CHC Certified in Healthcare Compliance Exam — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- A patient's name combined with their diagnosis
- A patient's date of birth combined with their ZIP code
- De-identified health data that meets Safe Harbor standards (Correct answer)
- A patient's medical record number
Correct answer: De-identified health data that meets Safe Harbor standards
De-identified data that meets HIPAA's Safe Harbor or Expert Determination standards is not PHI and is not subject to HIPAA protections.
Question 2: Under the ACA's 60-day rule, what must a healthcare provider do upon identifying a Medicare or Medicaid overpayment?
- Report and return the overpayment to the government within 60 days (Correct answer)
- Notify the OIG of the overpayment within 60 days without yet returning funds
- File a qui tam lawsuit to document the overpayment within 60 days
- Submit a corrected claim to the payer within 60 days of discovery
Correct answer: Report and return the overpayment to the government within 60 days
The ACA's 60-day rule requires providers to both report and return identified overpayments within 60 days; failure to do so can constitute a False Claims Act violation.
Question 3: An effective compliance program is described by the OIG as having seven core elements. Which of the following is one of these fundamental elements?
- Guaranteeing that no compliance violations will ever occur.
- Utilizing a government-mandated compliance software platform.
- Conducting internal monitoring and auditing. (Correct answer)
- Maintaining a specific ratio of compliance staff to total employees.
Correct answer: Conducting internal monitoring and auditing.
The OIG's Seven Elements of an Effective Compliance Program are the foundational framework for healthcare compliance. 'Internal Monitoring and Auditing' is a critical element that focuses on the ongoing evaluation of the program's effectiveness and adherence to policies.
Question 4: Which approach BEST supports consistent application of compliance policies across multiple facilities within a health system?
- Establishing system-wide policies with facility-specific addenda addressing local variations (Correct answer)
- Publishing policies exclusively on the corporate intranet without local distribution
- Requiring all facilities to follow only the most restrictive state's regulations
- Allowing each facility to develop its own independent compliance policies
Correct answer: Establishing system-wide policies with facility-specific addenda addressing local variations
System-wide policies ensure consistency while facility-specific addenda allow for legitimate local operational or regulatory differences.
Question 5: The 'Yates Memo' issued by the DOJ in 2015 primarily focused healthcare compliance on which area?
- Expanding qui tam whistleblower protections
- Strengthening HIPAA enforcement
- Requiring board-level compliance oversight
- Holding individual employees accountable for corporate misconduct (Correct answer)
Correct answer: Holding individual employees accountable for corporate misconduct
The Yates Memo directed DOJ attorneys to focus on individual accountability in corporate misconduct cases, emphasizing that individuals—not just organizations—should be held responsible.
Question 6: During a compliance investigation, legal counsel invokes attorney-client privilege over certain documents. The compliance officer should understand that privilege:
- Automatically applies to all compliance committee meeting minutes
- Covers communications between attorney and client made for the purpose of legal advice (Correct answer)
- Protects all documents created during an investigation regardless of author
- Can be asserted by the compliance officer independently without attorney involvement
Correct answer: Covers communications between attorney and client made for the purpose of legal advice
Attorney-client privilege applies specifically to confidential communications between a licensed attorney and their client made for purposes of obtaining legal advice.
Question 7: During an internal investigation interview regarding potential HIPAA violations, the compliance officer is questioning a witness who seems hesitant and fearful of retaliation. Which of the following interview techniques is most appropriate to encourage open communication?
- Conducting the interview in a busy, open-plan office to appear less formal.
- Asking leading questions to quickly confirm the suspected violations.
- Reminding the employee that failure to cooperate could result in disciplinary action.
- Explaining the non-retaliation policy and conducting the interview in a private, neutral setting. (Correct answer)
Correct answer: Explaining the non-retaliation policy and conducting the interview in a private, neutral setting.
To build rapport and encourage a witness to be forthcoming, it is crucial to create a safe and confidential environment. Explaining the organization's non-retaliation policy and choosing a private, neutral location for the interview helps to reduce anxiety and demonstrates the integrity of the process. Threatening discipline or asking leading questions can intimidate the witness, while a non-private setting undermines confidentiality.
Question 8: The HIPAA Breach Notification Rule's 'harm threshold' was eliminated by which regulation, requiring notification for all breaches unless the low probability of compromise is demonstrated?
- The HITECH Act of 2009
- The Security Rule of 2005
- The Omnibus Rule of 2013 (Correct answer)
- The Privacy Rule of 2003
Correct answer: The Omnibus Rule of 2013
The 2013 Omnibus Rule replaced the harm threshold with a four-factor risk assessment, requiring notification unless the covered entity demonstrates a low probability that PHI was compromised.
Question 9: Which oversight body enforces the Emergency Medical Treatment and Labor Act (EMTALA)?
- OIG
- State Health Departments
- CMS (Correct answer)
- DOJ
Correct answer: CMS
CMS is responsible for enforcing EMTALA, which requires hospitals participating in Medicare to provide stabilizing treatment to all patients regardless of ability to pay.
Question 10: A compliance officer at a large hospital system discovers that a recently implemented billing procedure conflicts with a long-standing coding policy, leading to claim submission errors. What is the BEST course of action for the compliance officer?
- Report the issue to the OIG without first attempting internal resolution.
- Discipline the department manager responsible for implementing the conflicting procedure.
- Immediately halt all billing until the procedure can be rewritten.
- Convene relevant stakeholders to review the conflict, revise the documents for consistency, and provide education on the corrected process. (Correct answer)
Correct answer: Convene relevant stakeholders to review the conflict, revise the documents for consistency, and provide education on the corrected process.
The best course of action is to address the problem systematically. This involves bringing together the relevant parties (e.g., from billing, coding, and compliance) to understand the discrepancy, revise the policy and/or procedure to ensure they are aligned and compliant, and then re-educate the staff on the correct, harmonized process. This approach corrects the root cause and prevents future errors.
Question 11: When developing a compliance training program, which population should receive the MOST specialized and detailed training content?
- New hires only, during their first week
- All employees equally, with identical content
- Administrative support staff
- High-risk employees whose job functions directly involve regulated activities (Correct answer)
Correct answer: High-risk employees whose job functions directly involve regulated activities
Employees in high-risk roles—such as coders, billers, and clinicians—need specialized training tailored to the specific compliance risks associated with their duties.
Question 12: A compliance officer is presenting risk assessment findings to the board of directors. Which format is MOST effective for communicating the overall risk landscape?
- A color-coded risk heat map with a summary of top 10 risks and proposed mitigations (Correct answer)
- A raw spreadsheet of all 200 individual risk items
- A 50-page technical narrative report
- A verbal briefing with no supporting documentation
Correct answer: A color-coded risk heat map with a summary of top 10 risks and proposed mitigations
A heat map with a top-risk summary gives board members a clear, actionable picture of priorities without overwhelming them with granular detail.
Question 13: A healthcare entity receives a subpoena from the DOJ for billing records. What is the compliance officer's first priority?
- Notify the CEO and preserve all relevant documents under a litigation hold (Correct answer)
- Immediately produce all records to avoid penalties
- Destroy any records that may be incriminating
- Contact CMS to report the investigation
Correct answer: Notify the CEO and preserve all relevant documents under a litigation hold
Upon receiving a government subpoena, the compliance officer must issue a litigation hold to preserve all relevant documents and promptly notify senior leadership and legal counsel.
Question 14: Which standard governs how healthcare organizations must safeguard electronic protected health information (ePHI) under federal law?
- HITECH Breach Notification Rule
- HIPAA Privacy Rule
- HIPAA Security Rule (Correct answer)
- 21st Century Cures Act Information Blocking provisions
Correct answer: HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.
Question 15: What is the significance of the '60-day rule' under the False Claims Act for healthcare compliance investigations?
- Investigations must be completed within 60 days of initiation
- Overpayments must be reported and returned within 60 days of identification (Correct answer)
- Employees must be interviewed within 60 days of a complaint
- Government contractors must respond to subpoenas within 60 days
Correct answer: Overpayments must be reported and returned within 60 days of identification
The ACA's 60-day rule requires providers to report and return identified overpayments within 60 days to avoid FCA liability for retaining them.
Question 16: Which element is MOST critical to include in a final compliance investigation report?
- The exact salaries of all employees interviewed
- A public-facing press statement about the investigation outcome
- A factual summary, evidence reviewed, findings, conclusions, and recommended corrective actions (Correct answer)
- The personal opinions of the investigative team on employee culpability
Correct answer: A factual summary, evidence reviewed, findings, conclusions, and recommended corrective actions
A thorough investigation report documents the process, evidence, factual findings, and actionable recommendations to support remediation and defensibility.
Question 17: What is a Recovery Audit Contractor (RAC) and what is its role in billing compliance?
- An internal hospital audit team focused on revenue cycle
- A state agency that audits Medicaid billing
- A CMS-contracted auditor that identifies and recovers improper Medicare payments (Correct answer)
- A private accreditation body for billing departments
Correct answer: A CMS-contracted auditor that identifies and recovers improper Medicare payments
RACs are private contractors authorized by CMS to review Medicare claims and recover improper payments, working on a contingency fee basis.
Question 18: Which federal statute prohibits submitting claims for services that were not actually rendered to Medicare or Medicaid?
- False Claims Act (Correct answer)
- Stark Law
- HITECH Act
- Anti-Kickback Statute
Correct answer: False Claims Act
The False Claims Act prohibits knowingly submitting false or fraudulent claims for payment to any federal program, including Medicare and Medicaid.
Question 19: Which of the following BEST describes a 'corporate integrity agreement' (CIA) in the context of remedial measures?
- A voluntary internal policy adopted after a risk assessment
- A binding settlement with the OIG requiring compliance program enhancements and monitoring (Correct answer)
- An agreement between two competing healthcare entities
- A state licensure requirement for new hospitals
Correct answer: A binding settlement with the OIG requiring compliance program enhancements and monitoring
A CIA is a formal agreement with the OIG that imposes specific compliance obligations and independent review as a condition of continued participation in federal healthcare programs.
Question 20: A compliance officer is rating risks on a 1-5 scale for both likelihood and impact. What does this technique produce?
- A compliance audit report
- A risk score used to rank and prioritize risks (Correct answer)
- A corrective action plan
- A regulatory submission document
Correct answer: A risk score used to rank and prioritize risks
Multiplying likelihood and impact scores produces a composite risk score that allows the compliance team to rank and prioritize mitigation efforts.
Question 21: Under the Medicare Fee Schedule, what does 'medical necessity' require for a claim to be reimbursable?
- The service was reasonable and necessary for the diagnosis or treatment of illness or injury (Correct answer)
- The service was ordered by a board-certified specialist
- The service was performed in an accredited facility
- The patient had prior authorization from their insurer
Correct answer: The service was reasonable and necessary for the diagnosis or treatment of illness or injury
Medicare requires that services be 'reasonable and necessary' for the diagnosis or treatment of illness or injury as a fundamental condition for reimbursement.
Question 22: A hospital's fundraising foundation wants to send a mailing to former patients. Under HIPAA, which of the following pieces of information may the hospital disclose to its foundation for fundraising purposes without obtaining prior patient authorization?
- Information about the patient's specific treating physician and outcome.
- Patient diagnosis and treatment details.
- Dates of service, demographic information, and health insurance status. (Correct answer)
- The patient's entire medical record.
Correct answer: Dates of service, demographic information, and health insurance status.
HIPAA permits a covered entity to use or disclose limited PHI for its own fundraising purposes without an individual's authorization. This is limited to demographic information (like name and address), dates of healthcare provided, department of service information, treating physician, outcome information, and health insurance status. The notice of privacy practices must inform patients about fundraising communications and their right to opt out.
Question 23: Which of the following scenarios describes a permissible incidental disclosure under HIPAA?
- A receptionist emails a patient's full medical record to the wrong address
- A nurse loudly announces a patient's HIV status in a crowded waiting room
- A hospital staff member discusses a patient's condition in a hallway while taking reasonable precautions to limit overheard information (Correct answer)
- A billing employee shares PHI with an unaffiliated third party for curiosity
Correct answer: A hospital staff member discusses a patient's condition in a hallway while taking reasonable precautions to limit overheard information
Incidental disclosures that occur as a byproduct of otherwise permissible communications are allowed if the covered entity has reasonable safeguards in place and follows minimum necessary standards.
Question 24: When a compliance policy conflicts with a state law that is MORE restrictive than federal law, the organization must:
- Follow federal law exclusively, as it preempts all state law
- Follow the more restrictive state law unless federal law explicitly preempts it (Correct answer)
- Petition the OIG for a waiver before implementing either standard
- Apply whichever standard is less burdensome to operations
Correct answer: Follow the more restrictive state law unless federal law explicitly preempts it
HIPAA and most federal healthcare laws set a floor, not a ceiling; organizations must comply with more restrictive state laws unless federal law explicitly preempts the state provision.
Question 25: A hospital compliance officer is developing metrics to measure the effectiveness of the compliance training program. Which metric is MOST directly relevant?
- Number of training sessions scheduled
- Number of employees hired in the past year
- Pre- and post-training assessment scores (Correct answer)
- Total training budget spent
Correct answer: Pre- and post-training assessment scores
Pre- and post-training assessment scores directly measure knowledge gained, making them the most relevant metric for training effectiveness.
Question 26: Which of the following BEST describes the 'scope creep' risk in healthcare compliance investigations?
- An investigation expanding beyond its original focus without proper authorization (Correct answer)
- Delays caused by interviewing too many witnesses
- Investigators reviewing too few records
- The cost of investigations exceeding the budget
Correct answer: An investigation expanding beyond its original focus without proper authorization
Scope creep occurs when an investigation expands beyond its defined parameters, potentially creating unmanaged legal exposure and resource drain.
Question 27: Which element is NOT typically included in a formal audit report?
- Scope and objectives of the audit
- Personal opinions of individual staff members (Correct answer)
- Methodology used to select records
- Findings and recommendations
Correct answer: Personal opinions of individual staff members
Formal audit reports are objective documents; they include scope, methodology, findings, and recommendations, but not personal opinions of staff.
Question 28: When conducting a medical record audit, what does 'legibility' of documentation primarily affect from a compliance perspective?
- The speed at which auditors can complete their review
- The organization's HIPAA privacy compliance
- The accuracy of ICD-10 code assignment by coders
- The ability of auditors to verify that services were documented and support the billed code (Correct answer)
Correct answer: The ability of auditors to verify that services were documented and support the billed code
Illegible documentation prevents auditors from verifying that services billed were actually rendered and properly supported, creating a compliance and reimbursement risk.
Question 29: Which best describes the 'reasonable inquiry' standard a compliance officer should apply before closing an investigation?
- Determining that no employees were harmed by the potential violation
- Ensuring the inquiry was sufficiently thorough that a competent professional would be satisfied the matter is resolved (Correct answer)
- Verifying that no government agencies are aware of the issue
- Confirming that the original complainant is satisfied with the outcome
Correct answer: Ensuring the inquiry was sufficiently thorough that a competent professional would be satisfied the matter is resolved
The reasonable inquiry standard requires that the investigation was conducted with appropriate diligence and that conclusions are well-supported by evidence.
Question 30: A compliance officer is reviewing the results of a claim audit and wants to report findings to leadership. Which metric BEST communicates the financial impact of identified errors?
- The confidence interval width of the audit sample
- The number of coders who submitted incorrect claims
- The extrapolated overpayment amount based on the sample error rate (Correct answer)
- The total number of claims reviewed in the sample
Correct answer: The extrapolated overpayment amount based on the sample error rate
Extrapolating the sample error rate to the full population provides leadership with the estimated financial exposure, which is the most actionable compliance metric.
Question 31: Which of the following scenarios would MOST likely require a self-disclosure to the OIG's Self-Disclosure Protocol?
- A documentation issue with no financial impact
- A minor HIPAA administrative safeguard deficiency
- Potential violations of the Anti-Kickback Statute involving physician arrangements (Correct answer)
- A coding error that resulted in a $50 underpayment
Correct answer: Potential violations of the Anti-Kickback Statute involving physician arrangements
The OIG Self-Disclosure Protocol is designed for providers who identify potential fraud violations, particularly Anti-Kickback Statute or False Claims Act issues.
Question 32: Under the OIG's compliance program guidance, effective discipline programs must be applied to:
- Physicians only, because they generate billing
- Temporary contractors who are not W-2 employees
- All levels of the organization, including senior management and executives (Correct answer)
- Only frontline staff and coders
Correct answer: All levels of the organization, including senior management and executives
The OIG emphasizes that compliance programs lose credibility if discipline is not applied consistently at all organizational levels, including leadership.
Question 33: A compliance officer at a large health system wants to benchmark the organization's compliance program. Which is the MOST credible benchmarking resource?
- Industry salary surveys
- HCCA/OIG Healthcare Compliance Program Effectiveness Resource Guide (Correct answer)
- Competitor press releases
- Social media compliance forums
Correct answer: HCCA/OIG Healthcare Compliance Program Effectiveness Resource Guide
The HCCA/OIG Healthcare Compliance Program Effectiveness Resource Guide provides authoritative benchmarks and practices for evaluating compliance programs.
Question 34: Which of the following is the MOST important characteristic of an effective healthcare compliance monitoring dashboard?
- It should be accessible only to the compliance officer to maintain confidentiality
- It must be submitted to CMS on a quarterly basis
- It should display real-time or near-real-time key risk indicators that allow for timely corrective action (Correct answer)
- It should replace the need for periodic audits entirely
Correct answer: It should display real-time or near-real-time key risk indicators that allow for timely corrective action
An effective monitoring dashboard provides timely, actionable key risk indicators so compliance issues can be identified and addressed promptly, before they escalate.
Question 35: What ethical obligation does a compliance officer have when an internal investigation implicates senior leadership?
- Proceed with the investigation objectively and report findings to the board or audit committee (Correct answer)
- Close the investigation to protect the organization's reputation
- Conduct the investigation privately without documenting findings
- Transfer investigative authority to the implicated executive's supervisor
Correct answer: Proceed with the investigation objectively and report findings to the board or audit committee
When leadership is implicated, the compliance officer must maintain independence and escalate findings to the board or audit committee to ensure objectivity.
Question 36: A compliance program tracks not only who completed training but also the specific modules completed, scores, and remediation history. This practice best supports which compliance program function?
- Monitoring, auditing, and demonstrating due diligence to regulators (Correct answer)
- Responding to detected offenses
- Developing open lines of communication
- Enforcing disciplinary standards
Correct answer: Monitoring, auditing, and demonstrating due diligence to regulators
Detailed training records support the monitoring and auditing element of a compliance program and provide evidence of due diligence if regulators or prosecutors review the program.
Question 37: A hospital's compliance officer is developing the annual audit plan. Which of the following is the most critical first step in this process?
- Reviewing the previous year's audit findings.
- Analyzing the OIG's most recent Work Plan.
- Conducting a comprehensive risk assessment. (Correct answer)
- Interviewing department heads about their concerns.
Correct answer: Conducting a comprehensive risk assessment.
A comprehensive risk assessment is the foundational element of an effective compliance program and should be the starting point for developing a risk-based audit plan. This process identifies and prioritizes the organization's specific risks, which then guides the focus of audit activities. The other options are valuable inputs to the risk assessment but are not the first or most critical step.
Question 38: When disciplining a licensed clinical professional for a compliance violation, the organization should also consider:
- Whether all prior performance reviews should be destroyed
- Whether the employee's salary should be reduced retroactively
- Whether the employee can be enrolled in a clinical research study
- Whether the violation triggers mandatory reporting to the relevant state licensing board (Correct answer)
Correct answer: Whether the violation triggers mandatory reporting to the relevant state licensing board
Many states require healthcare organizations to report certain practitioner misconduct to licensing boards, creating an obligation beyond internal discipline.
Question 39: Which federal law requires healthcare organizations to have compliance programs including auditing and monitoring as a condition of enrollment in federal healthcare programs?
- HIPAA
- The Affordable Care Act
- Social Security Act Section 6401 (Correct answer)
- Stark Law
Correct answer: Social Security Act Section 6401
Section 6401 of the Affordable Care Act, codified under the Social Security Act, requires certain providers to have compliance programs as a condition of enrollment in Medicare and Medicaid.
Question 40: A compliance officer discovers a pattern of upcoding in physician billing. Which type of audit should be initiated first?
- Reactive focused audit (Correct answer)
- Proactive scheduled audit
- Random baseline audit
- External third-party audit
Correct answer: Reactive focused audit
A reactive focused audit is triggered by a specific concern or identified risk, such as a pattern of upcoding, to investigate the issue promptly.
