analysis to inform management
Show answerHide answer
Using governed, quality data to produce insights that guide operational and strategic management decisions.
- Forms/template control
Show answerHide answer
Governing the design and approval of documentation forms and EHR templates so captured data is complete, consistent, and compliant.
- Information asset
Show answerHide answer
Any body of information (a database, record set, report) the organization manages and protects for its value.
- Data definition
Show answerHide answer
The documented, agreed meaning and allowable values of a data element, recorded in the data dictionary.
- Authorship/attribution
Show answerHide answer
Documentation must identify who created each entry; governance ensures every entry is attributable and signed.
- Amendment vs correction
Show answerHide answer
An amendment adds new information; a correction fixes an error — both must preserve the original entry (no deletion).
- Version control
Show answerHide answer
Tracking changes to documents, forms, and policies so the current authoritative version is always identifiable.
- Data ownership vs stewardship
Show answerHide answer
Ownership is organizational accountability for data; stewardship is the operational responsibility to maintain its quality.
- Information governance program office
Show answerHide answer
The function that coordinates IG strategy, policies, and metrics across departments.
- Record completeness
Show answerHide answer
Ensuring every required documentation element is present and authenticated before a record is considered complete.
- Deficiency analysis
Show answerHide answer
Reviewing records to identify missing or unauthenticated documentation (e.g., unsigned reports) for provider completion.
- Forms committee
Show answerHide answer
A governance body that approves the design and data elements of paper forms and EHR templates.
- Data classification
Show answerHide answer
Categorizing data by sensitivity (e.g., public, internal, confidential, PHI) to apply appropriate controls.
- Data lineage
Show answerHide answer
Documentation of where data originated and how it moved/transformed across systems — supports trust and audit.
- Information governance metrics
Show answerHide answer
Measures (data-quality rates, duplicate rates, policy adoption) that show IG program maturity and value.
Compliance: Access, Use & Disclosure of PHI (62)
- HIPAA
Show answerHide answer
The Health Insurance Portability and Accountability Act — federal law setting national standards to protect health information (Privacy, Security, and Breach Notification Rules).
- Protected Health Information (PHI)
Show answerHide answer
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form.
- HIPAA Privacy Rule
Show answerHide answer
Sets national standards for how PHI may be used and disclosed and gives patients rights over their information.
- HIPAA Security Rule
Show answerHide answer
Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI).
- Breach Notification Rule
Show answerHide answer
Requires covered entities to notify affected individuals, HHS, and sometimes the media when unsecured PHI is breached.
- Minimum necessary
Show answerHide answer
The HIPAA principle of using, disclosing, or requesting only the least PHI needed to accomplish the intended purpose.
- Covered entity
Show answerHide answer
Under HIPAA, a health plan, health-care clearinghouse, or provider that transmits health information electronically.
- Business associate
Show answerHide answer
A person or entity that performs functions involving PHI on behalf of a covered entity; bound by a business associate agreement (BAA).
- TPO (treatment, payment, operations)
Show answerHide answer
The three purposes for which a covered entity may use or disclose PHI without patient authorization.
- Patient right of access
Show answerHide answer
A patient's HIPAA right to inspect and obtain a copy of their PHI in a designated record set, generally within 30 days.
- Right to amend
Show answerHide answer
A patient's HIPAA right to request correction of inaccurate or incomplete PHI in their designated record set.
- Accounting of disclosures
Show answerHide answer
A patient's HIPAA right to receive a list of certain disclosures of their PHI made by the covered entity.
- Authorization
Show answerHide answer
A patient's signed permission required to use or disclose PHI for purposes other than treatment, payment, or operations.
- Release of information (ROI)
Show answerHide answer
The HIM process of validating, fulfilling, and tracking requests for copies of a patient's health information.
- Valid authorization elements
Show answerHide answer
A HIPAA authorization must specify the information, who may disclose and receive it, the purpose, an expiration, and the patient's signature/date.
- Notice of Privacy Practices (NPP)
Show answerHide answer
The document a covered entity must give patients describing how their PHI may be used and disclosed and their rights.
- Record retention
Show answerHide answer
The period an organization must keep records, set by the strictest of state law, federal rule, accreditation, and policy.
- Record destruction
Show answerHide answer
Disposing of records past retention using a method that renders PHI unreadable/unrecoverable, with a destruction log.
- Retention schedule
Show answerHide answer
A policy specifying how long each record type is kept and how it is destroyed when retention ends.
- Breach (HIPAA)
Show answerHide answer
An impermissible use or disclosure of unsecured PHI that compromises its security or privacy, unless a risk assessment shows low probability of compromise.
- Four-factor risk assessment
Show answerHide answer
The breach analysis of: nature/extent of PHI, who received it, whether PHI was actually acquired/viewed, and the extent of risk mitigation.
- Breach notification timeline
Show answerHide answer
Individuals must be notified without unreasonable delay and no later than 60 days from discovery of a breach.
- Subpoena vs court order
Show answerHide answer
A court order compels disclosure of PHI; a subpoena generally requires additional assurances (e.g., notice or a qualified protective order) before disclosure.
- Psychotherapy notes
Show answerHide answer
Separately kept notes that receive heightened HIPAA protection and generally require specific authorization to disclose.
- 42 CFR Part 2
Show answerHide answer
Federal rule giving stricter confidentiality protection to substance-use disorder treatment records than HIPAA alone.
- State preemption
Show answerHide answer
Where state privacy law is more stringent than HIPAA, the state law controls (HIPAA is a federal floor, not a ceiling).
- Privacy Officer
Show answerHide answer
The individual a covered entity must designate to develop and implement privacy policies and handle complaints.
- Security Officer
Show answerHide answer
The individual responsible for developing and implementing the organization's ePHI security policies under the Security Rule.
- Administrative safeguards
Show answerHide answer
Security Rule policies and procedures — risk analysis, workforce training, access management — that manage ePHI protection.
- Physical safeguards
Show answerHide answer
Security Rule controls protecting facilities and devices — facility access, workstation use, and device/media controls.
- Technical safeguards
Show answerHide answer
Security Rule technology controls — access control, audit controls, integrity, and transmission security for ePHI.
- Access control (security)
Show answerHide answer
Granting ePHI access by role and need-to-know via unique user IDs, authentication, and authorization.
- Role-based access control (RBAC)
Show answerHide answer
Assigning system permissions based on a user's job role so each user sees only the PHI their role requires.
- Audit controls / audit trail
Show answerHide answer
Hardware, software, and procedures that record and examine activity in systems containing ePHI.
- Risk analysis (Security Rule)
Show answerHide answer
The required, ongoing assessment of risks and vulnerabilities to ePHI confidentiality, integrity, and availability.
- Encryption
Show answerHide answer
Converting ePHI into unreadable form; encrypted data that is breached is 'secured' and may not trigger breach notification.
- HITECH Act
Show answerHide answer
The law that strengthened HIPAA enforcement, added breach notification, increased penalties, and extended rules to business associates.
- Privacy initiative monitoring
Show answerHide answer
Ongoing auditing of PHI access and ROI workflows to ensure the organization complies with privacy policies and law.
- Patient advocacy in ROI
Show answerHide answer
Helping patients and families understand and exercise their rights to obtain their health information appropriately.
- De-identification
Show answerHide answer
Removing identifiers from PHI (Safe Harbor's 18 identifiers or expert determination) so it is no longer protected under HIPAA.
- Consent vs authorization
Show answerHide answer
Consent is general permission to use PHI for TPO; authorization is specific written permission for other uses/disclosures.
- Accreditation standards (privacy)
Show answerHide answer
Joint Commission and similar bodies impose documentation and confidentiality standards beyond regulation that HIM must monitor.
- Confidentiality, integrity, availability (CIA)
Show answerHide answer
The three security objectives the Security Rule protects for ePHI.
- Workforce clearance/termination
Show answerHide answer
Administrative safeguards ensuring access is appropriate at hire and revoked promptly at termination.
- Contingency plan (Security Rule)
Show answerHide answer
Required data backup, disaster recovery, and emergency-mode operation plans to keep ePHI available.
- Sanction policy
Show answerHide answer
A required policy applying consequences to workforce members who violate security policies.
- Information access management
Show answerHide answer
Policies that authorize access to ePHI based on role and need, a required administrative safeguard.
- Transmission security
Show answerHide answer
Technical safeguards (e.g., encryption) protecting ePHI as it travels over a network.
- Integrity controls
Show answerHide answer
Measures ensuring ePHI is not improperly altered or destroyed.
- Two-factor authentication
Show answerHide answer
Verifying identity with two independent factors (something you know/have/are) to strengthen access control.
- Audit log review
Show answerHide answer
Routinely examining system access logs to detect inappropriate PHI access (snooping).
- Snooping
Show answerHide answer
Accessing PHI without a legitimate business need — a privacy violation even if no data leaves the organization.
- Mitigation
Show answerHide answer
Steps a covered entity takes to lessen harm after an impermissible use or disclosure of PHI.
- Substitute notice
Show answerHide answer
Public/media breach notice used when a breach affects 500+ residents of a state or contact information is insufficient.
- HHS Office for Civil Rights (OCR)
Show answerHide answer
The agency that enforces the HIPAA Privacy, Security, and Breach Notification Rules and investigates complaints.
- Civil monetary penalties (HIPAA)
Show answerHide answer
Tiered fines for HIPAA violations based on culpability, up to an annual maximum per provision.
- Business associate agreement (BAA)
Show answerHide answer
The contract that binds a business associate to safeguard PHI and comply with applicable HIPAA rules.
- Marketing/sale of PHI
Show answerHide answer
Uses generally requiring specific authorization, with HITECH restrictions on remuneration for PHI.
- Incidental disclosure
Show answerHide answer
A permitted secondary disclosure that cannot reasonably be prevented when reasonable safeguards are in place.
- Verification of identity
Show answerHide answer
HIPAA requires verifying the identity and authority of a person requesting PHI before disclosure.
- Restriction request
Show answerHide answer
A patient's right to request limits on uses/disclosures; must be honored for out-of-pocket-paid services to a health plan.
- Court-ordered disclosure
Show answerHide answer
PHI may be disclosed as expressly authorized by a court order without patient authorization.
Data Analytics & Informatics (66)
- Health informatics
Show answerHide answer
The interdisciplinary use of information technology and data to acquire, store, analyze, and present health data for better care and decisions.
- Healthcare statistics
Show answerHide answer
Quantitative measures (census, rates, length of stay) computed from health data to describe and monitor organizational performance.
- Length of stay (LOS)
Show answerHide answer
The number of days between a patient's admission and discharge; average LOS (ALOS) is total discharge days divided by discharges.
- Census
Show answerHide answer
The number of inpatients present in a facility at a point in time, used to compute occupancy and staffing measures.
- Average daily census
Show answerHide answer
Total inpatient service days for a period divided by the number of days in the period.
- Occupancy rate
Show answerHide answer
The percentage of available beds occupied — inpatient service days divided by available bed days, times 100.
- Mortality rate
Show answerHide answer
The proportion of inpatient deaths to discharges (including deaths) in a period, often expressed as a percentage.
- Morbidity
Show answerHide answer
The rate or incidence of disease within a defined population.
- Incidence rate
Show answerHide answer
The number of NEW cases of a condition in a population over a period.
- Prevalence rate
Show answerHide answer
The number of EXISTING cases (new and old) of a condition in a population at a point in time.
- Mean, median, mode
Show answerHide answer
Measures of central tendency: mean is the average, median is the middle value, mode is the most frequent value.
- Data mining
Show answerHide answer
Using database and statistical techniques to discover patterns, trends, and relationships in large data sets.
- Master patient index integrity
Show answerHide answer
Maintaining one accurate enterprise identifier per patient by preventing and resolving duplicates, overlays, and overlaps.
- Duplicate (MPI)
Show answerHide answer
Two or more records/identifiers created for the SAME patient — must be merged to preserve a single record.
- Overlay (MPI)
Show answerHide answer
One patient's information recorded under ANOTHER patient's identifier — a serious patient-safety error to resolve immediately.
- Overlap (MPI)
Show answerHide answer
The same patient has different enterprise identifiers across facilities in a system — reconciled in an EMPI.
- Data visualization
Show answerHide answer
Presenting data graphically (charts, dashboards) so trends and outliers are clear for decision-making.
- Dashboard
Show answerHide answer
A visual display of key performance indicators and metrics, updated for managers to monitor performance at a glance.
- Bar chart
Show answerHide answer
A graph using bars to compare values across discrete categories.
- Line graph
Show answerHide answer
A graph showing how a value changes over time — ideal for trends.
- Histogram
Show answerHide answer
A graph showing the frequency distribution of a continuous variable using adjacent bars.
- Pie chart
Show answerHide answer
A circular graph showing parts of a whole as proportional slices.
- Scatter plot
Show answerHide answer
A graph plotting two variables as points to reveal correlation or relationship.
- Key performance indicator (KPI)
Show answerHide answer
A quantifiable measure used to evaluate success against an objective (e.g., coding accuracy, DNFB days).
- Database management system (DBMS)
Show answerHide answer
Software (e.g., relational) for creating, querying, and maintaining structured data.
- Relational database
Show answerHide answer
Data organized into tables (relations) of rows and columns, linked by keys, and queried with SQL.
- Primary key
Show answerHide answer
A field (or set) that uniquely identifies each row in a database table.
- Foreign key
Show answerHide answer
A field in one table that references the primary key of another, linking related data.
- Structured Query Language (SQL)
Show answerHide answer
The standard language for querying and manipulating data in a relational database.
- Electronic Health Record (EHR)
Show answerHide answer
A longitudinal digital record of a patient's health information shared across providers and settings.
- EHR end-user support
Show answerHide answer
Helping clinicians and staff use EHR applications correctly — training, troubleshooting, and optimization.
- Health Information Exchange (HIE)
Show answerHide answer
The electronic sharing of health information among organizations to improve coordination of care.
- Interoperability
Show answerHide answer
The ability of different information systems and devices to exchange and use data — often via HL7 or FHIR standards.
- HL7
Show answerHide answer
Health Level Seven — a family of standards for exchanging clinical and administrative health data between systems.
- FHIR
Show answerHide answer
Fast Healthcare Interoperability Resources — a modern HL7 standard using web technologies for exchanging health data.
- Clinical decision support (CDS)
Show answerHide answer
EHR tools (alerts, reminders, order sets) that give clinicians knowledge and patient-specific information at the point of care.
- Audit (focused tool)
Show answerHide answer
Using a targeted tool/checklist to review documentation for CDI, quality, or safety against criteria.
- Productivity report
Show answerHide answer
A report measuring staff or department output (e.g., charts coded per hour) used to manage performance.
- Trend analysis
Show answerHide answer
Examining data over time to identify direction and patterns that inform summary reports for leadership.
- Data warehouse
Show answerHide answer
A central repository of integrated data from multiple sources, optimized for reporting and analysis.
- Healthcare statistics validation
Show answerHide answer
Verifying that computed statistics are accurate and correctly defined before reporting them to stakeholders.
- Population health analytics
Show answerHide answer
Analyzing data across groups of patients to improve outcomes and manage cost for a defined population.
- Registry
Show answerHide answer
An organized system that collects standardized data on a defined population (e.g., a cancer or trauma registry).
- Data abstraction
Show answerHide answer
Identifying and recording the specific data elements required for a report, registry, or quality measure from the record.
- Bed turnover rate
Show answerHide answer
The number of times each bed changes occupants in a period — discharges divided by available beds.
- Autopsy rate
Show answerHide answer
The proportion of deaths that are autopsied; the gross rate uses all inpatient deaths as the denominator.
- Nosocomial infection rate
Show answerHide answer
The rate of hospital-acquired infections among patients in a period.
- Standard deviation
Show answerHide answer
A measure of how spread out values are around the mean.
- Rate
Show answerHide answer
A measure of how often an event occurs relative to a population at risk, usually times a constant (e.g., per 1,000).
- Ratio vs proportion
Show answerHide answer
A ratio compares two quantities (a:b); a proportion is a ratio where the numerator is part of the denominator.
- Aggregate data
Show answerHide answer
Data combined across individuals to describe a group, with no patient identified.
- Patient-identifiable data
Show answerHide answer
Data that can be traced to a specific patient — protected and access-controlled.
- Primary data source
Show answerHide answer
The health record itself — data collected during direct patient care.
- Secondary data source
Show answerHide answer
Data derived from the record for other uses — registries, indexes, and databases.
- Disease index
Show answerHide answer
A secondary record listing diseases (by code) treated in a facility, used for studies and reporting.
- Operation/procedure index
Show answerHide answer
A secondary record listing procedures performed, organized by code.
- Data accuracy vs precision
Show answerHide answer
Accuracy is closeness to the true value; precision is consistency/reproducibility of the measurement.
- Optical character recognition (OCR scanning)
Show answerHide answer
Technology converting scanned text images into machine-readable data for the EHR.
- Natural language processing (NLP)
Show answerHide answer
AI that interprets free-text clinical narrative to extract or suggest structured data and codes.
- System implementation lifecycle
Show answerHide answer
Stages of deploying an information system — planning, analysis, design, implementation, and maintenance.
- Go-live support
Show answerHide answer
Concentrated end-user assistance during and immediately after a new system's launch.
- Data validation
Show answerHide answer
Checking data against rules (range, format, consistency) at entry to prevent errors.
- Benchmarking
Show answerHide answer
Comparing performance metrics against internal targets or external best-in-class organizations.
- Run chart
Show answerHide answer
A line graph of a metric over time used to detect shifts and trends in process improvement.
- Control chart
Show answerHide answer
A run chart with statistical control limits used to distinguish normal variation from special-cause variation.
- Report dashboard validation
Show answerHide answer
Confirming a dashboard's underlying data and calculations are correct before stakeholders rely on it.
Revenue Cycle Management (64)
- Revenue cycle
Show answerHide answer
All clinical and administrative functions that capture, manage, and collect patient-service revenue — from scheduling to final payment.
- Revenue cycle management (RCM)
Show answerHide answer
Overseeing the revenue cycle to maximize appropriate, compliant reimbursement and minimize denials and lost revenue.
- Front-end revenue cycle
Show answerHide answer
Patient-access functions before/at the encounter — scheduling, registration, insurance verification, and prior authorization.
- Middle revenue cycle
Show answerHide answer
Functions during care — charge capture, coding, CDI, and documentation — that translate services into billable data.
- Back-end revenue cycle
Show answerHide answer
Functions after care — claims submission, payment posting, denials management, and collections.
- Clinical documentation improvement (CDI)
Show answerHide answer
A program that improves the accuracy and completeness of clinical documentation so it supports correct codes and reflects severity.
- Provider query
Show answerHide answer
A compliant, non-leading question to a provider to clarify ambiguous, incomplete, or conflicting documentation before coding.
- Coding accuracy validation
Show answerHide answer
Auditing assigned codes against documentation and official guidelines to confirm they are correct and complete.
- Diagnosis-Related Group (DRG)
Show answerHide answer
An inpatient classification that pays a fixed amount per admission based on diagnoses and procedures (MS-DRG under Medicare).
- Ambulatory Payment Classification (APC)
Show answerHide answer
The outpatient hospital payment unit under Medicare's Outpatient Prospective Payment System.
- Case mix index (CMI)
Show answerHide answer
The average DRG relative weight for a facility's patients — a measure of clinical complexity that drives reimbursement.
- Prospective payment system (PPS)
Show answerHide answer
A method paying a predetermined amount per case/service (e.g., IPPS, OPPS) rather than per actual cost.
- Fee-for-service
Show answerHide answer
Reimbursement that pays separately for each service provided, rewarding volume.
- Value-based care
Show answerHide answer
Reimbursement tied to quality and outcomes rather than volume, shifting financial risk toward providers.
- Value-based purchasing (VBP)
Show answerHide answer
A CMS program adjusting hospital payment up or down based on quality and outcome measures.
- Bundled payment
Show answerHide answer
A single payment covering all services for an episode of care, encouraging coordination and efficiency.
- Accountable care organization (ACO)
Show answerHide answer
A group of providers jointly accountable for the cost and quality of care for a population, sharing savings or risk.
- Claim
Show answerHide answer
The billing record submitted to a payer (e.g., UB-04 for facilities, CMS-1500 for professionals) requesting reimbursement.
- Claims management
Show answerHide answer
Verifying, submitting, tracking, and reconciling claims to ensure timely, accurate payment.
- Denial management
Show answerHide answer
Analyzing, appealing, and preventing payer denials to recover and protect revenue.
- Clean claim
Show answerHide answer
A claim with no errors that can be processed and paid without additional information.
- Charge capture
Show answerHide answer
Recording all billable services and supplies provided so they appear on the claim.
- Charge description master (CDM/chargemaster)
Show answerHide answer
The master file of all billable items, their codes, descriptions, and prices used to generate charges.
- Revenue integrity
Show answerHide answer
Ensuring charges and coding are accurate, compliant, and complete so reimbursement is correct and defensible.
- Discharged not final billed (DNFB)
Show answerHide answer
Accounts discharged but not yet billed — a key revenue-cycle metric where high values signal bottlenecks (often coding).
- Accounts receivable (A/R) days
Show answerHide answer
The average number of days to collect payment after billing — a core revenue-cycle performance metric.
- Healthcare fraud
Show answerHide answer
Knowingly submitting false claims or misrepresenting services to obtain payment — illegal under the False Claims Act.
- Abuse (healthcare)
Show answerHide answer
Practices inconsistent with sound fiscal or medical practice causing unnecessary cost — improper but not necessarily intentional.
- Upcoding
Show answerHide answer
Assigning codes for more severe or expensive conditions/services than documented — a fraud and compliance risk.
- Unbundling
Show answerHide answer
Billing components of a service separately to obtain higher payment when a single combined code applies.
- False Claims Act
Show answerHide answer
Federal law imposing liability for knowingly submitting false or fraudulent claims to the government.
- National Correct Coding Initiative (NCCI)
Show answerHide answer
CMS edits that prevent improper code pairs and unbundling to promote correct coding.
- Recovery Audit Contractor (RAC)
Show answerHide answer
A CMS contractor that audits claims to identify and recover improper Medicare payments.
- Medical necessity
Show answerHide answer
The requirement that a service be reasonable and necessary; diagnosis codes must support the procedure billed.
- Local/National Coverage Determination (LCD/NCD)
Show answerHide answer
Medicare policies defining what is covered and when, used to demonstrate medical necessity.
- Hierarchical Condition Categories (HCC)
Show answerHide answer
A risk-adjustment model grouping diagnoses to predict cost and set capitated/value-based payment.
- Hard-coding vs soft-coding
Show answerHide answer
Hard-coding assigns charges automatically via the CDM; soft-coding is HIM coders assigning codes from documentation.
- Remittance advice (RA)
Show answerHide answer
The payer's explanation of how a claim was adjudicated — paid, adjusted, or denied — used to post payments.
- Explanation of benefits (EOB)
Show answerHide answer
The statement sent to the patient describing what the payer covered and what the patient owes.
- Revenue cycle audit
Show answerHide answer
A review of revenue-cycle data and processes to find compliance gaps, errors, and improvement opportunities.
- Patient access services
Show answerHide answer
Front-end functions (scheduling, registration, eligibility) that set up accurate billing and reduce denials.
- Prior authorization
Show answerHide answer
Payer approval obtained before a service to confirm coverage and prevent denial.
- Eligibility verification
Show answerHide answer
Confirming a patient's insurance coverage and benefits before service.
- Coordination of benefits (COB)
Show answerHide answer
Rules determining which payer is primary when a patient has more than one insurance.
- UB-04 (CMS-1450)
Show answerHide answer
The standard institutional/facility claim form.
- CMS-1500
Show answerHide answer
The standard professional/physician claim form.
- Present on admission (POA) indicator
Show answerHide answer
A value reported with each inpatient diagnosis showing whether it was present at admission; drives HAC payment.
- Hospital-acquired condition (HAC)
Show answerHide answer
A reasonably preventable condition not present on admission that can reduce Medicare payment.
- MS-DRG
Show answerHide answer
Medicare Severity DRG — the inpatient payment group reflecting diagnoses, procedures, and severity (CC/MCC).
- Complication/comorbidity (CC/MCC)
Show answerHide answer
Secondary conditions that raise the DRG tier; an MCC raises it more than a CC.
- Charge capture reconciliation
Show answerHide answer
Comparing services documented to charges posted to ensure all billable activity is captured.
- Late charge
Show answerHide answer
A charge posted after the claim has dropped, which can require rebilling and delay payment.
- Write-off/adjustment
Show answerHide answer
A reduction of the billed amount (contractual or bad debt) recorded on the account.
- Contractual allowance
Show answerHide answer
The difference between the charge and the payer's contracted (allowed) amount, written off.
- Days in A/R
Show answerHide answer
A revenue-cycle metric of average time to collect; lower is better cash flow.
- First-pass resolution rate
Show answerHide answer
The percentage of claims paid on first submission without rework — a clean-claim efficiency measure.
- Denial rate
Show answerHide answer
The percentage of claims denied by payers; a key RCM performance and compliance metric.
- Appeal
Show answerHide answer
A formal request to a payer to reconsider a denied or underpaid claim, supported by documentation.
- Compliance audit (coding)
Show answerHide answer
A scheduled review verifying coding meets official guidelines and payer rules to prevent fraud/abuse.
- OIG Work Plan
Show answerHide answer
The HHS Office of Inspector General's annual list of audit and enforcement priorities organizations monitor.
- Anti-Kickback Statute
Show answerHide answer
Federal law prohibiting paying for referrals of services reimbursed by federal health programs.
- Stark Law
Show answerHide answer
Federal law restricting physician self-referral for certain designated health services.
- Revenue cycle KPI dashboard
Show answerHide answer
A dashboard of metrics (DNFB, A/R days, denial rate, CMI) used to manage revenue-cycle performance.
- Outpatient code editor (OCE)
Show answerHide answer
Medicare edits applied to outpatient claims to check coding and coverage before payment.
Management & Leadership (68)
- Strategic planning
Show answerHide answer
Defining an organization's long-term direction and allocating resources to achieve its mission, vision, and goals.
- Mission statement
Show answerHide answer
A concise statement of an organization's core purpose and what it does.
- Vision statement
Show answerHide answer
A statement describing what an organization aspires to become in the future.
- SWOT analysis
Show answerHide answer
A planning tool assessing internal Strengths and Weaknesses and external Opportunities and Threats.
- Goal vs objective
Show answerHide answer
A goal is a broad desired outcome; an objective is a specific, measurable, time-bound step toward it.
- Strategic vs operational planning
Show answerHide answer
Strategic planning sets long-term direction; operational planning manages day-to-day execution to support it.
- Change management
Show answerHide answer
A structured approach to transitioning people and the organization from a current to a desired future state.
- Human resource management (HRM)
Show answerHide answer
Recruiting, developing, evaluating, and retaining staff and managing personnel issues within legal requirements.
- Job description
Show answerHide answer
A document defining a position's duties, responsibilities, required qualifications, and reporting relationships.
- Job specification
Show answerHide answer
The qualifications, skills, and experience a person needs to perform a particular job.
- Recruitment
Show answerHide answer
The process of attracting and identifying qualified candidates to fill positions.
- Onboarding/orientation
Show answerHide answer
Integrating and training new employees so they become productive and understand policy and culture.
- Performance appraisal
Show answerHide answer
A periodic, structured evaluation of an employee's job performance against expectations.
- Progressive discipline
Show answerHide answer
A graduated approach to addressing performance/conduct problems — verbal warning, written warning, suspension, termination.
- Productivity standard
Show answerHide answer
A defined expected level of output (e.g., charts coded per hour) used to set and measure performance.
- Staffing/scheduling
Show answerHide answer
Determining the number and mix of staff needed to meet workload while controlling labor cost.
- Span of control
Show answerHide answer
The number of subordinates a manager directly supervises.
- Organizational chart
Show answerHide answer
A diagram of an organization's structure, reporting relationships, and chain of command.
- Process improvement
Show answerHide answer
Systematically analyzing and redesigning workflows to increase quality, efficiency, or value.
- Performance improvement (PI)
Show answerHide answer
Ongoing measurement and improvement of organizational processes and outcomes (e.g., PDSA cycles).
- PDSA cycle
Show answerHide answer
Plan-Do-Study-Act — an iterative method for testing and implementing a process change on a small scale first.
- Lean
Show answerHide answer
A methodology that improves processes by eliminating waste and maximizing value to the customer.
- Six Sigma
Show answerHide answer
A data-driven methodology (DMAIC) that reduces process variation and defects.
- DMAIC
Show answerHide answer
Six Sigma's improvement steps: Define, Measure, Analyze, Improve, Control.
- Workflow/work design
Show answerHide answer
Arranging tasks, people, and tools so work flows efficiently and accurately.
- Project management
Show answerHide answer
Planning, executing, and closing a defined effort within scope, time, and budget constraints.
- Gantt chart
Show answerHide answer
A bar chart that schedules project tasks against time to track progress and dependencies.
- Budget
Show answerHide answer
A financial plan estimating revenue and expenses for a period; HIM managers help prepare and monitor it.
- Operating budget
Show answerHide answer
A budget for day-to-day revenue and expenses (salaries, supplies) over a fiscal year.
- Capital budget
Show answerHide answer
A budget for major, long-term asset purchases (e.g., a new EHR module or scanners).
- Variance analysis
Show answerHide answer
Comparing budgeted to actual amounts and explaining the differences to control finances.
- Return on investment (ROI)
Show answerHide answer
A measure of a project's financial benefit relative to its cost.
- Cost-benefit analysis
Show answerHide answer
Comparing the expected costs and benefits of an option to support a decision.
- Full-time equivalent (FTE)
Show answerHide answer
A unit expressing staffing as the hours of one full-time employee (e.g., two half-time staff = 1.0 FTE).
- Accreditation
Show answerHide answer
Voluntary review by an external body (e.g., The Joint Commission) confirming an organization meets quality standards.
- The Joint Commission
Show answerHide answer
A major accrediting body whose standards address documentation, safety, and information management.
- Licensure
Show answerHide answer
Government permission required for a facility or individual to operate or practice.
- Certification
Show answerHide answer
Recognition by a body that a person or program meets defined standards (e.g., CMS Conditions of Participation).
- Compliance program
Show answerHide answer
An organized system of policies, training, auditing, and reporting to prevent and detect violations of law and policy.
- Contract management
Show answerHide answer
Negotiating, monitoring, and renewing agreements with vendors and outsourced services (e.g., ROI, coding).
- Vendor/outsourcing oversight
Show answerHide answer
Managing third-party performance, service levels, and PHI safeguards (via a BAA) for outsourced functions.
- Training and development
Show answerHide answer
Building staff skills and competencies through structured education to improve performance and support change.
- Leadership vs management
Show answerHide answer
Leadership sets vision and motivates change; management plans, organizes, and controls day-to-day operations.
- Conflict resolution
Show answerHide answer
Techniques for addressing and resolving interpersonal or interdepartmental disputes constructively.
- Balanced scorecard
Show answerHide answer
A strategic tool measuring performance across financial, customer, internal-process, and learning perspectives.
- Key result area
Show answerHide answer
A category of outcomes critical to organizational success, tracked with objectives and KPIs.
- Delegation
Show answerHide answer
Assigning authority and responsibility for a task to a subordinate while retaining accountability.
- Motivation theory
Show answerHide answer
Frameworks (e.g., Maslow, Herzberg) explaining what drives employee performance and engagement.
- Team building
Show answerHide answer
Activities and leadership that develop a cohesive, high-performing work group.
- Productivity monitoring
Show answerHide answer
Measuring output against standards to manage staffing and identify training needs.
- Position control
Show answerHide answer
Managing the authorized number and type of positions and FTEs within budget.
- Competency assessment
Show answerHide answer
Verifying staff have the knowledge and skills required for their role, often at hire and periodically.
- Succession planning
Show answerHide answer
Identifying and developing employees to fill key roles in the future.
- Telecommuting/remote coding policy
Show answerHide answer
Policies governing remote HIM work, including PHI safeguards and productivity standards.
- Labor cost/budget
Show answerHide answer
Salaries and benefits — typically the largest HIM operating expense to plan and control.
- Cost center
Show answerHide answer
A department to which costs are assigned for budgeting and accountability.
- Fixed vs variable cost
Show answerHide answer
Fixed costs stay constant with volume (rent); variable costs change with volume (supplies).
- Productivity vs quality balance
Show answerHide answer
Managing output standards without sacrificing accuracy/quality (e.g., coding error rate).
- Root cause analysis (RCA)
Show answerHide answer
A structured method to identify the underlying cause of a problem or adverse event.
- Failure mode and effects analysis (FMEA)
Show answerHide answer
A proactive method identifying potential process failures and their effects before they occur.
- Workflow redesign
Show answerHide answer
Reengineering how work is done to remove non-value steps and improve efficiency and accuracy.
- Project scope
Show answerHide answer
The defined boundaries of a project — what is and is not included — guarding against scope creep.
- Milestone
Show answerHide answer
A significant checkpoint or deliverable date in a project schedule.
- Stakeholder
Show answerHide answer
Any person or group with an interest in or affected by a project or decision.
- Conditions of Participation (CoP)
Show answerHide answer
CMS requirements a facility must meet to participate in Medicare/Medicaid.
- Policy development
Show answerHide answer
Creating organizational rules that align operations with law, accreditation, and strategic goals.
- Standard operating procedure (SOP)
Show answerHide answer
A documented routine method for performing a recurring task consistently.
- Capital request justification
Show answerHide answer
A business case (cost-benefit, ROI) supporting a major asset purchase in the capital budget.
References
- 1.American Health Information Management Association. “Registered Health Information Administrator (RHIA) Certification.” ahima.org. ↑
- 2.American Health Information Management Association. “RHIA Exam Content Outline (effective 03/01/2021).” ahima.org. ↑
- 3.U.S. Department of Health & Human Services. “HIPAA for Professionals: The Privacy Rule.” hhs.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
