Browse all practice questions for the HCCA Certified in Healthcare Compliance (CHC) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

HCCA Certified in Healthcare Compliance (CHC) Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • When is the HIPAA Privacy Rule retraining of the workforce required?
  • What does 'upcoding' refer to in medical billing?
  • Which of the following have been identified as high-risk areas by the OIG?
  • What is defined as Unsecured PHI?
  • Which of the following describes the life cycle of records management?
  • Which entity administers the Medicare and Medicaid laws outlined in the Social Security Act?
  • What is one potential incentive for self-disclosing misconduct to the OIG?
  • Upon identifying a potential violation, what should be done first?
  • Which of the following would be classified as a technical safeguard?
  • If several medical records are missing and physicians are taking original records home, what should the privacy professional do first?
  • When a compliance officer finds an excluded provider has treated patients, what is the NEXT action they should take?
  • What is a common objective of an effective compliance program?
  • Which process focuses on identifying and addressing problems as they occur?
  • In a compliance investigation, what is the most important responsibility of the compliance professional?
  • Why is developing a variety of educational materials important?
  • True or False: An individual has unrestricted access to all PHI within their Designated Record Set (DRS).
  • Which safety measure should be included in a training presentation on privacy safeguards?
  • What workforce size typically qualifies as a large organization under FSG?
  • Which practice promotes a culture of compliance within healthcare organizations?
  • What is a grand jury subpoena used for in a government investigation?
  • Which type of security standards involve the automated processes to protect data, such as encryption?
  • What is the acceptable extrapolation of the review results for the Observation Room charges?
  • What is the definition of "Deposition" in medico-legal terms?
  • What is the maximum number of years a retrospective audit may need to cover due to the False Claims Act?
  • What type of feedback mechanism can reinforce positive behavior in compliance?
  • Which of the following levels of confidentiality is considered when handling personal health information (PHI)?
  • What is one responsibility that should NOT be handled by a compliance officer?
  • Which two main documents are essential for building a compliance program?
  • How should an organization respond to an employee who does not complete compliance training?
  • What is a potential result of an effective compliance program?
  • If someone did not know about a HIPAA violation, what is the potential civil penalty?
  • What is a fundamental principle of the Privacy Rule?
  • Which agency indicates a self-evaluation after the discovery of potentially fraudulent acts?
  • In a compliance audit, the fieldwork step generally involves which activity?
  • Fundamentally, compliance efforts are designed to establish a ______ within a hospital that promotes prevention, detection, and resolution of conduct that does not conform to Federal and State law.
  • What is a common measure to mitigate privacy risk when sharing patient information?
  • What does "Willfully Ignorant of the Offense" imply?
  • Which category of privacy is primarily concerned with health records under HIPAA?
  • What does the HCCA identify as two critical components of a compliance program?
  • What is a key difference between consent and authorization under HIPAA?
  • What is the purpose of Antitrust laws?
  • Which of the following principles addresses the obligation to the public?
  • What should the Chief Compliance Officer do first when faced with increased correspondence challenging medical necessity?
  • If a payment request from a diagnostic provider seems unusually high compared to others, what should you do?
  • The Deficit Reduction Act requires providers receiving over $5 million in Medicaid funds to inform employees of their ability to?
  • What does a preventive internal control involve?
  • Which of the following is a key activity related to 'Payment' in the TPO framework?
  • What must be established by entities receiving more than $5 million in annual Medicaid payments?
  • Why is it important to conduct a retrospective audit?
  • In compliance, what does "education and training" primarily aim to achieve?
  • Which type of audit identifies potential errors before the process is completed?
  • What does the General Services Administration (GSA) manage?
  • What is a significant outcome of performing a thorough risk assessment?
  • What significant action is referred to as "Qui Tam" under the FCA?
  • What type of arrangement might lead to OIG identifying an "outlier" for non-compliance?
  • What action should be included in the education plan regarding content areas?
  • Which type of information is specifically associated with the payment for healthcare services?
  • Does a Compliance Officer impose disciplinary actions within an organization?
  • What is a likely consequence of the board not having a solid understanding of compliance objectives?
  • The Office of Inspector General (OIG) is a division of which agency?
  • What does PHI stand for?
  • Is it permissible for covered entities to use patient sign-in sheets as long as the disclosed information is limited?
  • What does a Fiscal Intermediary do in the context of Medicare and Medicaid services?
  • A health care provider needs permission to notify public health authorities of a reportable disease occurrence. Is this statement true or false?
  • What is one of the seven elements emphasized in OIG CPG guidance for hospitals?
  • What is the penalty for a HIPAA violation committed under false pretenses?
  • Which term represents the process of identifying and dealing with risks in a compliance program?
  • What does the acronym SURS stand for?
  • What can ongoing monitoring help identify in a compliance program?
  • How is the sample size related to probe audits?
  • Who should be contacted immediately upon discovering a significant billing error?
  • What is the contact number for the OIG's Fraud and Abuse hotline?
  • Which of the following is a method for collecting compliance data?
  • The HIPAA Privacy Rule covers which of the following?
  • What is a primary benefit of conducting a contemporaneous review?
  • Which of the following statements about attorney-client privilege is true regarding the billing manager's review?
  • What is the first action a compliance professional should take upon detecting wrongdoing?
  • Which federal agency's guidance includes criteria on unbiased judgment and independence for IROs?
  • In the risk assessment process, which step involves assessing risk tolerance information and inherent risk?
  • What type of law is the False Claims Act categorized as?
  • What does the term 'Code of Conduct' encapsulate in a healthcare organization?
  • What is a key function of the compliance officer in a healthcare organization?
  • Which characteristic defines a Statistical Valid Sample?
  • What are the suggested development guidelines for compliance programs issued by the OIG called?
  • What is one of the main benefits of a Compliance Program?
  • Which of the following is a task that a Chief Compliance Officer should NOT focus on?
  • What should be included in a physician’s written policy regarding cash discounts?
  • If a provider is dissatisfied with an informal review by the state Medicaid Program, what action can they take?
  • Which process aims to identify the effectiveness of internal controls in place?
  • When resolving compliance issues, which aspect is emphasized as the most critical line of defense?
  • When is a covered entity permitted to use or disclose PHI for marketing purposes?
  • Which of the following is NOT required for an effective compliance program?
  • Organizations can reduce their culpability according to the Federal Sentencing Guidelines by?
  • What action should a compliance officer take if an ongoing investigation could be compromised by certain employees remaining present?
  • What is the primary purpose of conducting a contemporaneous review in healthcare compliance?
  • What does RAT STATS refer to in the context of healthcare compliance?
  • What must any laboratory performing testing on human specimens do?
  • Which type of information is NOT considered part of the Electronic Protected Health Information (ePHI)?
  • When anticipating what the government will measure during a compliance program review, which of the following should you consider?
  • What is the primary function of an Inspector General (IG)?
  • Which of the following best describes compliance program structure's importance?
  • What is the primary purpose of a compliance committee?
  • Why is the Caremark International Derivative Litigation significant?
  • What is the second step for a compliance professional upon detecting wrongdoing?
  • What crucial element is first called for in OIG guidance for compliance programs?
  • In dealing with medical necessity issues, whom should the compliance professional collaborate with?
  • Who benefits financially from a Qui Tam suit if successful?
  • Which of the following expenses related to compliance programs is NOT considered tax deductible?
  • What was a primary reason for the enactment of the Sarbanes-Oxley Act?
  • True or False: An excluded individual is automatically reinstated at the end of an exclusion term.
  • What type of information encompasses health information related to the health condition of an individual?
  • What year did OSHA establish the Bloodborne Pathogens Standard?
  • What is the general principle behind the HIPAA Privacy Rule?
  • When determining the extent of research monitoring activities, which factor is critical to consider?
  • How can a 100% confidence level in an audit be obtained?
  • Which of the following gifts is generally considered acceptable under a typical Code of Conduct?
  • When does the 60-day timeline for breach notifications initiate?
  • What is the next step for a privacy professional when receiving a hotline message about PHI misuse?
  • What is necessary for senior management to adopt an effective compliance program?
  • How long is a corporate integrity agreement typically enforced?
  • What should a healthcare organization do to ensure it is compliant with HIPAA regulations?
  • Which statement reflects the importance of compliance programs in healthcare?
  • What is a key item that can protect a medical practice from harassment liability?
  • In analyzing a potential issue with provider services agreements and management contracts, what should the compliance professional consider?
  • Which aspect does NOT typically form part of a compliance program's structure?
  • What principle is emphasized in the Code of Ethics for Healthcare Compliance Professionals?
  • Which of the following is considered a strict liability statute?
  • What type of actions may be subject to discipline according to compliance standards?
  • Which professionals are classified as physicians under Stark Law?
  • Which option should be considered for disclosing a violation of federal fraud laws?
  • What does LoProCo stand for in the context of HIPAA compliance?
  • Which of the following is the first step to take upon discovering a violation of federal fraud and abuse laws?
  • What act requires annual adjustments of CMP fine amounts?
  • What type of audit is characterized by a comprehensive inspection of records in anticipation of launching a compliance program?
  • How should complaints received through a Compliance Hotline be handled?
  • True or False: Employees may be required to give up their personal sense of right and wrong to function in the company.
  • What does the acronym SDN represent in healthcare compliance?
  • What type of actions can the Office of Inspector General initiate according to healthcare compliance regulations?
  • OIG believes that the Compliance Program should include a written policy statement addressing what?
  • Which of the following is NOT a typical role of the Board of Directors in compliance?
  • What should compliance programs include to understand and mitigate risk?
  • What historical context is associated with Lincoln's Law?
  • Which of the following is a key responsibility of a privacy professional?
  • Which of the following is NOT a key to successfully creating a risk assessment team?
  • The purpose of EMTALA primarily aims to prevent what action by hospitals?
  • What should be considered when evaluating a potential conflict of interest?
  • What is a formal statement outlining a plan for a specified subject area, usually citing state and/or federal required actions or standards?
  • Which of the following conditions is associated with the imposition of community service as part of probation?
  • Which of the following is NOT a regulatory agency that identifies compliance risks?
  • Which principle should guide the compliance professional throughout an investigation?
  • What document must be provided to patients that outlines their rights regarding PHI?
  • Which of the following is NOT a criterion for home health coverage?
  • According to US Courts, which of the following is NOT included in the obligations concerning statistical sampling for overpayment estimations?
  • What is the purpose of the response element in compliance?
  • What is the primary purpose of the Health Care Compliance Association (HCCA)?
  • What is the process to assess if an "impermissible" use of protected health information is a breach?
  • How is Medicaid primarily administered in the United States?
  • What is required for an "addressable" implementation specification?
  • What does Attorney-Client Privilege protect?
  • Who does the OIG urge to assist in the implementation of the compliance program?
  • If Leaf Hospital conducts a contemporaneous review, what might they uncover that warrants further action?
  • What is the scope of protection under GINA Title I related to?
  • What must a compliance program have in addition to a plan?
  • What does 'P' in TPO refer to in the context of healthcare?
  • What could happen to a physician who fails to respond to an emergency while on call?
  • How frequently is the IACUC required to conduct an inspection of a vivarium?
  • What is one result of poor compliance management within an organization?
  • Which areas are common health care risk areas?
  • What defines a breach in the context of healthcare compliance?
  • Which act contains the whistleblower provision?
  • Why was the Bloodborne Pathogens Standard introduced by OSHA?
  • During a corporate compliance investigation, which statement is false regarding Attorney-Client Privilege considerations?
  • What does a compliance committee primarily oversee?
  • How should an institution address a clause in a clinical trial agreement that gives the sponsor all rights to new interventions?
  • What is the correct method for destroying DVD medical records?
  • What is one function of safety data sheets in a hazard communication program?
  • Which act emphasizes the use of technology in health information?
  • What should be considered when designing practices for PHI confidentiality?
  • What type of training does OIG suggest should be a separate session and targeted?
  • Under what condition can a relator not pursue a qui tam action?
  • Are providers liable for fraud committed by their billing services without their knowledge?
  • The majority of fraud and abuse violations are related to which of the following?
  • True or False: Organizations are requested to indicate their adherence to the PHRMA CODE on their websites.
  • What must be documented when amending a medical record?
  • What is the purpose of the compliance program element referred to as Investigation/Mitigation/Non-Employment of Sanctioned Individuals?
  • Which of the following is NOT a permitted use of PHI?
  • True or False: The Public Health Service (PHS) defines a significant financial interest based on aggregated income exceeding $10,000 over a twelve-month period.
  • What was the primary purpose of the Sarbanes-Oxley Act of 2002?
  • In the context of compliance, what would a follow-up phase typically involve?
  • Which of the following describes an effective compliance program in terms of quality of care?
  • An employee was terminated for accessing sensitive information. What is the privacy official's responsibility regarding disciplinary actions?
  • What should a facility's policy be when contacted for patient information by an agency investigating a HIPAA privacy violation?
  • What type of testing requires a laboratory to enroll in the CLIA program?
  • Which of the following actions is considered equally serious in terms of noncompliance?
  • What type of analysis evaluates the effectiveness of compliance efforts over time?
  • True or False: Conducting a Controlled Self-Assessment contributes to increasing the awareness and targeting of audit work.
  • How can auditing be distinguished from monitoring in a compliance context?
  • What type of act is the False Claims Act, which offers incentives for whistleblowing?
  • What should a privacy officer do after identifying a deficiency in the Notice of Privacy Practices (NPP)?
  • Which statement best describes the concept of "integrity" as it relates to compliance programs?
  • Which of the following statements about de-identified health information is true?
  • What are the seven basic elements for a fundamental compliance program?
  • Which method is preferred for monitoring and auditing compliance effectively?
  • Which of the following two statements regarding RAT-STATS are true?
  • Which of the following describes one of the roles of a board member?
  • Why is it important for all members of a healthcare organization to participate in the compliance program?
  • What is the scope of Chapter 8 of the Federal Sentencing Guidelines?
  • Which statement accurately describes the Response and Prevention Element in compliance?
  • In GINA Title II, what is illegal for employers to use for employment decisions?
  • Is there currently legislation specifically regulating artificial intelligence systems?
  • If a provider receives a tainted referral, what is the main consequence under the Stark Law?
  • In what situation should immediate modification of procedures occur?
  • What is the function of risk assessment within a compliance program?
  • What action should organizations take if they discover a compliance violation?
  • In which context is the term "Physician Self-Referral" used?
  • What is the focus of the Anti-Kickback Statute?
  • What is the appropriate response to a spelling error in a patient's medical record?
  • What does attorney-client privilege protect in the context of healthcare compliance reviews?
  • Which of the following best illustrates the importance of diverse educational materials?
  • What approach is NOT one of the primary methods for Controlled Self-Assessment?
  • Which principle is essential for handling PHI?
  • Which component is key for preventing unethical behaviors in an organization?
  • Which of the following is an administrative safeguard?
  • What is the primary function of the Qui Tam provision?
  • Which factor is key in defining the scope of a monitoring plan?
  • What is the look back period for Medicare overpayment claims?
  • What does the HITECH Act primarily promote?
  • Which act established the Health Care Fraud and Abuse Control Program?
  • Which of the following can help reduce the risk of a qui tam lawsuit?
  • What does the term 'treatment' in a healthcare context refer to?
  • Which of the following is NOT a part of the Code of Conduct content checklist?
  • What is considered an appropriate start to implementing an effective compliance program for small physician group practices with limited resources?
  • What regulates the circumstances under which a covered entity may use or disclose an individual's PHI?
  • True or False: The Stark Law prohibits claims for designated health services based on tainted referrals.
  • What is a crucial element of corrective action plans (CAPs) following an audit?
  • Which contractors are responsible for reviewing and paying claims for Medicare?
  • What is a key factor for a healthcare organization to avoid unnecessary liability related to overpayments?
  • Which of the following is a responsibility under administrative safeguards?
  • Is a Business Associate required to have a contract with a Covered Entity to comply with HIPAA?
  • What kind of legislation is HIPAA considered?
  • True or False: The PHRMA CODE is a law that must be followed by organizations.
  • What aspect of healthcare does HITECH Subtitle D focus on?
  • Which term best describes the approach to punishment of the Federal Sentencing Guidelines (FSG)?
  • What type of information is NEVER acceptable to leave on an answering machine message?
  • Which of the following is part of preventive measures in compliance?
  • What types of tools are commonly utilized in government investigations?
  • What is one significant benefit of maintaining communication lines open in a compliance program?
  • What legal consequence can occur if Medicare overpayments are not refunded?
  • Which of the following options aligns with the foundation of an effective compliance program?
  • What is the illegal practice of submitting separate claims for maximum reimbursement known as?
  • What does P-D-F stand for in the context of audits and investigations?
  • If there's an employment issue that requires compliance intervention, what is the next step?
  • Which question is considered the most effective to include in an employee exit interview?
  • A covered entity must obtain the patient's written authorization for any use or disclosure of protected health information (PHI) in which circumstances?
  • What should be the outcome of conducting a baseline audit?
  • Which law does not require nursing facilities to conduct state FBI criminal background checks?
  • What is the first step one should take when establishing an effective compliance program?
  • The term OIG refers to which of the following organizations?
  • What does GINA Title I allow health insurers to request?
  • What is a key component that should be included in a compliance program according to the 2023 OIG guidance?
  • Which of the following statements best defines Reasonable Diligence in compliance?
  • What does risk assessment involve within an organization?
  • The HIPAA Security Rule requires a covered entity to implement policies and procedures for authorizing access to e-PHI only when such access is appropriate based on the user or recipient's role. True or False?
  • Which key performance indicator is NOT typically monitored in compliance programs?
  • Which of the following actions shows ethical leadership in a healthcare setting?
  • Which is an objective of HIPAA Administrative Simplification?
  • What is the most important communication device for a compliance program?
  • What is a critical responsibility of compliance training and education?
  • In the course of an audit, what is the first course of action if disciplinary actions against certain individuals are found to be unfair?
  • What is the role of proper documentation in compliance, according to HHS-OIG?
  • What does the acronym LEIE refer to?
  • What is the primary goal of maintaining the integrity of medical records?
  • Who is responsible for investigating potential overpayments in a healthcare organization?
  • Which of the following is NOT a legal requirement under the Equal Employment Opportunity law?
  • What is essential for a privacy professional to maintain in order to keep up with industry standards?
  • Which of the following describes an organization with an effective compliance program?
  • What can be said about self-reporting as a mitigating factor?
  • What is the best course of action after receiving an OHRP letter regarding a specimen bank without IRB approval?
  • If a referred patient has a hearing deficit, what should your practice do when scheduling an appointment?
  • What must compliance and ethics programs ensure according to the Federal Sentencing Commission?
  • What is the main purpose of general compliance training?
  • What should a compliance officer prioritize to enhance compliance in healthcare?
  • Are Business Associates required to comply with all Privacy Rules under HIPAA?
  • Which of the following is true about the monetary settlement a relator can receive in qui tam actions?
  • True or False: In the case of serious sensitive allegations, you should contact legal counsel to determine attorney-client privilege needs.
  • If an employee violates the non-retaliation policy by spreading rumors, the compliance professional's first action should be?
  • What is ensured by contract provisions for background checks of vendor employees?
  • What is the main purpose of the American Recovery and Reinvestment Act (ARRA)?
  • What is considered the most important aspect of a compliance program?
  • What is true regarding contemporaneous reviews in a compliance setting?
  • Which criminal offense is OIG required to exclude individuals from Federal health care programs for?
  • What incentive may a provider receive for making a good faith Self-Disclosure to the OIG?
  • What does the anti-kickback statute prohibit?
  • Which of the following statements is true about the regulation of conflicts of interest in healthcare?
  • Which entity is allowed to utilize a single notice of privacy practices?
  • Which section of the ACA prevents discrimination against individuals with limited English proficiency in healthcare programs?
  • Is it permissible for healthcare practices to remind patients of their appointments?
  • Which of the following could be a legal implication for an organization due to conflicts of interest identified through the Open Payments database?
  • Which of the following is considered a compliance activity in many organizations?
  • What is the FIRST action an employee should take when an investigator presents a search warrant?
  • True or False: Root cause analysis is a proactive activity performed after an incident has occurred.
  • What does the FSG Culpability Score measure?
  • Which of the following is a valid example of PHI use beyond TPO?
  • What is considered one of the most important foundations of a compliance program?
  • If wrongdoing is identified, what is the FIRST action to take if an overpayment is found?
  • What is the significance of the FSG Culpability Score?
  • What is an Independent Review Organization (IRO) responsible for in Corporate Integrity Agreements?
  • What are the two agencies that the Healthcare Fraud and Abuse Control program requires to coordinate federal, state, and local healthcare law enforcement activities?
  • What must a healthcare provider set up to become a Medicare biller?
  • Is it true that experienced compliance health care personnel can perform "double duty" as trainers and line performers?
  • What agency developed the Federal Sentencing Guidelines (FSG)?
  • During an investigation, why is it important to keep identities discreet?
  • What is defined as electronically transmitted or maintained individually identifiable health information?
  • In a compliance program, what is essential for risk assessment?
  • What is the effective consequence of HIPAA of 1996 regarding incorrect claims?
  • True or False: The OIG's Self-Disclosure Protocol can be utilized to disclose illegal arrangements related to the Anti-Kickback Statute (AKS) and Stark Law.
  • Compliance risk management professionals should design a framework to ensure management understands?
  • If a facility only performs blood draws and no testing, does it require a CLIA number?
  • At its most basic level, what does a compliance program entail?
  • As a new compliance officer under an OIG CIA, what should be your first course of action?
  • What is Attestation in a compliance context?
  • Which of the following is NOT a category of obligations in the HCCA Code of Ethics?
  • Which of the following is an obstacle to an effective compliance program?
  • According to HHS-OIG, what is one important reason for proper documentation in compliance?
  • What does Willful Neglect refer to in compliance context?
  • What is the primary purpose of progressive discipline according to OIG recommendations?
  • When a PI is accused of accepting kickbacks from a sponsor, who should a research compliance professional FIRST notify?
  • What key aspect should be included in disciplinary action policies?
  • What does an open door policy encourage in the workplace?
  • According to the content, which factor is essential for developing effective compliance programs?
  • Which compliance program guideline focuses on evaluating corporate compliance?
  • What does Stark Law aim to prevent?
  • What action cannot be taken without having informed employees of rules and expectations?
  • What is a good starting point for monitoring compliance in an organization?
  • What are Corporate Integrity Agreements negotiated between?
  • What is an example of a physical safeguard?
  • Who conducts and supervises audits and investigations for federal agencies?
  • At which level of the Medicare appeals process is the appeal reviewed by a qualified independent contractor?
  • True or False: A self-audit can help providers reduce chances of non-compliance.
  • Why is establishing compliance programs crucial for healthcare providers?
  • What element is significant for a compliance program in relation to healthcare fraud?
  • Which governmental body has the enforcement authority for HIPAA privacy?
  • If there is a detection of serious wrongdoing, what is the first step for the compliance professional?
  • What does the Anti-Kickback Statute safe harbors protect?
  • What action should be prioritized if a privacy incident involving PHI is suspected?
  • What is a benefit of using stories and analogies in training?
  • Which of the following is a key aspect of compliance awareness among employees?
  • What should a research compliance professional do NEXT after discovering device and serial numbers included in reporting data during a HIPAA audit?
  • Which of the following actions reflects a breach of ethical standards in research?
  • What is essential for compliance reporting regarding complaints?
  • What is the role of the Compliance Officer regarding department policies?
  • Is encryption required under HIPAA?
  • What is one of the main purposes of the Code of Conduct?
  • What is a significant obstacle to effective compliance implementation?
  • Can the same individual serve as both the designated privacy and security official under HIPAA?
  • A privacy official should inform a clinic that it can provide PHI to a researcher if the researcher:
  • What does the False Claims Act empower the government to do?
  • What impact does the Balance Budget Act of 1997 have on healthcare organizations with repeated fraud convictions?
  • Which of the following is considered an incidental disclosure of PHI?
  • In response to a call indicating potential research misconduct, what should the compliance professional assure the employee?
  • Which of the following describes the types of audits?
  • Which of the following is NOT an offense that could lead to OIG exclusion from Federal health care programs?
  • What is the first step in the monitoring and auditing two-step process?
  • Which of the following statements accurately reflects the attitude of ACA regarding statistical sampling?
  • What measure is most important for prevention in a compliance program?
  • What are the four impermissible acts associated with a HIPAA breach?
  • What is a key difference between the Anti-Kickback Statute and Stark Law?
  • In compliance training, what is the significance of providing a positive call for action?
  • What does the Yates Memo emphasize regarding corporate misconduct?
  • What action should be taken if there’s a directive from an immediate supervisor that conflicts with compliance protocols?
  • Which elements are effective for monitoring and auditing?
  • What does IACUC stand for?
  • Which resources are MOST relevant for developing and updating a research compliance work plan?
  • Which of the following is not an aggravating factor to a culpability score?
  • Which method is used to destroy laser disc medical records?
  • What organization develop standards and accredit hospitals and healthcare facilities?
  • A health system implemented an EHR in multiple clinics, and the privacy professional discovers inconsistent interpretations of access policies. What is the BEST strategy for the privacy professional?
  • What document does the OIG develop if a provider does not have a corporate integrity agreement in place?
  • Which of the following questions is NOT useful during an internal investigation?
  • What key element must compliance programs include according to US Sentencing Guidelines?
  • Which document outlines high expectations for organizational compliance programs as per the latest DOJ guidance?
  • What should be the focus of a healthcare organization's risk management strategy?
  • What outcome might occur if errors in billing are not promptly addressed?
  • What is indicated by cooperation with government investigators in compliance matters?
  • What consequence can result from violations of the Anti-Kickback Statute?
  • What is the record retention period for HIPAA-related work products?
  • The Privacy Rule does not restrict the use or disclosure of _______________, which neither identifies nor provides a reasonable basis to identify an individual.
  • To assess the seriousness of a high error rate in claims, which type of sample should be pulled?
  • What must be included in a covered entity’s Notice of Privacy Practices?
  • What is one consequence for providers who fully cooperate during an OIG self-disclosure?
  • True or False: OIG voluntary guidance is intended to enhance internal controls within organizations.
  • What is another term for a Probe Audit or Probe Sample?
  • What key principle underlies the regulations enforced by the US Sentencing Commission?
  • In providing appointment reminders to patients, what should an organization address in their notice of privacy practices (NPP)?
  • What does the HIPAA rule indicate about permissions versus requirements?
  • Training requirements for compliance should include which essential component?
  • In a compliance program, what does auditing and monitoring help ensure?
  • Before a government investigation occurs, which document should be reviewed carefully?
  • How can organizations effectively perform community service in the context of probation?
  • Who is primarily responsible for clinical trial billing compliance and enforcement?
  • Which agency is referred to by the acronym OCR?
  • What underlying goal does root cause analysis serve?
  • In the case of a 5-year CIA, which of the following statements is TRUE?
  • Which statement is true regarding compliance programs?
  • Which document is not typically associated with the self-disclosure process?
  • True or False: The government only assesses financial compliance during audits and not other areas.
  • Which designated health services are covered by the Stark Law?
  • Which of the following is a common type of evidence collected for compliance violations?
  • Which Act safeguards student educational records from unauthorized uses and disclosures?
  • What is considered the first and best line of defense in compliance?
  • Which agency is responsible for overseeing employee safety?
  • What is one method in managing risk in an organization?
  • After implementing the non-retaliation policy, what should the compliance officer do next?
  • An effective auditing/monitoring plan must consider what factor?
  • What was the main goal of the 1984 Sentencing Reform Act?
  • What is the time frame for protecting PHI after an individual’s death?
  • What does the acronym ACE signify in healthcare compliance?
  • Which organization is represented by the acronym EEOC?
  • What aspect of compliance do Corporate Integrity Agreements primarily focus on?
  • What is the first step when potential issues are identified within an organization?
  • What is the most effective delivery method for compliance content as recommended?
  • What policy is implemented to foster open communication in a healthcare setting?
  • What does ERISA stand for?
  • What is a primary function of the Compliance Officer?
  • What does PHI stand for in a healthcare context?
  • What is an example of a small organization according to FSG criteria?
  • Progressive discipline policies should be:
  • What is prohibited by the Omnibus Budget Reconciliation Act of 1987 (OBRA)?
  • Which area should targeted compliance training specifically address?
  • What do SURS or SUR Units refer to?
  • How many percutaneous injuries involving contaminated sharps occur annually according to CDC estimates?
  • What is a characteristic of an effective HR policy within a healthcare organization?
  • How many states currently require nursing facilities to perform a background check of state records for direct-access employees?
  • What type of control is exemplified by the requirement to purchase from approved suppliers?
  • Which law does not require proof of intent for violations?
  • Which acronym refers to legal protections between a lawyer and a client?
  • Which of the following is not one of the key objectives of internal controls?
  • Who is primarily responsible for auditing and monitoring compliance risks?
  • How many criteria must be met before a patient can be transferred to another facility under EMTALA?
  • What is the main objective of conducting compliance reviews in healthcare billing?
  • Which of the following elements is included in the Anti-Kickback Statute?
  • What do Standards of Conduct written Policies and Procedures demonstrate?
  • When can a patient instruct their provider not to share treatment information with their health plan?
  • In emergency situations, what is true about PHI disclosure?
  • What is the minimum duration for which the OIG can impose a mandatory exclusion?
  • For what reason might education not be labeled as punishment?
  • How long are Corporate Integrity Agreements (CIAs) typically enforced?
  • Which of the following is considered a substantial risk for health care compliance?
  • The Privacy Rule generally requires covered entities to limit uses, disclosures, or requests of PHI to the minimum necessary to accomplish the intended purpose. True or False?
  • Which of the following is NOT a requirement under the HIPAA Security Rule?
  • What should a research compliance professional do when an employee refuses a Hep B vaccination?
  • What is the deadline for reporting breaches affecting 500 or more individuals?
  • Why is it important to have a written set of safety standards before an audit?
  • Restitution can be made in which of the following forms?
  • What is the Teaching Physician Rule primarily concerned with?
  • What kind of actions might lead to a penalty of $100,000 for a HIPAA violation?
  • Which of the following comprises the entirety of a compliance program?
  • When implementing a compliance plan, what is required for approval?
  • Who has the authority to bring civil action under the False Claims Act?
  • Which document is essential for a laboratory performing high-complexity testing before a compliance review?
  • When is immediate notification to the government warranted according to OIG compliance guidance?
  • In compliance program education, what should be the focus of scenario-based training?
  • What is the primary purpose of the False Claims Act (FCA)?
  • Which factors should be considered when establishing a frequency schedule for monitoring activities?
  • Which of the following best describes the watchwords for enforcing standards of conduct in compliance?
  • What is a consequence of transferring a patient under EMTALA without appropriate medical records?
  • Which Act of 2003 was established to reduce medication errors due to illegible physician handwriting and to promote e-prescribing?
  • What is NOT one of the basic elements of compliance monitoring?
  • According to the OIG Compliance Program Guidance, what should be articulated to demonstrate commitment to compliance?
  • What is the primary purpose of a privacy exit interview?
  • What is an effective strategy to demonstrate compliance with personnel policies?
  • According to HIPAA, can pharmacists provide advice about over-the-counter medicines without restriction?
  • What should you do if you discover a minor inventory discrepancy in controlled substances?
  • How does EMTALA strengthen patient rights in emergency situations?
  • What term is used for Federal regulations that specify certain joint ventures concerning hospitals and/or physicians that are compliant with Medicare laws?
  • What safeguards are included in the HIPAA Security Rule?
  • What is the recommended frequency for general compliance training for employees, physicians, and volunteers?
  • Who can request an OIG Advisory Opinion?
  • The compliance program should address plans to verify adherence to applicable laws through what methods?
  • Why is training and education critical in compliance programs?
  • Which action does NOT support a robust compliance program?
  • Which of the following is a key component of a compliance program?
  • What term describes an organization's commitment to compliance by management, employees, and contractors?
  • Which of the following is included in the elements of a compliance program?
  • How long do providers have to refund overpayments once identified?
  • Under EMTALA, what is required from hospitals when a patient arrives in the emergency department?
  • What should be done in response to suspected misconduct or wrongdoing?
  • Under the US Federal Sentencing Guidelines, which process should be prioritized for effective compliance?
  • What is the purpose of the Health Care Fraud and Abuse Control Program?
  • True or False: Expanding contemporaneous reviews to include retrospective reviews is beneficial for providers.
  • True or False: The OIG advises the public on the governance of the PHRMA CODE.
  • What are the three benefits of an effective compliance program?
  • What is one of the main reasons cited for reinforcing employee’s innate sense of right and wrong through compliance programs?
  • What does the phrase "Res Ipsa Loquitur" mean in legal terms?
  • How many identifiers are listed in the HIPAA Privacy Rules?
  • What is a critical element to address when preparing a compliance plan for the year?
  • Which resource should clinical lab providers review to understand compliance requirements?
  • Which regulation should be reviewed in preparing an education session about lost thumb drives containing PHI?
  • What characteristic should disciplinary mechanisms possess to be effective?
  • Which of the following is a benefit of conducting a Control Self-Assessment?
  • One of the benefits of a Compliance Program is to:
  • What is a retrospective audit used for?
  • What is one characteristic of the "safe harbors" established by the OIG in the AKS?
  • Which of the following is NOT included in the five important federal fraud and abuse laws?
  • True or False: The OIG requests that organizations disclose their adherence to the PHRMA CODE on their website.
  • What encompasses any form of identifiable health information maintained by a healthcare provider or agency?
  • Is it true that Risk Management aligns with Quality Management in determining measures for risk avoidance and prevention?
  • According to HIPAA, what method can be used to de-identify PHI?
  • What are the four areas PHI can be used or disclosed by?
  • Compliance audits typically relate to which of the following functions?
  • How should reporting systems within healthcare organizations be handled?
  • What does the acronym OHCA stand for?
  • What does the Physician Self-Referral Law prohibit?
  • The Privacy Rule provides two de-identification methods. Which of the following is NOT one of them?
  • What is the lowest potential federal civil monetary penalty for a HIPAA violation?
  • What are the primary focus areas of a Board of Directors (BOD) concerning compliance?
  • What is the difference between an addressable and a required implementation specification under HIPAA?
  • Which of the following is not required in a written hazard communication program?
  • What should be taken into consideration when developing an audit agenda?
  • Which statement accurately describes fraudulent billing?
  • What is considered a violation when billing for items or services?
  • What does EMTALA require from participating hospitals regarding patient transfers?
  • Which group is least likely to report errors in a healthcare setting?
  • When is protected health information (PHI) considered compromised?
  • What subpart governs Breach Notifications in HIPAA?
  • What does the PhRMA Code prohibit?
  • Effective enforcement and discipline elements include:
  • How can organizations reduce their culpability according to the Federal Sentencing Guidelines?
  • Which regulation requires hospitals to provide medical screening exams regardless of insurance?
  • After an investigation that affects the organization's reputation, what should a Compliance Professional do next?
  • What type of test would be practical for a physician practice to determine unpaid claims?
  • When was the False Claims Act implemented?
  • Which of the following statements about the monitoring of internal controls is TRUE?
  • What is a significant benefit of a Corporate Compliance Program?
  • Which area is identified by the OIG as most prone to fraud, waste, and abuse in home health agencies?
  • Which action is voluntary for treatment, payment, and operations (TPO) under HIPAA?
  • What category of security standards includes delegation of security responsibilities and security training?
  • True or False: Upcoding has been a major focus of OIG's enforcement efforts, and HIPAA added another civil monetary penalty for upcoding violations.
  • Which of the following is a consequence of failing to comply with federal health care regulations?
  • What is a primary source of information for the team conducting an audit?
  • Which statement about breaches is correct?
  • Which subpart in Part 164 of HIPAA deals specifically with Privacy?
  • Routine waiver of co-pays would violate which law?
  • Which of the following is an example of healthcare operations?
  • Which of the following provides legal protection from prosecution for a specific party?
  • Which type of safeguards are fundamental for protecting physical systems and data from environmental hazards?
  • What is primarily emphasized for effective oversight in compliance programs?
  • What is the purpose of internal controls in an organization?
  • What does HIPAA Administrative Simplification aim to achieve?
  • What does the term "Duty of Care" refer to for a Board of Directors (BOD)?
  • What is one of the main responsibilities of a Compliance Officer?
  • In a compliance program, the focus should primarily be on what aspect?
  • Which part of the HIPAA rules applies to PHI in all formats?
  • What does HIPAA stand for?
  • What must a Business Associate obtain to claim compliance when selling an individual's PHI?
  • True or False: If a serious allegation is sensitive in nature, legal counsel should be contacted to determine if Attorney Client Privilege (ACP) needs to be attached.
  • What does a compliance program fundamentally involve?
  • True or False: A compliance program that never identifies problems is considered to be effective.
  • What is a primary focus of concurrent audits?
  • What was Chapter 8 of Federal Sentencing Guidelines designed for?
  • Who is allowed to file a complaint under the False Claims Act?
  • What aspect of compliance management focuses on addressing both current and future risks?
  • What type of guidelines does the OIG describe its compliance program guidance as?
  • When asked to approve a transfer form containing a patient's SS#, what should the privacy officer do first?
  • Which standard component is NOT typically included in codes of conduct?
  • Which law provides protection against discrimination in employment based on genetic information?
  • What role does Compliance play in a disciplinary action?
  • What is the main focus of Title II of GINA?
  • What can lead to the detection of errors in past billing practices?
  • According to Stark Law, financial relationships are scrutinized if they exist between which of the following?
  • What is a key feature of an effective compliance program?
  • If a provider is on the OIG sanctions list, what is the first step to take?
  • What was the primary purpose of the False Claims Act (FCA) when it was implemented?
  • What is required for a subpoena to be valid?
  • What is the main mission of the OIG?
  • What comprises a Designated Record Set (DRS) under HIPAA?
  • What is a key feature of a Non-Statistical Sample?
  • True or False: Communications between company counsel and employees are privileged, owned by the company.
  • Which individual goal is BEST for a privacy professional to include in their objectives?
  • What type of services does Stark Law apply to?
  • What is a key characteristic of a Covered Entity?
  • Which three qualities should communication to staff about compliance matters possess?
  • What is the primary purpose of preventive controls within an organization?
  • When conducting disciplinary actions related to privacy violations, what is crucial for consistency?
  • What is the focus of the 2022 Monaco Memo regarding corporate governance?
  • A covered entity must designate a ___________________ who is responsible for developing and implementing its security policies and procedures.
  • What is an important first step in creating or improving a compliance team?
  • How long is PHI protected after the person's death?
  • What should you do if certain employees are not being properly disciplined for misconduct?
  • What is the outcome of failing to adhere to compliance programs?
  • What should be done immediately regarding any identified compliance problems?
  • What is a requirement for auditors in the context of compliance?
  • When a medical record is inconsistent with the selected diagnosis code, who should the coder contact?
  • Which aspect of HIPAA aims to maintain the integrity of personal health information?
  • What are two of the mitigating factors according to the Federal Sentencing Guidelines?
  • What should be done to maintain the confidentiality of information during an investigation?
  • In responding to coding errors, what is a compliance professional's key responsibility?
  • When was the U.S. Federal Sentencing Commission organized, and when did it first publish its guidelines?
  • Is a Security Risk Analysis required annually for a Covered Entity to comply with HIPAA?
  • What is a key difference between enforcement and discipline in a compliance program?
  • When should counsel be involved during an internal investigation?
  • Which right is NOT included in the individual rights under the NPP?
  • Which agency emphasized that compliance and ethics programs should be designed to prevent and detect criminal conduct?
  • Which of the following is NOT a consideration when determining what to do FIRST in applying regulations?
  • What is a key reason for implementing compliance training in healthcare organizations?
  • What governs the HIPAA Security Rule?
  • What is one role of the Compliance Committee according to regulatory guidelines?
  • What does the OIG's voluntary self-disclosure protocol require providers to report?
  • What should you do if a patient walks into your practice with a leashed dog?
  • What critical information must be included when notifying individuals of a breach?
  • What type of information does the CMS Open Payments Program provide to the public?
  • Which certificate allows a laboratory to conduct moderate- to high-complexity testing until compliance is determined?
  • Which type of healthcare service management may include consultation between providers?
  • What is a mitigating factor to a culpability score?
  • Which of the following is a preventive measure to avoid a Qui Tam lawsuit?
  • At which level of the Medicare appeals process is an appeal decision made by the Office of Medicare Hearings and Appeals (OMHA)?
  • What is the purpose of EMTALA?
  • Are incidental disclosures allowed under the HIPAA Privacy Rule?
  • What is the Stark Period of Disallowance?
  • In what scenario can a covered entity disclose PHI for research without authorization?
  • Upon receiving a patient complaint about a research study invitation, what initial action is most appropriate?
  • Which of the following elements is considered absolutely essential for the success of a compliance program?
  • What type of audit is most likely used to identify the amount of repayment to Medicare for specific claims?
  • What does the False Claims Act primarily address?
  • If there are inconsistencies in PHI policies, what should the Compliance Officer do?
  • What is the MOST appropriate action for an IRB upon receiving self-reported investigator non-compliance regarding inclusion criteria?
  • In compliance investigations, why is it important to engage with outside counsel?
  • According to recent regulations, compliance programs must include written policies and what other core element?
  • What law can a healthcare organization violate by not returning overpayments within 60 days?
  • Who is eligible to bring a suit under the False Claims Act?
  • True or False: Underpayments identified during a CIA-Claim Review may be netted from overpayments.
  • What should organizations develop to effectively document compliance risks?
  • What is the significance of documenting how a complaint was handled?
  • How do patients typically learn about their privacy rights under HIPAA?
  • Which of the following is NOT listed as an obstacle to effective compliance program implementation?
  • Which of the following is a primary responsibility of a compliance officer according to the OIG?
  • What term would be used for actions that result in unnecessary costs to the Medicare program?
  • Which accrediting body is recognized as the largest for healthcare organizations in the United States?
  • When creating and implementing a compliance plan, what is required of the compliance officer?
  • Why should compliance officers set disciplinary policies for non-compliance?
  • Who is primarily responsible for carrying out discipline within a healthcare organization?
  • A billing manager notices a 50% increase in Federal health care program payments. What should be the NEXT step?
  • Which of the following is identified by CMS as a high-risk area for fraud?
  • Which document is used to assist employees in carrying out daily responsibilities within an appropriate legal standard?
  • Under HIPAA's Privacy Rule, who constitutes the covered entity's workforce?
  • What term is associated with the 2022 Monaco Memo in relation to corporate accountability?
  • What is an essential component of PHI management in healthcare?
  • Who is responsible for recommending an auditing and monitoring plan for an effective compliance program?
  • What is the purpose of the work product doctrine?
  • What does the acronym CIA stand for in healthcare compliance?
  • When training physicians and providers, which aspects should be covered?
  • Which Compliance Program Element is emphasized by the statement "the only thing worse than not having a policy is having a policy and not following it"?
  • According to compliance best practices, which is the primary factor for effective compliance communication?
  • Which Act requires providers to repay identified overpayments to Medicare and Medicaid within 60 days?
  • The compliance professional’s role in risk management includes which of the following?
  • In the context of healthcare compliance, the concept of 'Operations' primarily includes which of the following?
  • What is the minimum number of units to be sampled for a full statistical audit?
  • What is the primary function of the CMS (Centers for Medicare and Medicaid Services)?
  • What is the primary contribution of auditing and monitoring to a compliance program?
  • What is NOT one of the fiduciary duties of the board?
  • Which of the following practices supports the implementation of corrective actions after identifying compliance issues?
  • Where should enforcement of compliance begin according to best practices?
  • In case of a cyber-attack, what steps must an entity take?
  • What three checks does the OIG recommend for new employee policies?
  • One of the operations in healthcare includes reviewing the competence of providers. What classification does this operation fall under?
  • How often must new employees be trained about HIPAA regulations?
  • What is the primary focus of the Office of Inspector General (OIG) in healthcare compliance?
  • What does the Breach Notification under ARRA require covered entities to do?
  • In what year was the Equal Employment Opportunity Commission created?
  • Which type of monitoring review is designed to catch issues as they arise?
  • Examples of proper disposal methods of protected health information (PHI) may include:
  • What is a key benefit of conducting a Controlled Self-Assessment?
  • What is the purpose of root cause analysis in healthcare compliance investigations?
  • Health information that cannot identify an individual is termed as?
  • You are the new compliance officer at an institution with an established compliance committee. Which committee member's background would be most valuable in audit activities?
  • What is the main purpose of a Remedial Order in probation?
  • What does the "reverse false claims" provision under FERA require from healthcare providers?
  • Which training topic specifically addresses risks associated with privacy breaches?
  • What is the role of the Office for Human Research Protections?
  • What is indicated by the acronym POA?
  • What should be done after clarifying a suspected fraud violation?
  • What is a penalty for willful neglect if the violation is corrected in 30 days?
  • What does the Health Care Financing Administration (HCFA) encourage to promote consistency in interpretation of claims?
  • Which action demonstrates a commitment to compliance in a healthcare setting?
  • Which of the following rights allows an individual to request limits on the use of PHI?
  • Which statement is correct regarding the consequences of non-compliance?
  • How is a retrospective audit characterized?
  • What is considered the primary means of minimizing employee exposure to hazards in the workplace?
  • What are the types of sampling size characterized in audits?
  • What should a billing manager do if a significant error is identified in the billing process?
  • What general areas does an OCR investigation examine?
  • Which of the following statements is true about the Sarbanes-Oxley Act?
  • Which legislation mandates compliance programs for Medicare, Medicaid, and CHIP providers?
  • What is the classification of upcoding services to receive higher reimbursement from Medicare/Medicaid?
  • Who has the authority to impose a Corporate Integrity Agreement (CIA)?
  • Which act aimed to eliminate discrimination based on race, religion, sex, or national origin in employment?
  • Is root cause analysis a high priority among federal law enforcement and regulatory agencies during investigations?
  • When monitoring a high-risk area shows it was never implemented, what should the compliance professional do FIRST?
  • Which of the following is NOT a purpose of a Business Associate in healthcare?
  • If an IACUC manager identifies studies with lapsed approvals, what should the research compliance professional do?
  • When developing a privacy monitoring plan, where should the privacy professional initially focus?
  • What should a compliance professional's NEXT step be if they identify payments to physicians for medical directorships without written contracts?
  • Which behavior is classified as unethical?
  • Which of the following is NOT considered a possible sanction by the OIG?
  • Which element is seen as an absolute necessity for a successful Compliance Program?
  • What does the Family Educational Rights and Privacy Act (FERPA) protect?
  • What should be included in the provider self-disclosure to the government?
  • What Act created the Medicaid Integrity Program (MIP) to ensure that Medicaid payments are for covered services?
  • What does RAT-STATS provide for auditors?
  • What is one of the first actionable items after establishing a compliance program?
  • What is NOT included in technical safeguards?
  • Which entities are covered under the Physician Payment Sunshine Act?
  • What is one potential risk of failing to address overpayments found during a review?
  • Which of the following is an example of an administrative safeguard?
  • What right is NOT typically included in the Notice of Privacy Practices?
  • What does HITECH Subtitle A focus on?
  • In healthcare compliance, why is effective education and training emphasized as a key element?
  • Which of the following is a primary goal of compliance programs in healthcare organizations?
  • True or False: Unintentional billing mistakes and overpayments do not need to be reported to the OIG's SDP.
  • What type of audit should be conducted for historical data analysis?
  • Which privacy law pertains to the protection of financial information?
  • What law should a physician be educated about if they signed a clinical trial agreement and requested funds for referrals?
  • What does the Latin phrase "Qui tam pro domino rege quam pro se ipso in hac parte sequitur" mean?
  • What is an essential characteristic of an engaging compliance training session?
  • A compliance audit typically aims to do which of the following?
  • How are minor unintentional non-compliance infractions typically addressed?
  • What is the primary goal of a compliance program?
  • When assisting IT with data privacy controls, which of the following is an employee-related control?
  • What are the two primary objectives of a Board of Directors (BOD)?
  • If a compliance professional discovers non-compliance, what is the FIRST step they should take?
  • What does Part C of Medicare refer to?
  • What statement is true regarding the updating of a compliance program due to changing healthcare regulations?
  • In-kind payments as restitution may include which of the following?
  • A PI testing a hypothesis with de-identified medical records should first:
  • What is De-identified PHI?
  • True or False: It is illegal under the Anti-Kickback Statute to provide free or discounted services to uninsured individuals.
  • Which of the following is included in designated health services?
  • What type of rewards does the FSG suggest offering to those who adhere to compliance and ethics programs?
  • What is a sign of failed efforts to use statistical analysis in sampling?
  • Which method is NOT used to destroy paper medical records?
  • What is the consequence for organizations that fail to implement necessary compliance training?
  • Does HIPAA allow disclosure of protected health information about a student to a school nurse for treatment purposes?
  • Which type of medical record is destroyed by shredding and cutting?
  • True or False: An email request from a client is sufficient authorization for secure communication.
  • Which law creates liabilities for submitting false claims to federal healthcare programs?
  • Which of the following should be reflected in a billing company's written policies and procedures?
  • What should a privacy professional do first if an employee reports potential illegal activity involving misuse of identifiable information?
  • A Compliance Program with well-written policies will not be successful without what?
  • Which of the following does NOT fall under Attorney-Client Privilege?
  • Which of the following is NOT identified as a special area of OIG concern?
  • What is the maximum prison sentence for committing a HIPAA offense knowingly?
  • Which of the following is NOT typically included in codes of conduct?
  • In the context of healthcare compliance, what characterizes 'waste'?
  • What is the recommended frequency for exclusion verifications according to compliance standards?
  • What is a key goal of the Defense Industry Initiative?
  • What is the maximum penalty for noncompliance with HIPAA provisions?
  • What percentage of the government's total award can a relator receive if the DOJ intervenes in a qui tam action?
  • What is a potential result of a willful violation of HIPAA?
  • In which situation can the information of a deceased patient be released to the spouse?
  • Where does the compliance professional typically find guidelines for developing compliance programs?
  • Which of the following best describes the nature of a Compliance Program?
  • Who is responsible for enforcing the rules and regulations under Medicare and Medicaid laws?
  • What is the meaning of TPO in the context of HIPAA?
  • What kind of safeguards might include the use of visitor badges and surveillance cameras?
  • What defines the monetary gain for whistleblowers under the DOJ when it chooses to decline a case?
  • Which statement is true about patient rights under HIPAA?
  • Which of the following best describes an inadvertent violation of privacy?
  • When developing a compliance program, which of the following actions should be prioritized after risk assessment?
  • Which term describes the 'provision, coordination, or management of health care and related services'?
  • Which element is essential within the compliance department to foster compliance culture?
  • What is the correct term for physicians billing for services performed by residents in teaching hospitals?
  • What documentation is NOT critical for a Compliance Officer's review when opening files?
  • In the context of compliance, what role does a baseline audit play?
  • What compelling reason supports the continuation of an auditing program?
  • What should a compliance officer do if they discover a potential violation?
  • What does the acronym DOL represent?
  • Which elements should be included in policies regarding enforcement and disciplinary actions?
  • Which of the following is a key requirement of the Sunshine Act?
  • What is the source of notification requirements following a data breach of a clinical system containing PHI?
  • According to the Equal Employment Opportunity law, what is a protected characteristic?
  • Which of the following best describes welfare benefit plans?
  • What is the primary purpose of OIG’s Voluntary Self-Disclosure Protocol?
  • What does the Sunshine Act mandate regarding pharmaceutical and medical device manufacturers?
  • What is one of the requirements of the Gramm-Leach-Bliley Act concerning financial institutions?
  • What type of audit is typically performed after transactions have been completed?
  • In research compliance, what is a primary goal of an IRB?
  • What should the Privacy Officer do after learning about a lost encrypted USB drive containing sensitive PHI?
  • Which of the following is NOT a necessary policy or procedure for organizations?
  • True or False: The 2023 OIG Compliance Program Guidance requires organizations to conduct periodic compliance risk assessments at least annually.
  • What does the Medicaid - Deficit Reduction Act of 2005 allow states to do?
  • Which is a key goal of establishing a code of conduct in healthcare organizations?
  • What should a compliance program's goal focus primarily on from a monitoring perspective?
  • What aspect of Medicare does Part A cover?
  • What can a compliance professional use to quickly evaluate if more extensive audits are needed?
  • In a healthcare compliance setting, what is an example of behavior that could be considered reckless non-compliance?
  • What does HITECH stand for?
  • SNFs are Medicare certified facilities that provide extended skilled nursing or rehabilitative care. This care is reimbursed under which Medicare part(s)?
  • Which statement correctly reflects the Stark Law's requirement for referrals?
  • Which organization develops and administers standards relating to the well-being of workers at job sites?
  • What does the Deficit Reduction Act (DRA) mandate regarding education on the False Claims Act (FCA)?
  • Which area is NOT subject to the 250-yard zone rule under the definition of "hospital campus"?
  • How many states require nursing facilities to perform FBI checks on employees?
  • What does the acronym CPG stand for in the context of healthcare compliance?
  • Incentive programs based on employee performance may be tied to increases in what?
  • The RICO Act is associated with increased penalties for violations related to which of the following?
  • What is the MOST important training topic for investigators in a research compliance educational session?
  • What is included in "all the required safeguards" according to HIPAA?
  • If there is a suspicion of prescription forgery for a controlled substance, what is the next step?
  • Who holds the primary responsibility for the monitoring component of internal controls?
  • What are the three main responsibilities of hospitals under EMTALA when a patient arrives at the emergency department?
  • What is the first step in developing an annual compliance audit?
  • What should your first course of action be if a provider and secretary are found violating privacy regulations?
  • True or False: Randomness in sampling is crucial for representativeness.
  • Which characteristic is most important for a Compliance Professional in a newly acquired hospital?
  • Which area is NOT commonly associated with healthcare fraud according to CMS?
  • For what purpose should an investigation and necessary disciplinary action be taken if a limited data set is released?
  • Which of the following is one objective of a baseline audit?
  • What is the aim of the Physicians at a Teaching Hospital (PATH) review?
  • What are the three primary components of security according to the CIA triad?
  • What significant reforms did the Balance Budget Act of 1997 introduce concerning Medicare and Medicaid?
  • Which of the following is a benefit of having a compliance program?
  • What does the acronym OIG stand for in the context of healthcare compliance?
  • Which of the following is included as a Covered Entity?
  • What is the purpose of Project Bad Bundle?
  • Which statement is false regarding the financial error rate in a Claim Review under a CIA?
  • Your organization recently completed a contemporaneous audit of laboratory billing practices and found that copays have been written off. What should be your next step?
  • Which law exempts self-insured health plans from state laws governing health insurance?
  • When developing a compliance work plan, what does prioritizing physician contract management indicate?
  • Paying a hospital monthly rent significantly below fair market value would be a violation of which regulation?
  • Conducting what type of sample would indicate potential issues within a compliance framework?
  • After identifying non-systemic billing errors, what should be done next?
  • What does the investigation final report in documentation include?
  • To effectively manage compliance, what should the Compliance Officer ensure is in place?
  • Which of the following is noted for involving some of the largest breaches reported to HHS?
  • What is an example of a contingency planning safeguard?
  • What is the consequence of violating HIPAA regulations?
  • Under which circumstance can coinsurance and deductibles be waived?
  • What are primary safety concerns in the medical setting?
  • RAT-STATS is best described as:
  • As a new Compliance Officer, what should you do if the Code of Conduct is full of legal jargon?
  • Which agency has enforcement authority for HIPAA privacy regulations?
  • What is the main difference between HIPAA Privacy and Security?
  • What is NOT a feature of CMS programs?
  • A written education plan for compliance should include which of the following?
  • Why would an organization want to listen to employees regarding compliance?
  • What do the Federal Sentencing Guidelines (FSG) emphasize for corporations?
  • What does the acronym CIA stand for in a compliance context?
  • Regarding Compliance Program effectiveness, which statement is NOT true?
  • According to HIPAA, a healthcare provider or its business associate may disclose PHI when authorized to do so, but only to the extent necessary. This is known as:
  • How should an organization view expenses related to the compliance program?
  • What is the maximum amount an employer can charge for personal protective equipment (PPE)?
  • Which of the following is considered an Anti-Kickback Statute violation?
  • Before conducting a safety audit in an emergency department, what is the first item needed?
  • What is one drawback of an internal reporting system?
  • Which of the following is a focus of the Federal Sentencing Commission's 2004 changes?
  • What can restitution to an identifiable victim include?
  • What does Title I of the Genetic Information Non-discrimination Act (GINA) prevent?
  • Part B of Medicare primarily covers which type of services?
  • Which of the following documents outlines the corrective action plan?
  • What significant event does February 27, 1997, represent in the context of healthcare compliance?
  • True or False: CIA agreements can protect an organization from all forms of liability.
  • What is described as a multi-step process in progressive discipline?
  • What is the focus of GINA?
  • How often should compliance testing be performed?
  • What is a common consequence of non-compliance in healthcare organizations?
  • In the compliance framework, how should compliance professionals approach risk communication?
  • Which of the following best describes engineering controls in safety management?
  • What recent addition to compliance programs does the updated DOJ ECCP emphasize regarding new technologies?
  • What type of audit helps outline current operational standards in an internal assessment?
  • What is the first step a Compliance Officer should take when developing goals for a review?
  • In the context of healthcare compliance, what is the impact of proving intent under the Anti-Kickback Statute?
  • When is a breach assumed to be reportable?
  • Which part of HITECH is dedicated to funding grants and loans?
  • What was established by the DRA of 2005?
  • Which of the following is NOT a category of privacy incident under HIPAA?
  • Which of the following is a key component of training requirements for compliance?
  • An individual's understanding of the compliance aspects of their job can BEST be enhanced by including compliance in:
  • Which item is NOT required in a bloodborne pathogen training program?
  • When determining the amount of a civil money penalty for HIPAA violations, which factor is NOT considered?
  • When can you use or disclose PHI?
  • What does the acronym C.I.A. stand for in the context of HIPAA?
  • When should a breach be considered discovered?
  • According to OIG's Self Disclosure Protocol (SDP), which of the following must be submitted?
  • According to the Federal Sentencing Guidelines, which factor could increase an organization's punishment?
  • Which organization establishes written policies for Medicaid payment to prevent fraud, waste, and abuse?
  • Why are regular compliance training sessions important?
  • What does the oversight function of the Board of Directors entail?
  • Who is considered an immediate family member under the Stark Law?
  • In the context of a compliance program assessment, what key factor should be reviewed related to the prevention of fraud, waste, and abuse?
  • What identification is essential for employees in a compliance program?
  • What type of communication is NOT considered PHI?
  • What action warrants a civil penalty of $50,000 under HIPAA if not corrected within 30 days?
  • In what order should the sample sizes of different audit types be ranked from least to most?
  • What is necessary for a successful reporting method in compliance?
  • A record retention policy must be based on which of the following?
  • Under FERA, what may happen if overpayments are not returned in time?
  • A violation of PHI is considered a breach when:
  • Which approach emphasizes support and correction for non-compliant behavior in enforcement?
  • If a hospital's discovery sample reveals a financial error rate above 5%, what does the OIG require?
  • If a co-worker leaves a PC logged into the confidential system, what is the best action?
  • In HIPAA, which subpart deals with Security?
  • Which of the following accurately defines Medicare/Medicaid fraud?
  • What type of training sessions should a compliance professional conduct?
  • Which of the following is NOT one of the five most important federal fraud and abuse laws?
  • Which of the following are included as key performance indicators in compliance regulation and risk assessment?
  • Which of these is NOT considered a common trigger for a compliance audit?
  • What does a compliance program primarily aim to enforce within an organization?
  • Which of the following describes a requirement for conducting a statistical sample in compliance reviews?
  • HHS is primarily responsible for which aspect of public welfare?
  • What does OSHA stand for in the context of healthcare compliance?
  • What is the consequence for violating EMTALA regarding patient treatment in an emergency?
  • What does a directive internal control aim to do?
  • How are microfilm medical records typically destroyed?
  • In healthcare compliance, what does 'T' in TPO stand for?
  • What is a direct result of a Stark violation?
  • Qui tam actions allow an individual to bring forward a claim to whom?
  • What is the compliance professional's best action when confirming that PHI was posted on social media?
  • What is the least important qualification for a Compliance Officer in your organization?
  • What is the primary purpose of attorney-client privilege?
  • What is a common reason cited for the failure to implement compliance programs in healthcare?
  • What is one method used to monitor compliance?
  • What is defined as an emergency medical condition according to EMTALA?
  • Which regulation aims to enhance safety protocols in compliance programs?
  • Under what circumstances can a covered entity disclose PHI without authorization?
  • What is the primary function of a company's Code of Conduct?
  • What does HIPAA require for disclosures of protected health information for treatment?
  • In order to determine the required sample size for a statistical review, what factor must be considered?
  • What are the two instances in which PHI does not require authorization?
  • How can a Compliance Officer achieve higher levels of compliance engagement?
  • What is primarily assessed during the evaluation of compliance program effectiveness?
  • What is the primary role of the US Sentencing Commission?
  • In the context of healthcare compliance, what plays a critical role in monitoring Medicare fraud?
  • What is the process of identifying potential security risks and determining the probability and magnitude of risks called?
  • What cycle is part of continuous improvement as per compliance practices?
  • Which is not one of the seven fundamental elements of an effective compliance program?
  • What key principle must be included in a non-retaliation policy for reporting compliance issues?
  • If a whistleblower identifies fraudulent claims, what could be a true statement regarding potential rewards?
  • What type of safeguard is NOT included in the HIPAA Security Rule?
  • Which of the following actions could lead to termination as a consequence of non-compliance?
  • Before developing a Compliance Program, what should be conducted first?
  • Which scenario violates the Stark Law?
  • What outcome does the OIG expect from documented findings in compliance activities?
  • What is the ongoing process called that management performs to ensure processes are effective?
  • Which third-party plays a critical role in accurate billing and reimbursement?
  • Which statement is TRUE regarding compliance programs?
  • What is the primary function of HIPAA?
  • What is the aim of the Physician Payment Sunshine Act in relation to public transparency?
  • True or False: The STARK law prohibits Medicare payments for designated healthcare services referred by a physician with a financial relationship with the entity.
  • According to the Yates Memo, who may be held liable for corporate misconduct?
  • Protected health information (PHI) is considered de-identified by HIPAA Privacy Rule standards by:
  • What is a vital part of fostering compliance culture in healthcare organizations?
  • Which of the following actions is critical when conducting a claim review under a CIA?
  • On what basis should the compliance committee typically develop objectives and goals?
  • Which entity cannot bill for medically unnecessary services?
  • When a provider accidentally shares attorney-client privileged information with a third party, what is this considered?
  • When is it necessary to hire an outside consultant or legal counsel?
  • What does the Physician Payment Sunshine Act require manufacturers to disclose?
  • Is it permissible to send X-rays to a specialist without encryption?
  • How long does the Privacy Rule state that a practice or covered entity needs to retain medical records?
  • What should a compliance professional do to prevent a billing error from recurring after it has been identified?
  • Who must comply with the HIPAA Privacy Rule?
  • What should compliance professionals do in response to discovering a systemic billing error?
  • Why is it advantageous for healthcare organizations to voluntarily implement compliance programs?
  • What types of records are excluded from the Designated Record Set (DRS) under HIPAA?
  • What are the two types of OIG exclusions?
  • What main purpose does a subpoena serve in a compliance investigation?
  • What is a critical first step in the compliance auditing process?
  • The DOJ's ECCP is part of which broader initiative?
  • What legal obligation does the receiving CE have when a misdirected fax is sent?
  • What should be readily accessible to all coding staff?
  • True or False: The Anti-Kickback Statute applies to referrals from patients.
  • When a provider receives a PHI request from Social Security Administration, what is the appropriate action?
  • What is one way to prevent duplication of auditing efforts in an organization?
  • How should education for minor infractions be approached?
  • Are physicians allowed to offer cash discounts?
  • Which area of concern primarily deals with billing processes in healthcare compliance?
  • Which of the following is NOT a typical consideration in compliance policy reviews?
  • What is the purpose of having billing policies in an organization?
  • In which scenario can a probe sample be used?
  • When handling a data breach, which law requires notification regarding the breach?
  • Why should a supervisor explain the Code of Conduct to employees?
  • The FSG - Culpability Score is used to determine what?
  • Does the HIPAA Privacy Rule cover all forms of protected health information including electronic, written, or oral?
  • In which scenario should a compliance professional establish attorney-client privilege?
  • What is the maximum time allowed for reporting breaches affecting less than 500 individuals?
  • What is the primary focus of the general compliance training session?
  • What is the aim of conducting audits in healthcare organizations?
  • What serves as an effective support system for the desired organizational culture?
  • What should a research compliance professional instruct a study coordinator regarding payment for recruitment in a clinical trial?
  • What step should be taken when considering self-disclosure of a potential fraud issue?
  • What should be included in a comprehensive compliance program?
  • In an audit of billing practices, which statement about sampling is INCORRECT?
  • What is one of the main benefits of an effective compliance program?
  • The ACA requires that all providers adopt a compliance plan as a condition of enrollment with Medicare, Medicaid, and CHIP. Is this statement true or false?
  • According to the OIG, what is equally important to the successful implementation of a compliance program?
  • What are Limited Data Sets used for within HIPAA guidelines?
  • What requires necessary policy measures to prevent avoidable recurrence?
  • What should a department manager complete to ensure compliance with a new medical records policy?
  • One benefit of having an effective compliance program is to help create which of the following?
  • Which aspect is NOT part of the employee's responsibilities regarding the Code of Conduct?
  • Which statement regarding signed authorizations for release of information is correct?
  • What can be a potential penalty under the False Claims Act?
  • According to the OIG Compliance Program Guidance, how should patient care be seen in relation to compliance programs?
  • Which action is essential once compliance violations are identified?
  • When should the Code of Conduct be distributed to new employees?
  • What is the "Caremark Duty" related to?
  • Under what circumstances can PHI be disclosed without patient authorization?
  • What does a contemporaneous review involve in compliance auditing?
  • Which element is crucial for the effectiveness of compliance audits?
  • What must a provider do under Section 6402 of the ACA upon identifying an overpayment?
  • Which of the following is NOT a step in the audit process?
  • What does the OIG suggest should be included in a compliance program regarding discipline?
  • The Health ____ _______ Administration encouraged the use of statistical sampling in Medicare claims. Fill in the blanks.
  • What are the three types of internal controls?
  • Under which condition can PHI be disclosed for research purposes?
  • If serious wrongdoing is suspected, what is the FIRST step to take?
  • What is a potential requirement that the court may impose if future harm can be estimated?
  • What role does the Chief Compliance Officer play in an organization?
  • In a research study involving adolescents, what document must an adolescent subject sign?
  • Which document should serve as a reference for information about personnel policies and procedures?
  • False Claims Act violations can result from which other types of violations?
  • Under HIPAA, who has the authority to define the roles of privacy and security officials?
  • True or False: A vendor that stores encrypted copies of files from a covered entity is not a Business Associate because the ePHI is unreadable.
  • What principle states the obligation of compliance professionals to serve their organization with integrity?
  • How are computerized data medical records destroyed?
  • Before recommending disciplinary action for a nurse whose photo was posted online, what should the privacy professional determine?
  • Which of the following does NOT require authorization for the disclosure of PHI?
  • Code of conduct supersedes which of the following?
  • Which of the following statements are true regarding the Statute of Limitations under the False Claims Act?
  • Which aspect of compliance is essential for minimizing fraud risk?
  • What element should a privacy professional consider first when presenting to the board about a privacy program?
  • In an informed consent, which statement is appropriate when a Pet scan is deemed non-billable?
  • What is the first priority of the Justice Department according to its stated priorities?
  • What role does in-house legal counsel play in healthcare compliance reviews?
  • If you become aware of a bribing situation, what is the proper course of action?
  • Which of the following is NOT a risk management process?
  • Under Stark Law, what does "stand in the shoes" refer to?
  • What type of training should a compliance professional provide to meet learning styles of doctors and nurse practitioners?
  • What does Section 6401 of the Affordable Care Act specify about compliance programs?
  • What is another name commonly used for the Stark Law?
  • When under an imposed-CIA, which statement about Independent Review Organizations (IROs) is not true?
  • Who is primarily responsible for reviewing policies and procedures related to compliance in an organization?
  • Which type of audit takes place in real-time?
  • What is Part D of Medicare mainly focused on?
  • What is a Corporate Integrity Agreement (CIA)?
  • Which definition correctly describes Medicare/Medicaid abuse?
  • HITECH is an integral part of which legislative act aimed at economic recovery?
  • What is a Health Care Clearinghouse?
  • According to the Balance Budget Act of 1997, what is the "three strikes" rule associated with?
  • Which of the following is NOT a characteristic of a Corporate Integrity Agreement (CIA)?
  • In relation to compliance, what is a critical function of leadership within an organization?
  • The most important lines of defense for a compliance program is?
  • What is one key benefit of a well-implemented compliance program?
  • Which of these is NOT one of the six phases of a Corrective Action Plan (CAP)?
  • Which of the following is NOT considered part of the three C's of communication?
  • What is a Business Associate (BA) in healthcare?
  • What is the recommended minimum annual training duration suggested by OIG for compliance?
  • What does PHI stand for?
  • How often should providers check if employees are on the OIG List of Excluded Individuals after hiring?
  • Which of the following situations requires authorization for PHI disclosure?
  • Which act imposes penalties for knowingly submitting false claims to Medicare?
  • What is the best first step for a compliance professional when an employee reports unequal disciplinary action?
  • What should be done with a "required" implementation specification under HIPAA?
  • What can help establish a positive compliance atmosphere within an organization?
  • What is a primary benefit of implementing a compliance program in healthcare organizations?
  • How often are workforce retraining sessions mandated by the HIPAA Privacy Rule?
  • What is a critical element of a compliance professional's role when addressing a complaint's facts?
  • What does the term "condoned" refer to in a compliance context?
  • Which type of internal control is intended to signal the presence of a problem?
  • In CMS identified areas of high-risk fraud, which combination does NOT apply?
  • Which procedure must be included in a policy for statistically valid sampling if the financial error rate exceeds 5%?
  • What is the significance of implementing the False Claims Act during the Civil War?
  • What is a core role of the Chief of Compliance in a healthcare organization?
  • Which of the following best describes the intent of a risk management strategy?
  • How often are CIAs required to undergo regular monitoring?
  • What should the approach to penalties be based on?
  • Who should primarily participate in the development of goals and objectives for the compliance program?
  • What might documentation in a criminal or civil trial include?
  • Boards have vital roles in Compliance; which aspect is NOT among their responsibilities?
  • How long can a corporate integrity agreement last at maximum?
  • What can be a potential consequence of intentional or reckless non-compliance?
  • If the DOJ declines to take on a qui tam case, what percentage can a whistleblower expect to receive from the total award?
  • In the context of healthcare compliance, what does the term "fraud" refer to?
  • What role does a compliance officer typically fulfill in a healthcare organization?
  • What should a compliance professional do first upon receiving a complaint about unfair discipline?
  • How should a compliance professional assess the effectiveness of a training program?
  • What is a significant fear that can hinder an effective compliance program?
  • Which act requires providers to be permanently excluded from federal health care programs after being found guilty of fraud three times?
  • A covered entity may disclose protected health information (PHI) without a patient's written permission for:
  • Under the Anti-Kickback Statute, what term refers to regulatory exceptions for specific joint ventures?
  • When should the compliance plan be reviewed?
  • Which organization has had the authority to levy administrative penalties for filing false claims since 1981?
  • What is the purpose of a hotline or helpline in compliance monitoring?
  • What destruction method is used for magnetic tape medical records?
  • What is one of the purposes of ongoing monitoring in a compliance program?
  • What does the “Upjohn warning” procedure entail?
  • What encompasses demographic information collected from an individual in healthcare?
  • Which of the following can result in automatic disqualification of a relator from filing a qui tam action?
  • When a hotline caller reports coding discrepancies, what should the compliance professional do first?
  • What does the Quality Management Technique P-D-C-A stand for?
  • What is an essential component in establishing a culture of compliance within an organization?
  • Which of the following is NOT a governmental investigative tool?
  • What is the focus of a risk assessment in compliance?
  • Which option is a federal oversight related to Medicaid?
  • What does the Defense Industry Initiative aim to improve?
  • What is a primary characteristic of monitoring in an organization?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy