RHIA Compliance, Privacy, and Security 2 — Questions and Answers
Question 1: What is the purpose of a healthcare compliance program?
- Maximize reimbursement by selecting optimal DRGs
- Prevent, detect, and correct violations of laws, regulations, and internal policies (Correct answer)
- Manage patient satisfaction scores
- Oversee physician credentialing
Correct answer: Prevent, detect, and correct violations of laws, regulations, and internal policies
A healthcare compliance program establishes policies, training, and monitoring mechanisms to prevent, detect, and correct legal and regulatory violations.
Question 2: Under the Anti-Kickback Statute (AKS), which arrangement is prohibited?
- A hospital employing full-time physicians on salary
- Offering remuneration to induce referrals of items or services covered by federal health programs (Correct answer)
- Providing free educational seminars to medical staff
- Participating in a Medicare ACO
Correct answer: Offering remuneration to induce referrals of items or services covered by federal health programs
The AKS prohibits knowingly offering, paying, soliciting, or receiving remuneration to induce or reward referrals of items or services reimbursable by federal healthcare programs.
Question 3: What is the Stark Law (Physician Self-Referral Law) designed to prevent?
- Physicians from practicing in multiple states
- Physicians from referring patients to entities in which they have a financial relationship, unless an exception applies (Correct answer)
- Hospitals from owning physician practices
- Physicians from accepting gift cards from patients
Correct answer: Physicians from referring patients to entities in which they have a financial relationship, unless an exception applies
The Stark Law prohibits physicians from referring Medicare/Medicaid patients to entities with which the physician or immediate family member has a financial relationship, unless a specific exception applies.
Question 4: Which federal agency has primary authority to investigate and prosecute healthcare fraud and abuse?
- The Joint Commission
- The Office of Inspector General (OIG) of HHS (Correct answer)
- The American Hospital Association
- CMS directly
Correct answer: The Office of Inspector General (OIG) of HHS
The OIG of HHS has primary authority to investigate healthcare fraud, issue exclusions from federal programs, and impose civil monetary penalties on violators.
Question 5: What is a compliance audit in a health information management context?
- An annual financial audit of hospital accounts
- A systematic review of coded claims and documentation to assess accuracy and regulatory compliance (Correct answer)
- A HIPAA security vulnerability assessment
- A review of patient satisfaction data
Correct answer: A systematic review of coded claims and documentation to assess accuracy and regulatory compliance
A compliance audit in HIM systematically reviews coded claims and supporting documentation to identify errors, inconsistencies, and potential regulatory violations.
Question 6: Under HIPAA, what are the four tiers of civil money penalties for violations?
- Warning, fine, suspension, exclusion
- Unknowing violation, reasonable cause, willful neglect corrected, willful neglect not corrected (Correct answer)
- Minor, moderate, major, critical
- Level 1, Level 2, Level 3, Level 4
Correct answer: Unknowing violation, reasonable cause, willful neglect corrected, willful neglect not corrected
HIPAA civil penalties are tiered based on culpability: unknowing violation, reasonable cause, willful neglect that is corrected, and willful neglect that is not corrected — with escalating penalty amounts.
What is the purpose of a healthcare compliance program?