Question 41: When an organization decides to exclude an individual from participation in its operations following a compliance violation, it must first check the:
- Employee's social media profiles
- State tax records for outstanding liens
- Medicare Advantage plan enrollment database
- OIG List of Excluded Individuals and Entities (LEIE) and SAM.gov (Correct answer)
Correct answer: OIG List of Excluded Individuals and Entities (LEIE) and SAM.gov
Before and after any employment or contracting action, organizations must screen against the LEIE and SAM.gov to ensure they do not employ or contract with federally excluded parties.
Question 42: Which of the following best describes the role of compliance champions or departmental liaisons in a training program?
- They replace the compliance officer in investigations
- They serve as local points of contact who reinforce compliance messages, answer questions, and facilitate training within their departments (Correct answer)
- They audit financial transactions on behalf of the compliance department
- They are responsible for creating all compliance training content
Correct answer: They serve as local points of contact who reinforce compliance messages, answer questions, and facilitate training within their departments
Compliance champions extend the reach of the compliance program by embedding compliance awareness within each department and supporting peer-level education.
Question 43: When interviewing a potential whistleblower during an internal investigation, what is the MOST important protection to communicate?
- Their identity will be kept confidential from all parties
- They will receive financial compensation for cooperation
- Their statements will not be shared with legal counsel
- Retaliation for good-faith reporting is prohibited under company policy and law (Correct answer)
Correct answer: Retaliation for good-faith reporting is prohibited under company policy and law
Anti-retaliation protections are a legal and ethical obligation that must be clearly communicated to encourage candid participation.
Question 44: A patient requests an accounting of disclosures. Which type of disclosure must be included in the accounting?
- Disclosures made to the patient themselves
- Disclosures for treatment, payment, and operations
- Disclosures to public health authorities as required by law (Correct answer)
- Disclosures pursuant to a valid patient authorization
Correct answer: Disclosures to public health authorities as required by law
Disclosures required by law, such as those to public health authorities, must be included in the accounting of disclosures.
Question 45: What is the role of the HIPAA Privacy Officer in a covered entity?
- To personally review every request for PHI access
- To negotiate all business associate agreements on behalf of the organization
- To conduct all external audits of business associates
- To be responsible for development and implementation of privacy policies and procedures (Correct answer)
Correct answer: To be responsible for development and implementation of privacy policies and procedures
The HIPAA Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Question 46: What is the role of the Compliance and Ethics Officer in relation to the governing board of a healthcare organization?
- To provide regular compliance updates directly to the board to ensure independent oversight (Correct answer)
- To handle only billing compliance without board involvement
- To report only to the CEO and shield the board from compliance matters
- To manage legal counsel on the board's behalf
Correct answer: To provide regular compliance updates directly to the board to ensure independent oversight
Effective compliance programs require the Compliance Officer to report directly to the governing board, ensuring independent oversight separate from operational management.
Question 47: Which of the following scenarios most likely implicates the 'one-purpose test' applied to Anti-Kickback Statute analysis?
- A physician group shares profits equally among all partners regardless of referral volume
- A pharmaceutical company sponsors an accredited CME program open to all physicians
- A hospital pays a physician fair market value for administrative services under a written agreement
- A vendor provides free consulting services to a hospital, hoping the hospital will purchase its products (Correct answer)
Correct answer: A vendor provides free consulting services to a hospital, hoping the hospital will purchase its products
Under the one-purpose test, if one purpose of the remuneration is to induce referrals or purchases, the AKS is violated — even if there are legitimate business reasons too.
Question 48: Which document type provides the authoritative basis (the 'why') that all related procedures and work instructions should reference?
- Audit checklist
- Work instruction
- Standard operating procedure
- Policy (Correct answer)
Correct answer: Policy
A policy establishes the organizational rule or principle that gives authority and rationale to the procedures and work instructions that implement it.
Question 49: When a report is received through a compliance hotline, what should occur FIRST in the investigation process?
- Forward the report directly to the CEO for personal review
- Log the report and triage it for investigation priority based on risk level (Correct answer)
- Notify outside legal counsel before any internal review begins
- Immediately identify and interview the reporting employee
Correct answer: Log the report and triage it for investigation priority based on risk level
Initial logging and triage ensures all reports are tracked, helps prioritize by risk level, and creates the audit trail necessary for an effective compliance program.
Question 50: A compliance risk assessment should inform policy development by:
- Identifying high-risk areas where robust policy controls are most needed (Correct answer)
- Limiting policies to areas where violations have already occurred
- Delegating all policy writing to external consultants
- Replacing the need for written policies in low-risk areas
Correct answer: Identifying high-risk areas where robust policy controls are most needed
Risk assessments prioritize where policy controls are most needed, enabling the organization to allocate compliance resources to highest-risk operations.
Question 51: She implies that when hospital administrators said that most mistakes happen at the "sharp end," they meant that...
- They involve surgical tools or knives
- They are more likely to occur during busy periods
- They occur during the interactions between caregivers and patients (Correct answer)
- They occur in cluster
Correct answer: They occur during the interactions between caregivers and patients
In healthcare safety, the 'sharp end' refers to the point of direct patient care, where caregivers (e.g., nurses, doctors) interact immediately with patients. Mistakes at the sharp end are those that occur during these direct interactions, as opposed to 'blunt end' errors which are systemic issues in organizational design or policy.
Question 52: In healthcare compliance, what is the significance of the 'Sunshine Act' (Open Payments Program)?
- It mandates transparency in hospital pricing
- It requires public reporting of HIPAA breaches
- It governs disclosure of clinical trial data
- It requires manufacturers to report payments and transfers of value to physicians and teaching hospitals (Correct answer)
Correct answer: It requires manufacturers to report payments and transfers of value to physicians and teaching hospitals
The Physician Payments Sunshine Act requires drug and device manufacturers to report payments and other transfers of value to physicians and teaching hospitals to CMS for public disclosure.
Question 53: An employee who suffers retaliation for reporting healthcare compliance concerns under certain federal statutes may file a complaint with which agency within 180 days of the retaliatory action?
- Department of Labor Wage and Hour Division
- Securities and Exchange Commission (SEC)
- Occupational Safety and Health Administration (OSHA) (Correct answer)
- Equal Employment Opportunity Commission (EEOC)
Correct answer: Occupational Safety and Health Administration (OSHA)
For several federal whistleblower statutes, including those covering healthcare, OSHA investigates anti-retaliation complaints, which typically must be filed within 180 days of the retaliatory act.
Question 54: When an audit reveals overpayments from a federal healthcare program, within how many days must the overpayment be reported and returned under the 60-day rule?
- 60 days from identification (Correct answer)
- 90 days from identification
- 120 days from identification
- 30 days from identification
Correct answer: 60 days from identification
Under the 60-day rule (42 CFR § 401.305), providers must report and return identified Medicare/Medicaid overpayments within 60 days of identification.
Question 55: Under HIPAA's Security Rule, 'integrity' of ePHI means:
- ePHI is available and accessible when needed by authorized users
- ePHI is not altered or destroyed in an unauthorized manner (Correct answer)
- Only authorized users can access ePHI
- ePHI is encrypted during transmission
Correct answer: ePHI is not altered or destroyed in an unauthorized manner
Integrity under the Security Rule means ensuring that ePHI is not altered or destroyed in an unauthorized manner.
Question 56: After completing an internal investigation that substantiated a violation of the organization's code of conduct, what is a critical final step in the investigation process?
- Informing all employees via a company-wide email about the outcome.
- Archiving the investigation file in a publicly accessible folder for transparency.
- Identifying the root cause and implementing corrective actions to prevent recurrence. (Correct answer)
- Immediately terminating the subject of the investigation without further review.
Correct answer: Identifying the root cause and implementing corrective actions to prevent recurrence.
A key goal of any investigation is not just to address the specific incident but also to prevent future non-compliance. Therefore, analyzing the evidence to determine the root cause of the issue and implementing a corrective action plan (which may include policy changes, training, or system improvements) is a crucial final step to improve the overall effectiveness of the compliance program.
Question 57: Under a Corporate Integrity Agreement (CIA), what type of auditing is typically required of the organization?
- Annual audits conducted solely by the OIG
- Peer review by similar healthcare organizations
- Ad hoc self-auditing based on leadership discretion
- Independent Review Organization (IRO) audits of claims and arrangements (Correct answer)
Correct answer: Independent Review Organization (IRO) audits of claims and arrangements
CIAs typically require the organization to engage an Independent Review Organization (IRO) to conduct objective audits of claims, arrangements, or other specified areas.
Question 58: Under the HITECH Act, which type of organization is required to conduct a security risk analysis as part of compliance?
- Covered entities and business associates handling electronic protected health information (Correct answer)
- All publicly traded healthcare companies
- Any organization with more than 500 employees
- Only federally funded hospitals
Correct answer: Covered entities and business associates handling electronic protected health information
HITECH expanded HIPAA requirements to business associates, making both covered entities and their business associates responsible for conducting security risk analyses.
Question 59: Under the Exclusion Statute, which OIG exclusion type is mandatory and has no discretion for waiver?
- Exclusion for licensure revocation related to patient care
- Exclusion following conviction of program-related crimes (Correct answer)
- Exclusion for default on health education loans
- Exclusion for improper billing practices
Correct answer: Exclusion following conviction of program-related crimes
Mandatory exclusions under 42 U.S.C. § 1320a-7(a) are triggered by convictions for program-related crimes, patient abuse, felony healthcare fraud, and controlled substance felonies — the OIG has no discretion to waive these.
Question 60: What does the term 'Upjohn warning' refer to in the context of a healthcare compliance investigation?
- A notice to employees that their communications with company counsel represent the organization, not them personally (Correct answer)
- A notification to physicians about their billing audit results
- A mandatory disclosure to regulators about discovered violations
- A warning label required on all investigation reports
Correct answer: A notice to employees that their communications with company counsel represent the organization, not them personally
An Upjohn warning, derived from Upjohn Co. v. United States, informs employees that legal counsel represents the organization and that communications may be disclosed.
Question 61: When using a risk assessment survey to gather input from department managers, the compliance team should PRIMARILY ensure that:
- Responses are anonymous to encourage candid feedback (Correct answer)
- Questions are open-ended only, with no rating scales
- Surveys are completed only by the CEO and CFO
- All survey data is shared publicly with patients
Correct answer: Responses are anonymous to encourage candid feedback
Anonymity encourages honest reporting of risks and concerns that employees might otherwise fear disclosing to leadership.
Question 62: What role does a 'work plan' serve in an OIG compliance context for healthcare organizations?
- It replaces the need for a written compliance policy manual
- It is a required document that all providers must submit to CMS annually
- It details the internal staffing plan for a compliance department
- It is the annual list of OIG audit and enforcement priorities used to guide internal compliance focus (Correct answer)
Correct answer: It is the annual list of OIG audit and enforcement priorities used to guide internal compliance focus
The OIG Work Plan identifies the areas the OIG plans to review, helping healthcare organizations prioritize their own internal auditing and monitoring efforts.
Question 63: A hospital's policy prohibits employees from accepting gifts valued at more than $25 from vendors. An employee receives a $50 vendor gift but returns it immediately. According to compliance best practices, the employee should NEXT:
- Notify the vendor's sales manager directly
- Document the incident in their personal records only
- Take no further action since the gift was returned
- Report the offer to the compliance department per policy (Correct answer)
Correct answer: Report the offer to the compliance department per policy
Best practice requires reporting gift offers that exceed the policy threshold to the compliance department, even when the gift is returned, to enable tracking and monitoring of vendor relationships.
Question 64: The OIG's List of Excluded Individuals and Entities (LEIE) is significant for healthcare compliance programs primarily because:
- It applies only to individuals excluded for fraud, not for quality-of-care violations
- Entities that employ or pay excluded individuals may be subject to civil monetary penalties (Correct answer)
- Exclusion from the LEIE automatically triggers loss of a provider's state medical license
- It lists all providers who have been investigated but not charged
Correct answer: Entities that employ or pay excluded individuals may be subject to civil monetary penalties
Organizations that employ or contract with LEIE-excluded individuals for services paid by federal healthcare programs can face significant civil monetary penalties.
Question 65: Which of the following is a key difference between civil and criminal liability under the False Claims Act?
- Civil FCA applies only to healthcare, while criminal FCA applies to all industries
- Civil FCA requires proof of specific intent to defraud, while criminal does not
- Criminal FCA can result in imprisonment, while civil FCA results in monetary penalties and treble damages (Correct answer)
- Criminal FCA requires proof of actual monetary loss to the government
Correct answer: Criminal FCA can result in imprisonment, while civil FCA results in monetary penalties and treble damages
Criminal FCA convictions can result in fines and up to 10 years imprisonment, while civil FCA liability results in per-claim penalties plus treble the damages sustained by the government.
Question 66: Which metric is most useful for evaluating whether compliance training content remains current and relevant?
- Frequency of trainer availability
- Time since the training was first published
- Total number of staff who completed training
- Rate of policy violations in areas covered by existing training modules (Correct answer)
Correct answer: Rate of policy violations in areas covered by existing training modules
Ongoing violations in areas covered by training signal that content may be outdated, unclear, or ineffective and requires revision.
Question 67: What is the statute of limitations for the government to bring a False Claims Act civil suit not involving a qui tam relator?
- 5 years
- 6 years (Correct answer)
- 3 years
- 10 years
Correct answer: 6 years
The FCA provides a six-year statute of limitations for government-initiated civil actions, though it can extend to 10 years in qui tam cases depending on when the government knew or should have known of the violation.
Question 68: A compliance team wants to validate that their risk assessment methodology is consistent with industry standards. Which resource BEST supports this?
- OIG Compliance Program Guidance and the COSO Enterprise Risk Management Framework (Correct answer)
- Joint Commission National Patient Safety Goals
- IRS Publication 15 (Employer Tax Guide)
- CMS Medicare Advantage marketing guidelines only
Correct answer: OIG Compliance Program Guidance and the COSO Enterprise Risk Management Framework
The OIG compliance program guidance and the COSO ERM framework together provide the most authoritative and widely accepted standards for healthcare compliance risk assessment methodology.
Question 69: What is the OIG's recommended practice regarding documentation of compliance hotline reports?
- Document only reports that involve billing or coding issues
- Document all reports to maintain an audit trail and track investigation outcomes and patterns (Correct answer)
- Avoid documenting anonymous reports to protect source confidentiality
- Limit documentation to reports involving potential criminal activity
Correct answer: Document all reports to maintain an audit trail and track investigation outcomes and patterns
OIG guidance recommends documenting all hotline reports to maintain a complete audit trail, identify patterns of non-compliance, and demonstrate the organization's compliance efforts.
Question 70: Which of the following is an example of a 'red flag' that might trigger a reactive compliance audit?
- Renewal of the compliance officer's certification
- Receipt of an OIG advisory opinion
- Publication of the annual OIG Work Plan
- A whistleblower complaint alleging systematic billing fraud (Correct answer)
Correct answer: A whistleblower complaint alleging systematic billing fraud
A whistleblower complaint alleging systematic billing fraud is a specific trigger that warrants an immediate reactive audit to investigate the claim.
Question 71: A healthcare organization conducts an internal investigation and finds evidence of FCA violations. Under the voluntary disclosure protocol, to which agency should it disclose?
- The OIG's Self-Disclosure Protocol or the DOJ's Civil Division (Correct answer)
- The Department of Justice only
- The relevant Medicare Administrative Contractor
- The state Medicaid Fraud Control Unit
Correct answer: The OIG's Self-Disclosure Protocol or the DOJ's Civil Division
Organizations with potential FCA violations can use the OIG's Self-Disclosure Protocol or, for matters involving the Civil Division, the DOJ's Voluntary Self-Disclosure Program to receive more favorable settlement terms.
Question 72: An effective compliance education program should ensure that training is provided to employees at which key intervals?
- Every two years to align with CHC certification renewal cycles.
- Whenever a government agency releases a new advisory opinion.
- Only upon the initial hiring of the employee.
- Upon hire, annually, and when policies or job duties change significantly. (Correct answer)
Correct answer: Upon hire, annually, and when policies or job duties change significantly.
OIG guidance and compliance best practices state that training must be an ongoing process, not a one-time event. This includes initial training for new hires, regular periodic training (typically annually) for all employees, and additional, targeted training when an employee's responsibilities change or when new laws, regulations, or policies that affect their role are introduced.
Question 73: Which of the following is the PRIMARY output of a comprehensive healthcare compliance risk assessment process?
- A report detailing every potential compliance risk, regardless of severity
- A revised annual budget for the legal and compliance departments
- A list of employees who have violated the code of conduct
- A prioritized work plan for the compliance department's auditing, monitoring, and training activities (Correct answer)
Correct answer: A prioritized work plan for the compliance department's auditing, monitoring, and training activities
The ultimate goal of a risk assessment is not just to identify risks, but to evaluate and prioritize them to create an actionable plan. This prioritized work plan guides the compliance department's activities for the upcoming year, ensuring that resources are focused on the areas of greatest vulnerability and significance.
Question 74: Which document outlines the standards of conduct and ethical expectations for all employees in a healthcare organization's compliance program?
- The code of conduct (Correct answer)
- The compliance work plan
- The audit report
- The corporate integrity agreement
Correct answer: The code of conduct
The code of conduct establishes the organization's ethical standards and behavioral expectations that all employees are required to follow.
Question 75: How should a compliance program handle training for contracted vendors and third parties who access PHI?
- Business Associate Agreements should require vendors to train their staff, and compliance may audit training records (Correct answer)
- Only full-time employees need PHI-related training
- Training obligations end once a BAA is signed
- Vendors are solely responsible for their own HIPAA training
Correct answer: Business Associate Agreements should require vendors to train their staff, and compliance may audit training records
BAAs establish training obligations, and healthcare organizations should verify that business associates comply to mitigate downstream risk.
Question 76: In the context of healthcare compliance, what does 'HEAT' stand for?
- Health Care Fraud Prevention and Enforcement Action Team (Correct answer)
- Healthcare Expenditure Accountability Team
- Healthcare Enforcement and Audit Taskforce
- Hospital Error Analysis and Tracking
Correct answer: Health Care Fraud Prevention and Enforcement Action Team
HEAT (Health Care Fraud Prevention and Enforcement Action Team) is a joint DOJ and HHS initiative to prevent and combat Medicare and Medicaid fraud.
Question 77: Which law prohibits a physician from making referrals for designated health services to entities in which the physician has a financial relationship, absent an applicable exception?
- Civil Monetary Penalties Law
- Stark Law (Correct answer)
- False Claims Act
- Anti-Kickback Statute
Correct answer: Stark Law
The Physician Self-Referral Law (Stark Law) prohibits physicians from referring Medicare or Medicaid patients for designated health services to entities with which the physician has a financial relationship unless a specific exception applies.
Question 78: A compliance officer for a hospital system is initiating the annual compliance risk assessment. In addition to reviewing internal data such as incident reports and past audit findings, which external resource is MOST critical for identifying potential new areas of regulatory scrutiny?
- The Office of Inspector General (OIG) Work Plan (Correct answer)
- The American Medical Association (AMA) Code of Ethics
- The Joint Commission's accreditation manual
- Press releases from competing hospital systems
Correct answer: The Office of Inspector General (OIG) Work Plan
The OIG Work Plan publicly outlines the audits, evaluations, and inspections the OIG plans to conduct for HHS programs during the fiscal year. Reviewing the Work Plan is a crucial step for any healthcare compliance professional to identify the government's enforcement priorities and proactively assess their own organization's risk in those specific areas.
Question 79: A workforce member accesses the records of a celebrity patient out of curiosity without clinical need. This is best described as:
- A HIPAA Privacy Rule violation due to impermissible access (Correct answer)
- An authorized disclosure for treatment operations
- A permissible use for quality improvement purposes
- An incidental disclosure permissible under HIPAA
Correct answer: A HIPAA Privacy Rule violation due to impermissible access
Accessing PHI without a legitimate purpose violates the minimum necessary and permissible use standards of the HIPAA Privacy Rule.
Question 80: Which federal statute specifically prohibits healthcare providers from retaliating against employees who report Medicare or Medicaid fraud?
- HIPAA's workforce sanction policy requirement
- The National Labor Relations Act
- The False Claims Act's anti-retaliation provision (Correct answer)
- The Occupational Safety and Health Act
Correct answer: The False Claims Act's anti-retaliation provision
The False Claims Act contains an explicit anti-retaliation provision (31 U.S.C. § 3730(h)) protecting employees, contractors, and agents who engage in protected activity related to FCA violations from discharge, demotion, or harassment.
Question 81: What is the significance of conducting compliance program audits on a 'risk-stratified' basis?
- It allocates audit resources to areas with the highest compliance risk first (Correct answer)
- It focuses audits exclusively on billing and coding
- It eliminates the need for routine audits
- It ensures every department is audited equally regardless of risk level
Correct answer: It allocates audit resources to areas with the highest compliance risk first
Risk-stratified auditing directs compliance resources toward the areas most likely to have compliance issues, maximizing the program's effectiveness.
Question 82: An employee subject to discipline has the right to 'due process' in a healthcare compliance context. This PRIMARILY means:
- The employee must be given a jury trial before any discipline is imposed
- The employee receives notice of allegations and an opportunity to respond before final action (Correct answer)
- The employee can veto the disciplinary outcome
- All discipline must be reviewed by the state medical board
Correct answer: The employee receives notice of allegations and an opportunity to respond before final action
Due process in the employment context means the employee is informed of the specific allegations and given a meaningful opportunity to respond before discipline is finalized.
Question 83: EMTALA requires hospitals with emergency departments to provide which minimum level of service to all patients who present?
- A medical screening examination regardless of ability to pay (Correct answer)
- Admission to the hospital if any emergency condition is suspected
- Transfer to a facility accepting Medicaid within two hours
- Full treatment until the patient is cured or stabilized
Correct answer: A medical screening examination regardless of ability to pay
EMTALA mandates that hospitals provide an appropriate medical screening examination to any individual who comes to the emergency department requesting examination or treatment, regardless of payment status.
Question 84: When developing a new compliance policy, stakeholder input should be gathered PRIMARILY from:
- The compliance department in isolation to maintain independence
- External auditors only, to ensure objectivity
- Subject matter experts, operational staff, legal counsel, and leadership (Correct answer)
- Only the C-suite to ensure strategic alignment
Correct answer: Subject matter experts, operational staff, legal counsel, and leadership
Effective policies reflect operational realities and regulatory requirements, requiring input from those who implement the policy, legal counsel, and organizational leadership.
Question 85: A whistleblower files a qui tam lawsuit under the False Claims Act. The government decides to intervene. What percentage of the total recovery can the relator (whistleblower) generally receive?
- 10–25% (if the government intervenes) or 25–30% (if the government declines) (Correct answer)
- Up to 50%
- 15–30%
- 1–5%
Correct answer: 10–25% (if the government intervenes) or 25–30% (if the government declines)
Under the FCA, relators in government-intervened cases receive 15–25% of the recovery; if the government declines and the relator proceeds alone, the share is 25–30%.
Question 86: A hospital risk assessment reveals high inherent risk in physician self-referrals. Which law governs this area?
- Emergency Medical Treatment and Labor Act (EMTALA)
- Stark Law (Physician Self-Referral Law) (Correct answer)
- HIPAA Security Rule
- Anti-Kickback Statute only
Correct answer: Stark Law (Physician Self-Referral Law)
The Stark Law prohibits physicians from referring patients to entities with which they have a financial relationship unless a specific exception applies.
Question 87: Which of the following BEST describes the role of the compliance committee in a healthcare organization?
- Handling all employee grievances related to workplace issues
- Conducting annual financial audits
- Replacing the compliance officer's duties during vacations
- Providing oversight, guidance, and support for compliance program operations (Correct answer)
Correct answer: Providing oversight, guidance, and support for compliance program operations
The compliance committee provides oversight, guidance, and multidisciplinary support to help administer and strengthen the compliance program.
Question 88: What is 'place of service' coding and why is it critical in Medicare billing compliance?
- It identifies the type of insurance the patient carries
- It indicates where a service was rendered and affects reimbursement rates and coverage rules (Correct answer)
- It tracks which payer is responsible for the claim
- It identifies the city where the provider practices
Correct answer: It indicates where a service was rendered and affects reimbursement rates and coverage rules
Place of service codes on claims tell Medicare where the service was provided (e.g., office, hospital, telehealth), which directly affects applicable payment rates and coverage determinations.
Question 89: A compliance department uses a learning management system (LMS) to assign and track training. Which LMS capability is MOST critical from a compliance audit perspective?
- Automated audit trails showing who completed what training and when (Correct answer)
- Mobile-friendly interface for remote access
- Gamification features to increase engagement
- Integration with the organization's email system
Correct answer: Automated audit trails showing who completed what training and when
Audit trails provide the documented evidence needed to demonstrate training completion during government investigations or accreditation surveys.
Question 90: When scoping a compliance risk assessment, which approach ensures the HIGHEST coverage of organizational risks?
- Rely solely on department manager self-assessments
- Focus only on areas flagged in prior audits
- Limit scope to billing and coding
- Use a universe-based approach covering all business processes (Correct answer)
Correct answer: Use a universe-based approach covering all business processes
A universe-based approach inventories all business processes and systematically evaluates each for compliance risk, ensuring no area is overlooked.
Question 91: Which type of audit involves reviewing claims BEFORE they are submitted to payers to catch errors proactively?
- Prospective audit (Correct answer)
- Retrospective audit
- External audit
- Concurrent audit
Correct answer: Prospective audit
Prospective audits review claims before submission to identify and correct coding or documentation errors, preventing improper payments from occurring.
Question 92: Which of the following BEST represents a 'proactive' audit in a compliance program?
- An audit initiated after receiving a government subpoena
- An audit triggered by a pattern of payer denials
- An audit conducted in response to a media report about billing fraud
- A scheduled review of high-risk billing areas before any specific issue is identified (Correct answer)
Correct answer: A scheduled review of high-risk billing areas before any specific issue is identified
Proactive audits are scheduled in advance as part of the annual audit work plan to identify and correct issues before they become problems or attract external scrutiny.
Question 93: Which of the following arrangements would most likely qualify for the Anti-Kickback Statute 'employment safe harbor'?
- A per diem medical director paid per patient referred to surgery
- An independent contractor paid per referral made to the hospital
- A consultant paid based on the value of business generated
- A bona fide employee receiving a salary not based on referral volume (Correct answer)
Correct answer: A bona fide employee receiving a salary not based on referral volume
The employment safe harbor protects compensation paid by an employer to a bona fide employee for services in the employer's business, provided it is not based on the volume or value of referrals.
Question 94: Which of the following is the PRIMARY purpose of a healthcare organization's document retention policy?
- To prevent employees from accessing historical compliance documents
- To minimize the volume of paper stored in physical filing rooms
- To ensure records are retained for legally required periods and disposed of securely (Correct answer)
- To standardize font sizes and formatting across all organizational documents
Correct answer: To ensure records are retained for legally required periods and disposed of securely
Document retention policies ensure records are kept for legally mandated periods and destroyed securely afterward, balancing legal obligations with data minimization.
Question 95: Which of the following best describes 'phantom billing' in healthcare fraud?
- Billing separately for procedures that should be bundled
- Billing for services that were never provided to the patient (Correct answer)
- Billing for a non-covered service using a covered service code
- Billing for a more expensive procedure than performed
Correct answer: Billing for services that were never provided to the patient
Phantom billing refers to submitting claims for services, procedures, or supplies that were never actually provided to the patient.
Question 96: Which of the following BEST describes the concept of 'proportionality' in applying disciplinary actions under a compliance program?
- All violations should result in immediate termination to deter misconduct
- Discipline should only apply to senior-level employees
- Disciplinary actions should be kept secret to avoid embarrassment
- Discipline should be commensurate with the severity of the violation and applied consistently (Correct answer)
Correct answer: Discipline should be commensurate with the severity of the violation and applied consistently
Proportionality ensures that disciplinary sanctions fit the severity of the violation and are applied consistently to maintain fairness and deter future misconduct.
Question 97: A compliance officer discovers a physician has been upcoding claims for 18 months. Under the OIG's voluntary disclosure guidance, the organization should:
- Wait until the False Claims Act statute of limitations expires
- Report to the OIG Self-Disclosure Protocol and cooperate fully (Correct answer)
- Issue an internal written warning and monitor future claims
- Quietly refund overpayments without notifying the OIG
Correct answer: Report to the OIG Self-Disclosure Protocol and cooperate fully
The OIG Self-Disclosure Protocol is the appropriate channel when an organization identifies potential fraud that it wishes to resolve proactively.
Question 98: The OIG's Corporate Integrity Agreements (CIAs) typically require organizations to:
- Adopt voluntary self-disclosure as a permanent compliance strategy
- Replace their board of directors with government-appointed overseers
- Implement specific compliance program elements, reporting, and independent review (Correct answer)
- Immediately terminate all federal program participation
Correct answer: Implement specific compliance program elements, reporting, and independent review
CIAs obligate organizations to implement OIG-specified compliance enhancements, annual certifications, and often independent review organization (IRO) monitoring.
Question 99: A healthcare compliance officer receives an anonymous hotline report alleging that a supervisor is falsifying patient records. What is the correct FIRST step?
- Conduct a preliminary assessment to determine if an investigation is warranted (Correct answer)
- Notify the supervisor that a complaint has been filed
- Discard the report since it is anonymous
- Immediately terminate the supervisor
Correct answer: Conduct a preliminary assessment to determine if an investigation is warranted
All hotline reports, including anonymous ones, require a preliminary assessment to determine scope, severity, and whether a formal investigation is needed.
Question 100: Which of the following best describes 'just-in-time' compliance training?
- Training outsourced to an LMS vendor on a fixed schedule
- Training provided immediately before or at the point of a new process, policy, or regulation taking effect (Correct answer)
- Training that is completed in one session without breaks
- Training delivered exactly at the annual renewal date
Correct answer: Training provided immediately before or at the point of a new process, policy, or regulation taking effect
Just-in-time training delivers relevant information at the moment it is needed, maximizing application and reducing the gap between learning and practice.
Question 101: A hospital's new Compliance Officer is developing the annual compliance training plan. To ensure the training is effective and meets OIG recommendations, which of the following elements is most crucial to include?
- Job-specific training that addresses the high-risk areas relevant to different employee roles. (Correct answer)
- A detailed review of every federal healthcare law and regulation.
- A final exam with a mandatory 100% passing score for all employees.
- Training conducted exclusively by external legal counsel to ensure accuracy.
Correct answer: Job-specific training that addresses the high-risk areas relevant to different employee roles.
The OIG emphasizes that effective training should be tailored to the audience. While general compliance awareness is important for everyone, job-specific training focuses on the particular compliance risks employees face in their daily duties (e.g., coding, billing, clinical care), making the information more relevant and actionable.
Question 102: Which type of audit compares an organization's compliance performance to industry norms or peer organizations?
- Internal retrospective audit
- Desk audit
- Concurrent audit
- Benchmarking audit (Correct answer)
Correct answer: Benchmarking audit
Benchmarking audits compare an organization's results to external standards, peer organizations, or industry averages to identify areas of relative risk or performance gaps.
Question 103: Which statute imposes criminal and civil penalties for knowingly submitting false claims to federal healthcare programs?
- False Claims Act (Correct answer)
- HIPAA Privacy Rule
- Stark Law
- Anti-Kickback Statute
Correct answer: False Claims Act
The False Claims Act (31 U.S.C. §§ 3729–3733) imposes liability on persons who knowingly present false or fraudulent claims for payment to the federal government.
Question 104: How often does OIG guidance suggest that compliance training be provided to healthcare organization employees at a minimum?
- Only at initial hire
- Every three years
- Annually (Correct answer)
- Monthly
Correct answer: Annually
OIG guidance recommends annual compliance training at a minimum, with more frequent training when new risks or regulatory changes arise.
Question 105: Under the OIG's Seven Elements of an Effective Compliance Program, policies and procedures should be reviewed at minimum:
- Every five years
- Every ten years unless laws change
- Only when a violation is discovered
- Annually or when significant regulatory changes occur (Correct answer)
Correct answer: Annually or when significant regulatory changes occur
The OIG recommends policies be reviewed at least annually and updated promptly when laws, regulations, or organizational operations change.
Question 106: Under the Civil Monetary Penalties Law (CMPL), what is the maximum per-claim penalty for knowingly presenting a false claim to Medicare?
- $50,000
- $5,000
- $25,000
- $10,000 (Correct answer)
Correct answer: $10,000
The CMPL imposes penalties of up to $10,000 per false or fraudulent claim submitted to Medicare or Medicaid, in addition to three times the amount claimed.
Question 107: A Business Associate Agreement (BAA) must include which of the following provisions?
- A requirement for the BA to obtain malpractice insurance
- The business associate's annual revenue disclosures
- Permitted and required uses and disclosures of PHI by the business associate (Correct answer)
- A provision limiting the BA's subcontractors to US-based firms only
Correct answer: Permitted and required uses and disclosures of PHI by the business associate
A BAA must describe the permitted and required uses and disclosures of PHI that the business associate may make on behalf of the covered entity.
Question 108: In the context of healthcare compliance, what does 'downstream risk' refer to?
- Risks identified in lower-level staff positions
- Compliance risks passed to an organization through its business partners and vendors (Correct answer)
- Financial risks that decrease over time
- Audit findings from previous fiscal years
Correct answer: Compliance risks passed to an organization through its business partners and vendors
Downstream risk refers to compliance liability that an organization may inherit from its business associates, contractors, or referral partners who engage in non-compliant behavior.
Question 109: Which element of an effective compliance program focuses on identifying and addressing compliance risks before they result in violations?
- Proactive risk assessment (Correct answer)
- Punitive enforcement
- Reactive auditing
- Retrospective review
Correct answer: Proactive risk assessment
Proactive risk assessment identifies potential compliance vulnerabilities before they result in violations, allowing corrective action to be taken.
Question 110: What is the primary purpose of the OIG's List of Excluded Individuals and Entities (LEIE)?
- To identify parties excluded from participating in federal healthcare programs (Correct answer)
- To track providers under active DOJ investigation
- To list healthcare entities with HIPAA violations
- To identify providers with malpractice judgments
Correct answer: To identify parties excluded from participating in federal healthcare programs
The LEIE identifies individuals and entities excluded from participation in Medicare, Medicaid, and other federal healthcare programs due to fraud, abuse, or other disqualifying conduct.
Question 111: Which of the following scenarios demonstrates a conflict of interest in developing compliance training content?
- Aligning training content with an annually updated risk assessment
- A compliance officer using OIG advisory opinions to guide training topics
- Using internal subject matter experts to review training accuracy
- A vendor that sells billing software also providing the only approved coding compliance training to the organization (Correct answer)
Correct answer: A vendor that sells billing software also providing the only approved coding compliance training to the organization
Allowing a vendor with a financial interest in the subject matter to exclusively control compliance training creates an inherent conflict that could compromise the objectivity and rigor of the content.
Question 112: Which of the following scenarios represents a 'trigger event' that should prompt an unscheduled compliance risk assessment update?
- Annual open enrollment period for employee benefits
- Filing of the organization's annual tax return
- Acquisition of a new hospital or practice (Correct answer)
- Routine quarterly board meeting
Correct answer: Acquisition of a new hospital or practice
An acquisition introduces new processes, staff, systems, and regulatory exposures that must be assessed before they are fully integrated.
Question 113: A patient reviews their medical record and finds an error in their diagnosis history. Under the HIPAA Privacy Rule, the patient has the right to request an amendment to their PHI. What is the covered entity's obligation after receiving this request?
- Require the patient to obtain a court order before any amendment can be considered.
- Immediately delete the incorrect information from the record as requested by the patient.
- Act on the request within a reasonable time, typically within 60 days, by either making the amendment or providing a written denial. (Correct answer)
- Inform the patient that medical records cannot be changed once they are finalized.
Correct answer: Act on the request within a reasonable time, typically within 60 days, by either making the amendment or providing a written denial.
The HIPAA Privacy Rule gives individuals the right to request an amendment to their PHI in a designated record set. The covered entity must act on the request, typically within 60 days (with a possible 30-day extension). It can either accept the amendment and notify the patient and relevant parties, or provide the individual with a timely, written denial explaining the basis for the decision and their right to submit a disagreement.
Question 114: What is the PRIMARY purpose of maintaining a detailed investigation log during a healthcare compliance inquiry?
- To satisfy state licensing requirements
- To create a chronological record that supports defensibility and demonstrates thoroughness (Correct answer)
- To share progress updates with all hospital staff
- To calculate investigator billable hours
Correct answer: To create a chronological record that supports defensibility and demonstrates thoroughness
A detailed investigation log creates a contemporaneous record that demonstrates the investigation was conducted fairly, thoroughly, and in good faith.
Question 115: What is the recommended approach when a compliance investigation reveals that a violation was systemic rather than an isolated incident?
- Immediately self-disclose to all relevant government agencies
- Address only the individual employees involved and close the investigation
- Implement systemic corrective actions, update policies, and provide targeted retraining (Correct answer)
- Terminate the entire department involved
Correct answer: Implement systemic corrective actions, update policies, and provide targeted retraining
Systemic violations require systemic corrective actions including policy updates, process changes, and targeted training to prevent recurrence across the organization.
Question 116: Under the HIPAA Privacy Rule, which of the following is a required element of a valid patient authorization?
- The specific dollar amount of any payment for the disclosure
- Witness signature from a licensed clinician
- Notarization of the authorization document
- A statement that the individual may revoke the authorization in writing (Correct answer)
Correct answer: A statement that the individual may revoke the authorization in writing
A valid HIPAA authorization must include a statement that the individual has the right to revoke the authorization in writing.
Question 117: Which data source is LEAST useful when identifying compliance risks in a physician practice?
- Patient complaint records
- Claims denial patterns from payers
- Employee complaint hotline reports
- Office furniture inventory logs (Correct answer)
Correct answer: Office furniture inventory logs
Furniture inventory logs contain no information relevant to billing, coding, privacy, or other compliance risk areas for a physician practice.
Question 118: What does a non-retaliation policy in healthcare compliance primarily prohibit?
- Adverse employment actions against employees who report compliance concerns in good faith (Correct answer)
- Managers from disciplining employees for documented performance deficiencies
- Employees from discussing compliance issues with their coworkers
- Employees from filing complaints directly with government agencies
Correct answer: Adverse employment actions against employees who report compliance concerns in good faith
A non-retaliation policy prohibits adverse employment actions—such as demotion, termination, or harassment—against employees who report compliance concerns in good faith.
Question 119: Which element is MOST critical when documenting disciplinary actions to protect the organization in future legal proceedings?
- Documenting specific policy provisions violated and evidence supporting the finding (Correct answer)
- Using informal notes rather than official HR forms
- Omitting dates to preserve employee privacy
- Recording the supervisor's personal opinion of the employee
Correct answer: Documenting specific policy provisions violated and evidence supporting the finding
Precise documentation of the specific policy violated and supporting evidence creates a defensible record if the discipline is later challenged.
Question 120: Which federal agency publishes the OIG Work Plan that healthcare compliance officers use to prioritize audit areas each year?
- Centers for Medicare & Medicaid Services (CMS)
- Department of Justice (DOJ)
- Office for Civil Rights (OCR)
- Office of Inspector General (OIG) (Correct answer)
Correct answer: Office of Inspector General (OIG)
The OIG publishes its annual Work Plan to identify areas of focus for audits and investigations in Medicare and Medicaid programs.
Question 121: Which element distinguishes the Stark Law from the Anti-Kickback Statute with respect to intent?
- Stark requires proof of willful intent; AKS is strict liability
- Neither statute requires intent if the financial benefit exceeds $10,000
- Stark is strict liability; AKS requires proof of knowing and willful intent (Correct answer)
- Both statutes require proof of intentional misconduct
Correct answer: Stark is strict liability; AKS requires proof of knowing and willful intent
Stark Law is a strict liability civil statute — no proof of intent is needed — while the AKS requires the government to prove the defendant acted knowingly and willfully.
Question 122: The 'two-midnight rule' in Medicare billing primarily governs which type of admission?
- Emergency department visit coding
- Observation status billing
- Inpatient hospital admissions and whether they meet criteria for Part A payment (Correct answer)
- Outpatient surgery billing
Correct answer: Inpatient hospital admissions and whether they meet criteria for Part A payment
CMS's two-midnight rule states that inpatient admission is generally appropriate if the physician expects the patient to require hospital care spanning at least two midnights, qualifying for Part A reimbursement.
Question 123: A surgeon performs a procedure and separately bills for pre- and post-operative care that is normally included in the global surgical package. This billing practice is known as:
- Duplicate billing
- Balance billing
- Upcoding
- Unbundling (Correct answer)
Correct answer: Unbundling
Unbundling means billing separately for services that are components of a global service package that should be billed as a single comprehensive code.
Question 124: The False Claims Act (FCA) imposes liability on healthcare organizations that submit claims that are:
- Knowingly false or fraudulent to government payers (Correct answer)
- Denied and subsequently appealed
- Coded using outdated but not incorrect billing codes
- Late but accurate
Correct answer: Knowingly false or fraudulent to government payers
The FCA targets knowingly false, fraudulent, or recklessly disregarded claims submitted to federal healthcare programs.
Question 125: A compliance officer is asked to report to the board of directors on the compliance program. Which type of information is MOST important to include?
- A full list of all compliance policies in effect
- Detailed descriptions of all individual employee discipline cases
- The compliance officer's personal recommendations for salary increases
- Key metrics, significant risks identified, investigations completed, and program effectiveness measures (Correct answer)
Correct answer: Key metrics, significant risks identified, investigations completed, and program effectiveness measures
Board reports should focus on program performance metrics, significant risks, investigation outcomes, and overall effectiveness to enable informed governance oversight.
Question 126: A healthcare organization's policy version control system should MOST importantly track:
- The department that requested the policy change
- Effective dates, revision history, approving authority, and next review date (Correct answer)
- The number of employees who accessed each policy version
- The word count of each policy revision
Correct answer: Effective dates, revision history, approving authority, and next review date
Version control must capture effective dates, revision history, approvals, and scheduled reviews to demonstrate governance and support audit readiness.
Question 127: When a compliance investigation concludes that an employee violated policy unintentionally due to inadequate training, the MOST appropriate remedial measure is:
- Formal written warning with no follow-up
- Referral to the OIG for voluntary disclosure
- Immediate termination to deter future violations
- Mandatory retraining and closer supervision (Correct answer)
Correct answer: Mandatory retraining and closer supervision
Unintentional violations stemming from training gaps are best addressed through mandatory retraining and enhanced supervision rather than punitive termination.
Question 128: Under the False Claims Act, what is 'qui tam' as it relates to healthcare investigations?
- A requirement to report fraud to the OIG within 60 days
- A type of government subpoena for medical records
- A compliance program certification requirement
- A provision allowing private individuals to file suit on behalf of the government and share in any recovery (Correct answer)
Correct answer: A provision allowing private individuals to file suit on behalf of the government and share in any recovery
Qui tam provisions of the FCA allow whistleblowers (relators) to sue on behalf of the government and receive a portion of any funds recovered.
Question 129: A healthcare organization is developing its compliance program. Which of the following BEST distinguishes between policies and procedures?
- Policies are high-level statements of management's intent and values, while procedures provide mandatory, step-by-step instructions to implement those policies. (Correct answer)
- Policies are optional guidelines, whereas procedures are mandatory regulations enforced by government agencies.
- Policies are detailed, step-by-step instructions for specific tasks, while procedures are high-level statements of intent.
- Policies apply only to clinical staff, while procedures apply to all employees and contractors.
Correct answer: Policies are high-level statements of management's intent and values, while procedures provide mandatory, step-by-step instructions to implement those policies.
Policies are broad, high-level statements that communicate management's intent, goals, and the organization's values. Procedures are the detailed, mandatory, step-by-step instructions that describe how to carry out a policy. For example, a policy might state that the organization will protect patient information, while a procedure would outline the specific steps for accessing, sharing, and destroying PHI.
Question 130: Under the False Claims Act, what is 'qui tam' litigation?
- A type of compliance certification
- A mandatory self-disclosure to the OIG
- A government audit of Medicare claims
- A whistleblower lawsuit filed on behalf of the government by a private individual (Correct answer)
Correct answer: A whistleblower lawsuit filed on behalf of the government by a private individual
Qui tam provisions of the False Claims Act allow private individuals (relators) to sue on behalf of the government and share in any recovery.
Question 131: Which of the following is an essential component for demonstrating the effectiveness of a compliance training program to government auditors?
- Thorough documentation of attendance, topics covered, and comprehension assessments. (Correct answer)
- Employee testimonials about their engagement with the training materials.
- A detailed budget outlining the total cost of the training program.
- A list of all external vendors and consultants used to develop training content.
Correct answer: Thorough documentation of attendance, topics covered, and comprehension assessments.
To prove that a compliance training program is robust and functioning, an organization must maintain meticulous documentation. This serves as critical evidence and should include attendance logs, dates of training, the specific materials and topics covered, and results from any post-training assessments or quizzes used to gauge understanding. This documentation demonstrates a good-faith effort to educate the workforce.
Question 132: A hospital discovers that a physician has been receiving free office space from the hospital in exchange for referrals. This most likely violates which law?
- Anti-Kickback Statute (Correct answer)
- Clinical Laboratory Improvement Amendments (CLIA)
- HIPAA Privacy Rule
- Emergency Medical Treatment and Labor Act (EMTALA)
Correct answer: Anti-Kickback Statute
Receiving free office space in exchange for referrals constitutes remuneration linked to referral volume, which violates the Anti-Kickback Statute.
Question 133: Which of the following is a key requirement for the ongoing management of compliance policies and procedures?
- Archiving all policies that are more than three years old, regardless of their current relevance.
- Ensuring all policies are written exclusively by external legal counsel to guarantee compliance.
- A system for annual review and updates to reflect changes in laws, regulations, and business operations. (Correct answer)
- A process for certifying that every employee has memorized all key policies.
Correct answer: A system for annual review and updates to reflect changes in laws, regulations, and business operations.
Compliance policies and procedures are not static documents. An essential component of an effective compliance program is to have a system in place for their periodic (at least annual) review and update. This ensures they remain current with changing laws, regulations, and the organization's own operational realities.
Question 134: Under an OIG Corporate Integrity Agreement (CIA), what obligation does a healthcare organization typically have regarding internal investigations?
- Cease all operations under investigation until the CIA expires
- Notify the OIG within 30 days of initiating any internal investigation
- Share all attorney-client privileged investigation documents with the OIG
- Report certain investigations, findings, and corrective actions to an Independent Review Organization (IRO) (Correct answer)
Correct answer: Report certain investigations, findings, and corrective actions to an Independent Review Organization (IRO)
CIAs typically require reporting of significant compliance matters and corrective actions to an IRO that reports to the OIG.
Question 135: What is the primary function of compliance monitoring as distinct from compliance auditing?
- Monitoring is only conducted by external parties; auditing is internal
- Monitoring and auditing are identical activities with different names
- Monitoring is ongoing and routine; auditing involves in-depth, periodic review of specific areas (Correct answer)
- Monitoring involves one-time deep-dive reviews; auditing is ongoing
Correct answer: Monitoring is ongoing and routine; auditing involves in-depth, periodic review of specific areas
Monitoring is a continuous, routine process to detect potential issues early, while auditing is a more structured, periodic examination of specific risk areas.
Question 136: Which organization publishes the National Correct Coding Initiative (NCCI) edits used to prevent improper Medicare billing?
- OIG
- CMS (Correct answer)
- AMA
- AHA
Correct answer: CMS
CMS developed and publishes the NCCI to promote national correct coding methodologies and prevent improper payment of Part B claims.
Question 137: What is the recommended approach when an employee fails a compliance training assessment multiple times?
- Require remedial training, additional coaching, and documented follow-up (Correct answer)
- Waive the requirement due to the employee's difficulty
- Transfer the employee to a non-patient-facing role without further action
- Automatically terminate the employee
Correct answer: Require remedial training, additional coaching, and documented follow-up
Remediation with documented follow-up ensures the employee gains required knowledge while creating an audit trail showing compliance program responsiveness.
Question 138: Under the Anti-Kickback Statute (AKS), which element must the government prove to establish a criminal violation?
- The referral resulted in a Medicare overpayment
- The arrangement lacked a written contract
- The defendant received payment in excess of fair market value
- The defendant acted with willful intent to induce or reward referrals (Correct answer)
Correct answer: The defendant acted with willful intent to induce or reward referrals
The AKS requires proof that the defendant acted knowingly and willfully to offer, pay, solicit, or receive remuneration to induce or reward referrals of federal healthcare program business.
Question 139: In healthcare compliance, what is the significance of the '3-day payment window rule' for hospital outpatient services?
- Claims must be submitted within 3 days of service
- Providers have 3 days to correct billing errors
- Outpatient services provided within 3 days before an inpatient admission must be bundled into the inpatient claim (Correct answer)
- Medicare pays claims within 3 days of receipt
Correct answer: Outpatient services provided within 3 days before an inpatient admission must be bundled into the inpatient claim
Under the 3-day payment window rule, diagnostic and certain other outpatient services provided within 3 days prior to an inpatient admission are bundled into the DRG payment and cannot be billed separately.
Question 140: Under OIG compliance program guidance, how frequently should a healthcare organization's compliance risk assessment be reviewed?
- Only when a new regulation is enacted
- Every five years
- At least annually or when significant changes occur (Correct answer)
- Every two years as part of an accreditation cycle
Correct answer: At least annually or when significant changes occur
The OIG recommends that risk assessments be conducted at least annually and revisited whenever significant organizational or regulatory changes occur.
Question 141: Which of the OIG's seven elements of an effective compliance program specifically addresses reporting mechanisms?
- Element 5: Response to detected offenses and corrective action
- Element 1: Written standards of conduct and policies
- Element 4: Open lines of communication (Correct answer)
- Element 3: Effective training and education
Correct answer: Element 4: Open lines of communication
Element 4 of the OIG's seven elements calls for open lines of communication, including hotlines and anonymous reporting channels, so employees can report concerns without fear of retaliation.
Question 142: A compliance officer is reviewing a case where a nurse submitted false time records. The investigation is complete and discipline is warranted. Which sequence reflects BEST practice?
- Refer all cases to law enforcement before taking internal action
- Investigate thoroughly, document findings, consult HR and legal, then impose proportional discipline (Correct answer)
- Issue termination immediately upon allegation to protect the organization
- Discipline first, then investigate to confirm findings
Correct answer: Investigate thoroughly, document findings, consult HR and legal, then impose proportional discipline
Best practice requires completing a thorough investigation and consulting HR and legal before imposing discipline to ensure fairness, accuracy, and legal defensibility.
Question 143: Which federal law most directly creates the legal foundation for requiring compliance training programs in healthcare organizations receiving Medicare and Medicaid funds?
- The Occupational Safety and Health Act
- The Americans with Disabilities Act
- The Employee Retirement Income Security Act
- The Social Security Act and its conditions of participation (Correct answer)
Correct answer: The Social Security Act and its conditions of participation
The Social Security Act's conditions of participation require healthcare providers to maintain effective compliance programs, which include training elements.
Question 144: A compliance committee is reviewing the results of its annual risk assessment, which has identified over 50 potential compliance risks across various departments. What is the committee's BEST next step?
- Forward the entire list to the board of directors without comment.
- Systematically rank the risks based on probability and severity to determine which to address first. (Correct answer)
- Mandate organization-wide retraining on all policies and procedures.
- Assign every identified risk to the compliance officer for immediate investigation.
Correct answer: Systematically rank the risks based on probability and severity to determine which to address first.
After identifying risks, the critical next step in the risk assessment process is to analyze and prioritize them. A common method is to rank risks by considering their likelihood and potential impact. This allows the organization to develop a focused and manageable risk mitigation plan, addressing the most significant threats first.
Question 145: Which of the following best describes the primary purpose of ongoing monitoring activities in a healthcare compliance program?
- To detect and correct compliance issues in real-time or near real-time. (Correct answer)
- To satisfy the requirements of external government auditors.
- To serve as the sole basis for employee disciplinary actions.
- To provide an annual, independent assessment of the compliance program's effectiveness.
Correct answer: To detect and correct compliance issues in real-time or near real-time.
Ongoing monitoring is designed to be a continuous process that allows for the early detection of potential compliance issues, enabling prompt correction before they become systemic problems. Audits, by contrast, are periodic, point-in-time assessments.
Question 146: What role does the compliance risk assessment play within the broader framework of an effective compliance program?
- It eliminates all identified compliance risks permanently
- It serves as the foundation for directing compliance resources, training, and audit priorities (Correct answer)
- It replaces the need for a code of conduct
- It substitutes for mandatory government reporting
Correct answer: It serves as the foundation for directing compliance resources, training, and audit priorities
The risk assessment informs where the compliance program should focus its limited resources, including audits, training, and policy development.
Question 147: A compliance officer discovers that a department manager has been retaliating against an employee who reported a compliance concern. What is the MOST appropriate immediate action?
- Transfer the reporting employee to another department
- Issue a verbal warning to the manager
- Close the original compliance report
- Investigate the retaliation claim and protect the reporting employee (Correct answer)
Correct answer: Investigate the retaliation claim and protect the reporting employee
Non-retaliation policies must be enforced by immediately investigating retaliation claims and protecting the employee who reported the concern.
Question 148: After completing a self-disclosure to the OIG Self-Disclosure Protocol, the organization should expect the OIG to:
- Acknowledge receipt, conduct its own review, and negotiate a settlement that may include a multiplier on the overpayment (Correct answer)
- Automatically waive all penalties without further review
- Refer the matter to the DOJ for criminal prosecution in all cases
- Immediately exclude the organization from Medicare and Medicaid
Correct answer: Acknowledge receipt, conduct its own review, and negotiate a settlement that may include a multiplier on the overpayment
The OIG reviews self-disclosures and typically negotiates a settlement requiring repayment at a multiplier (often 1.5Ă—), which is lower than standard False Claims Act exposure.
Question 149: What does 'tone at the top' refer to in the context of healthcare compliance?
- Leadership's demonstrated commitment to ethical behavior and compliance (Correct answer)
- The order in which compliance policies are reviewed
- The hierarchy of compliance reporting lines
- The pitch of the compliance officer's presentation voice
Correct answer: Leadership's demonstrated commitment to ethical behavior and compliance
Tone at the top refers to the culture of integrity set by senior leadership, which significantly influences employee compliance behavior throughout the organization.
Question 150: Which of the following is a key output of a completed healthcare compliance risk assessment?
- A list of patients flagged for audits
- A prioritized risk register with recommended mitigation actions (Correct answer)
- A billing code crosswalk table
- A finalized employee disciplinary policy
Correct answer: A prioritized risk register with recommended mitigation actions
The risk register documents identified risks, their scores, responsible owners, and recommended controls, serving as the central deliverable of the assessment.
Question 151: A covered entity may use or disclose PHI without patient authorization for which of the following purposes?
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Disclosing to an employer for employment decisions
- Selling PHI to a data analytics company
- Marketing a third-party product using the patient's purchase history
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosure to law enforcement when required by law, such as mandatory reporting of gunshot wounds.
Question 152: An organization's corrective action plan submitted to the OIG following a self-disclosure should include all of the following EXCEPT:
- Steps taken to prevent recurrence
- Repayment amount and calculation methodology
- Names of all patients whose records were reviewed (Correct answer)
- Root cause analysis of the violation
Correct answer: Names of all patients whose records were reviewed
Corrective action plans address systemic fixes and repayment details; disclosing individual patient names is not a standard OIG requirement.
Question 153: A compliance investigation uncovers evidence of a criminal act by a hospital employee. What is the FIRST step the compliance officer should take?
- Notify law enforcement without further delay
- Consult with legal counsel and the organization's leadership (Correct answer)
- Immediately terminate the employee
- Publish the findings in an internal newsletter
Correct answer: Consult with legal counsel and the organization's leadership
Discovering criminal activity requires immediate consultation with legal counsel to determine reporting obligations and protect the organization.
Question 154: In a Corporate Integrity Agreement (CIA), what is the role of the Independent Review Organization (IRO)?
- To negotiate the terms of the CIA with the OIG
- To manage the organization's compliance training program
- To conduct independent reviews of claims and practices as required by the CIA (Correct answer)
- To replace the compliance officer during the CIA period
Correct answer: To conduct independent reviews of claims and practices as required by the CIA
An IRO conducts independent, objective reviews of the organization's billing, coding, and other practices as specified in the CIA to verify compliance.
Question 155: Which element of an effective compliance program does the OIG identify as critical for detecting potential violations early?
- Having a written compliance plan on file
- Conducting annual revenue audits
- Filing annual reports with CMS
- Maintaining open lines of communication including an anonymous hotline (Correct answer)
Correct answer: Maintaining open lines of communication including an anonymous hotline
The OIG's compliance guidance consistently emphasizes that open communication channels, including anonymous reporting hotlines, are critical for employees to report concerns without fear of retaliation.
Question 156: What stage of the Medicare Part A or Part B appeals procedure does a qualified independent contractor review the appeal?
- First level of appeal
- Fourth level of appeal
- Second level of appeal (Correct answer)
- Third level of appeal
Correct answer: Second level of appeal
In the Medicare Part A or Part B appeals process, the second level of appeal is where a Qualified Independent Contractor (QIC) reviews the appeal. The first level involves a redetermination by the Medicare Administrative Contractor (MAC), with subsequent levels including administrative law judges and federal court review.
Question 157: Under the Stark Law, which of the following financial relationships between a physician and a hospital would require a written exception?
- A physician treating Medicare patients at a non-related hospital
- A physician employed full-time by the hospital under a salary arrangement
- A physician who owns stock in the hospital and refers Medicare patients there (Correct answer)
- A physician providing pro bono care at a community health fair
Correct answer: A physician who owns stock in the hospital and refers Medicare patients there
Stark Law prohibits physician self-referrals unless a specific exception applies; physician ownership with referrals to that entity requires careful structuring under an applicable exception.
Question 158: Under the HITECH Act, which party became directly liable for compliance with certain HIPAA Security Rule provisions?
- Patients and their authorized representatives
- Covered entities only
- Business associates directly, not just through BAAs (Correct answer)
- HHS Office for Civil Rights investigators
Correct answer: Business associates directly, not just through BAAs
HITECH made business associates directly liable for compliance with many HIPAA Security Rule and Privacy Rule provisions, not just contractually liable through BAAs.
Question 159: Which of the following is an example of a required 'Technical Safeguard' under the HIPAA Security Rule?
- Developing a security awareness and training program for the workforce.
- Establishing a contingency plan for data backup and disaster recovery.
- Implementing policies for the proper use of workstations.
- Implementing audit controls to record and examine activity in information systems. (Correct answer)
Correct answer: Implementing audit controls to record and examine activity in information systems.
The HIPAA Security Rule is divided into Administrative, Physical, and Technical Safeguards. Audit controls, which involve hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI, are a required implementation specification under the Technical Safeguards standard. The other options are examples of Physical (A) and Administrative (B, C) Safeguards.
Question 160: A physician receives free tickets to a sporting event from a medical device company. Under the AKS, the primary risk is that these tickets may constitute what?
- A Stark Law financial relationship
- An illegal assignment of benefits
- Remuneration intended to induce referrals or purchases (Correct answer)
- A violation of the Beneficiary Inducement statute
Correct answer: Remuneration intended to induce referrals or purchases
Providing gifts of value to physicians can constitute remuneration under the AKS if given with the intent to induce or reward referrals of items or services reimbursable by federal healthcare programs.
Question 161: To ensure the independence and objectivity of the Compliance Officer, their reporting relationship should ideally be structured so they report directly to:
- The Chief Executive Officer (CEO) and/or the governing body (e.g., Board of Directors). (Correct answer)
- The Director of Human Resources to manage disciplinary actions for non-compliance.
- The General Counsel to ensure all actions are legally sound.
- The Chief Financial Officer (CFO) to align compliance with financial goals.
Correct answer: The Chief Executive Officer (CEO) and/or the governing body (e.g., Board of Directors).
To maintain independence and avoid conflicts of interest, the Compliance Officer should have a direct line of communication to the highest levels of the organization, such as the CEO and the Board of Directors. This structure ensures they can raise concerns and implement the program without undue influence from departments they may be reviewing.
Question 162: A covered entity discovers that a business associate has experienced a breach of unsecured protected health information (PHI) affecting 450 individuals. The business associate notified the covered entity 50 days after discovering the breach. According to the HIPAA Breach Notification Rule, what is the covered entity's primary notification responsibility?
- Notify the affected individuals without unreasonable delay, but no later than 60 days from when the covered entity was informed of the breach.
- Notify the Secretary of HHS of the breach on the same day it notifies the affected individuals.
- Notify the affected individuals and the Secretary of HHS annually, as the breach affects fewer than 500 individuals. (Correct answer)
- Notify prominent media outlets in the state within 10 days of being notified by the business associate.
Correct answer: Notify the affected individuals and the Secretary of HHS annually, as the breach affects fewer than 500 individuals.
For breaches affecting fewer than 500 individuals, covered entities are required to notify the Secretary of HHS by submitting an annual report of all such breaches within 60 days after the end of the calendar year in which the breaches were discovered. They must still notify the affected individuals without unreasonable delay and within 60 days of discovery.
CHC Certified in Healthcare Compliance Exam
The CHC (Certified in Healthcare Compliance) Exam is administered by the Health Care Compliance Association (HCCA) and tests knowledge across all major domains of healthcare compliance including fraud and abuse prevention, HIPAA privacy and security, billing and coding compliance, auditing and monitoring, compliance program administration, and regulatory oversight. Candidates must demonstrate competency in designing and managing effective compliance programs within healthcare organizations.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds