Security Flashcards

1
Q

What is the Ser Master file?

A

````````````The provider (SER) master file can be thought of as a directory of clinicians and resources affiliated with your organization. The provider master file includes one record for every clinician who provides care to your patients, as well as other schedulable resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is clinical authority?

A

A person’s provider record also records their clinical authority, including whether they can:
Authorize medications or other orders
write orders in the hospital
admit or attend on patients

A provider record is also used to track referrals to or from a particular provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False: There is one provider (Ser) record for each person or resource meeting?

A

True, there is one provider (ser) record or each person or resource meeting ANY of the following criteria:
* C has credentials
*A Authorizes orders
*R Can be referred to or send referrals
*S- Can be scheduled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the EMP Master file?

A

The User master file contains one record for every person who logs into your instance of EPIC. your user records contain your login ID and password and links to security settings that determine what functionality you can access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

If someone needs to log into the system to complete their job, what user do they use?

A

They need a user record.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What type of templates are EMP records?

A

User templates are EMP records that are used to configure groups of users. they allow for build and maintenance of user settings in one location that is linked to by other user records. For instance, all inpatient nurses can be assigned the same template which controls their security, user role, and more. If a change is needed, it can be made once in the template instead of needing to update each nurses user record individually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the ECL master File?

A

It is security and it is used to give access or permission to activities and information within EPIC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Security (ECL) do?

A

Security is used to give access or permission to activities and information within EPIC.

  • Video-They collect information about what a user is able to do. It is a key ring/card lets people do things. access to functionality. Depending on the security class, it lets you run reports, edit criteria, create public report columns, edit query template.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the two key security concepts:

A

Security points and Security class

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does security point do?

A

Security point grants access to one feature within epic. Think of these like a key that grants you access to one room.

If a user has a security point, they have access to an activity. if they do not have the required security point, then the activity will not be available to them; they wont even see it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does security class do?

A

security class does grouping of security points that grant access to related activities and functionality in an epic application. Think of this as a ring of keys.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False: security classes are application specific?

A

True, security classes are application specific and attach to a user or template record. Any given user could have upwards of 15- different key rings (Security classes) depending on their job responsibilities. The more applications they need to access, the more security classes they will have.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a user role (E2R)?

A

The user role record defines the visual appearance (or layout) of hyperspace. It works very closely with security in determining how a user can get to a given activity. It is attached to a user or template record and is required to log in to Hyperspace.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The Cogito form in the user security can be used across all of our tools to limit which data a user sees in their results. What are some examples of when these values ?

A

*Some slicerdicer data models require a user to have an authorized service area. Without one, the data model is completely inaccessible.

*SlicerDicer data models can filter results automatically using the service areas listed.

*Many workbench templates use required “Dynamic” Parameters that filter by these values whenever the report is run. This means two users running the same HRX would see different results cased on the values stored here.

*Dashboard summary level parameter selection is limited to the values stored here for all users viewing a dashboard.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

For user roles in the security section, what do user roles define?

A

The user role record defines the visual appearance (or layout) of hyperspace.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In the section of User Role (E2R), it talks about user role records, What are some things a role record controls?

A

Some of the controls are:
What startup open automatically upon logging into hyperspace

What buttons you have access your hyperspace toolbar and under the epic menu

How long the system will stay idle before logging you out.

17
Q

In a workbench report action security, what are the two main types of actions that can appear at the top of a report?

A

Activity based actions and extension based actions.

18
Q

In workbench report action security what is an activity based action?

A

An activity based action jumps the user to a place in hyperspace. This could be opening the patients chart, creating an encounter, or opening any other activity. These types of actions are assigned to the template in the template editor.

19
Q

In workbench report action security what is an extension-based action?

A

Extension based actions execute M code when click. This could include setting a flag in a record or populating data in a record.

20
Q

How would you assign extension based actions to templates and reports?

A

Assign extension-based actions to templates and reports on the actions tab of the analytics system settings activity.

21
Q

True or False: Extension based actions are records in the HGA master file?

A

True, extension based actions are records in the HGA master file. to view the action groups on an extension based action, find the record in the record viewer.

22
Q

What are report groups?

A

Report groups are the primary means of distributing cogito content.

23
Q

When is a user granted access to content?

A

A user is granted access to content if both of the following are true.

  • The user has a security class that grants them the appropriate functionality to view/run that content.
  • the user and content share at least one report group.
24
Q

How would you determine who may see a template and its reports?

A

Assigning a report group to a template is just one part of making a template available to users. For a template to be available. it must be configured. For a template to be configured, it must have:

*One report type assign to it
*at least one report group.

25
Q

True or False: You can assign report groups at the report level instead of the template level?

A

True, you are able to assign report groups at the report level instead of the template level if the use in the group should not have access to all reports made from a template.

26
Q

True or False: Do groups assigned at the report level override the groups set at the template level?

A

True, groups that are assigned at the report level override the groups set at the template level for that report. Groups assigned at the eport level often lead to more long term maintenance.

27
Q

Where can you assign a report group to a public report?

A

You can do this in the metadata editor in the analytics catalog. You can also do so in the report settings window while editing the report. On the general tab, in the report access section, you can see the report groups inherited from the template and add in report level overrides.

28
Q

True or False: You cannot distribute dashboards to large groups of users with the same report group or user type?

A

False, you can distribute dashboards to large groups of users with the same report groups or user type, and/or assign individual dashboards to specific users for ease of setup and maintenance.

29
Q

How would you distribute dashboards by report groups?

A

You can assign report groups to dashboards either by:
*Editing the dashboard’s details in the metadata editor or
*listing the report group on the access form in the dashboard editor.

30
Q

What are User Types?

A

Epic builds and maintains user types. They are used to broadly describe a user’s responsibilities and capabilities in the system. For most users, the system automatically assigns user types upon login, but your organization can also explicitly assign user types to user records.

31
Q

How would you distribute dashboards by User Types?

A

Assign user types to dashboards in the same places that you assign report groups.

32
Q

What happens when a user and a dashboard share a user type?

A

If a user and a dashboard share a user type, the user can access the dashboard.

33
Q

True or False: you can distribute dashboards by User Security?

A

True, sometimes report groups and user types are insufficient for your desired dashboard distribution strategy. Setting up access to dashboards through user records or user templates is another option to distribute dashboards.

34
Q

True or False: You grant access to a dashboard to the individual user record?

A

True, to grant access to a dashboard on the individual user record, you must access the Radar form of the users record in User Security.

35
Q

True or False: If a user and a component share any report group or user type, the user can add the component to the main dashboard?

A

False, the user can add the component to the dashboard view not the main dashboard.

36
Q

Where would you assign report groups in a component?

A

Assign report groups and user types to components in the metadata editor or on the distribution form of the component editor.

37
Q

True or False: A builder can add any component to a source dashboard, regardless of the report groups?

A

From the designer UI or the dashboard editor, a builder can add any component to a source dashboard, regardless of the report groups attached to that component or user. Report groups only control what components a user can add to their own dashboard views?

38
Q

True or False: report groups do not control what components a user can add to their own dashboard views?

A

False, Report groups only control what components a user can add to their own dashboard views. If a user and a component share any report group or user type, the user can add the component to any dashboard view.