← All CBCS Flashcard Decks

Regulatory Compliance and HIPAA Flashcards

6 cards from real CBCS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Regulatory Compliance and HIPAA flashcards as text
  1. A billing specialist notices a pattern of a specific provider consistently using a higher-level evaluation and management (E/M) code for routine office visits, which is not supported by the medical documentation. Under which federal law could this practice be considered fraudulent?

    Answer: The False Claims Act (FCA)

    The False Claims Act (FCA) makes it illegal to knowingly submit false or fraudulent claims to a government healthcare program. Consistently billing at a higher code level than what is supported by the documentation, a practice known as 'upcoding,' is a classic example of a false claim because it seeks reimbursement for services that were not medically necessary at that level or not actually performed to that extent.

  2. A business associate of a covered entity discovers a breach of unsecured protected health information (PHI) affecting 600 individuals. According to the HIPAA Breach Notification Rule, what is the business associate's primary and most immediate responsibility?

    Answer: Notify the covered entity of the breach without unreasonable delay.

    The HIPAA Breach Notification Rule requires a business associate to notify the covered entity after discovering a breach of unsecured PHI. This notification must happen 'without unreasonable delay and in no case later than 60 days' following the discovery. It is then the covered entity's responsibility to notify the affected individuals, HHS, and potentially the media.

  3. Which of the following is an example of a 'technical safeguard' under the HIPAA Security Rule?

    Answer: Implementing unique user IDs and password requirements for EHR access.

    The HIPAA Security Rule mandates three types of safeguards: administrative, physical, and technical. Technical safeguards are technology-based and relate to the policies and procedures for its use that protect electronic PHI (ePHI) and control access to it. Implementing unique user IDs, passwords, and other access controls is a core requirement of the technical safeguards.

  4. A hospital owns a diagnostic imaging center. A physician employed by the hospital routinely refers their Medicare patients to this imaging center for services. This arrangement could potentially violate which of the following laws if no exception is met?

    Answer: The Stark Law

    The Stark Law, also known as the Physician Self-Referral Law, prohibits physicians from referring Medicare or Medicaid patients for 'designated health services' (DHS) to an entity with which the physician or an immediate family member has a financial relationship, unless an exception applies. In this scenario, the physician has a financial relationship (employment) with the hospital, which owns the imaging center (a provider of DHS).

  5. A patient's friend calls the billing office to ask about the details of a recent bill. The billing specialist, wanting to be helpful, confirms the patient's recent surgery date and the outstanding balance. This action is a violation of which HIPAA principle?

    Answer: The Minimum Necessary Standard

    The HIPAA Privacy Rule establishes the principle of 'minimum necessary,' which requires covered entities to make reasonable efforts to limit the use or disclosure of Protected Health Information (PHI) to the minimum necessary to accomplish the intended purpose. Disclosing details of a patient's bill and surgery to an unauthorized individual, like a friend, without the patient's explicit consent is a violation of their privacy and goes against this standard.

  6. A covered entity must notify the Secretary of HHS of a breach of unsecured PHI. If the breach affects fewer than 500 individuals, when must this notification be provided?

    Answer: No later than 60 days from the end of the calendar year in which the breach was discovered.

    According to the HIPAA Breach Notification Rule, if a breach of unsecured PHI affects fewer than 500 individuals, the covered entity may notify the Secretary of HHS on an annual basis. These notifications must be submitted no later than 60 days after the end of the calendar year in which the breaches were discovered.