Strand 6 Study Notes: Building Health Information Literacy for Medical and Dental Offices

6.1.1 Health Information Management (HIM): data vs. information vs. competency

What Health Information Management is

Health Information Management (HIM) is the field that collects, organizes, protects, and uses health information so it supports high-quality patient care, legal and ethical requirements, billing and reimbursement, operations, and research/quality improvement. In a medical or dental office, HIM is not “just filing”—it is the disciplined way the practice makes sure health records are accurate, complete, timely, secure, and usable.

A helpful way to picture HIM is as the “information infrastructure” of healthcare. Clinicians provide care, but the record is how that care becomes:

  • Communicable (so another provider can safely continue treatment)
  • Defensible (so the office can show what happened and why)
  • Billable (so payers can verify services and medical necessity)
  • Measurable (so quality can be monitored and improved)

In an office setting, HIM tasks commonly include maintaining the record (paper or electronic), ensuring proper documentation, managing release of information, supporting coding and claims, and maintaining privacy and security practices.

Data vs. information (and why the difference matters)

Students often use these words interchangeably, but in HIM they are meaningfully different.

  • Data are raw facts—individual measurements or observations that haven’t been interpreted yet. Examples: a blood pressure reading, a tooth number with a notation, a lab value, a date of service, a diagnosis code.
  • Information is data that has been organized and given meaning so it can support a decision. Examples: a trend showing blood pressure is rising over three visits; a periodontal chart showing disease progression; a problem list that explains why certain labs were ordered.

Why it matters: if you only collect data without structuring it into information, you can’t reliably support clinical decisions, quality reporting, or compliant billing. HIM helps transform scattered facts into a coherent story.

What “competency” means in health information literacy

Competency is the demonstrated ability to perform a task to an expected standard. In health information literacy, competency means you can reliably do things like:

  • Enter information correctly (right patient, right date, right content)
  • Use appropriate terminology and approved abbreviations
  • Follow documentation rules (timeliness, authentication, corrections)
  • Protect privacy and follow access policies
  • Retrieve and communicate information appropriately (for care coordination, audits, referrals)

Competency is not just “knowing about” documentation—it’s being able to do it consistently under real workplace conditions.

How these concepts connect in real office work

A common workflow shows the relationship:

  1. A clinician observes something (pain score, caries, swelling) → data.
  2. They document assessment and plan in context (diagnosis, rationale, next steps) → information.
  3. The office team follows policies for timely entry, proper signatures, correct corrections, secure handling → competency.

If any part breaks down, downstream problems occur: patient safety issues (wrong meds, missed allergies), legal vulnerability (“If it’s not documented, it didn’t happen”), or payer denials (“insufficient documentation”).

Example: turning raw entries into meaningful information

Suppose a dental assistant records:

  • Tooth #30: bleeding on probing
  • Pocket depth values across multiple sites
  • Patient reports “bleeding when brushing”

Those are data. When the provider documents “Generalized gingival inflammation consistent with gingivitis; OHI reviewed; re-evaluate in 3 months,” the record becomes information that supports a care plan and future comparison.

Exam Focus
  • Typical question patterns:
    • Distinguish “data” vs. “information” using short office scenarios.
    • Identify what HIM is responsible for (clinical support, legal, billing, privacy/security).
    • Choose the best example of “competency” (performance-based, policy-aligned behavior).
  • Common mistakes:
    • Treating data and information as identical—remember: information is interpreted/organized.
    • Defining HIM as only “medical records filing”—it also includes quality, compliance, privacy, and data use.
    • Calling “competency” a credential—competency is demonstrated ability, not a job title.

6.1.2 Primary vs. Secondary Health Data Sources and Databases

Start with the idea of “where the data came from”

In health information literacy, data source means the origin of the data. The key distinction:

  • Primary health data sources: data created as a direct result of patient care.
  • Secondary health data sources: data re-used for purposes beyond the immediate care encounter (often aggregated, coded, or derived from primary sources).

This matters because primary sources are closest to the patient story and are the strongest evidence of what happened. Secondary sources are incredibly useful—but they are only as accurate as the primary documentation and the abstraction/coding process.

Primary data sources (what they are and why they’re trusted)

Primary sources are produced during care delivery. They include:

  • Provider notes (history, exam, assessment, plan)
  • Nursing/assistant notes and clinical documentation
  • Diagnostic test results (labs, imaging reports)
  • Medication lists and e-prescribing records
  • Dental charting and periodontal charting
  • Consents, procedure notes, anesthesia/sedation documentation

Primary data tends to be the “court of record” for what was observed, decided, and done.

Secondary data sources (how data gets reused)

Secondary sources are created by taking information from primary records and reorganizing it for other functions—operations, reimbursement, public health, research, and quality improvement.

Common secondary sources include:

  • Billing/claims data (procedure codes, diagnosis codes, charges, payer responses)
  • Registries (e.g., immunization registries, disease registries)
  • Quality reporting datasets (performance measures built from chart data)
  • Administrative datasets (utilization, scheduling, productivity)
  • Research datasets (de-identified or consented data extracted from records)

A critical nuance: secondary data is not “less important,” but it can drift from reality if documentation is vague or coding is incorrect.

What “databases” means in this context

A database is a structured way to store and retrieve data. In healthcare offices, you may encounter:

  • An EHR database (clinical documentation, results, orders)
  • A practice management system database (appointments, billing, insurance)
  • A document management/scanning database (images of paper forms)
  • External databases (state immunization registry, payer portals)

The same patient encounter can create entries in multiple databases—one reason policies for consistency (patient identifiers, dates, version control) are so important.

Comparison table: primary vs. secondary
FeaturePrimary SourcesSecondary Sources
Created when?During patient careAfter/derived from care documentation
PurposeSupport diagnosis/treatment and continuity of careSupport billing, reporting, research, operations
ExamplesProgress notes, dental charting, lab reports, consentsClaims databases, registries, quality dashboards
Main risk if wrongDirect patient harmDenials, compliance issues, distorted reporting
Example: how one encounter becomes multiple data products

A patient visit for tooth pain produces:

  1. Primary: exam note, radiograph report, diagnosis, procedure note, consent.
  2. Secondary: claim with coded procedures/diagnoses, accounts receivable entry, productivity report.

If the primary record lacks detail (e.g., no documentation of medical necessity), the secondary claim may be denied—even if the procedure was appropriate.

Exam Focus
  • Typical question patterns:
    • Classify a listed item as a primary vs. secondary data source.
    • Identify which source is most defensible for “what happened” (usually primary documentation).
    • Explain why secondary data errors often trace back to primary documentation gaps.
  • Common mistakes:
    • Thinking “claims data” is primary—it is secondary (derived for payment).
    • Assuming “database” means only EHR—billing and document systems are databases too.
    • Forgetting that registries and quality reports often depend on accurate abstraction/coding.

6.1.6 Types and Content of Patient Health Records (and What Data They Collect)

What a patient health record is supposed to do

A patient health record is a structured collection of information that documents a patient’s health status and healthcare over time. No matter the format, a useful record must support:

  • Clinical care (safe, continuous, coordinated)
  • Communication (between providers, referrals)
  • Legal documentation (what was done and why)
  • Payment (substantiating billed services)

Different record types store similar categories of information but vary in ownership, accessibility, and how information is exchanged.

Paper-based records

A paper-based record is documentation kept on paper forms—often in a chart or folder. It may include handwritten notes, printed lab reports, signed consents, and paper billing forms.

Why it still matters: Many offices still have paper components (older archives, scanned documents, outside records received by fax). Understanding paper workflows helps you manage scanning, retention, and completeness.

Strengths and risks:

  • Strength: Can be straightforward to use in small settings.
  • Risks: Harder to share, easier to misfile, limited audit trails, handwriting legibility issues.

A classic problem in paper charts is that incomplete signatures or missing pages are difficult to detect until an audit or legal request occurs.

Electronic Medical Record (EMR) and Electronic Health Record (EHR)

People often mix these terms. In everyday office language they may be used interchangeably, but conceptually:

  • EMR is commonly used to mean an electronic record within one organization/practice.
  • EHR emphasizes a broader, more longitudinal record intended to support sharing across settings.

Regardless of label, electronic records typically include:

  • Patient demographics and identifiers
  • Problem list and medical/dental history
  • Allergies and medications
  • Clinical notes (HPI, exam findings, assessment/diagnosis, plan)
  • Orders and results (labs, imaging)
  • Procedure documentation (including materials used, tooth/surface details where relevant)
  • Immunizations (medical) and periodontal charting (dental)
  • Consents and advance directives (when applicable)
  • Care coordination (referrals, consults)
  • Billing interfaces (coding and claim generation may link to the clinical note)

Why electronic systems change documentation behavior: EHRs add templates, checkboxes, copy-forward features, and audit trails. These can improve standardization but also introduce new errors—like copying outdated information or relying on pre-filled text that doesn’t match the patient.

Personal Health Records (PHRs)

A Personal Health Record (PHR) is a health record managed by the patient, not the provider. It can be a paper folder, a patient portal view, or an app where the patient stores immunizations, medications, allergies, and visit summaries.

Why it matters in office practice: Patients increasingly arrive with app-based histories or portal printouts. PHRs can improve accuracy (med lists, past procedures) but can also contain unverified entries. Your job is to treat PHR information as helpful input—then confirm and document verification appropriately.

Clearinghouses (and how they relate to “records”)

A clearinghouse in healthcare usually refers to an entity/service that routes and processes electronic transactions, especially insurance claims, between providers and payers. Clearinghouses commonly:

  • Validate claim formatting and required fields
  • Scrub claims for common errors
  • Transmit claims to payers and return responses (rejections, remittance advice)

Key point: A clearinghouse is not the same thing as the clinical health record, but it produces and stores transaction data connected to the patient’s care (dates of service, billed codes, payer responses). Understanding clearinghouses helps you link documentation quality to reimbursement outcomes.

What data is collected in a typical patient record

Although details differ between medical and dental settings, most records include:

  • Administrative/demographic data: name, DOB, contact info, emergency contact, insurance.
  • Clinical history: medical history, dental history, family history, social history as appropriate.
  • Clinical findings: vitals (medical), exam findings, charting (dental).
  • Diagnoses/assessment: working and confirmed diagnoses.
  • Plan of care: treatments planned, patient instructions, follow-up.
  • Treatment/procedure documentation: what was done, when, by whom, materials/medications, site/tooth details.
  • Consents and authorizations: treatment consent, HIPAA acknowledgments, release forms.
  • Communication: referrals, consult notes, phone calls, portal messages (per policy).
  • Financial/insurance data (often in linked systems): codes, charges, payments, EOB/ERA.
Example: why “content” matters, not just having a note

Two notes can look equally complete on the surface, but only one supports care and payment.

  • Weak: “Tooth extraction performed. Patient tolerated well.”
  • Stronger: Documents indication/diagnosis, which tooth, anesthesia details, complications (or none), post-op instructions, and follow-up plan.

The second note is more clinically useful and more defensible if questioned.

Exam Focus
  • Typical question patterns:
    • Compare paper vs. electronic records using advantages/risks (legibility, access, audit trail).
    • Identify which record is patient-managed (PHR) vs. provider-managed (EHR/EMR).
    • Explain what a clearinghouse does in the claim workflow and how it differs from the health record.
  • Common mistakes:
    • Saying a clearinghouse “stores the patient’s full medical record”—it typically processes transactions, not clinical documentation.
    • Assuming templates guarantee quality—auto-text can create inaccuracies if not edited.
    • Ignoring that dental records require precise site/tooth/surface documentation for clarity and billing.

6.1.7 External Health Record Documentation Requirements (Agencies, Organizations, and Standards)

Why external requirements exist

Healthcare documentation isn’t just an internal preference—it is influenced by outside organizations that set expectations for safety, legality, quality, and payment. External requirements matter because they can trigger:

  • Reimbursement denials or take-backs
  • Licensure/credentialing problems
  • Legal exposure
  • Accreditation findings and corrective action plans

A practical way to think about it is: external agencies define the “rules of the road,” and your office policies operationalize them.

Major categories of external requirements
Accrediting bodies

Accrediting bodies evaluate organizations against published standards. Accreditation can be required for certain facilities or can be important for reputation and payer participation.

What documentation-focused standards often emphasize:

  • Completeness of records (history, assessment, plan)
  • Authentication (signatures/credentials)
  • Timeliness (entries made promptly)
  • Documentation of informed consent and patient rights
  • Quality and safety processes (incident documentation, follow-up)

Even if a small office is not directly accredited like a hospital, many best practices in documentation are influenced by accreditation-style standards.

Regulatory bodies

Regulatory bodies are government agencies that enforce laws and regulations. Their requirements can affect:

  • Privacy and security of health information (e.g., HIPAA in the U.S.)
  • Record retention rules (often state-specific)
  • Scope-of-practice rules (what different licensed professionals can do and document)
  • Required reporting (certain infectious diseases, immunizations, etc., depending on jurisdiction)

Regulatory expectations often show up in documentation rules like: protect access, document disclosures, maintain audit trails, and ensure accurate patient identification.

Professional review organizations and audits

Organizations that perform utilization review, quality review, or peer review examine records to decide whether care was appropriate, necessary, and documented.

In many payer contexts, reviews focus on:

  • Medical necessity: Was the service justified by the documented condition?
  • Level of service: Does documentation support what was billed?
  • Continuity: Do notes show reasoning, response to treatment, and follow-up?

A common failure point is when the clinician did appropriate care but the record doesn’t show the “why,” so reviewers cannot confirm necessity.

Licensure requirements

State boards and licensure rules (medical, dental, hygiene, assisting) influence documentation by requiring that:

  • Services are performed and recorded by appropriately licensed/authorized individuals
  • Supervision requirements are reflected when relevant
  • Certain procedures include specific documentation elements (varies by discipline and jurisdiction)

A frequent misconception is that licensure is “separate” from records. In reality, documentation is one of the main ways a board can evaluate whether practice stayed within scope.

Reimbursement requirements (payers)

Payment systems (public and private) require documentation that supports:

  • Correct patient and date of service
  • Covered benefit and eligibility (administrative side)
  • Correct coding and billing rules
  • Medical necessity and appropriate diagnosis linkage
  • Required supporting details (procedure specifics, prior authorization when required)

This is where documentation and coding meet: the record must contain the clinical story that makes the billed codes believable and compliant.

Discipline-specific standards and evidence-based practice

Different disciplines require different content to be meaningful. For example:

  • Dental documentation often needs tooth number/surface, periodontal charting, radiographs, and materials used.
  • Medical documentation may focus more on differential diagnosis, chronic condition monitoring, and medication management.

Evidence-based good practice influences documentation by encouraging clear rationales: you document not only what you did, but why it fits the patient’s condition and accepted practice standards.

Example: external requirements in action

A payer requests records for a claim review. If your note includes diagnosis/assessment, exam findings, and plan linked to the billed procedure, it is much easier to defend. If the note is missing the assessment or the patient-specific details (only a template), the payer may decide documentation does not support the service—even if it was performed.

Exam Focus
  • Typical question patterns:
    • Identify which external force is involved (regulatory vs. accrediting vs. payer).
    • Apply “medical necessity” logic: what documentation elements must be present to justify billing.
    • Scenario questions about audits: what would reviewers look for in the record?
  • Common mistakes:
    • Treating “documentation for care” and “documentation for billing” as separate—good documentation supports both.
    • Assuming a signature alone is enough—authentication also involves credentials, date/time, and integrity of the entry.
    • Overrelying on generic templates that don’t show patient-specific decision-making.

6.1.8 Internal Documentation Requirements: Office Policies and Procedures

Why internal policies exist (even when external rules already exist)

External rules are often broad. Internal policies and procedures translate those broad expectations into consistent daily practice in your specific office. Without internal standards, documentation becomes inconsistent across staff and providers—creating safety risks and compliance problems.

Think of internal policy as the office’s “how we do it here” guide that ensures everyone documents in a way that is:

  • Legible/understandable
  • Complete and timely
  • Secure and properly shared
  • Standardized enough for reporting and billing
Typical internal documentation requirements (what you usually see)
Standards for content and format

Offices often standardize:

  • Required fields for new patient intake
  • Required components of clinical notes (history, exam, assessment, plan)
  • Documentation elements for common procedures (e.g., anesthesia type, tooth number, materials)
  • Where certain information must be entered (problem list vs. note vs. messaging)

This reduces the risk that critical data is “somewhere in the chart” but not findable.

Timeliness rules

Policies often state when documentation must be completed (for example, same day or within a set period). Timeliness matters because delayed documentation is more likely to be inaccurate and less defensible.

A subtle issue: some systems allow saving drafts. Internal policy typically clarifies when a note counts as completed and available for care coordination.

Authentication and responsibility

Internal rules usually cover:

  • Who can enter which types of documentation
  • Who must sign/attest to notes
  • How to handle verbal orders or delegated documentation (as applicable)
  • Use of credentials and co-sign requirements

This protects against situations where someone documents outside their role or a note lacks a responsible provider.

Approved abbreviations and error prevention

Many organizations maintain lists of approved abbreviations to reduce misinterpretation. Internal policy may also address:

  • Avoiding ambiguous terms
  • Using standardized terminology in templates
  • Double-checking patient identity before documenting

A common real-world failure is documenting in the wrong patient chart—policies often require verifying at least two identifiers before entry.

Corrections, amendments, and late entries

Internal procedures should teach you how to correct errors without compromising record integrity. Good practice typically avoids deleting original content in a way that hides the history. Instead, the process usually involves:

  • Clearly labeling an amendment/correction
  • Dating/timing and authenticating the correction
  • Explaining what was wrong and what is now correct

The key concept is transparency: records should show what changed and who changed it.

Scanning and document management

If paper documents are scanned into an electronic system, internal procedures often define:

  • How to label documents (date, type, author)
  • Quality checks (legible scan, all pages present)
  • What to do with originals (retain vs. shred per policy)
  • How to handle external records (faxed referrals, outside radiographs)

Poor scanning practices create “legal-looking” charts that are functionally useless because documents are mislabeled or unreadable.

Privacy, access, and release-of-information workflows

Internal policies typically specify:

  • Role-based access (who can see what)
  • How to respond to patient requests for records
  • How to document disclosures (what was released, to whom, when, and why)
  • Secure communication rules (portal vs. email vs. phone)

Even when laws set the baseline, internal procedures make sure the office can execute requests consistently.

Downtime and contingency procedures

If the EHR goes down, offices need a plan for:

  • How to document care temporarily
  • How to enter data later (and label it correctly)
  • How to prevent loss of orders/results

Downtime documentation is a common audit problem—entries made later must still be accurate, traceable, and properly timed/labeled.

Example: internal policy preventing a compliance issue

If policy requires documenting the procedure site/tooth in a specific field, it reduces the risk that billing submits a claim missing required specificity. This is a practical example of how internal rules prevent downstream denials.

Exam Focus
  • Typical question patterns:
    • Scenario questions asking which internal policy applies (corrections, abbreviations, scanning, timeliness).
    • Identify the purpose of role-based access and documentation authentication.
    • Explain why downtime procedures are necessary and what they should include.
  • Common mistakes:
    • Thinking internal policies are optional—on exams, they are often treated as required for compliance.
    • Believing “fixing” a note means deleting—good practice is transparent amendments.
    • Overlooking scanning quality and labeling as part of record integrity.

6.1.9 Applying Policies and Procedures for Compliance (Including Medicare, Medicaid, and Other Third-Party Payers)

What “compliance” means in everyday office terms

Compliance means the office consistently follows applicable laws, regulations, payer rules, and internal policies. In health information literacy, compliance focuses on the record as proof that:

  • Care was provided appropriately
  • Documentation is accurate and complete
  • Billing is supported by the clinical record
  • Privacy and security protections were followed

A useful mindset is: compliance is not just “avoiding trouble.” It is how you create a trustworthy record that supports safe care and proper payment.

How payer compliance connects to documentation

Medicare, Medicaid, and other third-party payers generally require that claims be supported by documentation showing:

  • The service occurred (date, provider, patient)
  • The service was medically necessary (or dentally necessary, depending on benefit)
  • The service matches what was billed (correct codes and required details)
  • Any special requirements were met (e.g., prior authorization when required, appropriate referrals)

While exact rules vary by payer and service, the core logic is consistent: if it isn’t documented, it can’t be verified.

Step-by-step: applying policies to stay compliant
1) Document with “audit eyes”

A strong approach is to document as if an outside reviewer will read the record later with no background knowledge. That means your note should clearly answer:

  • What was the patient’s problem/need?
  • What did you find (objective/supporting details)?
  • What did you decide (assessment/diagnosis)?
  • What did you do (procedure/treatment)?
  • What instructions/follow-up did you provide?

This doesn’t mean writing excessively long notes—it means writing notes that connect decisions to evidence.

2) Use correct workflows for orders, results, and communications

Compliance is not only what you write, but where and how you document it. Following workflow policies helps ensure:

  • Results are routed to the right clinician
  • Critical results are acknowledged and acted upon
  • Patient communications are recorded appropriately

A common compliance breakdown is handling significant clinical communication “off the record” (e.g., personal email) instead of using approved systems.

3) Follow coding/billing support procedures

Even if you are not the coder, your documentation affects coding accuracy. Compliance-friendly documentation includes:

  • Specificity (site, laterality, tooth/surface, units, complexity when relevant)
  • Clear linkage between diagnosis/assessment and procedures performed
  • Documentation of supplies/medications administered when required

Many offices use internal tools such as charge capture sheets, claim scrubbers, or coding prompts. These are not a substitute for documentation; they are reminders to document what supports the codes.

4) Handle corrections properly

Corrections must protect record integrity. Compliance procedures typically require:

  • No “silent” changes that hide the original documentation
  • Clear identification of what is being corrected and why
  • Proper authentication and timestamps

Silent edits are risky because audit trails can reveal them and raise integrity concerns.

5) Protect privacy and security as part of compliance

Compliance includes ensuring only authorized access to records and proper release processes. Applying policy here looks like:

  • Using role-based access appropriately (no “shared logins”)
  • Verifying identity before releasing information
  • Documenting disclosures according to policy
  • Using secure channels for patient information

Security lapses can become compliance violations even if clinical documentation is perfect.

6) Monitor and improve: audits, training, and corrective action

Organizations stay compliant through continuous reinforcement:

  • Internal audits (documentation completeness, signature compliance, coding support)
  • Education and competency checks (new staff onboarding, annual refreshers)
  • Denial tracking (identify documentation-related denial patterns)
  • Corrective action (policy updates, template changes, focused retraining)

Denials and audit findings are not just administrative headaches—they are feedback that the record is not reliably telling the care story in a way external reviewers accept.

Example: avoiding a denial with better documentation linkage

If a claim is billed for a higher-complexity visit or a more involved procedure, the payer may request records. Documentation that supports compliance typically includes:

  • Patient complaint and relevant history
  • Exam findings
  • Clinical rationale for chosen treatment
  • Specific details of what was done

A frequent reason for denial is a note that lists a procedure but doesn’t document the findings or necessity that led to it.

Common payer-related compliance pitfalls (and how policy prevents them)
  • Cloned notes/copy-forward without updates: Policies may require editing templates so documentation reflects the current visit.
  • Missing signatures/credentials: Authentication policies prevent “unsigned note” vulnerabilities.
  • Mismatched dates or wrong patient chart: Patient identification procedures and encounter verification reduce these high-risk errors.
  • Insufficient specificity: Procedure documentation standards (including dental site/tooth details) help ensure claims match the record.
Exam Focus
  • Typical question patterns:
    • Scenario-based questions: choose which policy step prevents a compliance issue (signature, correction, privacy, specificity).
    • Identify what documentation supports payer reimbursement (medical necessity, linkage of diagnosis to service).
    • Explain how internal audits and denial management improve compliance.
  • Common mistakes:
    • Treating compliance as “billing only”—it includes privacy/security and record integrity.
    • Thinking a claim scrubber or clearinghouse “fixes” missing clinical documentation—it can’t create medical necessity.
    • Believing late documentation is harmless—timeliness affects credibility and audit outcomes.