CPCS FREE CPCS Knowledge Questions and Answers 2 — Questions and Answers
Question 1: What is the role of the Federation of State Medical Boards (FSMB) in the credentialing process?
- FSMB licenses physicians directly and replaces state medical boards
- FSMB maintains databases of physician licensure information and disciplinary actions that can be used for PSV (Correct answer)
- FSMB accredits hospital credentialing programs
- FSMB manages the NPDB on behalf of HRSA
Correct answer: FSMB maintains databases of physician licensure information and disciplinary actions that can be used for PSV
The FSMB maintains centralized databases of physician license and disciplinary information across all state medical boards, which can be used as a resource for primary source verification.
The Federation of State Medical Boards (FSMB) is a national organization representing the 71 U.S. and territorial medical and osteopathic boards. FSMB maintains the DocInfo database, which contains information on physician licenses, adverse actions, and disciplinary history from member boards. The FSMB Physician Data Center can be used by credentialing organizations as a resource for license verification and disciplinary history. The FSMB does not replace individual state medical boards but provides a centralized information resource. FSMB also administers the USMLE.
Question 2: Which of the following is a key difference between 'occurrence-based' and 'claims-made' malpractice insurance policies for credentialing purposes?
- Occurrence-based policies cost more but are otherwise identical
- Claims-made policies cover claims filed during the policy period regardless of when the incident occurred; occurrence-based policies cover incidents that occurred during the policy period regardless of when the claim is filed (Correct answer)
- Claims-made policies are only available to board-certified physicians
- There is no practical difference for credentialing purposes
Correct answer: Claims-made policies cover claims filed during the policy period regardless of when the incident occurred; occurrence-based policies cover incidents that occurred during the policy period regardless of when the claim is filed
Occurrence-based policies cover incidents that occurred during the policy period (even if the claim is filed later), while claims-made policies cover only claims filed while the policy is active, creating a 'tail' coverage concern when the policy ends.
Understanding malpractice insurance policy types is important for credentialing specialists. Occurrence-based policies provide coverage for any incident that occurred during the policy period, even if the claim is filed years after the policy has ended, no tail coverage is needed. Claims-made policies only cover claims filed while the policy is active; when the policy ends, claims arising from incidents during the policy period are not covered unless the practitioner purchases 'tail' coverage (extended reporting endorsement). Credentialing specialists should verify that practitioners with claims-made policies have appropriate tail coverage when changing carriers.
Question 3: A hospital is implementing a new electronic health records (EHR) system and plans to link it to the credentialing database to automatically check that only credentialed practitioners are ordering and documenting care. This type of integration is an example of which quality improvement concept?
- Peer review
- Privileging automation
- Hard stop / forcing function (Correct answer)
- Continuous monitoring
Correct answer: Hard stop / forcing function
Linking the EHR to the credentialing database to block non-credentialed practitioners from ordering or documenting is a 'hard stop' or 'forcing function', a system design that makes it physically impossible to do the wrong thing.
In patient safety and quality improvement, a 'forcing function' or 'hard stop' is a system design that makes it impossible (or very difficult) to proceed with an unsafe action. Linking the EHR to the credentialing database to prevent non-credentialed practitioners from ordering medications, procedures, or documentation is a classic forcing function, the system enforces credentialing compliance automatically without relying on manual checks. This is more reliable than soft stops (warnings that can be overridden) and reflects best practices in human factors engineering applied to healthcare credentialing.
Question 4: Which of the following organizations administers the ABMS Continuing Certification (formerly Maintenance of Certification) program?
- ACGME
- ABMS and its member specialty boards (Correct answer)
- The Joint Commission
- NAMSS
Correct answer: ABMS and its member specialty boards
The American Board of Medical Specialties (ABMS) and its 24 member specialty boards administer the Continuing Certification (formerly MOC) programs for their respective specialties.
ABMS Continuing Certification (formerly called Maintenance of Certification or MOC) is administered by the ABMS and each of its 24 member specialty boards. The program requires physicians to demonstrate ongoing professional development and competency through a combination of learning, quality improvement activities, and periodic assessment. The specific requirements vary by specialty board. For credentialing purposes, verifying ABMS Continuing Certification status through the ABMS Certification Matters website (certificationmatters.org) confirms whether a physician's certification is current or has lapsed.
Question 5: Under the Health Insurance Portability and Accountability Act (HIPAA), a health plan sharing credentialing information with a hospital about a mutual network practitioner is most likely covered under which HIPAA provision?
- Treatment, Payment, or Healthcare Operations (TPO) (Correct answer)
- Minimum Necessary Disclosure
- Business Associate Agreement
- De-identification Safe Harbor
Correct answer: Treatment, Payment, or Healthcare Operations (TPO)
Sharing credentialing information (a healthcare operations activity) between covered entities about their mutual practitioners falls under HIPAA's 'Treatment, Payment, or Healthcare Operations' (TPO) exception, which permits information sharing without individual authorization.
HIPAA's Privacy Rule permits covered entities to use or disclose PHI for treatment, payment, or healthcare operations without patient authorization. Credentialing is specifically identified as a healthcare operations activity under HIPAA. However, it is important to note that credentialing files contain practitioner information, not patient PHI, so HIPAA's patient privacy provisions generally do not directly apply to practitioner credentials. For practitioner health information that does fall within HIPAA definitions, the healthcare operations exception would apply to information sharing for credentialing purposes between covered entities.
Question 6: A credentialing specialist at a large health plan is told that the organization has decided to stop querying the NPDB at recredentialing to save costs. What should the specialist do?
- Follow the directive since management has authority over credentialing policy
- Document the concern, explain that NPDB queries at recredentialing are required by NCQA and CMS standards, and escalate through appropriate channels if the directive stands (Correct answer)
- Proceed but query the NPDB informally on a personal basis
- Resign because this makes the organization's credentialing non-compliant
Correct answer: Document the concern, explain that NPDB queries at recredentialing are required by NCQA and CMS standards, and escalate through appropriate channels if the directive stands
NPDB queries at recredentialing are required by NCQA, URAC, and CMS standards. The specialist should professionally document the concern, explain the compliance implications, and escalate through appropriate channels.
The credentialing specialist has a professional and ethical responsibility to raise compliance concerns when organizational decisions would violate accreditation standards or regulatory requirements. NPDB queries at recredentialing are specifically required by NCQA CR 3, URAC standards, and for hospitals, CMS Conditions of Participation. The appropriate response is to: (1) document the concern in writing, (2) clearly articulate the specific standards requiring NPDB queries, (3) explain the compliance consequences (potential loss of accreditation, CMS sanctions, FCA liability), and (4) escalate to legal counsel, compliance department, or senior leadership if the directive stands. Professional escalation, not silent compliance or resignation, is the appropriate response.
What is the role of the Federation of State Medical Boards (FSMB) in the credentialing process?