Browse all practice questions for the HCCA Certified in Healthcare Compliance (CHC) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

HCCA Certified in Healthcare Compliance (CHC) Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • How long can a corporate integrity agreement last at maximum?
  • What type of audit helps outline current operational standards in an internal assessment?
  • What does the “Upjohn warning” procedure entail?
  • Which regulation requires hospitals to provide medical screening exams regardless of insurance?
  • What must compliance and ethics programs ensure according to the Federal Sentencing Commission?
  • What does the OIG's voluntary self-disclosure protocol require providers to report?
  • The Deficit Reduction Act requires providers receiving over $5 million in Medicaid funds to inform employees of their ability to?
  • A privacy official should inform a clinic that it can provide PHI to a researcher if the researcher:
  • If there is a suspicion of prescription forgery for a controlled substance, what is the next step?
  • What type of audit should be conducted for historical data analysis?
  • What is NOT a feature of CMS programs?
  • What does the Breach Notification under ARRA require covered entities to do?
  • What role does in-house legal counsel play in healthcare compliance reviews?
  • How should an organization respond to an employee who does not complete compliance training?
  • What is the minimum number of units to be sampled for a full statistical audit?
  • One benefit of having an effective compliance program is to help create which of the following?
  • Which of the following is NOT a criterion for home health coverage?
  • What is the minimum duration for which the OIG can impose a mandatory exclusion?
  • Which of the following is NOT a typical role of the Board of Directors in compliance?
  • Which privacy law pertains to the protection of financial information?
  • Under what circumstances can PHI be disclosed without patient authorization?
  • What is a Corporate Integrity Agreement (CIA)?
  • What consequence can result from violations of the Anti-Kickback Statute?
  • In compliance training, what is the significance of providing a positive call for action?
  • What is the purpose of the Notice of Privacy Practices (NPP)?
  • Which of the following is NOT a key to successfully creating a risk assessment team?
  • What is the maximum amount an employer can charge for personal protective equipment (PPE)?
  • How is Medicaid primarily administered in the United States?
  • Why is it advantageous for healthcare organizations to voluntarily implement compliance programs?
  • Which method is NOT used to destroy paper medical records?
  • If someone did not know about a HIPAA violation, what is the potential civil penalty?
  • What outcome does the OIG expect from documented findings in compliance activities?
  • What is the main purpose of a Remedial Order in probation?
  • What approach is NOT one of the primary methods for Controlled Self-Assessment?
  • What does HITECH stand for?
  • What is the first step in developing an annual compliance audit?
  • Which law does not require proof of intent for violations?
  • If Leaf Hospital conducts a contemporaneous review, what might they uncover that warrants further action?
  • Which of the following provides legal protection from prosecution for a specific party?
  • What is a critical responsibility of compliance training and education?
  • What is the primary purpose of OIG’s Voluntary Self-Disclosure Protocol?
  • A PI testing a hypothesis with de-identified medical records should first:
  • What does EMTALA require from participating hospitals regarding patient transfers?
  • What is the effective consequence of HIPAA of 1996 regarding incorrect claims?
  • Who has the authority to impose a Corporate Integrity Agreement (CIA)?
  • What is the purpose of internal controls in an organization?
  • Which of the following is included as a Covered Entity?
  • If wrongdoing is identified, what is the FIRST action to take if an overpayment is found?
  • What law can a healthcare organization violate by not returning overpayments within 60 days?
  • Which of the following describes an organization with an effective compliance program?
  • Which of the following is noted for involving some of the largest breaches reported to HHS?
  • What is the role of the Compliance Officer regarding department policies?
  • Which of the following is a key component of a compliance program?
  • What kind of actions might lead to a penalty of $100,000 for a HIPAA violation?
  • Which type of safeguards are fundamental for protecting physical systems and data from environmental hazards?
  • What is the focus of GINA?
  • What policy is implemented to foster open communication in a healthcare setting?
  • What type of services does Stark Law apply to?
  • True or False: The Public Health Service (PHS) defines a significant financial interest based on aggregated income exceeding $10,000 over a twelve-month period.
  • What is the compliance professional's best action when confirming that PHI was posted on social media?
  • How many states require nursing facilities to perform FBI checks on employees?
  • What main purpose does a subpoena serve in a compliance investigation?
  • Which statement reflects the importance of compliance programs in healthcare?
  • Which of the following is NOT a purpose of a Business Associate in healthcare?
  • What legal obligation does the receiving CE have when a misdirected fax is sent?
  • HITECH is an integral part of which legislative act aimed at economic recovery?
  • What document does the OIG develop if a provider does not have a corporate integrity agreement in place?
  • What type of arrangement might lead to OIG identifying an "outlier" for non-compliance?
  • What does LoProCo stand for in the context of HIPAA compliance?
  • According to the Yates Memo, who may be held liable for corporate misconduct?
  • Which of the following best describes engineering controls in safety management?
  • Which of the following is a key responsibility of a privacy professional?
  • In order to determine the required sample size for a statistical review, what factor must be considered?
  • What does GINA Title I allow health insurers to request?
  • What is one of the main benefits of an effective compliance program?
  • Who is primarily responsible for clinical trial billing compliance and enforcement?
  • What is a common objective of an effective compliance program?
  • An effective auditing/monitoring plan must consider what factor?
  • What defines a breach in the context of healthcare compliance?
  • Which aspect is NOT part of the employee's responsibilities regarding the Code of Conduct?
  • Which of the following statements is true about the regulation of conflicts of interest in healthcare?
  • What is a requirement for auditors in the context of compliance?
  • Before conducting a safety audit in an emergency department, what is the first item needed?
  • Compliance risk management professionals should design a framework to ensure management understands?
  • What critical information must be included when notifying individuals of a breach?
  • Which document outlines high expectations for organizational compliance programs as per the latest DOJ guidance?
  • Health information that cannot identify an individual is termed as?
  • What term describes an organization's commitment to compliance by management, employees, and contractors?
  • How often are CIAs required to undergo regular monitoring?
  • What is the purpose of the Health Care Fraud and Abuse Control Program?
  • Which of the following describes the types of audits?
  • What is the maximum time allowed for reporting breaches affecting less than 500 individuals?
  • What is the main purpose of general compliance training?
  • HHS is primarily responsible for which aspect of public welfare?
  • What is the function of risk assessment within a compliance program?
  • What type of information does the CMS Open Payments Program provide to the public?
  • Which area is identified by the OIG as most prone to fraud, waste, and abuse in home health agencies?
  • Which of the following is a key activity related to 'Payment' in the TPO framework?
  • Which of the following is NOT a category of obligations in the HCCA Code of Ethics?
  • When resolving compliance issues, which aspect is emphasized as the most critical line of defense?
  • What was a primary reason for the enactment of the Sarbanes-Oxley Act?
  • Which of the following best describes the watchwords for enforcing standards of conduct in compliance?
  • The DOJ's ECCP is part of which broader initiative?
  • What are the three benefits of an effective compliance program?
  • What should a compliance professional do to prevent a billing error from recurring after it has been identified?
  • True or False: In the case of serious sensitive allegations, you should contact legal counsel to determine attorney-client privilege needs.
  • Which of the following is a primary responsibility of a compliance officer according to the OIG?
  • Which of the following is considered a substantial risk for health care compliance?
  • What does ERISA stand for?
  • What documentation is NOT critical for a Compliance Officer's review when opening files?
  • Which law provides protection against discrimination in employment based on genetic information?
  • What is the consequence of violating HIPAA regulations?
  • Which resource should clinical lab providers review to understand compliance requirements?
  • Which of the following statements about de-identified health information is true?
  • Why is it important to have a written set of safety standards before an audit?
  • Which of the following documents outlines the corrective action plan?
  • What is one method used to monitor compliance?
  • What does Willful Neglect refer to in compliance context?
  • True or False: CIA agreements can protect an organization from all forms of liability.
  • According to compliance best practices, which is the primary factor for effective compliance communication?
  • Which of the following does NOT require authorization for the disclosure of PHI?
  • What key element must compliance programs include according to US Sentencing Guidelines?
  • What is the contact number for the OIG's Fraud and Abuse hotline?
  • According to US Courts, which of the following is NOT included in the obligations concerning statistical sampling for overpayment estimations?
  • What must any laboratory performing testing on human specimens do?
  • In HIPAA, which subpart deals with Security?
  • Which Act requires providers to repay identified overpayments to Medicare and Medicaid within 60 days?
  • What type of training should a compliance professional provide to meet learning styles of doctors and nurse practitioners?
  • How can auditing be distinguished from monitoring in a compliance context?
  • How should a compliance professional assess the effectiveness of a training program?
  • Does HIPAA allow disclosure of protected health information about a student to a school nurse for treatment purposes?
  • Which of the following describes the life cycle of records management?
  • What does Title I of the Genetic Information Non-discrimination Act (GINA) prevent?
  • What is a critical element of a compliance professional's role when addressing a complaint's facts?
  • What should the Chief Compliance Officer do first when faced with increased correspondence challenging medical necessity?
  • What does IACUC stand for?
  • What year did OSHA establish the Bloodborne Pathogens Standard?
  • RAT-STATS is best described as:
  • What does "Willfully Ignorant of the Offense" imply?
  • What is a primary benefit of implementing a compliance program in healthcare organizations?
  • When a compliance officer finds an excluded provider has treated patients, what is the NEXT action they should take?
  • What comprises a Designated Record Set (DRS) under HIPAA?
  • What should the approach to penalties be based on?
  • What was the main goal of the 1984 Sentencing Reform Act?
  • Which type of security standards involve the automated processes to protect data, such as encryption?
  • Why is training and education critical in compliance programs?
  • Which type of monitoring review is designed to catch issues as they arise?
  • What should you do if certain employees are not being properly disciplined for misconduct?
  • What is a key function of the compliance officer in a healthcare organization?
  • What element is significant for a compliance program in relation to healthcare fraud?
  • True or False: A self-audit can help providers reduce chances of non-compliance.
  • Why are regular compliance training sessions important?
  • Which of the following options aligns with the foundation of an effective compliance program?
  • In-kind payments as restitution may include which of the following?
  • True or False: The Anti-Kickback Statute applies to referrals from patients.
  • Which of the following is considered an incidental disclosure of PHI?
  • Which characteristic is most important for a Compliance Professional in a newly acquired hospital?
  • Which element is essential within the compliance department to foster compliance culture?
  • What is another name commonly used for the Stark Law?
  • What is considered an appropriate start to implementing an effective compliance program for small physician group practices with limited resources?
  • How should education for minor infractions be approached?
  • What type of training does OIG suggest should be a separate session and targeted?
  • What are the four areas PHI can be used or disclosed by?
  • What is the process to assess if an "impermissible" use of protected health information is a breach?
  • Which component is key for preventing unethical behaviors in an organization?
  • What is the main purpose of the American Recovery and Reinvestment Act (ARRA)?
  • What aspect of Medicare does Part A cover?
  • Which of the following is a key aspect of compliance awareness among employees?
  • Organizations can reduce their culpability according to the Federal Sentencing Guidelines by?
  • What does OSHA stand for in the context of healthcare compliance?
  • According to HIPAA, what method can be used to de-identify PHI?
  • When assisting IT with data privacy controls, which of the following is an employee-related control?
  • Which behavior is classified as unethical?
  • What should be done to maintain the confidentiality of information during an investigation?
  • Which criminal offense is OIG required to exclude individuals from Federal health care programs for?
  • What was the primary purpose of the False Claims Act (FCA) when it was implemented?
  • What is the illegal practice of submitting separate claims for maximum reimbursement known as?
  • In compliance, what does "education and training" primarily aim to achieve?
  • True or False: The OIG advises the public on the governance of the PHRMA CODE.
  • Which of the following is NOT a risk management process?
  • What is the first step in the monitoring and auditing two-step process?
  • In an informed consent, which statement is appropriate when a Pet scan is deemed non-billable?
  • What is a significant fear that can hinder an effective compliance program?
  • Which of the following statements are true regarding the Statute of Limitations under the False Claims Act?
  • Which of the following is NOT one of the five most important federal fraud and abuse laws?
  • When anticipating what the government will measure during a compliance program review, which of the following should you consider?
  • What is the correct method for destroying DVD medical records?
  • What is the FIRST action an employee should take when an investigator presents a search warrant?
  • Is it permissible for covered entities to use patient sign-in sheets as long as the disclosed information is limited?
  • What is the first priority of the Justice Department according to its stated priorities?
  • Which statement best describes the concept of "integrity" as it relates to compliance programs?
  • What might documentation in a criminal or civil trial include?
  • What is the focus of a risk assessment in compliance?
  • In research compliance, what is a primary goal of an IRB?
  • What is the Stark Period of Disallowance?
  • Which of the following is considered an Anti-Kickback Statute violation?
  • What does the Quality Management Technique P-D-C-A stand for?
  • Which type of internal control is intended to signal the presence of a problem?
  • What does the Yates Memo emphasize regarding corporate misconduct?
  • Which of the following is one objective of a baseline audit?
  • Which document is essential for a laboratory performing high-complexity testing before a compliance review?
  • What action warrants a civil penalty of $50,000 under HIPAA if not corrected within 30 days?
  • What should be considered when evaluating a potential conflict of interest?
  • Which of the following is NOT a necessary policy or procedure for organizations?
  • Which aspect of compliance is essential for minimizing fraud risk?
  • Which organization develops and administers standards relating to the well-being of workers at job sites?
  • In which situation can the information of a deceased patient be released to the spouse?
  • How can a 100% confidence level in an audit be obtained?
  • For what purpose should an investigation and necessary disciplinary action be taken if a limited data set is released?
  • Which of the following statements about attorney-client privilege is true regarding the billing manager's review?
  • What is the role of proper documentation in compliance, according to HHS-OIG?
  • What is the next step for a privacy professional when receiving a hotline message about PHI misuse?
  • What should a compliance officer do if they discover a potential violation?
  • What is a characteristic of an effective HR policy within a healthcare organization?
  • What is the primary function of HIPAA?
  • What impact does the Balance Budget Act of 1997 have on healthcare organizations with repeated fraud convictions?
  • What role does the Chief Compliance Officer play in an organization?
  • What is the primary purpose of preventive controls within an organization?
  • What is the primary purpose of the Health Care Compliance Association (HCCA)?
  • Who is primarily responsible for auditing and monitoring compliance risks?
  • When should counsel be involved during an internal investigation?
  • Which factors should be considered when establishing a frequency schedule for monitoring activities?
  • What significant reforms did the Balance Budget Act of 1997 introduce concerning Medicare and Medicaid?
  • How long does the Privacy Rule state that a practice or covered entity needs to retain medical records?
  • Compliance audits typically relate to which of the following functions?
  • Which of the following can result in automatic disqualification of a relator from filing a qui tam action?
  • Which law does not require nursing facilities to conduct state FBI criminal background checks?
  • Which of these is NOT considered a common trigger for a compliance audit?
  • Is it true that Risk Management aligns with Quality Management in determining measures for risk avoidance and prevention?
  • How are minor unintentional non-compliance infractions typically addressed?
  • What is a key characteristic of a Covered Entity?
  • When should a breach be considered discovered?
  • In the context of healthcare compliance, what does the term "fraud" refer to?
  • What is the primary purpose of a compliance committee?
  • What is an Independent Review Organization (IRO) responsible for in Corporate Integrity Agreements?
  • When should the compliance plan be reviewed?
  • Under HIPAA's Privacy Rule, who constitutes the covered entity's workforce?
  • True or False: An excluded individual is automatically reinstated at the end of an exclusion term.
  • Which designated health services are covered by the Stark Law?
  • The purpose of EMTALA primarily aims to prevent what action by hospitals?
  • True or False: An individual has unrestricted access to all PHI within their Designated Record Set (DRS).
  • How should an organization view expenses related to the compliance program?
  • Effective enforcement and discipline elements include:
  • Boards have vital roles in Compliance; which aspect is NOT among their responsibilities?
  • What are the two instances in which PHI does not require authorization?
  • What is the focus of the Anti-Kickback Statute?
  • What does the term "condoned" refer to in a compliance context?
  • Which agency has enforcement authority for HIPAA privacy regulations?
  • Which statement is TRUE regarding compliance programs?
  • What can help establish a positive compliance atmosphere within an organization?
  • A written education plan for compliance should include which of the following?
  • Which term represents the process of identifying and dealing with risks in a compliance program?
  • Regarding Compliance Program effectiveness, which statement is NOT true?
  • In the context of compliance, what would a follow-up phase typically involve?
  • What is a common consequence of non-compliance in healthcare organizations?
  • What does the Medicaid - Deficit Reduction Act of 2005 allow states to do?
  • Which statement is false regarding the financial error rate in a Claim Review under a CIA?
  • What is a key component that should be included in a compliance program according to the 2023 OIG guidance?
  • What does the acronym OIG stand for in the context of healthcare compliance?
  • Which of the following levels of confidentiality is considered when handling personal health information (PHI)?
  • Which of the following is an administrative safeguard?
  • Which of the following is an example of healthcare operations?
  • One of the operations in healthcare includes reviewing the competence of providers. What classification does this operation fall under?
  • What organization develop standards and accredit hospitals and healthcare facilities?
  • What key aspect should be included in disciplinary action policies?
  • When creating and implementing a compliance plan, what is required of the compliance officer?
  • Which statement correctly reflects the Stark Law's requirement for referrals?
  • What does the oversight function of the Board of Directors entail?
  • In dealing with medical necessity issues, whom should the compliance professional collaborate with?
  • What type of rewards does the FSG suggest offering to those who adhere to compliance and ethics programs?
  • What are the two types of OIG exclusions?
  • How long are Corporate Integrity Agreements (CIAs) typically enforced?
  • True or False: Communications between company counsel and employees are privileged, owned by the company.
  • Which part of the HIPAA rules applies to PHI in all formats?
  • Under FERA, what may happen if overpayments are not returned in time?
  • What should be done in response to suspected misconduct or wrongdoing?
  • What is the most important communication device for a compliance program?
  • What should be included in a physician’s written policy regarding cash discounts?
  • In emergency situations, what is true about PHI disclosure?
  • One of the benefits of a Compliance Program is to:
  • Which area of concern primarily deals with billing processes in healthcare compliance?
  • What is one significant benefit of maintaining communication lines open in a compliance program?
