Certified Compliance Technician (CCT) Exam — Questions and Answers
Question 1: The OIG's Compliance Program Guidance is considered:
- Mandatory for all healthcare providers, with criminal penalties for non-adoption.
- Applicable only to large hospital systems and not small physician practices.
- A voluntary framework that provides recommendations and best practices. (Correct answer)
- A set of regulations that is updated and re-issued annually by Congress.
Correct answer: A voluntary framework that provides recommendations and best practices.
The OIG's compliance program guidances are voluntary and not legally binding. They are intended to assist healthcare providers by providing a framework and suggestions for establishing effective internal controls to prevent fraud, waste, and abuse.
Question 2: What should compliance training documentation include to demonstrate program effectiveness?
- Attendance records, training content, and test scores (Correct answer)
- Vendor contracts
- Employee social security numbers
- Patient health information
Correct answer: Attendance records, training content, and test scores
Documenting attendance, content covered, and assessment results proves that training was conducted and comprehended.
Question 3: Which agency enforces the Foreign Corrupt Practices Act (FCPA) jointly with the Department of Justice?
- State Department
- FinCEN
- SEC (Correct answer)
- OFAC
Correct answer: SEC
The SEC and DOJ share FCPA enforcement jurisdiction — the SEC focuses on civil enforcement for issuers while DOJ handles criminal prosecution.
Question 4: A company's compliance program includes policies, but a risk assessment has never been conducted. Which fundamental program element is missing?
- Written policies and procedures
- Monitoring and auditing
- Risk assessment (Correct answer)
- Training and communication
Correct answer: Risk assessment
The DOJ and SEC regard periodic risk assessments as foundational — without identifying and prioritizing risks, other program elements cannot be properly tailored.
Question 5: Under the HIPAA Security Rule, an 'addressable' implementation specification means:
- It is optional and may be skipped
- The covered entity must assess whether it is reasonable and appropriate, and document the decision (Correct answer)
- It must be implemented exactly as written
- It applies only to large covered entities
Correct answer: The covered entity must assess whether it is reasonable and appropriate, and document the decision
Addressable specifications require covered entities to assess their applicability and either implement them, implement an alternative, or document why they are not reasonable and appropriate.
Question 6: Which of the following is the correct hierarchy of HIPAA civil monetary penalty tiers (lowest to highest culpability)?
- Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected (Correct answer)
- Unknowing → Willful neglect corrected → Reasonable cause → Willful neglect uncorrected
- Willful neglect corrected → Willful neglect uncorrected → Reasonable cause → Unknowing
- Reasonable cause → Unknowing → Willful neglect corrected → Willful neglect uncorrected
Correct answer: Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected
HIPAA penalty tiers escalate from unknowing violations, to reasonable cause, to willful neglect that is corrected, to willful neglect that is not corrected.
Question 7: What is 'key risk indicator' (KRI) primarily used for in compliance programs?
- Documenting past regulatory violations
- Providing early warning signals of increasing risk exposure (Correct answer)
- Replacing the need for periodic risk assessments
- Measuring the profitability of compliance investments
Correct answer: Providing early warning signals of increasing risk exposure
KRIs are metrics that signal when risk levels are trending toward or beyond acceptable thresholds, enabling proactive intervention.
Question 8: Under the False Claims Act, what is 'qui tam' litigation?
- A lawsuit filed by the DOJ directly against a healthcare provider
- A government audit of healthcare claims for potential overpayments
- A whistleblower lawsuit filed by a private individual on behalf of the government (Correct answer)
- An administrative appeal process for denied Medicare claims
Correct answer: A whistleblower lawsuit filed by a private individual on behalf of the government
Qui tam provisions of the False Claims Act allow private individuals (relators/whistleblowers) to file lawsuits on behalf of the government against those who defraud federal programs and share in any monetary recovery.
Question 9: Under an OIG-recommended compliance program, who bears primary responsibility for overseeing the compliance training program?
- The CEO
- The HR Director
- The Compliance Officer (Correct answer)
- The CFO
Correct answer: The Compliance Officer
The Compliance Officer is responsible for developing, implementing, and overseeing all aspects of the compliance training program.
Question 10: The Office of Foreign Assets Control (OFAC) operates under which federal department?
- Department of Homeland Security
- Department of Justice
- Department of the Treasury (Correct answer)
- Department of Commerce
Correct answer: Department of the Treasury
OFAC is a division of the U.S. Department of the Treasury responsible for administering economic and trade sanctions.
Question 11: Which of the following is a key element of ethical corporate governance?
- Secrecy in board meetings.
- Bias in promotions.
- Accountability and transparency (Correct answer)
- Favoritism in hiring.
Correct answer: Accountability and transparency
Accountability and transparency are cornerstones of ethical corporate governance. Accountability ensures that individuals and the organization are responsible for their actions and decisions, while transparency means that information is openly communicated to stakeholders. Together, they build trust, reduce the likelihood of misconduct, and enable informed decision-making by all parties.
Question 12: A compliance officer at a publicly traded company notices that their audit committee has a member who may not qualify as 'financially literate' under SOX. Which agency's rules define audit committee independence requirements for listed companies?
- PCAOB
- FASB
- SEC (Correct answer)
- Federal Reserve
Correct answer: SEC
The SEC implemented SOX Section 301 audit committee requirements, and stock exchanges impose additional independence and financial literacy standards under SEC-approved listing rules.
Question 13: Why is whistleblower protection essential in corporate governance?
- It encourages retaliation.
- It ensures ethical violations are hidden.
- It allows anonymous reporting without fear (Correct answer)
- It limits transparency.
Correct answer: It allows anonymous reporting without fear
Whistleblower protection is essential because it encourages individuals to report unethical or illegal activities without fear of retaliation. By providing a safe and anonymous channel for reporting, organizations can uncover misconduct that might otherwise remain hidden. This mechanism is vital for maintaining transparency, accountability, and the integrity of corporate governance.
Question 14: A Suspicious Activity Report (SAR) under the BSA must be filed within how many days of detecting suspicious activity?
- 60 days
- 15 days
- 30 days (Correct answer)
- 90 days
Correct answer: 30 days
Financial institutions must file a SAR with FinCEN within 30 calendar days of detecting a suspicious transaction (60 days if no suspect is identified initially).
Question 15: How should a compliance officer handle a situation where an employee claims they did not understand training material?
- Report to the OIG
- Provide additional one-on-one education and document the remediation (Correct answer)
- Terminate the employee
- Dismiss the concern
Correct answer: Provide additional one-on-one education and document the remediation
Providing remedial education and documenting it demonstrates good-faith effort to ensure employee comprehension.
Question 16: Under the Clean Air Act, what daily maximum civil penalty can EPA impose on a company for violations?
- $100,000 per day (Correct answer)
- $5,000 per day
- $10,000 per day
- $25,000 per day
Correct answer: $100,000 per day
EPA can seek civil penalties up to $100,000 per day for Clean Air Act violations, adjusted for inflation under the Civil Penalties Inflation Adjustment Act.
Question 17: Which scenario best demonstrates effective internal monitoring under the Seven Elements?
- Requiring department managers to self-certify compliance annually
- Posting the Code of Conduct in the employee break room
- Conducting an annual review of the compliance policy manual
- Running quarterly claims audits comparing billed codes to documentation (Correct answer)
Correct answer: Running quarterly claims audits comparing billed codes to documentation
Regular audits comparing billing codes to clinical documentation constitute active internal monitoring, the fifth element of an effective compliance program.
Question 18: When an organization updates its compliance policies due to a regulatory change, training on the new policy should occur:
- Three years after the change
- Only at the next annual training cycle
- Within a reasonable timeframe of the policy update (Correct answer)
- Only for managers
Correct answer: Within a reasonable timeframe of the policy update
Employees must be trained on policy changes within a reasonable period so they can immediately comply with updated requirements.
Question 19: Which entity has examination authority over third-party service providers that serve multiple federally regulated financial institutions?
- CFPB
- FINRA
- State banking regulators
- Federal Financial Institutions Examination Council (FFIEC) (Correct answer)
Correct answer: Federal Financial Institutions Examination Council (FFIEC)
The FFIEC coordinates examination authority over technology service providers and other third parties serving FFIEC member agency-regulated institutions.
Question 20: A compliance officer preparing a board report should PRIMARILY focus on which type of information?
- A comprehensive list of all employees who completed training
- Technical descriptions of each monitoring tool used
- Detailed transaction-level data from the past month
- Trending risk indicators, material exceptions, and corrective action status (Correct answer)
Correct answer: Trending risk indicators, material exceptions, and corrective action status
Board reports should provide decision-relevant information such as risk trends, significant exceptions, and status of remediation rather than granular operational data.
Question 21: Which fiduciary duty requires directors to act on an informed basis after adequate deliberation before making a business decision?
- Duty of obedience
- Duty of care (Correct answer)
- Duty of loyalty
- Duty of candor
Correct answer: Duty of care
The duty of care requires directors to act with the care of a reasonably prudent person, which includes being adequately informed before making decisions.
Question 22: Which scenario best illustrates a 'tone at the top' failure in corporate governance?
- A front-line employee submits a fraudulent reimbursement claim
- The compliance department fails to update its policy manual
- A vendor delivers goods late without penalty
- Senior executives routinely override expense approval controls (Correct answer)
Correct answer: Senior executives routinely override expense approval controls
Tone at the top refers to leadership's demonstrated commitment to ethical conduct; executives who override controls signal that rules do not apply to them, undermining the entire compliance culture.
Question 23: Which of the following is an example of a preventive control designed to reduce compliance risk?
- Performing quarterly audits of transaction records
- Conducting post-incident investigations after a policy breach
- Reviewing exception reports after transactions are processed
- Requiring management approval before a new vendor is onboarded (Correct answer)
Correct answer: Requiring management approval before a new vendor is onboarded
Preventive controls act before a risk event occurs; requiring approval before onboarding a vendor stops noncompliant vendors from entering the system.
Question 24: A compliance officer wants to proactively identify billing patterns that may attract a RAC audit. Which internal tool is MOST useful for this purpose?
- Provider Enrollment data review
- Internal claims data analytics and comparison against CMS edit libraries (Correct answer)
- HIPAA privacy impact assessment
- Staff credentialing file review
Correct answer: Internal claims data analytics and comparison against CMS edit libraries
Analyzing internal claims data against known CMS edits and national billing benchmarks helps identify outlier patterns before external auditors do.
Question 25: Under the Clean Air Act, which program requires facilities with large quantities of hazardous chemicals to develop risk management plans?
- Toxic Release Inventory (TRI)
- Emergency Planning and Community Right-to-Know (EPCRA)
- Risk Management Program (RMP) (Correct answer)
- Spill Prevention Control and Countermeasure (SPCC)
Correct answer: Risk Management Program (RMP)
EPA's Risk Management Program under Clean Air Act Section 112(r) requires facilities using regulated substances above threshold quantities to develop RMPs.
Question 26: Which of the following BEST describes the relationship between compliance training and a culture of compliance?
- Training replaces the need for written policies
- Training reinforces values and behaviors that build a sustained compliance culture over time (Correct answer)
- Culture is irrelevant to compliance
- Training alone creates a compliance culture
Correct answer: Training reinforces values and behaviors that build a sustained compliance culture over time
Training is one tool that, combined with leadership commitment and consistent enforcement, builds a lasting compliance culture.
Question 27: Which of the following is an example of a compliance record that must be maintained?
- Training attendance logs and completion certificates (Correct answer)
- Employee lunch orders
- Vendor holiday cards
- Personal employee emails
Correct answer: Training attendance logs and completion certificates
Training attendance logs and completion certificates are required compliance records demonstrating that education requirements were fulfilled.
Question 28: Under the False Claims Act, what is the meaning of 'reverse false claims'?
- Knowingly avoiding or concealing an obligation to pay money to the government (Correct answer)
- Claims submitted by government contractors rather than healthcare providers
- Whistleblower lawsuits filed against the government
- Claims that are corrected and resubmitted after an audit
Correct answer: Knowingly avoiding or concealing an obligation to pay money to the government
The 2009 Fraud Enforcement and Recovery Act clarified that reverse false claims cover situations where a person knowingly conceals or improperly avoids a financial obligation owed to the government, such as failing to return overpayments.
Question 29: A 'three lines of defense' model assigns the primary ownership of risk management to which line?
- Business unit management (Correct answer)
- Compliance and risk functions
- Board of directors
- Internal audit
Correct answer: Business unit management
The first line of defense consists of business unit management, who own and manage risks in day-to-day operations.
Question 30: Which agency enforces workplace anti-discrimination laws including Title VII of the Civil Rights Act for private sector employers?
- Department of Labor
- EEOC (Correct answer)
- Department of Justice
- OFCCP
Correct answer: EEOC
The EEOC investigates and enforces Title VII and other federal employment discrimination laws for private sector employers.
Question 31: A company identifies that a risk's likelihood is low but its potential impact is catastrophic. How should this risk typically be prioritized?
- Ignored until impact occurs
- Escalated and monitored closely due to high impact (Correct answer)
- Treated as low priority because probability is minimal
- Transferred without further analysis
Correct answer: Escalated and monitored closely due to high impact
High-impact risks require attention regardless of low probability because the potential harm to the organization can be severe or irreversible.
Question 32: Which federal law requires healthcare organizations to train employees on patient privacy as part of HIPAA compliance?
- HIPAA Privacy Rule (Correct answer)
- Anti-Kickback Statute
- Stark Law
- False Claims Act
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule mandates that covered entities train all workforce members on privacy policies and procedures.
Question 33: Under the Gramm-Leach-Bliley Act (GLBA), which agency enforces the Safeguards Rule for non-bank financial institutions not covered by a federal functional regulator?
- FTC (Correct answer)
- OCC
- CFPB
- SEC
Correct answer: FTC
The FTC enforces the GLBA Safeguards Rule for financial institutions not subject to oversight by a federal functional regulator such as a banking agency.
Question 34: Under the concept of 'corporate culture' in compliance, what does a 'speak-up culture' primarily aim to achieve?
- Requiring employees to report competitors' misconduct
- Encouraging employees to raise concerns without fear of retaliation (Correct answer)
- Empowering management to override employee objections
- Mandating public disclosure of all internal grievances
Correct answer: Encouraging employees to raise concerns without fear of retaliation
A speak-up culture creates psychological safety so employees report concerns internally, enabling the organization to detect and remediate issues before they escalate.
Question 35: What is the benefit of ethical leadership in an organization?
- It creates confusion among employees.
- It builds a positive and ethical culture (Correct answer)
- It reduces employee morale.
- It encourages unethical decisions.
Correct answer: It builds a positive and ethical culture
Ethical leadership sets the moral tone for an entire organization, inspiring employees to act with integrity and adhere to high ethical standards. Leaders who consistently demonstrate ethical behavior build a positive and trustworthy culture, which in turn enhances employee morale, loyalty, and overall organizational reputation. This fosters an environment where ethical decision-making is prioritized and rewarded.
Question 36: A bank holding company's compliance team needs guidance on Volcker Rule compliance. Which agencies jointly issued Volcker Rule regulations?
- SEC and CFTC only
- OCC and FDIC only
- Federal Reserve and OCC only
- Five agencies including Fed, OCC, FDIC, SEC, and CFTC (Correct answer)
Correct answer: Five agencies including Fed, OCC, FDIC, SEC, and CFTC
The Volcker Rule was implemented jointly by five federal agencies: the Fed, OCC, FDIC, SEC, and CFTC, reflecting its broad scope.
Question 37: An employee refuses to complete mandatory annual compliance training. What is the appropriate organizational response?
- Waive the requirement for that employee
- Enforce disciplinary action consistent with written policy (Correct answer)
- Notify the OIG immediately
- Ignore the refusal
Correct answer: Enforce disciplinary action consistent with written policy
Consistent enforcement of training requirements through disciplinary action demonstrates program integrity and deters non-compliance.
Question 38: Which of the following situations would trigger a mandatory exclusion from participation in all Federal health care programs by the Office of Inspector General (OIG)?
- A misdemeanor conviction related to health care fraud.
- Defaulting on a health education loan.
- A felony conviction for Medicare fraud. (Correct answer)
- Losing a medical license for reasons of professional incompetence.
Correct answer: A felony conviction for Medicare fraud.
The OIG is required by law to exclude individuals and entities convicted of certain criminal offenses. These mandatory exclusions include felony convictions for Medicare or Medicaid fraud, patient abuse or neglect, and other healthcare-related felonies. The other options are grounds for permissive exclusion, where the OIG has discretion.
Question 39: The EU General Data Protection Regulation (GDPR) applies to U.S. companies under which circumstance?
- Only when the company earns more than €10 million in EU revenue
- When the company employs EU citizens
- Only if the company has a physical office in an EU country
- When processing personal data of EU residents regardless of company location (Correct answer)
Correct answer: When processing personal data of EU residents regardless of company location
GDPR has extraterritorial reach and applies to any organization processing personal data of EU residents, regardless of where the company is located.
Question 40: Which principle from the OECD Guidelines for Multinational Enterprises relates most directly to corporate governance transparency?
- Prohibition of all political contributions worldwide
- Elimination of all intra-group transactions
- Disclosure of material information to shareholders and the public in a timely manner (Correct answer)
- Mandatory local sourcing of materials
Correct answer: Disclosure of material information to shareholders and the public in a timely manner
The OECD Guidelines emphasize timely and accurate disclosure of material information on financial performance, ownership, and governance as a core transparency principle.
Question 41: What is the compliance significance of maintaining signed acknowledgment forms when employees receive policies?
- They serve as marketing materials
- They provide evidence that employees were informed of and agreed to follow compliance requirements (Correct answer)
- They are required by OSHA only
- They replace the need for training
Correct answer: They provide evidence that employees were informed of and agreed to follow compliance requirements
Signed acknowledgments prove that employees received, reviewed, and agreed to abide by compliance policies, reducing the organization's liability.
Question 42: A compliance officer discovers that a key control has been failing silently for 60 days with no alert generated. What does this scenario most likely indicate?
- External auditors are responsible for detecting such failures
- A gap in the monitoring system's alert thresholds or coverage (Correct answer)
- The control failure is not material and requires no action
- The control was intentionally disabled by management
Correct answer: A gap in the monitoring system's alert thresholds or coverage
Silent control failures typically expose gaps in monitoring coverage, alert thresholds, or logging configurations that allowed the issue to go undetected.
Question 43: A compliance team discovers that a control designed to prevent unauthorized system access has not been functioning for three months. The compliance officer should first:
- Notify regulators before conducting an internal investigation
- Implement an interim compensating control and escalate to senior management (Correct answer)
- Document the failure and include it in next year's risk assessment
- Remove the control from the risk register as ineffective
Correct answer: Implement an interim compensating control and escalate to senior management
When a primary control fails, deploying a compensating control immediately limits ongoing exposure while escalation ensures appropriate oversight and remediation.
Question 44: What does 'three lines of defense' mean in the context of compliance monitoring?
- Three annual audits conducted at different times of year
- Operational management, compliance/risk functions, and internal audit serving distinct oversight roles (Correct answer)
- Three separate legal entities each with their own compliance team
- Three regulators that each have oversight of the same institution
Correct answer: Operational management, compliance/risk functions, and internal audit serving distinct oversight roles
The three lines of defense model assigns ownership of controls to operational management (1st), oversight to compliance and risk functions (2nd), and independent assurance to internal audit (3rd).
Question 45: A new medical device company wants to enter into a financial arrangement with physicians to promote its product. To mitigate risks associated with the Anti-Kickback Statute, the company could request a formal opinion from which agency?
- The Centers for Medicare & Medicaid Services (CMS)
- The Department of Justice (DOJ)
- The Office of Inspector General (OIG) (Correct answer)
- The Food and Drug Administration (FDA)
Correct answer: The Office of Inspector General (OIG)
The OIG issues advisory opinions to healthcare providers about the application of its fraud and abuse authorities, including the Federal Anti-Kickback Statute, to their existing or proposed business arrangements. While not mandatory, a favorable advisory opinion can provide assurance that the arrangement poses a low risk of sanctions.
Question 46: A healthcare organization's compliance training log shows several employees are overdue for annual training. Under an effective compliance program, this information should be:
- Shared publicly
- Escalated to management with a remediation plan (Correct answer)
- Deleted from records
- Ignored until the next audit
Correct answer: Escalated to management with a remediation plan
Overdue training must be escalated and remediated promptly to maintain program effectiveness and reduce risk exposure.
Question 47: Which international standard provides a framework for anti-bribery management systems that organizations can certify against?
- ISO 37001 (Correct answer)
- COSO ERM
- ISO 27001
- ISO 9001
Correct answer: ISO 37001
ISO 37001 is the international standard specifically designed to help organizations establish, implement, and certify an anti-bribery management system.
Question 48: What is the purpose of a compliance training needs assessment?
- To review patient satisfaction scores
- To identify gaps in staff knowledge and tailor training accordingly (Correct answer)
- To audit vendor performance
- To determine employee salaries
Correct answer: To identify gaps in staff knowledge and tailor training accordingly
A needs assessment identifies where knowledge deficiencies exist so training can be focused where it will have the most impact.
Question 49: A hospital is preparing for potential RAC audits. The scope of a RAC's post-payment review includes the identification of which of the following?
- Both overpayments and underpayments (Correct answer)
- Only claims with incorrect CPT codes
- Overpayments only
- Underpayments only
Correct answer: Both overpayments and underpayments
The mission of the RAC program is to identify all types of improper payments, which explicitly includes both overpayments made to providers and underpayments owed to providers. RACs look for various types of errors, including but not limited to incorrect coding, services that were not medically necessary, and incorrectly paid services.
Question 50: How does transparency affect corporate governance?
- Hinders organizational growth.
- Leads to secrecy in operations.
- Reduces stakeholder trust.
- Promotes trust and informed decisions (Correct answer)
Correct answer: Promotes trust and informed decisions
Transparency in corporate governance means openly communicating information about the company's operations, financial performance, and decision-making processes to stakeholders. This openness builds trust among investors, employees, customers, and the public. It also enables stakeholders to make informed decisions and hold the organization accountable, fostering a more ethical and responsible corporate environment.
Question 51: What does 'role-specific' compliance training mean in practice?
- Training is only for compliance staff
- Training content is tailored to the compliance risks specific to each job function (Correct answer)
- Training is optional for senior staff
- All employees receive identical training content
Correct answer: Training content is tailored to the compliance risks specific to each job function
Role-specific training addresses the particular regulatory risks and responsibilities associated with each employee's position.
Question 52: Which agency conducts examinations of registered investment advisers with assets under management of $100 million or more?
- State securities regulators
- FINRA
- SEC (Correct answer)
- OCC
Correct answer: SEC
Investment advisers managing $100 million or more in assets must register with and are examined by the SEC.
Question 53: Which scenario represents a violation of the anti-kickback provisions of the Stark Law and Anti-Kickback Statute in the healthcare compliance context?
- A hospital offers free parking to employees who work night shifts
- A compliance officer receives a salary from the company she oversees
- A physician group negotiates volume discounts with a supplier
- A medical device company pays physicians per referral of Medicare patients (Correct answer)
Correct answer: A medical device company pays physicians per referral of Medicare patients
Paying physicians per referral of federal healthcare program patients constitutes an illegal kickback under the Anti-Kickback Statute and may trigger Stark Law liability.
Question 54: Which of the following best describes 'operational risk' in a compliance context?
- The risk of regulatory changes that affect profitability
- The risk that a borrower will default on a loan
- The risk arising from inadequate internal processes, people, systems, or external events (Correct answer)
- The risk of loss from fluctuations in market interest rates
Correct answer: The risk arising from inadequate internal processes, people, systems, or external events
Operational risk encompasses losses resulting from failed internal processes, human error, system failures, or external disruptions.
Question 55: Under an effective CCT compliance program, how often should general compliance training be provided to all employees?
- Only when regulations change
- Every three years
- At least annually (Correct answer)
- Only at initial hire
Correct answer: At least annually
OIG guidance recommends that compliance training be conducted at least annually for all employees to maintain awareness.
Question 56: The Children's Online Privacy Protection Act (COPPA) applies to websites that collect personal information from children under the age of:
- 18
- 13 (Correct answer)
- 16
- 21
Correct answer: 13
COPPA applies to operators of commercial websites and online services directed to children under 13, requiring verifiable parental consent for data collection.
Question 57: A hospital's employee inappropriately accesses the medical records of a celebrity patient. Which type of HIPAA breach is this?
- Physical theft
- Environmental breach
- Accidental disclosure
- Unauthorized internal access (Correct answer)
Correct answer: Unauthorized internal access
Accessing PHI without a valid treatment, payment, or operations reason by an insider constitutes unauthorized internal access, a common HIPAA violation.
Question 58: Which federal agency administers the Medicare and Medicaid programs?
- Department of Justice (DOJ)
- Office of Inspector General (OIG)
- Centers for Medicare & Medicaid Services (CMS) (Correct answer)
- Health Resources and Services Administration (HRSA)
Correct answer: Centers for Medicare & Medicaid Services (CMS)
The Centers for Medicare & Medicaid Services (CMS) is the federal agency responsible for administering Medicare, Medicaid, CHIP, and other federal health programs.
Question 59: What is a conflict of interest in corporate ethics?
- Reporting to supervisors.
- Making objective decisions.
- Taking on extra job duties.
- Allowing personal interests to influence actions (Correct answer)
Correct answer: Allowing personal interests to influence actions
A conflict of interest arises when an individual's personal interests, relationships, or affiliations have the potential to improperly influence their professional judgment or actions within the organization. This can compromise objectivity and lead to decisions that benefit the individual rather than the company or its stakeholders. Recognizing and managing conflicts of interest is crucial for ethical conduct.
Question 60: A company provides a lavish resort trip to a government procurement officer before a contract decision. Under the FCPA's antibribery provisions, this is most likely:
- Prohibited only if the value exceeds $250
- Prohibited because the intent is to influence an official act (Correct answer)
- Permitted as a reasonable business entertainment expense
- Permitted if it falls under the facilitating payments exception
Correct answer: Prohibited because the intent is to influence an official act
The FCPA prohibits giving anything of value to a foreign official to influence an official act, and lavish entertainment provided to influence a contract award meets that standard regardless of dollar amount.
Question 61: Which ethical theory holds that the morality of an action is determined solely by its consequences and outcomes?
- Deontology
- Consequentialism (Correct answer)
- Social contract theory
- Virtue ethics
Correct answer: Consequentialism
Consequentialism (including utilitarianism) judges actions as right or wrong based solely on the outcomes they produce.
Question 62: Which federal program sets specific medical record retention requirements that compliance officers must consider?
- OSHA
- ERISA
- Medicare Conditions of Participation (Correct answer)
- FLSA
Correct answer: Medicare Conditions of Participation
Medicare Conditions of Participation include specific record retention requirements that healthcare providers must follow to maintain Medicare eligibility.
Question 63: When an OIG Compliance Program Guidance recommends that providers conduct 'risk assessments,' what is the intended outcome?
- To calculate the financial reserves needed for potential False Claims Act settlements
- To satisfy mandatory reporting requirements under the Stark Law
- To document patient safety incidents for accreditation purposes
- To identify areas of greatest compliance vulnerability specific to the organization (Correct answer)
Correct answer: To identify areas of greatest compliance vulnerability specific to the organization
Risk assessments help organizations identify and prioritize their specific areas of regulatory and compliance vulnerability so resources can be focused accordingly.
Question 64: Which of the following scenarios qualifies as a HIPAA-compliant 'de-identification' method?
- Encrypting PHI with a key held by the covered entity
- Removing all 18 specific identifiers listed in the Safe Harbor method (Correct answer)
- Replacing patient names with pseudonyms while retaining zip codes
- Storing PHI on a password-protected server
Correct answer: Removing all 18 specific identifiers listed in the Safe Harbor method
The Safe Harbor method requires removal of all 18 enumerated identifiers, after which the data is no longer considered PHI under HIPAA.
Question 65: A compliance officer discovers that new hires in the billing department have not received fraud and abuse training. What is the FIRST action to take?
- Terminate the employees
- Report the finding to the OIG
- Notify CMS directly
- Schedule immediate training for those employees (Correct answer)
Correct answer: Schedule immediate training for those employees
The immediate corrective action is to schedule training so the employees gain required compliance knowledge as soon as possible.
Question 66: A newly appointed compliance officer discovers the company has no formal third-party due diligence process. Which risk does this gap most directly expose the company to?
- Non-compliance with product safety regulations
- Breach of domestic employment discrimination laws
- Violations of the Americans with Disabilities Act
- Liability for misconduct by agents and intermediaries under the FCPA (Correct answer)
Correct answer: Liability for misconduct by agents and intermediaries under the FCPA
The FCPA holds companies liable for corrupt payments made through third-party agents and intermediaries, making due diligence on such parties a critical compliance safeguard.
Question 67: Which international standard provides a framework for establishing, implementing, and maintaining an Information Security Management System (ISMS)?
- ISO 27001 (Correct answer)
- ISO 14001
- ISO 9001
- ISO 31000
Correct answer: ISO 27001
ISO/IEC 27001 is the international standard for information security management systems and provides requirements for establishing an ISMS.
Question 68: Which training delivery format is MOST appropriate for reaching large numbers of geographically dispersed employees?
- In-person classroom sessions only
- One-on-one coaching exclusively
- Online or e-learning modules (Correct answer)
- Printed manuals only
Correct answer: Online or e-learning modules
Online e-learning modules allow consistent, trackable compliance training delivery across multiple locations simultaneously.
Question 69: A provider routinely waives Medicare copayments for all patients without determining financial need. This practice may violate the Anti-Kickback Statute because:
- It violates patient financial privacy rights
- Routine waivers can induce patients to select providers based on financial benefit (Correct answer)
- It reduces provider revenue unnecessarily
- CMS requires all copayments to be collected
Correct answer: Routine waivers can induce patients to select providers based on financial benefit
Routine waiver of Medicare cost-sharing can constitute illegal remuneration under the AKS by inducing beneficiaries to choose providers based on the financial benefit rather than clinical judgment.
Question 70: During a RAC audit, a physician practice receives an ADR for records supporting E/M level 4 and 5 visits. What is the MOST likely reason for this request?
- The practice recently enrolled in Medicare
- The practice changed billing software
- The practice has unusually high utilization of high-complexity E/M codes compared to peers (Correct answer)
- The physician retired mid-year
Correct answer: The practice has unusually high utilization of high-complexity E/M codes compared to peers
RACs use data analytics to flag providers who bill high-level E/M codes at rates that significantly exceed peer benchmarks, triggering record requests.
Question 71: A compliance officer wants to verify that training is effective. Which method BEST evaluates knowledge retention?
- Counting attendance
- Reviewing employee timesheets
- Post-training knowledge assessments or tests (Correct answer)
- Checking patient satisfaction surveys
Correct answer: Post-training knowledge assessments or tests
Post-training assessments directly measure whether employees retained and understood the compliance material presented.
Question 72: Under the Telephone Consumer Protection Act (TCPA), which practice requires prior express written consent?
- Sending marketing text messages using an autodialer (Correct answer)
- Mailing a physical marketing brochure
- Making a manually dialed call to a business landline
- Sending a transactional email confirmation
Correct answer: Sending marketing text messages using an autodialer
The TCPA requires prior express written consent before sending marketing texts or calls using an automatic telephone dialing system to cell phones.
Question 73: What role does the board of directors play in governance?
- Focuses solely on marketing.
- Manages HR functions.
- Provides governance and oversight (Correct answer)
- Handles day-to-day operations.
Correct answer: Provides governance and oversight
The board of directors is responsible for the overall strategic direction, oversight, and governance of an organization. They provide guidance to management, ensure compliance with laws and regulations, and protect the interests of shareholders and other stakeholders. Their role is critical in setting the tone for ethical conduct and ensuring long-term success.
Question 74: Which governance mechanism allows shareholders to remove underperforming directors without a contested election by majority vote?
- Proxy access rule
- Plurality voting standard
- Majority voting standard (Correct answer)
- Cumulative voting
Correct answer: Majority voting standard
Under a majority voting standard, directors who receive more 'withheld' votes than 'for' votes must tender their resignation for board consideration.
Question 75: A compliance training program for a healthcare organization should include which of the following topics as a CORE component?
- Fraud, waste, and abuse prevention (Correct answer)
- Marketing strategies
- Social media branding
- Investment planning
Correct answer: Fraud, waste, and abuse prevention
Fraud, waste, and abuse prevention is a federally required core topic for healthcare compliance training programs.
Question 76: A financial institution's Customer Identification Program (CIP) under the USA PATRIOT Act must collect which minimum set of information from individual customers?
- Name, employer, income, and Social Security number
- Name, address, and credit score
- Name, phone number, email, and government ID copy
- Name, date of birth, address, and identification number (Correct answer)
Correct answer: Name, date of birth, address, and identification number
CIP regulations require collection of name, date of birth, address, and an identification number (such as SSN for U.S. persons) for individual customers.
Question 77: The 'three lines of defense' model assigns internal audit to which line?
- Fourth line
- Third line (Correct answer)
- First line
- Second line
Correct answer: Third line
Internal audit serves as the third line of defense by providing independent assurance over the effectiveness of the first and second lines.
Question 78: Why is a code of ethics important in an organization?
- To increase reporting delays.
- To reduce company profits.
- To help employees make ethical choices (Correct answer)
- To confuse employees.
Correct answer: To help employees make ethical choices
A code of ethics provides clear guidelines and principles that help employees navigate complex situations and make decisions consistent with the organization's values. It sets expectations for professional conduct, fostering a culture of integrity and responsibility. This guidance is crucial for maintaining ethical standards across all levels of the company.
Question 79: Which of the following is an example of insider trading based on the 'misappropriation theory'?
- A CEO sells stock after the company announces earnings
- A director buys stock 30 days before a scheduled earnings call
- A financial journalist trades on material nonpublic information learned during news gathering (Correct answer)
- An employee exercises vested options under a 10b5-1 plan
Correct answer: A financial journalist trades on material nonpublic information learned during news gathering
The misappropriation theory extends insider trading liability to outsiders who trade on material nonpublic information in breach of a duty owed to the information source, such as an employer.
Question 80: A compliance officer discovers that the CEO approved a transaction that personally benefited the CEO's spouse. Which governance concept is most directly implicated?
- Whistleblower retaliation
- Duty of loyalty conflict of interest (Correct answer)
- Sarbanes-Oxley disclosure failure
- Business judgment rule violation
Correct answer: Duty of loyalty conflict of interest
A duty of loyalty conflict of interest arises when a director or officer acts in a way that benefits themselves or related parties rather than the corporation.
Question 81: Under HIPAA, which of the following is a physical safeguard required by the Security Rule?
- Encryption of data in transit
- Facility access controls to limit physical access to systems containing ePHI (Correct answer)
- Automatic logoff after inactivity
- Audit controls on ePHI access logs
Correct answer: Facility access controls to limit physical access to systems containing ePHI
Facility access controls are a required physical safeguard under the HIPAA Security Rule, governing who may physically enter areas housing ePHI.
Question 82: Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
- Healthcare providers who transmit PHI electronically
- Law firms that advise hospitals (Correct answer)
- Healthcare clearinghouses
- Health insurance companies
Correct answer: Law firms that advise hospitals
Law firms that advise healthcare entities are business associates, not covered entities; covered entities are providers, health plans, and clearinghouses.
Question 83: When assessing whether a board director is 'independent' under NYSE listing standards, which relationship would disqualify independence?
- Service on another public company's board
- Membership in the same professional association as the CEO
- Ownership of 2% of the company's stock
- Former employee of the company within the last three years (Correct answer)
Correct answer: Former employee of the company within the last three years
NYSE standards disqualify directors who were employees of the listed company within the preceding three years from being classified as independent.
Question 84: Which of the Seven Elements requires that an organization have a mechanism to receive and investigate reports of potential misconduct without fear of retaliation?
- Effective lines of communication (Correct answer)
- Enforcement of disciplinary standards
- Written policies and procedures
- Prompt response to detected offenses
Correct answer: Effective lines of communication
Effective lines of communication—the fourth element—include anonymous hotlines and non-retaliation policies to encourage reporting of suspected violations.
Question 85: A compliance training program that includes real-world case studies and role-playing scenarios is primarily designed to achieve what outcome?
- Replace written policies
- Reduce training time
- Improve employee engagement and retention of compliance concepts (Correct answer)
- Satisfy OSHA requirements
Correct answer: Improve employee engagement and retention of compliance concepts
Interactive methods like case studies improve retention and help employees apply compliance principles to actual situations.
Question 86: What is 'phantom billing' in the context of healthcare fraud?
- Billing for services at a higher complexity level than was actually provided
- Billing for services, procedures, or supplies that were never actually provided to the patient (Correct answer)
- Billing under another provider's NPI without their knowledge
- Submitting a claim after the timely filing deadline has passed
Correct answer: Billing for services, procedures, or supplies that were never actually provided to the patient
Phantom billing involves submitting claims for services or items that were never actually rendered to the patient, constituting outright fraud against Medicare, Medicaid, or other payers.
Question 87: Which element of the Seven Elements of Compliance specifically addresses employee education and training?
- Training and education (Correct answer)
- Effective lines of communication
- Written policies and procedures
- Internal monitoring and auditing
Correct answer: Training and education
Training and education is the third element of the OIG's Seven Elements of an effective compliance program.
Question 88: OIG compliance guidance specifically warns against 'physician inducement' arrangements where:
- Hospitals provide physicians with benefits intended to influence their referral patterns (Correct answer)
- Physician group practices share risk under a capitated managed care contract
- Physicians are paid fair market value for legitimate medical director services
- Physicians serve on a hospital board and receive standard director compensation
Correct answer: Hospitals provide physicians with benefits intended to influence their referral patterns
Arrangements where hospitals provide physicians with items of value—such as free office space, staff, or equipment—specifically to influence referral patterns can violate the AKS.
Question 89: An anti-money laundering (AML) compliance program must include all of the following EXCEPT:
- Internal controls and policies
- Ongoing employee training
- Designation of a compliance officer
- Annual criminal background checks on all customers (Correct answer)
Correct answer: Annual criminal background checks on all customers
The Bank Secrecy Act's four pillars of AML compliance are internal controls, a designated compliance officer, employee training, and independent testing — annual criminal background checks on all customers are not required.
Question 90: Under EPA's RCRA regulations, a Conditionally Exempt Small Quantity Generator (CESQG) generates how much hazardous waste per month?
- Between 1,000 and 10,000 kg
- Less than 100 kg (Correct answer)
- Between 100 and 1,000 kg
- More than 10,000 kg
Correct answer: Less than 100 kg
CESQGs (now called Very Small Quantity Generators) generate less than 100 kg of hazardous waste per month and have the least stringent requirements.
Question 91: What is the primary purpose of corporate governance?
- To increase employee workloads.
- To reduce customer engagement.
- To ensure proper management and accountability (Correct answer)
- To eliminate board oversight.
Correct answer: To ensure proper management and accountability
The primary purpose of corporate governance is to establish a framework of rules, practices, and processes by which a company is directed and controlled. This ensures proper management, accountability, and ethical conduct within the organization. Effective governance protects stakeholder interests and promotes long-term sustainability.
Question 92: The concept of 'disgorgement' as an enforcement remedy requires a violator to:
- Return all ill-gotten gains or profits from the wrongful conduct (Correct answer)
- Pay the victim's legal fees
- Fund a compliance monitor for three years
- Pay punitive damages triple the actual harm caused
Correct answer: Return all ill-gotten gains or profits from the wrongful conduct
Disgorgement is an equitable remedy that compels a wrongdoer to give up profits obtained through illegal activity, preventing unjust enrichment.
Question 93: A hospital compliance officer discovers a pattern of incorrect billing for a specific procedure. According to OIG Compliance Guidance, which of the following actions is the most appropriate initial response?
- Developing a corrective action plan and responding to the detected offense. (Correct answer)
- Ignoring the issue unless a government audit occurs.
- Immediately terminating the employees responsible.
- Reporting the issue to the local news to ensure transparency.
Correct answer: Developing a corrective action plan and responding to the detected offense.
A key element of an effective compliance program is responding appropriately to detected offenses and developing corrective action initiatives. This involves investigating the issue, implementing corrective measures to prevent recurrence, and, if necessary, disclosing the issue to the appropriate governmental agency.
Question 94: What is a chargemaster (charge description master) in a hospital setting?
- A database of all Medicare and Medicaid beneficiaries served by the facility
- A list of credentialed physicians and their contracted billing rates
- A government-issued fee schedule for Medicare facility reimbursement
- A comprehensive listing of all services, procedures, and items a facility may bill for along with their standard charges (Correct answer)
Correct answer: A comprehensive listing of all services, procedures, and items a facility may bill for along with their standard charges
A chargemaster is the hospital's internal master price list containing every billable item and service with its associated standard charge, serving as the starting point for all billing.
Question 95: Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 404 (Correct answer)
- Section 302
- Section 806
- Section 1107
Correct answer: Section 404
SOX Section 404 mandates that management assess internal controls over financial reporting and that external auditors attest to that assessment.
Question 96: Which federal agency primarily enforces the Foreign Corrupt Practices Act (FCPA) regarding bribery of foreign officials?
- Treasury and State Department jointly
- FTC and FCC jointly
- FBI alone
- DOJ and SEC jointly (Correct answer)
Correct answer: DOJ and SEC jointly
The Department of Justice (DOJ) and Securities and Exchange Commission (SEC) share FCPA enforcement authority for criminal and civil matters respectively.
Question 97: Which regulation implements the Home Mortgage Disclosure Act (HMDA)?
- Regulation Z
- Regulation B
- Regulation E
- Regulation C (Correct answer)
Correct answer: Regulation C
Regulation C implements HMDA, requiring covered lenders to collect and report data on home loan applications and originations.
Question 98: The Seven Elements framework was originally derived from which foundational federal document?
- The Anti-Kickback Statute regulations
- The False Claims Act (1863, as amended)
- The Deficit Reduction Act (2005)
- Chapter 8 of the Federal Sentencing Guidelines for Organizations (1991) (Correct answer)
Correct answer: Chapter 8 of the Federal Sentencing Guidelines for Organizations (1991)
Chapter 8 of the 1991 Federal Sentencing Guidelines introduced the criteria for an effective compliance and ethics program that the OIG later adapted into the Seven Elements.
Question 99: Which staff group typically requires specialized compliance training beyond general annual education?
- Coding and billing personnel (Correct answer)
- Security guards
- Cafeteria workers
- Maintenance staff
Correct answer: Coding and billing personnel
Coding and billing personnel handle sensitive claims data and face higher fraud and abuse risk, requiring specialized training.
Question 100: Which exception to Stark Law allows physicians to refer patients to an entity for designated health services if those services are provided within the physician's own practice?
- Fair market value exception
- In-office ancillary services exception (Correct answer)
- Rural provider exception
- Bona fide employment exception
Correct answer: In-office ancillary services exception
The in-office ancillary services exception permits physicians to refer within their own group practice for certain designated health services if specific supervision, location, and billing requirements are met.
Certified Compliance Technician (CCT) Exam
The CCT certification validates foundational knowledge in regulatory compliance, risk management, and ethical practices relevant to various industries.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds