โ† All CMAS Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CMAS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. A medical administrative specialist is reviewing contracts with vendors who access patient data. Which risk mitigation document is REQUIRED under HIPAA?

    Answer: A Business Associate Agreement (BAA)

    HIPAA requires a signed Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity.

  2. Which of the following BEST describes the risk mitigation technique of 'risk transfer'?

    Answer: Shifting financial consequences of a risk to another party via insurance or contracts

    Risk transfer shifts the financial burden of a risk to another entity, most commonly through purchasing insurance or including indemnification clauses in contracts.

  3. A patient's family member calls requesting the patient's test results. The patient has not filed a HIPAA authorization. What is the GREATEST risk if the staff member discloses results?

    Answer: A HIPAA Privacy Rule violation and potential OCR investigation

    Disclosing PHI to an unauthorized individual without patient authorization violates HIPAA's Privacy Rule and can trigger an OCR complaint and investigation.

  4. Which metric is used in a risk matrix to prioritize risks for action?

    Answer: Probability of occurrence multiplied by severity of impact

    Risk matrices score risks by multiplying likelihood (probability) by impact (severity), helping organizations prioritize which risks require the most urgent attention.

  5. A coding audit reveals consistent upcoding of evaluation and management services. Which action should the compliance officer recommend FIRST?

    Answer: Conduct a comprehensive internal audit and implement corrective action before self-disclosing if appropriate

    The appropriate first step is a thorough internal audit and corrective action plan; voluntary self-disclosure to the OIG may follow if systemic fraud is confirmed.

  6. What is the PRIMARY purpose of a healthcare practice's compliance hotline?

    Answer: To allow employees to anonymously report suspected fraud, waste, or abuse

    A compliance hotline provides employees with a confidential, anonymous channel to report suspected violations without fear of retaliation, which is a key element of an effective compliance program.

  7. Under OSHA's Hazard Communication Standard (HazCom), what is a medical practice's obligation regarding hazardous chemicals?

    Answer: Maintain Safety Data Sheets (SDS) and train staff on chemical hazards

    OSHA HazCom requires employers to maintain Safety Data Sheets for hazardous chemicals and provide staff training on identification, handling, and emergency response.