  • What types of records are excluded from the Designated Record Set (DRS) under HIPAA?
  • An employee was terminated for accessing sensitive information. What is the privacy official's responsibility regarding disciplinary actions?
  • As a new compliance officer under an OIG CIA, what should be your first course of action?
  • What is ensured by contract provisions for background checks of vendor employees?
  • According to the OIG Compliance Program Guidance, what should be articulated to demonstrate commitment to compliance?
  • What is the purpose of EMTALA?
  • What is a sign of failed efforts to use statistical analysis in sampling?
  • Which of the following is NOT a typical consideration in compliance policy reviews?
  • To assess the seriousness of a high error rate in claims, which type of sample should be pulled?
  • If you become aware of a bribing situation, what is the proper course of action?
  • Which of the following actions shows ethical leadership in a healthcare setting?
  • What must a healthcare provider set up to become a Medicare biller?
  • What significant event does February 27, 1997, represent in the context of healthcare compliance?
  • Why is it important to conduct a retrospective audit?
  • Which area should targeted compliance training specifically address?
  • In case of a cyber-attack, what steps must an entity take?
  • Which of the following accurately defines Medicare/Medicaid fraud?
  • What should be done with a "required" implementation specification under HIPAA?
  • What type of guidelines does the OIG describe its compliance program guidance as?
  • When determining the amount of a civil money penalty for HIPAA violations, which factor is NOT considered?
  • What should organizations develop to effectively document compliance risks?
  • True or False: Upcoding has been a major focus of OIG's enforcement efforts, and HIPAA added another civil monetary penalty for upcoding violations.
  • What does the False Claims Act primarily address?
  • At its most basic level, what does a compliance program entail?
  • If there's an employment issue that requires compliance intervention, what is the next step?
  • True or False: It is illegal under the Anti-Kickback Statute to provide free or discounted services to uninsured individuals.
  • What incentive may a provider receive for making a good faith Self-Disclosure to the OIG?
  • If the DOJ declines to take on a qui tam case, what percentage can a whistleblower expect to receive from the total award?
  • What is a key benefit of conducting a Controlled Self-Assessment?
  • What must be established by entities receiving more than $5 million in annual Medicaid payments?
  • Which method is used to destroy laser disc medical records?
  • How long is a corporate integrity agreement typically enforced?
  • Which organization has had the authority to levy administrative penalties for filing false claims since 1981?
  • What is a primary focus of concurrent audits?
  • Which resources are MOST relevant for developing and updating a research compliance work plan?
  • A violation of PHI is considered a breach when:
  • What should be considered when designing practices for PHI confidentiality?
  • In a research study involving adolescents, what document must an adolescent subject sign?
  • What should a billing manager do if a significant error is identified in the billing process?
  • What is the first step when potential issues are identified within an organization?
  • What does the General Services Administration (GSA) manage?
  • Which of the following statements about the monitoring of internal controls is TRUE?
  • What subpart governs Breach Notifications in HIPAA?
  • Which of the following conditions is associated with the imposition of community service as part of probation?
  • Which is an objective of HIPAA Administrative Simplification?
  • Which of the following is part of preventive measures in compliance?
  • What does a directive internal control aim to do?
  • What should a privacy officer do after identifying a deficiency in the Notice of Privacy Practices (NPP)?
  • When a PI is accused of accepting kickbacks from a sponsor, who should a research compliance professional FIRST notify?
  • What does the HITECH Act primarily promote?
  • Conducting what type of sample would indicate potential issues within a compliance framework?
  • What are the three primary components of security according to the CIA triad?
  • What kind of safeguards might include the use of visitor badges and surveillance cameras?
  • What does 'upcoding' refer to in medical billing?
  • What action cannot be taken without having informed employees of rules and expectations?
  • What are the suggested development guidelines for compliance programs issued by the OIG called?
  • What is the primary contribution of auditing and monitoring to a compliance program?
  • What does the acronym OHCA stand for?
  • Who is primarily responsible for reviewing policies and procedures related to compliance in an organization?
  • What significant action is referred to as "Qui Tam" under the FCA?
  • Which of the following is a responsibility under administrative safeguards?
  • What type of test would be practical for a physician practice to determine unpaid claims?
  • True or False: The OIG requests that organizations disclose their adherence to the PHRMA CODE on their website.
  • In an audit of billing practices, which statement about sampling is INCORRECT?
  • How many criteria must be met before a patient can be transferred to another facility under EMTALA?
  • What is a common measure to mitigate privacy risk when sharing patient information?
  • What is the acceptable extrapolation of the review results for the Observation Room charges?
  • What are primary safety concerns in the medical setting?
  • What is the difference between an addressable and a required implementation specification under HIPAA?
  • What is the significance of documenting how a complaint was handled?
  • What is the look back period for Medicare overpayment claims?
  • In a compliance investigation, what is the most important responsibility of the compliance professional?
  • Which of the following is NOT considered a possible sanction by the OIG?
  • What is a direct result of a Stark violation?
  • What does RAT-STATS provide for auditors?
  • True or False: Unintentional billing mistakes and overpayments do not need to be reported to the OIG's SDP.
  • When determining the extent of research monitoring activities, which factor is critical to consider?
  • What can ongoing monitoring help identify in a compliance program?
  • Which of these is NOT one of the six phases of a Corrective Action Plan (CAP)?
  • What is the main focus of Title II of GINA?
  • Which item is NOT required in a bloodborne pathogen training program?
  • Which individual goal is BEST for a privacy professional to include in their objectives?
  • A Compliance Program with well-written policies will not be successful without what?
  • What should be included in a comprehensive compliance program?
  • Why would an organization want to listen to employees regarding compliance?
  • What is the consequence for violating EMTALA regarding patient treatment in an emergency?
  • Which element is seen as an absolute necessity for a successful Compliance Program?
  • What are the three main responsibilities of hospitals under EMTALA when a patient arrives at the emergency department?
  • What does the acronym DOL represent?
  • A health care provider needs permission to notify public health authorities of a reportable disease occurrence. Is this statement true or false?
  • If a co-worker leaves a PC logged into the confidential system, what is the best action?
  • What should you do if you discover a minor inventory discrepancy in controlled substances?
  • Which statement is correct regarding the consequences of non-compliance?
  • What does Section 6401 of the Affordable Care Act specify about compliance programs?
  • What is the recommended frequency for exclusion verifications according to compliance standards?
  • Which type of audit identifies potential errors before the process is completed?
  • What are Limited Data Sets used for within HIPAA guidelines?
  • What is one potential incentive for self-disclosing misconduct to the OIG?
  • What role does a compliance officer typically fulfill in a healthcare organization?
  • What document must be provided to patients that outlines their rights regarding PHI?
  • What regulates the circumstances under which a covered entity may use or disclose an individual's PHI?
  • What should be done after clarifying a suspected fraud violation?
  • Why should compliance officers set disciplinary policies for non-compliance?
  • Which aspect does NOT typically form part of a compliance program's structure?
  • Which document should serve as a reference for information about personnel policies and procedures?
  • What requires necessary policy measures to prevent avoidable recurrence?
  • What is essential for a privacy professional to maintain in order to keep up with industry standards?
  • What is one of the first actionable items after establishing a compliance program?
  • What does the FSG Culpability Score measure?
  • Which type of information is NOT considered part of the Electronic Protected Health Information (ePHI)?
  • What should a compliance professional do first upon receiving a complaint about unfair discipline?
  • What is a penalty for willful neglect if the violation is corrected in 30 days?
  • How long do providers have to refund overpayments once identified?
  • A billing manager notices a 50% increase in Federal health care program payments. What should be the NEXT step?
  • What type of training sessions should a compliance professional conduct?
  • What is the maximum penalty for noncompliance with HIPAA provisions?
  • Which of the following is true about the monetary settlement a relator can receive in qui tam actions?
  • True or False: The government only assesses financial compliance during audits and not other areas.
  • What agency developed the Federal Sentencing Guidelines (FSG)?
  • What are two of the mitigating factors according to the Federal Sentencing Guidelines?
  • What can lead to the detection of errors in past billing practices?
  • How often are workforce retraining sessions mandated by the HIPAA Privacy Rule?
  • On what basis should the compliance committee typically develop objectives and goals?
  • A covered entity may disclose protected health information (PHI) without a patient's written permission for:
  • Which of the following is a consequence of failing to comply with federal health care regulations?
  • Which statement accurately describes the Response and Prevention Element in compliance?
  • Which type of audit takes place in real-time?
  • Which Act safeguards student educational records from unauthorized uses and disclosures?
  • According to OIG's Self Disclosure Protocol (SDP), which of the following must be submitted?
  • What is the lowest potential federal civil monetary penalty for a HIPAA violation?
  • Which of the following best describes welfare benefit plans?
  • What legal consequence can occur if Medicare overpayments are not refunded?
  • What is the aim of conducting audits in healthcare organizations?
  • What does an open door policy encourage in the workplace?
  • What does a compliance committee primarily oversee?
  • When asked to approve a transfer form containing a patient's SS#, what should the privacy officer do first?
  • Which of the following is a common type of evidence collected for compliance violations?
  • OIG believes that the Compliance Program should include a written policy statement addressing what?
  • What is a key goal of the Defense Industry Initiative?
  • What is one potential risk of failing to address overpayments found during a review?
  • Which of the following gifts is generally considered acceptable under a typical Code of Conduct?
  • What is a Business Associate (BA) in healthcare?
  • What does the HCCA identify as two critical components of a compliance program?
  • Which option should be considered for disclosing a violation of federal fraud laws?
  • Which act requires providers to be permanently excluded from federal health care programs after being found guilty of fraud three times?
  • If a facility only performs blood draws and no testing, does it require a CLIA number?
  • What is the time frame for protecting PHI after an individual’s death?
  • True or False: The Stark Law prohibits claims for designated health services based on tainted referrals.
  • What does the Health Care Financing Administration (HCFA) encourage to promote consistency in interpretation of claims?
  • According to HIPAA, can pharmacists provide advice about over-the-counter medicines without restriction?
  • What is the second step for a compliance professional upon detecting wrongdoing?
  • What does Stark Law aim to prevent?
  • What should a compliance program's goal focus primarily on from a monitoring perspective?
  • What is prohibited by the Omnibus Budget Reconciliation Act of 1987 (OBRA)?
  • What is the primary purpose of attorney-client privilege?
  • What is a key feature of an effective compliance program?
  • Which of the following describes a requirement for conducting a statistical sample in compliance reviews?
  • After an investigation that affects the organization's reputation, what should a Compliance Professional do next?
  • Which entity administers the Medicare and Medicaid laws outlined in the Social Security Act?
  • Are physicians allowed to offer cash discounts?
  • What could happen to a physician who fails to respond to an emergency while on call?
  • Which regulation aims to enhance safety protocols in compliance programs?
  • What can be a potential penalty under the False Claims Act?
  • What is a crucial element of corrective action plans (CAPs) following an audit?
  • What type of actions may be subject to discipline according to compliance standards?
  • What is a critical first step in the compliance auditing process?
  • What is one function of safety data sheets in a hazard communication program?
  • Which third-party plays a critical role in accurate billing and reimbursement?
  • What is defined as Unsecured PHI?
  • Which of the following actions is considered equally serious in terms of noncompliance?
  • Who is eligible to bring a suit under the False Claims Act?
  • In GINA Title II, what is illegal for employers to use for employment decisions?
  • What is NOT one of the basic elements of compliance monitoring?
  • True or False: Root cause analysis is a proactive activity performed after an incident has occurred.
  • Which of the following expenses related to compliance programs is NOT considered tax deductible?
  • What is one characteristic of the "safe harbors" established by the OIG in the AKS?
  • Under which condition can PHI be disclosed for research purposes?
  • What is the primary purpose of a privacy exit interview?
  • What is the scope of protection under GINA Title I related to?
  • What is a critical element to address when preparing a compliance plan for the year?
  • What should be the focus of a healthcare organization's risk management strategy?
  • In the context of compliance, what role does a baseline audit play?
  • What does a compliance program fundamentally involve?
  • What is the scope of Chapter 8 of the Federal Sentencing Guidelines?
  • True or False: Conducting a Controlled Self-Assessment contributes to increasing the awareness and targeting of audit work.
  • Which of the following is not required in a written hazard communication program?
  • What does HITECH Subtitle A focus on?
  • What does HIPAA stand for?
  • Which right is NOT included in the individual rights under the NPP?
  • What does the Defense Industry Initiative aim to improve?
  • What does attorney-client privilege protect in the context of healthcare compliance reviews?
  • What is the least important qualification for a Compliance Officer in your organization?
  • What are the two agencies that the Healthcare Fraud and Abuse Control program requires to coordinate federal, state, and local healthcare law enforcement activities?
  • Which of the following is a key requirement of the Sunshine Act?
  • What is the most effective delivery method for compliance content as recommended?
  • What cycle is part of continuous improvement as per compliance practices?
  • In compliance program education, what should be the focus of scenario-based training?
  • When should the Code of Conduct be distributed to new employees?
  • Which areas are common health care risk areas?
  • Which element is crucial for the effectiveness of compliance audits?
  • How long is PHI protected after the person's death?
  • What is the primary purpose of the False Claims Act (FCA)?
  • When is immediate notification to the government warranted according to OIG compliance guidance?
  • Under what circumstances can a covered entity disclose PHI without authorization?
  • Who benefits financially from a Qui Tam suit if successful?
  • Is a Security Risk Analysis required annually for a Covered Entity to comply with HIPAA?
  • What is the aim of the Physician Payment Sunshine Act in relation to public transparency?
  • Fundamentally, compliance efforts are designed to establish a ______ within a hospital that promotes prevention, detection, and resolution of conduct that does not conform to Federal and State law.
  • According to the content, which factor is essential for developing effective compliance programs?
  • What does the Latin phrase "Qui tam pro domino rege quam pro se ipso in hac parte sequitur" mean?
  • When a hotline caller reports coding discrepancies, what should the compliance professional do first?
  • After implementing the non-retaliation policy, what should the compliance officer do next?
  • In which scenario can a probe sample be used?
  • Who should primarily participate in the development of goals and objectives for the compliance program?
  • What is a mitigating factor to a culpability score?
  • The HIPAA Security Rule requires a covered entity to implement policies and procedures for authorizing access to e-PHI only when such access is appropriate based on the user or recipient's role. True or False?
  • What term is used for Federal regulations that specify certain joint ventures concerning hospitals and/or physicians that are compliant with Medicare laws?
  • True or False: The OIG's Self-Disclosure Protocol can be utilized to disclose illegal arrangements related to the Anti-Kickback Statute (AKS) and Stark Law.
  • In a compliance program, what does auditing and monitoring help ensure?
  • What is the primary function of a company's Code of Conduct?
  • Which area is NOT subject to the 250-yard zone rule under the definition of "hospital campus"?
  • What is the significance of implementing the False Claims Act during the Civil War?
  • What action should be included in the education plan regarding content areas?
  • What is a key difference between consent and authorization under HIPAA?
  • What is the purpose of Project Bad Bundle?
  • Which of the following practices supports the implementation of corrective actions after identifying compliance issues?
  • Is it permissible for healthcare practices to remind patients of their appointments?
  • The Privacy Rule generally requires covered entities to limit uses, disclosures, or requests of PHI to the minimum necessary to accomplish the intended purpose. True or False?
  • What was Chapter 8 of Federal Sentencing Guidelines designed for?
  • Which law exempts self-insured health plans from state laws governing health insurance?
  • At which level of the Medicare appeals process is an appeal decision made by the Office of Medicare Hearings and Appeals (OMHA)?
  • Which of the following have been identified as high-risk areas by the OIG?
  • Which of the following are included as key performance indicators in compliance regulation and risk assessment?
  • What governs the HIPAA Security Rule?
  • What are the three types of internal controls?
  • How should reporting systems within healthcare organizations be handled?
  • What must a provider do under Section 6402 of the ACA upon identifying an overpayment?
  • When developing a compliance program, which of the following actions should be prioritized after risk assessment?
  • What key principle must be included in a non-retaliation policy for reporting compliance issues?
  • Which subpart in Part 164 of HIPAA deals specifically with Privacy?
  • After identifying non-systemic billing errors, what should be done next?
  • What element should a privacy professional consider first when presenting to the board about a privacy program?
  • If an employee violates the non-retaliation policy by spreading rumors, the compliance professional's first action should be?
  • True or False: Employees may be required to give up their personal sense of right and wrong to function in the company.
  • What is a key difference between enforcement and discipline in a compliance program?
  • What is one of the main reasons cited for reinforcing employee’s innate sense of right and wrong through compliance programs?
  • Which of the following is NOT a legal requirement under the Equal Employment Opportunity law?
  • How can organizations reduce their culpability according to the Federal Sentencing Guidelines?
  • What is a key item that can protect a medical practice from harassment liability?
  • What destruction method is used for magnetic tape medical records?
  • If there is a detection of serious wrongdoing, what is the first step for the compliance professional?
  • What is the maximum prison sentence for committing a HIPAA offense knowingly?
  • Which statement regarding signed authorizations for release of information is correct?
  • What does the acronym SURS stand for?
  • Which key performance indicator is NOT typically monitored in compliance programs?
  • True or False: OIG voluntary guidance is intended to enhance internal controls within organizations.
  • Before a government investigation occurs, which document should be reviewed carefully?
  • What is the main difference between HIPAA Privacy and Security?
  • True or False: An email request from a client is sufficient authorization for secure communication.
  • What is the appropriate response to a spelling error in a patient's medical record?
  • Which acronym refers to legal protections between a lawyer and a client?
  • Is a Business Associate required to have a contract with a Covered Entity to comply with HIPAA?
  • The most important lines of defense for a compliance program is?
  • According to the OIG Compliance Program Guidance, how should patient care be seen in relation to compliance programs?
  • What does P-D-F stand for in the context of audits and investigations?
  • Who has the authority to bring civil action under the False Claims Act?
  • In what situation should immediate modification of procedures occur?
  • What does the Sunshine Act mandate regarding pharmaceutical and medical device manufacturers?
  • How should complaints received through a Compliance Hotline be handled?
  • What is a likely consequence of the board not having a solid understanding of compliance objectives?
  • What is primarily emphasized for effective oversight in compliance programs?
  • What is defined as an emergency medical condition according to EMTALA?
  • What is the outcome of failing to adhere to compliance programs?
  • What is the source of notification requirements following a data breach of a clinical system containing PHI?
  • Which principle is essential for handling PHI?
  • What is required for an "addressable" implementation specification?
  • What does a preventive internal control involve?
  • What is an essential component of PHI management in healthcare?
  • Who holds the primary responsibility for the monitoring component of internal controls?
  • An individual's understanding of the compliance aspects of their job can BEST be enhanced by including compliance in:
  • Which of the following is a preventive measure to avoid a Qui Tam lawsuit?
  • What is an effective strategy to demonstrate compliance with personnel policies?
  • What type of analysis evaluates the effectiveness of compliance efforts over time?
  • Which factor is key in defining the scope of a monitoring plan?
  • What is the purpose of root cause analysis in healthcare compliance investigations?
  • Who is responsible for recommending an auditing and monitoring plan for an effective compliance program?
  • What does PHI stand for?
  • What is a common reason cited for the failure to implement compliance programs in healthcare?
  • When implementing a compliance plan, what is required for approval?
  • Which statement about breaches is correct?
  • Which of the following could be a legal implication for an organization due to conflicts of interest identified through the Open Payments database?
  • In responding to coding errors, what is a compliance professional's key responsibility?
  • If several medical records are missing and physicians are taking original records home, what should the privacy professional do first?
  • The compliance program should address plans to verify adherence to applicable laws through what methods?
  • What type of communication is NOT considered PHI?
  • What is indicated by cooperation with government investigators in compliance matters?
  • What is the main mission of the OIG?
  • What compelling reason supports the continuation of an auditing program?
  • What do the Federal Sentencing Guidelines (FSG) emphasize for corporations?
  • Which of the following is a method for collecting compliance data?
  • What recent addition to compliance programs does the updated DOJ ECCP emphasize regarding new technologies?
  • A compliance audit typically aims to do which of the following?
  • What is a consequence of transferring a patient under EMTALA without appropriate medical records?
  • Which of the following is NOT a characteristic of a Corporate Integrity Agreement (CIA)?
  • Which approach emphasizes support and correction for non-compliant behavior in enforcement?
  • What is the primary focus of the general compliance training session?
  • Training requirements for compliance should include which essential component?
  • A covered entity must designate a ___________________ who is responsible for developing and implementing its security policies and procedures.
  • True or False: A vendor that stores encrypted copies of files from a covered entity is not a Business Associate because the ePHI is unreadable.
  • What does 'P' in TPO refer to in the context of healthcare?
  • What is one way to prevent duplication of auditing efforts in an organization?
  • When developing a compliance work plan, what does prioritizing physician contract management indicate?
  • What is the classification of upcoding services to receive higher reimbursement from Medicare/Medicaid?
  • Which of the following should be reflected in a billing company's written policies and procedures?
  • What general areas does an OCR investigation examine?
  • Code of conduct supersedes which of the following?
  • Why is establishing compliance programs crucial for healthcare providers?
  • What is one of the main responsibilities of a Compliance Officer?
  • Which of the following is NOT identified as a special area of OIG concern?
  • How are microfilm medical records typically destroyed?
  • Which of the following is NOT listed as an obstacle to effective compliance program implementation?
  • What was established by the DRA of 2005?
  • Which of the following is identified by CMS as a high-risk area for fraud?
  • What is a potential result of a willful violation of HIPAA?
  • Which term describes the 'provision, coordination, or management of health care and related services'?
  • Which of the following is a benefit of having a compliance program?
  • Which professionals are classified as physicians under Stark Law?
  • If a provider receives a tainted referral, what is the main consequence under the Stark Law?
  • What is the meaning of TPO in the context of HIPAA?
  • Which of the following best illustrates the importance of diverse educational materials?
  • False Claims Act violations can result from which other types of violations?
  • If a payment request from a diagnostic provider seems unusually high compared to others, what should you do?
  • What does the Family Educational Rights and Privacy Act (FERPA) protect?
  • Which of the following does NOT fall under Attorney-Client Privilege?
  • What does the phrase "Res Ipsa Loquitur" mean in legal terms?
  • In the compliance framework, how should compliance professionals approach risk communication?
  • Which agency is referred to by the acronym OCR?
  • Upon identifying a potential violation, what should be done first?
  • Which compliance program guideline focuses on evaluating corporate compliance?
  • What is true regarding contemporaneous reviews in a compliance setting?
  • What is one of the seven elements emphasized in OIG CPG guidance for hospitals?
  • What underlying goal does root cause analysis serve?
  • What can a compliance professional use to quickly evaluate if more extensive audits are needed?
  • What is the first step one should take when establishing an effective compliance program?
  • Which area is NOT commonly associated with healthcare fraud according to CMS?
  • What is described as a multi-step process in progressive discipline?
  • Which of the following is a valid example of PHI use beyond TPO?
  • What does the acronym ACE signify in healthcare compliance?
  • What are the primary focus areas of a Board of Directors (BOD) concerning compliance?
  • Which of the following is a benefit of conducting a Control Self-Assessment?
  • Why is it important for all members of a healthcare organization to participate in the compliance program?
  • What key principle underlies the regulations enforced by the US Sentencing Commission?
  • What does a contemporaneous review involve in compliance auditing?
  • What should a department manager complete to ensure compliance with a new medical records policy?
  • What does HIPAA require for disclosures of protected health information for treatment?
  • Which of the following would be classified as a technical safeguard?
  • What is the primary goal of maintaining the integrity of medical records?
  • What is a primary characteristic of monitoring in an organization?
  • Before recommending disciplinary action for a nurse whose photo was posted online, what should the privacy professional determine?
  • Which is a key goal of establishing a code of conduct in healthcare organizations?
  • What is considered the most important aspect of a compliance program?
  • Which of the following is a primary goal of compliance programs in healthcare organizations?
  • What does the False Claims Act empower the government to do?
  • Which of the following is NOT a step in the audit process?
  • Which of the following statements accurately reflects the attitude of ACA regarding statistical sampling?
  • According to recent regulations, compliance programs must include written policies and what other core element?
  • How should an institution address a clause in a clinical trial agreement that gives the sponsor all rights to new interventions?
  • Under HIPAA, who has the authority to define the roles of privacy and security officials?
  • Is there currently legislation specifically regulating artificial intelligence systems?
  • How is a retrospective audit characterized?
  • What is a retrospective audit used for?
  • Which of the following actions is critical when conducting a claim review under a CIA?
  • What must a Business Associate obtain to claim compliance when selling an individual's PHI?
  • What type of audit is characterized by a comprehensive inspection of records in anticipation of launching a compliance program?
  • Which action demonstrates a commitment to compliance in a healthcare setting?
  • Which of the following actions could lead to termination as a consequence of non-compliance?
  • How do patients typically learn about their privacy rights under HIPAA?
  • Under which circumstance can coinsurance and deductibles be waived?
  • What is NOT included in technical safeguards?
  • If a hospital's discovery sample reveals a financial error rate above 5%, what does the OIG require?
  • When a provider accidentally shares attorney-client privileged information with a third party, what is this considered?
  • When does the 60-day timeline for breach notifications initiate?
  • What is the focus of the 2022 Monaco Memo regarding corporate governance?
  • Which legislation mandates compliance programs for Medicare, Medicaid, and CHIP providers?
  • In healthcare compliance, why is effective education and training emphasized as a key element?
  • What is the deadline for reporting breaches affecting 500 or more individuals?
  • Where should enforcement of compliance begin according to best practices?
  • When conducting disciplinary actions related to privacy violations, what is crucial for consistency?
  • At which level of the Medicare appeals process is the appeal reviewed by a qualified independent contractor?
  • What does the acronym LEIE refer to?
  • When handling a data breach, which law requires notification regarding the breach?
  • Which of the following is an obstacle to an effective compliance program?
  • Which document is not typically associated with the self-disclosure process?
  • Which is not one of the seven fundamental elements of an effective compliance program?
  • True or False: The STARK law prohibits Medicare payments for designated healthcare services referred by a physician with a financial relationship with the entity.
  • What term would be used for actions that result in unnecessary costs to the Medicare program?
  • Which type of healthcare service management may include consultation between providers?
  • Which standard component is NOT typically included in codes of conduct?
  • What is one key benefit of a well-implemented compliance program?
  • The term OIG refers to which of the following organizations?
  • If a provider is dissatisfied with an informal review by the state Medicaid Program, what action can they take?
  • Who is considered an immediate family member under the Stark Law?
  • What is Attestation in a compliance context?
  • Who is responsible for investigating potential overpayments in a healthcare organization?
  • What is indicated by the acronym POA?
  • What is one of the purposes of ongoing monitoring in a compliance program?
  • What is the primary focus of the Office of Inspector General (OIG) in healthcare compliance?
  • Which of the following is NOT a permitted use of PHI?
  • According to HIPAA, a healthcare provider or its business associate may disclose PHI when authorized to do so, but only to the extent necessary. This is known as:
  • Which document is used to assist employees in carrying out daily responsibilities within an appropriate legal standard?
  • Who conducts and supervises audits and investigations for federal agencies?
  • What is a key feature of a Non-Statistical Sample?
  • What is one of the main purposes of the Code of Conduct?
  • When was the U.S. Federal Sentencing Commission organized, and when did it first publish its guidelines?
  • What do SURS or SUR Units refer to?
  • In providing appointment reminders to patients, what should an organization address in their notice of privacy practices (NPP)?
  • What type of testing requires a laboratory to enroll in the CLIA program?
  • What is the correct term for physicians billing for services performed by residents in teaching hospitals?
  • Progressive discipline policies should be:
  • Which of the following questions is NOT useful during an internal investigation?
  • What is the primary goal of a compliance program?
  • What should a healthcare organization do to ensure it is compliant with HIPAA regulations?
  • According to the Balance Budget Act of 1997, what is the "three strikes" rule associated with?
  • Which group is least likely to report errors in a healthcare setting?
  • In the case of a 5-year CIA, which of the following statements is TRUE?
  • When developing a privacy monitoring plan, where should the privacy professional initially focus?
  • When was the False Claims Act implemented?
  • Who does the OIG urge to assist in the implementation of the compliance program?
  • Which method is preferred for monitoring and auditing compliance effectively?
  • When monitoring a high-risk area shows it was never implemented, what should the compliance professional do FIRST?
  • What type of feedback mechanism can reinforce positive behavior in compliance?
  • What is an example of a physical safeguard?
  • You are the new compliance officer at an institution with an established compliance committee. Which committee member's background would be most valuable in audit activities?
  • Which three qualities should communication to staff about compliance matters possess?
  • If a referred patient has a hearing deficit, what should your practice do when scheduling an appointment?
  • Which process aims to identify the effectiveness of internal controls in place?
  • Which statement is true regarding compliance programs?
  • What is the recommended minimum annual training duration suggested by OIG for compliance?
  • What should compliance programs include to understand and mitigate risk?
  • In response to a call indicating potential research misconduct, what should the compliance professional assure the employee?
  • Which of the following statements best defines Reasonable Diligence in compliance?
  • How does EMTALA strengthen patient rights in emergency situations?
  • What is a primary function of the Compliance Officer?
  • Which contractors are responsible for reviewing and paying claims for Medicare?
  • A covered entity must obtain the patient's written authorization for any use or disclosure of protected health information (PHI) in which circumstances?
  • A record retention policy must be based on which of the following?
  • Which of the following is NOT a governmental investigative tool?
  • When can a patient instruct their provider not to share treatment information with their health plan?
  • Which characteristic defines a Statistical Valid Sample?
  • Who is responsible for enforcing the rules and regulations under Medicare and Medicaid laws?
  • What should be readily accessible to all coding staff?
  • What is the ongoing process called that management performs to ensure processes are effective?
  • What should a compliance professional's NEXT step be if they identify payments to physicians for medical directorships without written contracts?
  • The majority of fraud and abuse violations are related to which of the following?
  • Which of the following is considered a compliance activity in many organizations?
  • If a compliance professional discovers non-compliance, what is the FIRST step they should take?
  • How often should providers check if employees are on the OIG List of Excluded Individuals after hiring?
  • What should a research compliance professional instruct a study coordinator regarding payment for recruitment in a clinical trial?
  • Which process focuses on identifying and addressing problems as they occur?
  • What is the Teaching Physician Rule primarily concerned with?
  • Which term best describes the approach to punishment of the Federal Sentencing Guidelines (FSG)?
  • Which act established the Health Care Fraud and Abuse Control Program?
  • What is an essential component in establishing a culture of compliance within an organization?
  • What does a Fiscal Intermediary do in the context of Medicare and Medicaid services?
  • What does the HIPAA rule indicate about permissions versus requirements?
  • What is essential for compliance reporting regarding complaints?
  • What outcome might occur if errors in billing are not promptly addressed?
  • When is protected health information (PHI) considered compromised?
  • Which federal agency's guidance includes criteria on unbiased judgment and independence for IROs?
  • Does a Compliance Officer impose disciplinary actions within an organization?
  • Which of the following principles addresses the obligation to the public?
  • True or False: Randomness in sampling is crucial for representativeness.
  • Which accrediting body is recognized as the largest for healthcare organizations in the United States?
  • Protected health information (PHI) is considered de-identified by HIPAA Privacy Rule standards by:
  • What must a compliance program have in addition to a plan?
  • Which of the following best describes the intent of a risk management strategy?
  • Which entity cannot bill for medically unnecessary services?
  • What is the primary function of the CMS (Centers for Medicare and Medicaid Services)?
  • What is a significant obstacle to effective compliance implementation?
  • SNFs are Medicare certified facilities that provide extended skilled nursing or rehabilitative care. This care is reimbursed under which Medicare part(s)?
  • Why should a supervisor explain the Code of Conduct to employees?
  • Which organization is represented by the acronym EEOC?
  • Which principle should guide the compliance professional throughout an investigation?
  • True or False: The 2023 OIG Compliance Program Guidance requires organizations to conduct periodic compliance risk assessments at least annually.
  • According to the Equal Employment Opportunity law, what is a protected characteristic?
  • During an investigation, why is it important to keep identities discreet?
  • True or False: Underpayments identified during a CIA-Claim Review may be netted from overpayments.
  • Which of the following elements is considered absolutely essential for the success of a compliance program?
  • What is the purpose of the work product doctrine?
  • What right is NOT typically included in the Notice of Privacy Practices?
  • Which statement accurately describes fraudulent billing?
  • What crucial element is first called for in OIG guidance for compliance programs?
  • What is the primary purpose of progressive discipline according to OIG recommendations?
  • Who should be contacted immediately upon discovering a significant billing error?
  • Which practice promotes a culture of compliance within healthcare organizations?
  • What is considered a violation when billing for items or services?
  • What is the first action a compliance professional should take upon detecting wrongdoing?
  • What is a primary benefit of conducting a contemporaneous review?
  • Are Business Associates required to comply with all Privacy Rules under HIPAA?
  • What is the purpose of the response element in compliance?
  • Which act contains the whistleblower provision?
  • What is the primary role of the US Sentencing Commission?
  • What characteristic should disciplinary mechanisms possess to be effective?
  • True or False: The PHRMA CODE is a law that must be followed by organizations.
  • To effectively manage compliance, what should the Compliance Officer ensure is in place?
  • Are incidental disclosures allowed under the HIPAA Privacy Rule?
  • What does PHI stand for?
  • What act requires annual adjustments of CMP fine amounts?
  • What historical context is associated with Lincoln's Law?
  • Which elements are effective for monitoring and auditing?
  • What is an essential characteristic of an engaging compliance training session?
  • Before developing a Compliance Program, what should be conducted first?
  • What principle states the obligation of compliance professionals to serve their organization with integrity?
  • What is a primary source of information for the team conducting an audit?
  • True or False: If a serious allegation is sensitive in nature, legal counsel should be contacted to determine if Attorney Client Privilege (ACP) needs to be attached.
  • Which of the following is NOT a requirement under the HIPAA Security Rule?
  • What does RAT STATS refer to in the context of healthcare compliance?
  • What should be the outcome of conducting a baseline audit?
  • What is the role of the Office for Human Research Protections?
  • If serious wrongdoing is suspected, what is the FIRST step to take?
  • Under Stark Law, what does "stand in the shoes" refer to?
  • What does the acronym SDN represent in healthcare compliance?
  • Which of the following best describes compliance program structure's importance?
  • What does Attorney-Client Privilege protect?
  • What should a research compliance professional do when an employee refuses a Hep B vaccination?
  • How often must new employees be trained about HIPAA regulations?
  • Which of the following is a task that a Chief Compliance Officer should NOT focus on?
  • What does the PhRMA Code prohibit?
  • What is the consequence for organizations that fail to implement necessary compliance training?
  • In the context of healthcare compliance, what plays a critical role in monitoring Medicare fraud?
  • What is the purpose of having billing policies in an organization?
  • What is a good starting point for monitoring compliance in an organization?
  • Which act emphasizes the use of technology in health information?
  • What category of security standards includes delegation of security responsibilities and security training?
  • How can a Compliance Officer achieve higher levels of compliance engagement?
  • What does the "reverse false claims" provision under FERA require from healthcare providers?
  • What was the primary purpose of the Sarbanes-Oxley Act of 2002?
  • Why is the Caremark International Derivative Litigation significant?
  • Which of the following situations requires authorization for PHI disclosure?
  • What identification is essential for employees in a compliance program?
  • What Act created the Medicaid Integrity Program (MIP) to ensure that Medicaid payments are for covered services?
  • What step should be taken when considering self-disclosure of a potential fraud issue?
  • Which regulation should be reviewed in preparing an education session about lost thumb drives containing PHI?
  • Which of the following is included in the elements of a compliance program?
  • What is the best course of action after receiving an OHRP letter regarding a specimen bank without IRB approval?
  • What type of act is the False Claims Act, which offers incentives for whistleblowing?
  • Who is allowed to file a complaint under the False Claims Act?
  • Are providers liable for fraud committed by their billing services without their knowledge?
  • Which of the following is NOT considered part of the three C's of communication?
  • What does Part C of Medicare refer to?
  • What is the record retention period for HIPAA-related work products?
  • Which act aimed to eliminate discrimination based on race, religion, sex, or national origin in employment?
  • When training physicians and providers, which aspects should be covered?
  • Who is primarily responsible for carrying out discipline within a healthcare organization?
  • If an IACUC manager identifies studies with lapsed approvals, what should the research compliance professional do?
  • What must be included in a covered entity’s Notice of Privacy Practices?
  • What is the "Caremark Duty" related to?
  • What is considered the first and best line of defense in compliance?
  • In a healthcare compliance setting, what is an example of behavior that could be considered reckless non-compliance?
  • Which of the following statements is true about the Sarbanes-Oxley Act?
  • Is root cause analysis a high priority among federal law enforcement and regulatory agencies during investigations?
  • Which scenario violates the Stark Law?
  • What should you do if a patient walks into your practice with a leashed dog?
  • What type of information is NEVER acceptable to leave on an answering machine message?
  • What is another term for a Probe Audit or Probe Sample?
  • What is the first step a Compliance Officer should take when developing goals for a review?
  • What does the Physician Self-Referral Law prohibit?
  • What does a compliance program primarily aim to enforce within an organization?
  • What is the primary purpose of conducting a contemporaneous review in healthcare compliance?
  • When a medical record is inconsistent with the selected diagnosis code, who should the coder contact?
  • In what year was the Equal Employment Opportunity Commission created?
  • In the course of an audit, what is the first course of action if disciplinary actions against certain individuals are found to be unfair?
  • What are the types of sampling size characterized in audits?
  • Which Act of 2003 was established to reduce medication errors due to illegible physician handwriting and to promote e-prescribing?
  • What defines the monetary gain for whistleblowers under the DOJ when it chooses to decline a case?
  • The Office of Inspector General (OIG) is a division of which agency?
  • What action should be prioritized if a privacy incident involving PHI is suspected?
  • What is the MOST appropriate action for an IRB upon receiving self-reported investigator non-compliance regarding inclusion criteria?
  • What is the primary function of the Qui Tam provision?
  • Which type of medical record is destroyed by shredding and cutting?
  • What is an important first step in creating or improving a compliance team?
  • The Health ____ _______ Administration encouraged the use of statistical sampling in Medicare claims. Fill in the blanks.
  • In which scenario should a compliance professional establish attorney-client privilege?
  • Which procedure must be included in a policy for statistically valid sampling if the financial error rate exceeds 5%?
  • Which of the following is NOT required for an effective compliance program?
  • What aspect of compliance management focuses on addressing both current and future risks?
  • What action should be taken if there’s a directive from an immediate supervisor that conflicts with compliance protocols?
  • Which of the following is a focus of the Federal Sentencing Commission's 2004 changes?
  • In analyzing a potential issue with provider services agreements and management contracts, what should the compliance professional consider?
  • Restitution can be made in which of the following forms?
  • What does the Deficit Reduction Act (DRA) mandate regarding education on the False Claims Act (FCA)?
  • Which of the following is NOT a consideration when determining what to do FIRST in applying regulations?
  • For what reason might education not be labeled as punishment?
  • What is one of the main benefits of a Compliance Program?
  • Is it true that experienced compliance health care personnel can perform "double duty" as trainers and line performers?
  • If a whistleblower identifies fraudulent claims, what could be a true statement regarding potential rewards?
  • Which statement is true about patient rights under HIPAA?
  • What should a research compliance professional do NEXT after discovering device and serial numbers included in reporting data during a HIPAA audit?
  • What safeguards are included in the HIPAA Security Rule?
  • Which of the following comprises the entirety of a compliance program?
  • What type of audit is typically performed after transactions have been completed?
  • Which of the following best describes an inadvertent violation of privacy?
  • What is the penalty for a HIPAA violation committed under false pretenses?
  • What percentage of the government's total award can a relator receive if the DOJ intervenes in a qui tam action?
  • Which of the following is NOT typically included in codes of conduct?
  • According to the OIG, what is equally important to the successful implementation of a compliance program?
  • Is encryption required under HIPAA?
  • What is the purpose of a hotline or helpline in compliance monitoring?
  • What should be taken into consideration when developing an audit agenda?
  • Which elements should be included in policies regarding enforcement and disciplinary actions?
  • Which of the following rights allows an individual to request limits on the use of PHI?
  • As a new Compliance Officer, what should you do if the Code of Conduct is full of legal jargon?
  • According to the Federal Sentencing Guidelines, which factor could increase an organization's punishment?
  • Your organization recently completed a contemporaneous audit of laboratory billing practices and found that copays have been written off. What should be your next step?
  • What should compliance professionals do in response to discovering a systemic billing error?
  • What is one drawback of an internal reporting system?
  • The FSG - Culpability Score is used to determine what?
  • What can be a potential consequence of intentional or reckless non-compliance?
  • What should a privacy professional do first if an employee reports potential illegal activity involving misuse of identifiable information?
  • What is included in "all the required safeguards" according to HIPAA?
  • Which entity is allowed to utilize a single notice of privacy practices?
  • What is the definition of "Deposition" in medico-legal terms?
  • The Privacy Rule provides two de-identification methods. Which of the following is NOT one of them?
  • Which of the following can help reduce the risk of a qui tam lawsuit?
  • Which action does NOT support a robust compliance program?
  • What is the general principle behind the HIPAA Privacy Rule?
  • What does the Anti-Kickback Statute safe harbors protect?
  • What are the four impermissible acts associated with a HIPAA breach?
  • What is defined as electronically transmitted or maintained individually identifiable health information?
  • How is the sample size related to probe audits?
  • What encompasses any form of identifiable health information maintained by a healthcare provider or agency?
  • What is the purpose of Antitrust laws?
  • In the context of a compliance program assessment, what key factor should be reviewed related to the prevention of fraud, waste, and abuse?
  • What type of actions can the Office of Inspector General initiate according to healthcare compliance regulations?
  • What type of law is the False Claims Act categorized as?
  • What is a formal statement outlining a plan for a specified subject area, usually citing state and/or federal required actions or standards?
  • What is an example of a small organization according to FSG criteria?
  • What is the primary function of an Inspector General (IG)?
  • What encompasses demographic information collected from an individual in healthcare?
  • In healthcare compliance, what does 'T' in TPO stand for?
  • Which safety measure should be included in a training presentation on privacy safeguards?
  • What is NOT one of the fiduciary duties of the board?
  • When can you use or disclose PHI?
  • According to Stark Law, financial relationships are scrutinized if they exist between which of the following?
  • What type of information encompasses health information related to the health condition of an individual?
  • What is a potential requirement that the court may impose if future harm can be estimated?
  • What does the acronym CPG stand for in the context of healthcare compliance?
  • What is De-identified PHI?
  • In a compliance audit, the fieldwork step generally involves which activity?
  • Who can request an OIG Advisory Opinion?
  • What is considered the primary means of minimizing employee exposure to hazards in the workplace?
  • Which of the following describes an effective compliance program in terms of quality of care?
  • What is the process of identifying potential security risks and determining the probability and magnitude of risks called?
  • Routine waiver of co-pays would violate which law?
  • The HIPAA Privacy Rule covers which of the following?
  • What does PHI stand for in a healthcare context?
  • The compliance professional’s role in risk management includes which of the following?
  • What is one consequence for providers who fully cooperate during an OIG self-disclosure?
  • What is a benefit of using stories and analogies in training?
  • What is a Health Care Clearinghouse?
  • What is necessary for senior management to adopt an effective compliance program?
  • How many states currently require nursing facilities to perform a background check of state records for direct-access employees?
  • Paying a hospital monthly rent significantly below fair market value would be a violation of which regulation?
  • The Privacy Rule does not restrict the use or disclosure of _______________, which neither identifies nor provides a reasonable basis to identify an individual.
  • What is considered one of the most important foundations of a compliance program?
  • What can be said about self-reporting as a mitigating factor?
  • What does the Physician Payment Sunshine Act require manufacturers to disclose?
  • How can organizations effectively perform community service in the context of probation?
  • What are the seven basic elements for a fundamental compliance program?
  • What is required for a subpoena to be valid?
  • What is the significance of the FSG Culpability Score?
  • What should be done immediately regarding any identified compliance problems?
  • What do Standards of Conduct written Policies and Procedures demonstrate?
  • Which of the following is not one of the key objectives of internal controls?
  • What types of tools are commonly utilized in government investigations?
  • What role does Compliance play in a disciplinary action?
  • Which question is considered the most effective to include in an employee exit interview?
  • During a corporate compliance investigation, which statement is false regarding Attorney-Client Privilege considerations?
  • What three checks does the OIG recommend for new employee policies?
  • In a compliance program, the focus should primarily be on what aspect?
  • What is the aim of the Physicians at a Teaching Hospital (PATH) review?
  • How often should compliance testing be performed?
  • What is an example of a contingency planning safeguard?
  • What type of control is exemplified by the requirement to purchase from approved suppliers?
  • A health system implemented an EHR in multiple clinics, and the privacy professional discovers inconsistent interpretations of access policies. What is the BEST strategy for the privacy professional?
  • In the risk assessment process, which step involves assessing risk tolerance information and inherent risk?
  • What must be documented when amending a medical record?
  • What is one of the requirements of the Gramm-Leach-Bliley Act concerning financial institutions?
  • Which definition correctly describes Medicare/Medicaid abuse?
  • What are Corporate Integrity Agreements negotiated between?
  • The ACA requires that all providers adopt a compliance plan as a condition of enrollment with Medicare, Medicaid, and CHIP. Is this statement true or false?
  • What is a significant outcome of performing a thorough risk assessment?
  • Which of the following is included in designated health services?
  • Which part of HITECH is dedicated to funding grants and loans?
  • What is a vital part of fostering compliance culture in healthcare organizations?
  • Where does the compliance professional typically find guidelines for developing compliance programs?
  • What principle is emphasized in the Code of Ethics for Healthcare Compliance Professionals?
  • When is it necessary to hire an outside consultant or legal counsel?
  • When a provider receives a PHI request from Social Security Administration, what is the appropriate action?
  • What does the acronym CIA stand for in a compliance context?
  • How are computerized data medical records destroyed?
  • Which of the following is NOT an offense that could lead to OIG exclusion from Federal health care programs?
  • True or False: A compliance program that never identifies problems is considered to be effective.
  • If a provider is on the OIG sanctions list, what is the first step to take?
  • What is one responsibility that should NOT be handled by a compliance officer?
  • What should the Privacy Officer do after learning about a lost encrypted USB drive containing sensitive PHI?
  • What does the acronym C.I.A. stand for in the context of HIPAA?
  • Which type of information is specifically associated with the payment for healthcare services?
  • What is necessary for a successful reporting method in compliance?
  • Which option is a federal oversight related to Medicaid?
  • What is the maximum number of years a retrospective audit may need to cover due to the False Claims Act?
  • What statement is true regarding the updating of a compliance program due to changing healthcare regulations?
  • Which governmental body has the enforcement authority for HIPAA privacy?
  • Examples of proper disposal methods of protected health information (PHI) may include:
  • Which law creates liabilities for submitting false claims to federal healthcare programs?
  • What is a significant benefit of a Corporate Compliance Program?
  • Which of the following is NOT included in the five important federal fraud and abuse laws?
  • Who must comply with the HIPAA Privacy Rule?
  • Qui tam actions allow an individual to bring forward a claim to whom?
  • Under what condition can a relator not pursue a qui tam action?
  • In a compliance program, what is essential for risk assessment?
  • Which two main documents are essential for building a compliance program?
  • Can the same individual serve as both the designated privacy and security official under HIPAA?
  • What should be included in the provider self-disclosure to the government?
  • Which agency emphasized that compliance and ethics programs should be designed to prevent and detect criminal conduct?
  • What aspect of compliance do Corporate Integrity Agreements primarily focus on?
  • When is a covered entity permitted to use or disclose PHI for marketing purposes?
  • Which of the following is not an aggravating factor to a culpability score?
  • Which agency indicates a self-evaluation after the discovery of potentially fraudulent acts?
  • Under EMTALA, what is required from hospitals when a patient arrives in the emergency department?
  • When is a breach assumed to be reportable?
  • When is the HIPAA Privacy Rule retraining of the workforce required?
  • In the context of healthcare compliance, what is the impact of proving intent under the Anti-Kickback Statute?
  • True or False: Expanding contemporaneous reviews to include retrospective reviews is beneficial for providers.
  • In relation to compliance, what is a critical function of leadership within an organization?
  • What is the MOST important training topic for investigators in a research compliance educational session?
  • What can restitution to an identifiable victim include?
  • What is a key reason for implementing compliance training in healthcare organizations?
  • What does risk assessment involve within an organization?
  • Under the Anti-Kickback Statute, what term refers to regulatory exceptions for specific joint ventures?
  • Which of the following best describes the nature of a Compliance Program?
  • Which of the following is NOT a part of the Code of Conduct content checklist?
  • What is the main objective of conducting compliance reviews in healthcare billing?
  • Why is developing a variety of educational materials important?
  • Which of the following is NOT a category of privacy incident under HIPAA?
  • In which context is the term "Physician Self-Referral" used?
  • What law should a physician be educated about if they signed a clinical trial agreement and requested funds for referrals?
  • What is one role of the Compliance Committee according to regulatory guidelines?
  • What is one result of poor compliance management within an organization?
  • What is the purpose of the compliance program element referred to as Investigation/Mitigation/Non-Employment of Sanctioned Individuals?
  • True or False: Organizations are requested to indicate their adherence to the PHRMA CODE on their websites.
  • What is one method in managing risk in an organization?
  • In the context of healthcare compliance, the concept of 'Operations' primarily includes which of the following?
  • What is a fundamental principle of the Privacy Rule?
  • According to HHS-OIG, what is one important reason for proper documentation in compliance?
  • Which of the following is a key component of training requirements for compliance?
  • What is a potential result of an effective compliance program?
  • What type of audit is most likely used to identify the amount of repayment to Medicare for specific claims?
  • What does the term 'treatment' in a healthcare context refer to?
  • Upon receiving a patient complaint about a research study invitation, what initial action is most appropriate?
  • What is a key difference between the Anti-Kickback Statute and Stark Law?
  • In what order should the sample sizes of different audit types be ranked from least to most?
  • How frequently is the IACUC required to conduct an inspection of a vivarium?
  • In the context of healthcare compliance, what characterizes 'waste'?
  • What type of safeguard is NOT included in the HIPAA Security Rule?
  • Which aspect of HIPAA aims to maintain the integrity of personal health information?
  • Which action is voluntary for treatment, payment, and operations (TPO) under HIPAA?
  • What workforce size typically qualifies as a large organization under FSG?
  • Which agency is responsible for overseeing employee safety?
  • Which of the following is an example of an administrative safeguard?
  • Does the HIPAA Privacy Rule cover all forms of protected health information including electronic, written, or oral?
  • What is a grand jury subpoena used for in a government investigation?
  • What does the investigation final report in documentation include?
  • What is primarily assessed during the evaluation of compliance program effectiveness?
  • Which section of the ACA prevents discrimination against individuals with limited English proficiency in healthcare programs?
  • What aspect of healthcare does HITECH Subtitle D focus on?
  • What does the term "Duty of Care" refer to for a Board of Directors (BOD)?
  • Part B of Medicare primarily covers which type of services?
  • What is a core role of the Chief of Compliance in a healthcare organization?
  • When under an imposed-CIA, which statement about Independent Review Organizations (IROs) is not true?
  • Which act imposes penalties for knowingly submitting false claims to Medicare?
  • What serves as an effective support system for the desired organizational culture?
  • Which entities are covered under the Physician Payment Sunshine Act?
  • What kind of legislation is HIPAA considered?
  • In what scenario can a covered entity disclose PHI for research without authorization?
  • Which of the following actions reflects a breach of ethical standards in research?
  • Under the US Federal Sentencing Guidelines, which process should be prioritized for effective compliance?
  • How many identifiers are listed in the HIPAA Privacy Rules?
  • Incentive programs based on employee performance may be tied to increases in what?
  • What is Part D of Medicare mainly focused on?
  • Which training topic specifically addresses risks associated with privacy breaches?
  • What should a facility's policy be when contacted for patient information by an agency investigating a HIPAA privacy violation?
  • What is the best first step for a compliance professional when an employee reports unequal disciplinary action?
  • Which of the following elements is included in the Anti-Kickback Statute?
  • What should a compliance officer prioritize to enhance compliance in healthcare?
  • What is a key factor for a healthcare organization to avoid unnecessary liability related to overpayments?
  • What is the recommended frequency for general compliance training for employees, physicians, and volunteers?
  • What term is associated with the 2022 Monaco Memo in relation to corporate accountability?
  • What are the two primary objectives of a Board of Directors (BOD)?
  • What action should a compliance officer take if an ongoing investigation could be compromised by certain employees remaining present?
  • In compliance investigations, why is it important to engage with outside counsel?
  • How many percutaneous injuries involving contaminated sharps occur annually according to CDC estimates?
  • What does the acronym CIA stand for in healthcare compliance?
  • What measure is most important for prevention in a compliance program?
  • What action should organizations take if they discover a compliance violation?
  • In CMS identified areas of high-risk fraud, which combination does NOT apply?
  • Is it permissible to send X-rays to a specialist without encryption?
  • Which action is essential once compliance violations are identified?
  • What should your first course of action be if a provider and secretary are found violating privacy regulations?
  • If there are inconsistencies in PHI policies, what should the Compliance Officer do?
  • Which of the following two statements regarding RAT-STATS are true?
  • Which of the following is NOT a regulatory agency that identifies compliance risks?
  • Which category of privacy is primarily concerned with health records under HIPAA?
  • What does the OIG suggest should be included in a compliance program regarding discipline?
  • Which of the following is considered a strict liability statute?
  • What does the term 'Code of Conduct' encapsulate in a healthcare organization?
  • What does HIPAA Administrative Simplification aim to achieve?
  • What does the anti-kickback statute prohibit?
  • Which of the following describes one of the roles of a board member?
  • Which organization establishes written policies for Medicaid payment to prevent fraud, waste, and abuse?
  • Which Compliance Program Element is emphasized by the statement "the only thing worse than not having a policy is having a policy and not following it"?
  • Why was the Bloodborne Pathogens Standard introduced by OSHA?
  • Which of the following is the first step to take upon discovering a violation of federal fraud and abuse laws?
  • Which certificate allows a laboratory to conduct moderate- to high-complexity testing until compliance is determined?
  • The RICO Act is associated with increased penalties for violations related to which of the following?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy