HAC Healthcare Analyst Risk Assessment & Compliance 2 โ Questions and Answers
Question 1: Which federal law requires healthcare organizations to implement administrative, physical, and technical safeguards to protect electronic PHI?
- HITECH Act
- HIPAA Security Rule (Correct answer)
- Stark Law
- False Claims Act
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically mandates administrative, physical, and technical safeguards for electronic protected health information (ePHI).
Question 2: A healthcare analyst discovers that a vendor accessing patient data has not signed a Business Associate Agreement (BAA). What is the primary compliance risk?
- Violation of the Stark Law
- HIPAA breach due to unauthorized PHI disclosure (Correct answer)
- Medicare fraud under the False Claims Act
- Violation of the Anti-Kickback Statute
Correct answer: HIPAA breach due to unauthorized PHI disclosure
Without a signed BAA, any vendor access to PHI constitutes an unauthorized disclosure under HIPAA, creating significant breach liability.
Question 3: In healthcare risk assessment, what does the term 'residual risk' refer to?
- Risk eliminated after controls are applied
- Risk remaining after mitigation controls are implemented (Correct answer)
- Risk transferred to a third-party insurer
- Inherent risk before any analysis
Correct answer: Risk remaining after mitigation controls are implemented
Residual risk is the level of risk that remains after an organization has applied its risk management and mitigation controls.
Question 4: Which CMS program penalizes hospitals for excessive rates of hospital-acquired conditions (HACs)?
- Hospital Value-Based Purchasing Program
- Hospital Readmissions Reduction Program
- HAC Reduction Program (Correct answer)
- Merit-based Incentive Payment System
Correct answer: HAC Reduction Program
The CMS Hospital-Acquired Condition (HAC) Reduction Program penalizes hospitals in the worst-performing quartile for HAC rates with a 1% payment reduction.
Question 5: An analyst is assessing compliance risk related to physician self-referrals. Which law is most directly applicable?
- Anti-Kickback Statute
- Stark Law (Physician Self-Referral Law) (Correct answer)
- False Claims Act
- Emergency Medical Treatment and Labor Act
Correct answer: Stark Law (Physician Self-Referral Law)
The Stark Law (42 U.S.C. ยง 1395nn) directly prohibits physicians from referring Medicare patients to entities with which they have a financial relationship unless an exception applies.
Question 6: What is the purpose of a healthcare organization's compliance hotline?
- To report billing codes to CMS directly
- To provide an anonymous channel for reporting suspected violations (Correct answer)
- To communicate regulatory updates to staff
- To submit prior authorization requests to payers
Correct answer: To provide an anonymous channel for reporting suspected violations
A compliance hotline provides employees with a confidential or anonymous mechanism to report suspected fraud, waste, abuse, or other compliance violations without fear of retaliation.
Question 7: Under OIG guidelines, which element is NOT one of the seven components of an effective compliance program?
- Written policies and procedures
- Designated compliance officer
- Mandatory profit-sharing agreements with physicians (Correct answer)
- Effective lines of communication
Correct answer: Mandatory profit-sharing agreements with physicians
The OIG's seven compliance program components do not include physician profit-sharing; they focus on policies, training, communication, auditing, enforcement, and response to detected offenses.
Which federal law requires healthcare organizations to implement administrative, physical, and technical safeguards to protect electronic PHI?