Browse all practice questions for the HCCA Certified in Healthcare Compliance (CHC) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

HCCA CHC Practice Exam 2026 – Complete Exam Prep course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which category of privacy is primarily concerned with health records under HIPAA?
  • Is encryption required under HIPAA?
  • What was the primary purpose of the Sarbanes-Oxley Act of 2002?
  • The purpose of EMTALA primarily aims to prevent what action by hospitals?
  • What type of analysis evaluates the effectiveness of compliance efforts over time?
  • Compliance audits typically relate to which of the following functions?
  • Training requirements for compliance should include which essential component?
  • In research compliance, what is a primary goal of an IRB?
  • True or False: Root cause analysis is a proactive activity performed after an incident has occurred.
  • The HIPAA Security Rule requires a covered entity to implement policies and procedures for authorizing access to e-PHI only when such access is appropriate based on the user or recipient's role. True or False?
  • Conducting what type of sample would indicate potential issues within a compliance framework?
  • Which element is crucial for the effectiveness of compliance audits?
  • True or False: CIA agreements can protect an organization from all forms of liability.
  • What key element must compliance programs include according to US Sentencing Guidelines?
  • Is it permissible to send X-rays to a specialist without encryption?
  • Why is the Caremark International Derivative Litigation significant?
  • What serves as an effective support system for the desired organizational culture?
  • Which document outlines high expectations for organizational compliance programs as per the latest DOJ guidance?
  • What is the maximum amount an employer can charge for personal protective equipment (PPE)?
  • What does the Quality Management Technique P-D-C-A stand for?
  • When conducting disciplinary actions related to privacy violations, what is crucial for consistency?
  • HITECH is an integral part of which legislative act aimed at economic recovery?
  • What is essential for compliance reporting regarding complaints?
  • How often should compliance testing be performed?
  • What does the Breach Notification under ARRA require covered entities to do?
  • Which aspect of compliance is essential for minimizing fraud risk?
  • Which organization develops and administers standards relating to the well-being of workers at job sites?
  • What does the acronym CIA stand for in healthcare compliance?
  • Which of the following could be a legal implication for an organization due to conflicts of interest identified through the Open Payments database?
  • What does a compliance program fundamentally involve?
  • What document must be provided to patients that outlines their rights regarding PHI?
  • In the context of healthcare compliance, the concept of 'Operations' primarily includes which of the following?
  • Which act emphasizes the use of technology in health information?
  • Which statement accurately describes fraudulent billing?
  • What type of services does Stark Law apply to?
  • What does the PhRMA Code prohibit?
  • In the context of healthcare compliance, what does the term "fraud" refer to?
  • What is the first step a Compliance Officer should take when developing goals for a review?
  • What percentage of the government's total award can a relator receive if the DOJ intervenes in a qui tam action?
  • What does the acronym SURS stand for?
  • In providing appointment reminders to patients, what should an organization address in their notice of privacy practices (NPP)?
  • What is the compliance professional's best action when confirming that PHI was posted on social media?
  • What is a key feature of an effective compliance program?
  • What is one role of the Compliance Committee according to regulatory guidelines?
  • What safeguards are included in the HIPAA Security Rule?
  • What is the FIRST action an employee should take when an investigator presents a search warrant?
  • What is indicated by cooperation with government investigators in compliance matters?
  • What is the general principle behind the HIPAA Privacy Rule?
  • What is the purpose of the Notice of Privacy Practices (NPP)?
  • What is a vital part of fostering compliance culture in healthcare organizations?
  • The compliance program should address plans to verify adherence to applicable laws through what methods?
  • Which process focuses on identifying and addressing problems as they occur?
  • What key principle must be included in a non-retaliation policy for reporting compliance issues?
  • What main purpose does a subpoena serve in a compliance investigation?
  • What is De-identified PHI?
  • True or False: If a serious allegation is sensitive in nature, legal counsel should be contacted to determine if Attorney Client Privilege (ACP) needs to be attached.
  • What action warrants a civil penalty of $50,000 under HIPAA if not corrected within 30 days?
  • What approach is NOT one of the primary methods for Controlled Self-Assessment?
  • What should a research compliance professional do when an employee refuses a Hep B vaccination?
  • What is the definition of "Deposition" in medico-legal terms?
  • If a referred patient has a hearing deficit, what should your practice do when scheduling an appointment?
  • What is the first step one should take when establishing an effective compliance program?
  • When developing a privacy monitoring plan, where should the privacy professional initially focus?
  • Which of the following have been identified as high-risk areas by the OIG?
  • Which criminal offense is OIG required to exclude individuals from Federal health care programs for?
  • Part B of Medicare primarily covers which type of services?
  • Which option should be considered for disclosing a violation of federal fraud laws?
  • A health care provider needs permission to notify public health authorities of a reportable disease occurrence. Is this statement true or false?
  • Which of the following is NOT a step in the audit process?
  • What is the focus of GINA?
  • An employee was terminated for accessing sensitive information. What is the privacy official's responsibility regarding disciplinary actions?
  • Which statement correctly reflects the Stark Law's requirement for referrals?
  • What is the recommended frequency for exclusion verifications according to compliance standards?
  • Which type of information is specifically associated with the payment for healthcare services?
  • When developing a compliance work plan, what does prioritizing physician contract management indicate?
  • Which entities are covered under the Physician Payment Sunshine Act?
  • What is the purpose of the work product doctrine?
  • Which elements are effective for monitoring and auditing?
  • What must a provider do under Section 6402 of the ACA upon identifying an overpayment?
  • When was the U.S. Federal Sentencing Commission organized, and when did it first publish its guidelines?
  • Who has the authority to bring civil action under the False Claims Act?
  • When is protected health information (PHI) considered compromised?
  • Is root cause analysis a high priority among federal law enforcement and regulatory agencies during investigations?
  • What is the primary function of a company's Code of Conduct?
  • If there's an employment issue that requires compliance intervention, what is the next step?
  • Which of the following actions reflects a breach of ethical standards in research?
  • What type of audit is typically performed after transactions have been completed?
  • Which of the following is NOT considered part of the three C's of communication?
  • What significant event does February 27, 1997, represent in the context of healthcare compliance?
  • What are the three types of internal controls?
  • What is the first step when potential issues are identified within an organization?
  • True or False: The OIG requests that organizations disclose their adherence to the PHRMA CODE on their website.
  • What is defined as electronically transmitted or maintained individually identifiable health information?
  • What must be established by entities receiving more than $5 million in annual Medicaid payments?
  • What legal consequence can occur if Medicare overpayments are not refunded?
  • Which of the following documents outlines the corrective action plan?
  • The compliance professional’s role in risk management includes which of the following?
  • What type of guidelines does the OIG describe its compliance program guidance as?
  • What does the acronym CPG stand for in the context of healthcare compliance?
  • During an investigation, why is it important to keep identities discreet?
  • Who has the authority to impose a Corporate Integrity Agreement (CIA)?
  • What workforce size typically qualifies as a large organization under FSG?
  • What type of training should a compliance professional provide to meet learning styles of doctors and nurse practitioners?
  • What is a key item that can protect a medical practice from harassment liability?
  • What does the acronym LEIE refer to?
  • Is it true that Risk Management aligns with Quality Management in determining measures for risk avoidance and prevention?
  • Which of the following statements about de-identified health information is true?
  • What is a primary characteristic of monitoring in an organization?
  • Which certificate allows a laboratory to conduct moderate- to high-complexity testing until compliance is determined?
  • What is a significant fear that can hinder an effective compliance program?
  • Which legislation mandates compliance programs for Medicare, Medicaid, and CHIP providers?
  • What does the acronym OIG stand for in the context of healthcare compliance?
  • Is a Security Risk Analysis required annually for a Covered Entity to comply with HIPAA?
  • What does HITECH Subtitle A focus on?
  • Under what condition can a relator not pursue a qui tam action?
  • Which right is NOT included in the individual rights under the NPP?
  • Which act established the Health Care Fraud and Abuse Control Program?
  • Which of these is NOT one of the six phases of a Corrective Action Plan (CAP)?
  • Which method is NOT used to destroy paper medical records?
  • What is the primary contribution of auditing and monitoring to a compliance program?
  • What is the primary purpose of the Health Care Compliance Association (HCCA)?
  • What is the primary purpose of conducting a contemporaneous review in healthcare compliance?
  • What is the MOST important training topic for investigators in a research compliance educational session?
  • True or False: Employees may be required to give up their personal sense of right and wrong to function in the company.
  • Which of the following describes a requirement for conducting a statistical sample in compliance reviews?
  • Who does the OIG urge to assist in the implementation of the compliance program?
  • What is the contact number for the OIG's Fraud and Abuse hotline?
  • Is a Business Associate required to have a contract with a Covered Entity to comply with HIPAA?
  • Health information that cannot identify an individual is termed as?
  • What is the look back period for Medicare overpayment claims?
  • What crucial element is first called for in OIG guidance for compliance programs?
  • What is NOT included in technical safeguards?
  • Which of the following is NOT included in the five important federal fraud and abuse laws?
  • Which of the following is a key component of training requirements for compliance?
  • What is the primary function of the CMS (Centers for Medicare and Medicaid Services)?
  • What is the purpose of a hotline or helpline in compliance monitoring?
  • In the case of a 5-year CIA, which of the following statements is TRUE?
  • When can a patient instruct their provider not to share treatment information with their health plan?
  • True or False: The OIG advises the public on the governance of the PHRMA CODE.
  • Why is it important to have a written set of safety standards before an audit?
  • How are microfilm medical records typically destroyed?
  • Which of the following actions is considered equally serious in terms of noncompliance?
  • What is the best first step for a compliance professional when an employee reports unequal disciplinary action?
  • What are the three primary components of security according to the CIA triad?
  • According to HHS-OIG, what is one important reason for proper documentation in compliance?
  • If Leaf Hospital conducts a contemporaneous review, what might they uncover that warrants further action?
  • HHS is primarily responsible for which aspect of public welfare?
  • Which of the following can result in automatic disqualification of a relator from filing a qui tam action?
  • What is a sign of failed efforts to use statistical analysis in sampling?
  • Which of the following statements best defines Reasonable Diligence in compliance?
  • What is the classification of upcoding services to receive higher reimbursement from Medicare/Medicaid?
  • What is a key difference between consent and authorization under HIPAA?
  • What legal obligation does the receiving CE have when a misdirected fax is sent?
  • What should the Chief Compliance Officer do first when faced with increased correspondence challenging medical necessity?
  • What is one responsibility that should NOT be handled by a compliance officer?
  • Are Business Associates required to comply with all Privacy Rules under HIPAA?
  • Which area should targeted compliance training specifically address?
  • What is one of the main reasons cited for reinforcing employee’s innate sense of right and wrong through compliance programs?
  • What is Part D of Medicare mainly focused on?
  • What is an essential component of PHI management in healthcare?
  • What is defined as an emergency medical condition according to EMTALA?
  • Who is eligible to bring a suit under the False Claims Act?
  • According to the OIG Compliance Program Guidance, how should patient care be seen in relation to compliance programs?
  • The HIPAA Privacy Rule covers which of the following?
  • How does EMTALA strengthen patient rights in emergency situations?
  • What is one potential incentive for self-disclosing misconduct to the OIG?
  • According to the Yates Memo, who may be held liable for corporate misconduct?
  • Which statement best describes the concept of "integrity" as it relates to compliance programs?
  • What type of act is the False Claims Act, which offers incentives for whistleblowing?
  • What is the second step for a compliance professional upon detecting wrongdoing?
  • Why would an organization want to listen to employees regarding compliance?
  • Are providers liable for fraud committed by their billing services without their knowledge?
  • What is the most effective delivery method for compliance content as recommended?
  • What is the Stark Period of Disallowance?
  • How long can a corporate integrity agreement last at maximum?
  • What does a compliance program primarily aim to enforce within an organization?
  • What governs the HIPAA Security Rule?
  • Is there currently legislation specifically regulating artificial intelligence systems?
  • What does OSHA stand for in the context of healthcare compliance?
  • Which statement is true about patient rights under HIPAA?
  • A billing manager notices a 50% increase in Federal health care program payments. What should be the NEXT step?
  • Who is allowed to file a complaint under the False Claims Act?
  • What should be included in a comprehensive compliance program?
  • What key aspect should be included in disciplinary action policies?
  • Which governmental body has the enforcement authority for HIPAA privacy?
  • What is the first action a compliance professional should take upon detecting wrongdoing?
  • How is the sample size related to probe audits?
  • True or False: In the case of serious sensitive allegations, you should contact legal counsel to determine attorney-client privilege needs.
  • Which aspect of HIPAA aims to maintain the integrity of personal health information?
  • When creating and implementing a compliance plan, what is required of the compliance officer?
  • What is a requirement for auditors in the context of compliance?
  • Which of the following describes the life cycle of records management?
  • Which of the following best describes an inadvertent violation of privacy?
  • What three checks does the OIG recommend for new employee policies?
  • What should a privacy professional do first if an employee reports potential illegal activity involving misuse of identifiable information?
  • What is one characteristic of the "safe harbors" established by the OIG in the AKS?
  • What can be a potential consequence of intentional or reckless non-compliance?
  • Are incidental disclosures allowed under the HIPAA Privacy Rule?
  • Which of the following is included in the elements of a compliance program?
  • What is a consequence of transferring a patient under EMTALA without appropriate medical records?
  • What does the OIG suggest should be included in a compliance program regarding discipline?
  • Which contractors are responsible for reviewing and paying claims for Medicare?
  • Boards have vital roles in Compliance; which aspect is NOT among their responsibilities?
  • What are the suggested development guidelines for compliance programs issued by the OIG called?
  • Which principle is essential for handling PHI?
  • What does the "reverse false claims" provision under FERA require from healthcare providers?
  • Which entity is allowed to utilize a single notice of privacy practices?
  • False Claims Act violations can result from which other types of violations?
  • Under Stark Law, what does "stand in the shoes" refer to?
  • A privacy official should inform a clinic that it can provide PHI to a researcher if the researcher:
  • What is an effective strategy to demonstrate compliance with personnel policies?
  • What does HITECH stand for?
  • In the compliance framework, how should compliance professionals approach risk communication?
  • In a healthcare compliance setting, what is an example of behavior that could be considered reckless non-compliance?
  • What is a potential result of a willful violation of HIPAA?
  • Which of the following is considered a strict liability statute?
  • Where does the compliance professional typically find guidelines for developing compliance programs?
  • What is the role of the Compliance Officer regarding department policies?
  • When should the Code of Conduct be distributed to new employees?
  • What is considered a violation when billing for items or services?
  • Which procedure must be included in a policy for statistically valid sampling if the financial error rate exceeds 5%?
  • What term is used for Federal regulations that specify certain joint ventures concerning hospitals and/or physicians that are compliant with Medicare laws?
  • How often are workforce retraining sessions mandated by the HIPAA Privacy Rule?
  • What does the HIPAA rule indicate about permissions versus requirements?
  • What should be readily accessible to all coding staff?
  • Which agency is referred to by the acronym OCR?
  • What historical context is associated with Lincoln's Law?
  • When should a breach be considered discovered?
  • What action should organizations take if they discover a compliance violation?
  • What is a Corporate Integrity Agreement (CIA)?
  • When implementing a compliance plan, what is required for approval?
  • Which definition correctly describes Medicare/Medicaid abuse?
  • What does a directive internal control aim to do?
  • What is a primary focus of concurrent audits?
  • What type of audit helps outline current operational standards in an internal assessment?
  • What are two of the mitigating factors according to the Federal Sentencing Guidelines?
  • Who is primarily responsible for auditing and monitoring compliance risks?
  • What is a significant outcome of performing a thorough risk assessment?
  • What does the Sunshine Act mandate regarding pharmaceutical and medical device manufacturers?
  • How should a compliance professional assess the effectiveness of a training program?
  • Which of the following is a key responsibility of a privacy professional?
  • Who can request an OIG Advisory Opinion?
  • Which of the following is the first step to take upon discovering a violation of federal fraud and abuse laws?
  • Which organization establishes written policies for Medicaid payment to prevent fraud, waste, and abuse?
  • Which of the following is NOT a regulatory agency that identifies compliance risks?
  • What is the primary focus of the Office of Inspector General (OIG) in healthcare compliance?
  • What type of information encompasses health information related to the health condition of an individual?
  • What is one consequence for providers who fully cooperate during an OIG self-disclosure?
  • Which action demonstrates a commitment to compliance in a healthcare setting?
  • What is indicated by the acronym POA?
  • Which entity administers the Medicare and Medicaid laws outlined in the Social Security Act?
  • Under which condition can PHI be disclosed for research purposes?
  • What is an Independent Review Organization (IRO) responsible for in Corporate Integrity Agreements?
  • What documentation is NOT critical for a Compliance Officer's review when opening files?
  • Who is considered an immediate family member under the Stark Law?
  • Which of the following is NOT a criterion for home health coverage?
  • Paying a hospital monthly rent significantly below fair market value would be a violation of which regulation?
  • Which of the following are included as key performance indicators in compliance regulation and risk assessment?
  • What is the recommended frequency for general compliance training for employees, physicians, and volunteers?
  • What critical information must be included when notifying individuals of a breach?
  • Which of the following is a primary responsibility of a compliance officer according to the OIG?
  • Which of the following does NOT fall under Attorney-Client Privilege?
  • What document does the OIG develop if a provider does not have a corporate integrity agreement in place?
  • Which of the following is NOT a risk management process?
  • What is the focus of the 2022 Monaco Memo regarding corporate governance?
  • In what order should the sample sizes of different audit types be ranked from least to most?
  • When asked to approve a transfer form containing a patient's SS#, what should the privacy officer do first?
  • What does the acronym SDN represent in healthcare compliance?
  • What is one of the first actionable items after establishing a compliance program?
  • Which of the following is a common type of evidence collected for compliance violations?
  • What measure is most important for prevention in a compliance program?
  • What is the first priority of the Justice Department according to its stated priorities?
  • What types of records are excluded from the Designated Record Set (DRS) under HIPAA?
  • To assess the seriousness of a high error rate in claims, which type of sample should be pulled?
  • How long does the Privacy Rule state that a practice or covered entity needs to retain medical records?
  • If you become aware of a bribing situation, what is the proper course of action?
  • Under what circumstances can a covered entity disclose PHI without authorization?
  • What are the primary focus areas of a Board of Directors (BOD) concerning compliance?
  • What is another term for a Probe Audit or Probe Sample?
  • What type of audit is most likely used to identify the amount of repayment to Medicare for specific claims?
  • Is it permissible for healthcare practices to remind patients of their appointments?
  • What does Willful Neglect refer to in compliance context?
  • What are the two instances in which PHI does not require authorization?
  • When a compliance officer finds an excluded provider has treated patients, what is the NEXT action they should take?
  • What is necessary for a successful reporting method in compliance?
  • What should a privacy officer do after identifying a deficiency in the Notice of Privacy Practices (NPP)?
  • What is a key goal of the Defense Industry Initiative?
  • You are the new compliance officer at an institution with an established compliance committee. Which committee member's background would be most valuable in audit activities?
  • What is the primary goal of a compliance program?
  • What is a key difference between enforcement and discipline in a compliance program?
  • What type of test would be practical for a physician practice to determine unpaid claims?
  • Which process aims to identify the effectiveness of internal controls in place?
  • In compliance training, what is the significance of providing a positive call for action?
  • The Health ____ _______ Administration encouraged the use of statistical sampling in Medicare claims. Fill in the blanks.
  • If the DOJ declines to take on a qui tam case, what percentage can a whistleblower expect to receive from the total award?
  • Who is responsible for investigating potential overpayments in a healthcare organization?
  • What should a compliance officer prioritize to enhance compliance in healthcare?
  • If several medical records are missing and physicians are taking original records home, what should the privacy professional do first?
  • What does attorney-client privilege protect in the context of healthcare compliance reviews?
  • Which act contains the whistleblower provision?
  • What do the Federal Sentencing Guidelines (FSG) emphasize for corporations?
  • A covered entity must designate a ___________________ who is responsible for developing and implementing its security policies and procedures.
  • What aspect of Medicare does Part A cover?
  • What does the Yates Memo emphasize regarding corporate misconduct?
  • When should counsel be involved during an internal investigation?
  • What impact does the Balance Budget Act of 1997 have on healthcare organizations with repeated fraud convictions?
  • Progressive discipline policies should be:
  • What is the primary goal of maintaining the integrity of medical records?
  • Why is it important to conduct a retrospective audit?
  • Which of the following options aligns with the foundation of an effective compliance program?
  • What is the purpose of the Health Care Fraud and Abuse Control Program?
  • What category of security standards includes delegation of security responsibilities and security training?
  • True or False: An email request from a client is sufficient authorization for secure communication.
  • If a co-worker leaves a PC logged into the confidential system, what is the best action?
  • What is the deadline for reporting breaches affecting 500 or more individuals?
  • What action should be taken if there’s a directive from an immediate supervisor that conflicts with compliance protocols?
  • What is one method used to monitor compliance?
  • What role does the Chief Compliance Officer play in an organization?
  • What is the primary purpose of preventive controls within an organization?
  • What is the difference between an addressable and a required implementation specification under HIPAA?
  • Which subpart in Part 164 of HIPAA deals specifically with Privacy?
  • Which of the following is a key aspect of compliance awareness among employees?
  • Which of the following is considered an Anti-Kickback Statute violation?
  • What agency developed the Federal Sentencing Guidelines (FSG)?
  • What type of arrangement might lead to OIG identifying an "outlier" for non-compliance?
  • What does the “Upjohn warning” procedure entail?
  • What does 'upcoding' refer to in medical billing?
  • True or False: OIG voluntary guidance is intended to enhance internal controls within organizations.
  • True or False: The OIG's Self-Disclosure Protocol can be utilized to disclose illegal arrangements related to the Anti-Kickback Statute (AKS) and Stark Law.
  • What should a research compliance professional instruct a study coordinator regarding payment for recruitment in a clinical trial?
  • In healthcare compliance, what does 'T' in TPO stand for?
  • What might documentation in a criminal or civil trial include?
  • Which three qualities should communication to staff about compliance matters possess?
  • What was a primary reason for the enactment of the Sarbanes-Oxley Act?
  • What type of actions can the Office of Inspector General initiate according to healthcare compliance regulations?
  • What should be included in a physician’s written policy regarding cash discounts?
  • What are the types of sampling size characterized in audits?
  • According to HIPAA, what method can be used to de-identify PHI?
  • Which of the following is considered a substantial risk for health care compliance?
  • Which characteristic is most important for a Compliance Professional in a newly acquired hospital?
  • Why is training and education critical in compliance programs?
  • What is a critical responsibility of compliance training and education?
  • True or False: The Public Health Service (PHS) defines a significant financial interest based on aggregated income exceeding $10,000 over a twelve-month period.
  • Why is it advantageous for healthcare organizations to voluntarily implement compliance programs?
  • What is the record retention period for HIPAA-related work products?
  • True or False: The 2023 OIG Compliance Program Guidance requires organizations to conduct periodic compliance risk assessments at least annually.
  • In what scenario can a covered entity disclose PHI for research without authorization?
  • What is primarily emphasized for effective oversight in compliance programs?
  • Why was the Bloodborne Pathogens Standard introduced by OSHA?
  • Which resource should clinical lab providers review to understand compliance requirements?
  • Which type of audit takes place in real-time?
  • Which of the following is NOT identified as a special area of OIG concern?
  • What is necessary for senior management to adopt an effective compliance program?
  • Your organization recently completed a contemporaneous audit of laboratory billing practices and found that copays have been written off. What should be your next step?
  • To effectively manage compliance, what should the Compliance Officer ensure is in place?
  • In compliance program education, what should be the focus of scenario-based training?
  • According to recent regulations, compliance programs must include written policies and what other core element?
  • Which factor is key in defining the scope of a monitoring plan?
  • When does the 60-day timeline for breach notifications initiate?
  • True or False: Randomness in sampling is crucial for representativeness.
  • What does the acronym C.I.A. stand for in the context of HIPAA?
  • What is the purpose of having billing policies in an organization?
  • Which type of security standards involve the automated processes to protect data, such as encryption?
  • What can be said about self-reporting as a mitigating factor?
  • Why should a supervisor explain the Code of Conduct to employees?
  • What is the primary purpose of progressive discipline according to OIG recommendations?
  • Which key performance indicator is NOT typically monitored in compliance programs?
  • Which privacy law pertains to the protection of financial information?
  • Which two main documents are essential for building a compliance program?
  • Which document should serve as a reference for information about personnel policies and procedures?
  • What action should be included in the education plan regarding content areas?
  • Which of the following is a responsibility under administrative safeguards?
  • If an employee violates the non-retaliation policy by spreading rumors, the compliance professional's first action should be?
  • Which third-party plays a critical role in accurate billing and reimbursement?
  • Which item is NOT required in a bloodborne pathogen training program?
  • What is a common consequence of non-compliance in healthcare organizations?
  • What is a common reason cited for the failure to implement compliance programs in healthcare?
  • Which of the following describes one of the roles of a board member?
  • Which of the following does NOT require authorization for the disclosure of PHI?
  • After implementing the non-retaliation policy, what should the compliance officer do next?
  • Which of the following is included as a Covered Entity?
  • Code of conduct supersedes which of the following?
  • What are the two types of OIG exclusions?
  • What is the consequence for organizations that fail to implement necessary compliance training?
  • Which of the following is NOT a category of privacy incident under HIPAA?
  • What is a mitigating factor to a culpability score?
  • Upon identifying a potential violation, what should be done first?
  • Which area is NOT subject to the 250-yard zone rule under the definition of "hospital campus"?
  • Which type of healthcare service management may include consultation between providers?
  • What is another name commonly used for the Stark Law?
  • What can restitution to an identifiable victim include?
  • Is it permissible for covered entities to use patient sign-in sheets as long as the disclosed information is limited?
  • Which regulation aims to enhance safety protocols in compliance programs?
  • What does RAT-STATS provide for auditors?
  • What does the Deficit Reduction Act (DRA) mandate regarding education on the False Claims Act (FCA)?
  • According to the Balance Budget Act of 1997, what is the "three strikes" rule associated with?
  • Which statement is TRUE regarding compliance programs?
  • What are primary safety concerns in the medical setting?
  • In analyzing a potential issue with provider services agreements and management contracts, what should the compliance professional consider?
  • What are the two agencies that the Healthcare Fraud and Abuse Control program requires to coordinate federal, state, and local healthcare law enforcement activities?
  • What aspect of compliance do Corporate Integrity Agreements primarily focus on?
  • The most important lines of defense for a compliance program is?
  • What is the scope of protection under GINA Title I related to?
  • Which professionals are classified as physicians under Stark Law?
  • What is the main focus of Title II of GINA?
  • Which of the following is a consequence of failing to comply with federal health care regulations?
  • The Office of Inspector General (OIG) is a division of which agency?
  • True or False: The Anti-Kickback Statute applies to referrals from patients.
  • Which regulation should be reviewed in preparing an education session about lost thumb drives containing PHI?
  • According to the content, which factor is essential for developing effective compliance programs?
  • What does the acronym ACE signify in healthcare compliance?
  • Which areas are common health care risk areas?
  • Which statement reflects the importance of compliance programs in healthcare?
  • If a provider is dissatisfied with an informal review by the state Medicaid Program, what action can they take?
  • Which part of the HIPAA rules applies to PHI in all formats?
  • Which elements should be included in policies regarding enforcement and disciplinary actions?
  • Which of the following is considered an incidental disclosure of PHI?
  • In the risk assessment process, which step involves assessing risk tolerance information and inherent risk?
  • Which of the following elements is considered absolutely essential for the success of a compliance program?
  • What is an example of a physical safeguard?
  • Which of the following statements is true about the regulation of conflicts of interest in healthcare?
  • What is the appropriate response to a spelling error in a patient's medical record?
  • How should an organization view expenses related to the compliance program?
  • What compelling reason supports the continuation of an auditing program?
  • What characteristic should disciplinary mechanisms possess to be effective?
  • What is the best course of action after receiving an OHRP letter regarding a specimen bank without IRB approval?
  • What cycle is part of continuous improvement as per compliance practices?
  • What key principle underlies the regulations enforced by the US Sentencing Commission?
  • Which element is essential within the compliance department to foster compliance culture?
  • What does HIPAA require for disclosures of protected health information for treatment?
  • Under the Anti-Kickback Statute, what term refers to regulatory exceptions for specific joint ventures?
  • What does the HITECH Act primarily promote?
  • Which agency indicates a self-evaluation after the discovery of potentially fraudulent acts?
  • What act requires annual adjustments of CMP fine amounts?
  • Which behavior is classified as unethical?
  • A covered entity may disclose protected health information (PHI) without a patient's written permission for:
  • When a medical record is inconsistent with the selected diagnosis code, who should the coder contact?
  • True or False: A compliance program that never identifies problems is considered to be effective.
  • What are the four areas PHI can be used or disclosed by?
  • Which of the following is true about the monetary settlement a relator can receive in qui tam actions?
  • In GINA Title II, what is illegal for employers to use for employment decisions?
  • What do Standards of Conduct written Policies and Procedures demonstrate?
  • What is an important first step in creating or improving a compliance team?
  • Which of the following is NOT a typical role of the Board of Directors in compliance?
  • True or False: The PHRMA CODE is a law that must be followed by organizations.
  • What is the primary function of an Inspector General (IG)?
  • What does the anti-kickback statute prohibit?
  • Which of the following describes an effective compliance program in terms of quality of care?
  • Qui tam actions allow an individual to bring forward a claim to whom?
  • What is the purpose of Project Bad Bundle?
  • Examples of proper disposal methods of protected health information (PHI) may include:
  • Which of the following elements is included in the Anti-Kickback Statute?
  • What is the time frame for protecting PHI after an individual’s death?
  • What is the primary focus of the general compliance training session?
  • True or False: Organizations are requested to indicate their adherence to the PHRMA CODE on their websites.
  • What does the FSG Culpability Score measure?
  • What is the maximum number of years a retrospective audit may need to cover due to the False Claims Act?
  • Which of the following best illustrates the importance of diverse educational materials?
  • When a hotline caller reports coding discrepancies, what should the compliance professional do first?
  • What does GINA Title I allow health insurers to request?
  • What must be documented when amending a medical record?
  • What type of actions may be subject to discipline according to compliance standards?
  • What type of feedback mechanism can reinforce positive behavior in compliance?
  • What type of control is exemplified by the requirement to purchase from approved suppliers?
  • Before developing a Compliance Program, what should be conducted first?
  • Which of the following is a primary goal of compliance programs in healthcare organizations?
  • What is a primary source of information for the team conducting an audit?
  • What must a compliance program have in addition to a plan?
  • What is the main purpose of the American Recovery and Reinvestment Act (ARRA)?
  • What kind of legislation is HIPAA considered?
  • Which component is key for preventing unethical behaviors in an organization?
  • The DOJ's ECCP is part of which broader initiative?
  • Which of the following accurately defines Medicare/Medicaid fraud?
  • When anticipating what the government will measure during a compliance program review, which of the following should you consider?
  • What term is associated with the 2022 Monaco Memo in relation to corporate accountability?
  • An effective auditing/monitoring plan must consider what factor?
  • What should be done to maintain the confidentiality of information during an investigation?
  • What can a compliance professional use to quickly evaluate if more extensive audits are needed?
  • Who is primarily responsible for reviewing policies and procedures related to compliance in an organization?
  • What should a department manager complete to ensure compliance with a new medical records policy?
  • What does the acronym CIA stand for in a compliance context?
  • What does RAT STATS refer to in the context of healthcare compliance?
  • What are Corporate Integrity Agreements negotiated between?
  • What is required for an "addressable" implementation specification?
  • Which of the following is NOT a purpose of a Business Associate in healthcare?
  • OIG believes that the Compliance Program should include a written policy statement addressing what?
  • What can ongoing monitoring help identify in a compliance program?
  • Which document is essential for a laboratory performing high-complexity testing before a compliance review?
  • How can a Compliance Officer achieve higher levels of compliance engagement?
  • After an investigation that affects the organization's reputation, what should a Compliance Professional do next?
  • If a hospital's discovery sample reveals a financial error rate above 5%, what does the OIG require?
  • What does the False Claims Act empower the government to do?
  • What is the least important qualification for a Compliance Officer in your organization?
  • Which of the following is a preventive measure to avoid a Qui Tam lawsuit?
  • Which is not one of the seven fundamental elements of an effective compliance program?
  • In CMS identified areas of high-risk fraud, which combination does NOT apply?
  • In order to determine the required sample size for a statistical review, what factor must be considered?
  • Restitution can be made in which of the following forms?
  • Who must comply with the HIPAA Privacy Rule?
  • The Privacy Rule provides two de-identification methods. Which of the following is NOT one of them?
  • Which of the following is NOT a permitted use of PHI?
  • What is an essential characteristic of an engaging compliance training session?
  • What is the main difference between HIPAA Privacy and Security?
  • Which of the following is NOT a key to successfully creating a risk assessment team?
  • In which context is the term "Physician Self-Referral" used?
  • What does the Physician Self-Referral Law prohibit?
  • What is a critical element of a compliance professional's role when addressing a complaint's facts?
  • Which type of audit identifies potential errors before the process is completed?
  • What type of audit is characterized by a comprehensive inspection of records in anticipation of launching a compliance program?
  • Which of the following is NOT an offense that could lead to OIG exclusion from Federal health care programs?
  • If a facility only performs blood draws and no testing, does it require a CLIA number?
  • What should you do if certain employees are not being properly disciplined for misconduct?
  • Which of the following actions shows ethical leadership in a healthcare setting?
  • Protected health information (PHI) is considered de-identified by HIPAA Privacy Rule standards by:
  • Which of the following statements are true regarding the Statute of Limitations under the False Claims Act?
  • True or False: Underpayments identified during a CIA-Claim Review may be netted from overpayments.
  • Which of the following actions is critical when conducting a claim review under a CIA?
  • A health system implemented an EHR in multiple clinics, and the privacy professional discovers inconsistent interpretations of access policies. What is the BEST strategy for the privacy professional?
  • Who is responsible for enforcing the rules and regulations under Medicare and Medicaid laws?
  • According to the OIG Compliance Program Guidance, what should be articulated to demonstrate commitment to compliance?
  • What is a key characteristic of a Covered Entity?
  • A written education plan for compliance should include which of the following?
  • What should be done immediately regarding any identified compliance problems?
  • Which statement is false regarding the financial error rate in a Claim Review under a CIA?
  • Which of the following is NOT one of the five most important federal fraud and abuse laws?
  • What should a facility's policy be when contacted for patient information by an agency investigating a HIPAA privacy violation?
  • What is NOT one of the fiduciary duties of the board?
  • What is one potential risk of failing to address overpayments found during a review?
  • Which agency is responsible for overseeing employee safety?
  • What does the oversight function of the Board of Directors entail?
  • What should be considered when designing practices for PHI confidentiality?
  • What must compliance and ethics programs ensure according to the Federal Sentencing Commission?
  • Which of the following is considered a compliance activity in many organizations?
  • Which of the following actions could lead to termination as a consequence of non-compliance?
  • In a compliance program, what is essential for risk assessment?
  • If an IACUC manager identifies studies with lapsed approvals, what should the research compliance professional do?
  • Which type of monitoring review is designed to catch issues as they arise?
  • What was the primary purpose of the False Claims Act (FCA) when it was implemented?
  • Why is it important for all members of a healthcare organization to participate in the compliance program?
  • What role does a compliance officer typically fulfill in a healthcare organization?
  • True or False: The STARK law prohibits Medicare payments for designated healthcare services referred by a physician with a financial relationship with the entity.
  • What does the Latin phrase "Qui tam pro domino rege quam pro se ipso in hac parte sequitur" mean?
  • Does the HIPAA Privacy Rule cover all forms of protected health information including electronic, written, or oral?
  • Which law does not require nursing facilities to conduct state FBI criminal background checks?
  • What was the main goal of the 1984 Sentencing Reform Act?
  • According to OIG's Self Disclosure Protocol (SDP), which of the following must be submitted?
  • What is the primary purpose of OIG’s Voluntary Self-Disclosure Protocol?
  • According to compliance best practices, which is the primary factor for effective compliance communication?
  • True or False: The Stark Law prohibits claims for designated health services based on tainted referrals.
  • What does Stark Law aim to prevent?
  • True or False: Communications between company counsel and employees are privileged, owned by the company.
  • Which of the following is identified by CMS as a high-risk area for fraud?
  • How is a retrospective audit characterized?
  • Which of the following describes the types of audits?
  • Which group is least likely to report errors in a healthcare setting?
  • What encompasses demographic information collected from an individual in healthcare?
  • What is the ongoing process called that management performs to ensure processes are effective?
  • According to the Equal Employment Opportunity law, what is a protected characteristic?
  • Which type of medical record is destroyed by shredding and cutting?
  • Under HIPAA, who has the authority to define the roles of privacy and security officials?
  • What incentive may a provider receive for making a good faith Self-Disclosure to the OIG?
  • Upon receiving a patient complaint about a research study invitation, what initial action is most appropriate?
  • Does HIPAA allow disclosure of protected health information about a student to a school nurse for treatment purposes?
  • Which method is used to destroy laser disc medical records?
  • When is immediate notification to the government warranted according to OIG compliance guidance?
  • What can lead to the detection of errors in past billing practices?
  • In an audit of billing practices, which statement about sampling is INCORRECT?
  • Which organization is represented by the acronym EEOC?
  • Which of the following best describes engineering controls in safety management?
  • Which of the following is NOT a requirement under the HIPAA Security Rule?
  • What is a potential requirement that the court may impose if future harm can be estimated?
  • What does HIPAA Administrative Simplification aim to achieve?
  • How long are Corporate Integrity Agreements (CIAs) typically enforced?
  • What is NOT one of the basic elements of compliance monitoring?
  • What is the main purpose of a Remedial Order in probation?
  • True or False: An individual has unrestricted access to all PHI within their Designated Record Set (DRS).
  • True or False: It is illegal under the Anti-Kickback Statute to provide free or discounted services to uninsured individuals.
  • Which of the following best describes the nature of a Compliance Program?
  • What is a key function of the compliance officer in a healthcare organization?
  • Fundamentally, compliance efforts are designed to establish a ______ within a hospital that promotes prevention, detection, and resolution of conduct that does not conform to Federal and State law.
  • What is the primary purpose of the False Claims Act (FCA)?
  • What type of training sessions should a compliance professional conduct?
  • Which of the following provides legal protection from prosecution for a specific party?
  • What should be the outcome of conducting a baseline audit?
  • What subpart governs Breach Notifications in HIPAA?
  • Which of the following is a focus of the Federal Sentencing Commission's 2004 changes?
  • What is included in "all the required safeguards" according to HIPAA?
  • In emergency situations, what is true about PHI disclosure?
  • Who benefits financially from a Qui Tam suit if successful?
  • Which of the following gifts is generally considered acceptable under a typical Code of Conduct?
  • Which document is not typically associated with the self-disclosure process?
  • What does PHI stand for in a healthcare context?
  • What should a healthcare organization do to ensure it is compliant with HIPAA regulations?
  • The Privacy Rule does not restrict the use or disclosure of _______________, which neither identifies nor provides a reasonable basis to identify an individual.
  • Who should primarily participate in the development of goals and objectives for the compliance program?
  • Which action is voluntary for treatment, payment, and operations (TPO) under HIPAA?
  • In which situation can the information of a deceased patient be released to the spouse?
  • What is the recommended minimum annual training duration suggested by OIG for compliance?
  • What is one result of poor compliance management within an organization?
  • Which of the following is an example of an administrative safeguard?
  • Which term best describes the approach to punishment of the Federal Sentencing Guidelines (FSG)?
  • What is described as a multi-step process in progressive discipline?
  • If a provider receives a tainted referral, what is the main consequence under the Stark Law?
  • How should complaints received through a Compliance Hotline be handled?
  • What is the source of notification requirements following a data breach of a clinical system containing PHI?
  • Compliance risk management professionals should design a framework to ensure management understands?
  • If serious wrongdoing is suspected, what is the FIRST step to take?
  • What is one key benefit of a well-implemented compliance program?
  • When is a breach assumed to be reportable?
  • Under the US Federal Sentencing Guidelines, which process should be prioritized for effective compliance?
  • What is the consequence of violating HIPAA regulations?
  • What are the four impermissible acts associated with a HIPAA breach?
  • What is the primary role of the US Sentencing Commission?
  • Which Act of 2003 was established to reduce medication errors due to illegible physician handwriting and to promote e-prescribing?
  • What is the scope of Chapter 8 of the Federal Sentencing Guidelines?
  • Which of the following practices supports the implementation of corrective actions after identifying compliance issues?
  • What law should a physician be educated about if they signed a clinical trial agreement and requested funds for referrals?
  • What is the next step for a privacy professional when receiving a hotline message about PHI misuse?
  • What kind of actions might lead to a penalty of $100,000 for a HIPAA violation?
  • What is the focus of the Anti-Kickback Statute?
  • What is a benefit of using stories and analogies in training?
  • When under an imposed-CIA, which statement about Independent Review Organizations (IROs) is not true?
  • Which safety measure should be included in a training presentation on privacy safeguards?
  • What is a primary function of the Compliance Officer?
  • What should you do if a patient walks into your practice with a leashed dog?
  • In responding to coding errors, what is a compliance professional's key responsibility?
  • How many percutaneous injuries involving contaminated sharps occur annually according to CDC estimates?
  • What is the first step in developing an annual compliance audit?
  • When should the compliance plan be reviewed?
  • Which of the following expenses related to compliance programs is NOT considered tax deductible?
  • What is required for a subpoena to be valid?
  • Which of the following is a benefit of having a compliance program?
  • What law can a healthcare organization violate by not returning overpayments within 60 days?
  • Who conducts and supervises audits and investigations for federal agencies?
  • What is primarily assessed during the evaluation of compliance program effectiveness?
  • What is the aim of the Physician Payment Sunshine Act in relation to public transparency?
  • Which section of the ACA prevents discrimination against individuals with limited English proficiency in healthcare programs?
  • What is the primary function of the Qui Tam provision?
  • What is the maximum time allowed for reporting breaches affecting less than 500 individuals?
  • What is the consequence for violating EMTALA regarding patient treatment in an emergency?
  • Which of the following two statements regarding RAT-STATS are true?
  • Which Act safeguards student educational records from unauthorized uses and disclosures?
  • What is the aim of the Physicians at a Teaching Hospital (PATH) review?
  • Which aspect is NOT part of the employee's responsibilities regarding the Code of Conduct?
  • Which of the following is a benefit of conducting a Control Self-Assessment?
  • What is the effective consequence of HIPAA of 1996 regarding incorrect claims?
  • What does the HCCA identify as two critical components of a compliance program?
  • What does Part C of Medicare refer to?
  • If a payment request from a diagnostic provider seems unusually high compared to others, what should you do?
  • If there is a suspicion of prescription forgery for a controlled substance, what is the next step?
  • In the context of compliance, what role does a baseline audit play?
  • What is the purpose of the compliance program element referred to as Investigation/Mitigation/Non-Employment of Sanctioned Individuals?
  • What is an essential component in establishing a culture of compliance within an organization?
  • Which characteristic defines a Statistical Valid Sample?
  • What does Title I of the Genetic Information Non-discrimination Act (GINA) prevent?
  • Which of the following is an obstacle to an effective compliance program?
  • In a compliance program, the focus should primarily be on what aspect?
  • Before a government investigation occurs, which document should be reviewed carefully?
  • At which level of the Medicare appeals process is the appeal reviewed by a qualified independent contractor?
  • What type of audit should be conducted for historical data analysis?
  • When a provider accidentally shares attorney-client privileged information with a third party, what is this considered?
  • What should be included in the provider self-disclosure to the government?
  • What is the purpose of EMTALA?
  • What is an example of a small organization according to FSG criteria?
  • Which of the following situations requires authorization for PHI disclosure?
  • What is a key benefit of conducting a Controlled Self-Assessment?
  • What is defined as Unsecured PHI?
  • Which designated health services are covered by the Stark Law?
  • The Deficit Reduction Act requires providers receiving over $5 million in Medicaid funds to inform employees of their ability to?
  • What is one of the purposes of ongoing monitoring in a compliance program?
  • As a new Compliance Officer, what should you do if the Code of Conduct is full of legal jargon?
  • What is the main mission of the OIG?
  • What is a characteristic of an effective HR policy within a healthcare organization?
  • Which of the following best describes welfare benefit plans?
  • What is the maximum penalty for noncompliance with HIPAA provisions?
  • Which type of information is NOT considered part of the Electronic Protected Health Information (ePHI)?
  • What principle states the obligation of compliance professionals to serve their organization with integrity?
  • What is a key factor for a healthcare organization to avoid unnecessary liability related to overpayments?
  • Which entity cannot bill for medically unnecessary services?
  • What action should be prioritized if a privacy incident involving PHI is suspected?
  • Which area is NOT commonly associated with healthcare fraud according to CMS?
  • What is one of the main benefits of an effective compliance program?
  • What is Attestation in a compliance context?
  • As a new compliance officer under an OIG CIA, what should be your first course of action?
  • How long is PHI protected after the person's death?
  • How can organizations reduce their culpability according to the Federal Sentencing Guidelines?
  • Why should compliance officers set disciplinary policies for non-compliance?
  • What outcome does the OIG expect from documented findings in compliance activities?
  • Which area of concern primarily deals with billing processes in healthcare compliance?
  • What is a Business Associate (BA) in healthcare?
  • Which of the following rights allows an individual to request limits on the use of PHI?
  • The term OIG refers to which of the following organizations?
  • What is the purpose of Antitrust laws?
  • Which of the following is included in designated health services?
  • Under EMTALA, what is required from hospitals when a patient arrives in the emergency department?
  • Which of the following best describes compliance program structure's importance?
  • What is the MOST appropriate action for an IRB upon receiving self-reported investigator non-compliance regarding inclusion criteria?
  • What is considered the first and best line of defense in compliance?
  • What does a contemporaneous review involve in compliance auditing?
  • What does HIPAA stand for?
  • In the context of compliance, what would a follow-up phase typically involve?
  • In HIPAA, which subpart deals with Security?
  • In an informed consent, which statement is appropriate when a Pet scan is deemed non-billable?
  • In response to a call indicating potential research misconduct, what should the compliance professional assure the employee?
  • What is the "Caremark Duty" related to?
  • Who is primarily responsible for clinical trial billing compliance and enforcement?
  • What does Section 6401 of the Affordable Care Act specify about compliance programs?
  • What outcome might occur if errors in billing are not promptly addressed?
  • What types of tools are commonly utilized in government investigations?
  • A record retention policy must be based on which of the following?
  • What was Chapter 8 of Federal Sentencing Guidelines designed for?
  • After identifying non-systemic billing errors, what should be done next?
  • Which of the following principles addresses the obligation to the public?
  • Which of the following is a task that a Chief Compliance Officer should NOT focus on?
  • What type of information is NEVER acceptable to leave on an answering machine message?
  • Before conducting a safety audit in an emergency department, what is the first item needed?
  • What is the minimum duration for which the OIG can impose a mandatory exclusion?
  • Which law provides protection against discrimination in employment based on genetic information?
  • What should organizations develop to effectively document compliance risks?
  • When a provider receives a PHI request from Social Security Administration, what is the appropriate action?
  • Which principle should guide the compliance professional throughout an investigation?
  • What requires necessary policy measures to prevent avoidable recurrence?
  • Which of the following statements about the monitoring of internal controls is TRUE?
  • One of the operations in healthcare includes reviewing the competence of providers. What classification does this operation fall under?
  • Is it true that experienced compliance health care personnel can perform "double duty" as trainers and line performers?
  • What are the three benefits of an effective compliance program?
  • How are computerized data medical records destroyed?
  • The majority of fraud and abuse violations are related to which of the following?
  • What should compliance programs include to understand and mitigate risk?
  • What should a billing manager do if a significant error is identified in the billing process?
  • In the context of healthcare compliance, what plays a critical role in monitoring Medicare fraud?
  • Which statement accurately describes the Response and Prevention Element in compliance?
  • What does ERISA stand for?
  • How often should providers check if employees are on the OIG List of Excluded Individuals after hiring?
  • When is a covered entity permitted to use or disclose PHI for marketing purposes?
  • How many states currently require nursing facilities to perform a background check of state records for direct-access employees?
  • On what basis should the compliance committee typically develop objectives and goals?
  • What action should a compliance officer take if an ongoing investigation could be compromised by certain employees remaining present?
  • When developing a compliance program, which of the following actions should be prioritized after risk assessment?
  • A PI testing a hypothesis with de-identified medical records should first:
  • What is the purpose of internal controls in an organization?
  • If someone did not know about a HIPAA violation, what is the potential civil penalty?
  • What should the Privacy Officer do after learning about a lost encrypted USB drive containing sensitive PHI?
  • What is the purpose of the response element in compliance?
  • Regarding Compliance Program effectiveness, which statement is NOT true?
  • What general areas does an OCR investigation examine?
  • At which level of the Medicare appeals process is an appeal decision made by the Office of Medicare Hearings and Appeals (OMHA)?
  • Which option is a federal oversight related to Medicaid?
  • Which law exempts self-insured health plans from state laws governing health insurance?
  • Which of the following is a key component of a compliance program?
  • What does 'P' in TPO refer to in the context of healthcare?
  • What is one method in managing risk in an organization?
  • The Privacy Rule generally requires covered entities to limit uses, disclosures, or requests of PHI to the minimum necessary to accomplish the intended purpose. True or False?
  • What is the process of identifying potential security risks and determining the probability and magnitude of risks called?
  • Which part of HITECH is dedicated to funding grants and loans?
  • What does Attorney-Client Privilege protect?
  • What is the primary function of HIPAA?
  • What does the Defense Industry Initiative aim to improve?
  • Which regulation requires hospitals to provide medical screening exams regardless of insurance?
  • How should an organization respond to an employee who does not complete compliance training?
  • What does the Physician Payment Sunshine Act require manufacturers to disclose?
  • What is the correct method for destroying DVD medical records?
  • Which of the following is a key activity related to 'Payment' in the TPO framework?
  • What encompasses any form of identifiable health information maintained by a healthcare provider or agency?
  • Which element is seen as an absolute necessity for a successful Compliance Program?
  • What does the Anti-Kickback Statute safe harbors protect?
  • Who is responsible for recommending an auditing and monitoring plan for an effective compliance program?
  • What does the acronym DOL represent?
  • What is the focus of a risk assessment in compliance?
  • What step should be taken when considering self-disclosure of a potential fraud issue?
  • What type of training does OIG suggest should be a separate session and targeted?
  • Which of the following conditions is associated with the imposition of community service as part of probation?
  • Which is a key goal of establishing a code of conduct in healthcare organizations?
  • When can you use or disclose PHI?
  • How should an institution address a clause in a clinical trial agreement that gives the sponsor all rights to new interventions?
  • What was established by the DRA of 2005?
  • What is a primary benefit of implementing a compliance program in healthcare organizations?
  • Which of the following is NOT a typical consideration in compliance policy reviews?
  • An individual's understanding of the compliance aspects of their job can BEST be enhanced by including compliance in:
  • What does the investigation final report in documentation include?
  • If a provider is on the OIG sanctions list, what is the first step to take?
  • What is a retrospective audit used for?
  • What is the meaning of TPO in the context of HIPAA?
  • Which organization has had the authority to levy administrative penalties for filing false claims since 1981?
  • Which of the following is an example of healthcare operations?
  • Which of the following questions is NOT useful during an internal investigation?
  • What does the term 'treatment' in a healthcare context refer to?
  • The RICO Act is associated with increased penalties for violations related to which of the following?
  • Which of the following best describes the intent of a risk management strategy?
  • What is a grand jury subpoena used for in a government investigation?
  • What should a compliance professional's NEXT step be if they identify payments to physicians for medical directorships without written contracts?
  • What is considered one of the most important foundations of a compliance program?
  • Which approach emphasizes support and correction for non-compliant behavior in enforcement?
  • In the context of healthcare compliance, what is the impact of proving intent under the Anti-Kickback Statute?
  • What Act created the Medicaid Integrity Program (MIP) to ensure that Medicaid payments are for covered services?
  • Where should enforcement of compliance begin according to best practices?
  • In a compliance audit, the fieldwork step generally involves which activity?
  • True or False: Expanding contemporaneous reviews to include retrospective reviews is beneficial for providers.
  • How many states require nursing facilities to perform FBI checks on employees?
  • Which training topic specifically addresses risks associated with privacy breaches?
  • Under which circumstance can coinsurance and deductibles be waived?
  • What is the lowest potential federal civil monetary penalty for a HIPAA violation?
  • Which individual goal is BEST for a privacy professional to include in their objectives?
  • How frequently is the IACUC required to conduct an inspection of a vivarium?
  • What is the most important communication device for a compliance program?
  • What must a Business Associate obtain to claim compliance when selling an individual's PHI?
  • Which of the following is NOT a governmental investigative tool?
  • What term describes an organization's commitment to compliance by management, employees, and contractors?
  • What term would be used for actions that result in unnecessary costs to the Medicare program?
  • What significant action is referred to as "Qui Tam" under the FCA?
  • Which of the following statements about attorney-client privilege is true regarding the billing manager's review?
  • How often must new employees be trained about HIPAA regulations?
  • What should be done with a "required" implementation specification under HIPAA?
  • When handling a data breach, which law requires notification regarding the breach?
  • True or False: Unintentional billing mistakes and overpayments do not need to be reported to the OIG's SDP.
  • What is a crucial element of corrective action plans (CAPs) following an audit?
  • What type of rewards does the FSG suggest offering to those who adhere to compliance and ethics programs?
  • In the context of a compliance program assessment, what key factor should be reviewed related to the prevention of fraud, waste, and abuse?
  • What should be the focus of a healthcare organization's risk management strategy?
  • Why is establishing compliance programs crucial for healthcare providers?
  • Which aspect does NOT typically form part of a compliance program's structure?
  • What should be done after clarifying a suspected fraud violation?
  • What does PHI stand for?
  • Before recommending disciplinary action for a nurse whose photo was posted online, what should the privacy professional determine?
  • When was the False Claims Act implemented?
  • What aspect of compliance management focuses on addressing both current and future risks?
  • True or False: A vendor that stores encrypted copies of files from a covered entity is not a Business Associate because the ePHI is unreadable.
  • What is a Health Care Clearinghouse?
  • How many criteria must be met before a patient can be transferred to another facility under EMTALA?
  • What is a potential result of an effective compliance program?
  • What is the Teaching Physician Rule primarily concerned with?
  • What should your first course of action be if a provider and secretary are found violating privacy regulations?
  • In a compliance investigation, what is the most important responsibility of the compliance professional?
  • Which of the following is NOT a consideration when determining what to do FIRST in applying regulations?
  • Which act aimed to eliminate discrimination based on race, religion, sex, or national origin in employment?
  • What policy is implemented to foster open communication in a healthcare setting?
  • What is the primary purpose of attorney-client privilege?
  • When a PI is accused of accepting kickbacks from a sponsor, who should a research compliance professional FIRST notify?
  • What should a compliance program's goal focus primarily on from a monitoring perspective?
  • Which factors should be considered when establishing a frequency schedule for monitoring activities?
  • What do SURS or SUR Units refer to?
  • How long do providers have to refund overpayments once identified?
  • Which statement is correct regarding the consequences of non-compliance?
  • What is the aim of conducting audits in healthcare organizations?
  • True or False: Upcoding has been a major focus of OIG's enforcement efforts, and HIPAA added another civil monetary penalty for upcoding violations.
  • What comprises a Designated Record Set (DRS) under HIPAA?
  • What regulates the circumstances under which a covered entity may use or disclose an individual's PHI?
  • What are the three main responsibilities of hospitals under EMTALA when a patient arrives at the emergency department?
  • What is a key reason for implementing compliance training in healthcare organizations?
  • What should compliance professionals do in response to discovering a systemic billing error?
  • Which law does not require proof of intent for violations?
  • What should a compliance officer do if they discover a potential violation?
  • How often are CIAs required to undergo regular monitoring?
  • What is one drawback of an internal reporting system?
  • How should reporting systems within healthcare organizations be handled?
  • Which law creates liabilities for submitting false claims to federal healthcare programs?
  • For what purpose should an investigation and necessary disciplinary action be taken if a limited data set is released?
  • Which of the following can help reduce the risk of a qui tam lawsuit?
  • At its most basic level, what does a compliance program entail?
  • What is the primary purpose of a compliance committee?
  • In compliance investigations, why is it important to engage with outside counsel?
  • True or False: The government only assesses financial compliance during audits and not other areas.
  • Why are regular compliance training sessions important?
  • Which of the following is NOT a necessary policy or procedure for organizations?
  • How should education for minor infractions be approached?
  • What is a direct result of a Stark violation?
  • Which accrediting body is recognized as the largest for healthcare organizations in the United States?
  • What can help establish a positive compliance atmosphere within an organization?
  • What is a core role of the Chief of Compliance in a healthcare organization?
  • Which statement is true regarding compliance programs?
  • SNFs are Medicare certified facilities that provide extended skilled nursing or rehabilitative care. This care is reimbursed under which Medicare part(s)?
  • What underlying goal does root cause analysis serve?
  • A covered entity must obtain the patient's written authorization for any use or disclosure of protected health information (PHI) in which circumstances?
  • Organizations can reduce their culpability according to the Federal Sentencing Guidelines by?
  • What is the function of risk assessment within a compliance program?
  • What action cannot be taken without having informed employees of rules and expectations?
  • What must any laboratory performing testing on human specimens do?
  • If wrongdoing is identified, what is the FIRST action to take if an overpayment is found?
  • Which is an objective of HIPAA Administrative Simplification?
  • Effective enforcement and discipline elements include:
  • Which resources are MOST relevant for developing and updating a research compliance work plan?
  • In what situation should immediate modification of procedures occur?
  • What does a compliance committee primarily oversee?
  • What is a good starting point for monitoring compliance in an organization?
  • What organization develop standards and accredit hospitals and healthcare facilities?
  • What is a significant benefit of a Corporate Compliance Program?
  • What role does in-house legal counsel play in healthcare compliance reviews?
  • Which of the following is noted for involving some of the largest breaches reported to HHS?
  • According to US Courts, which of the following is NOT included in the obligations concerning statistical sampling for overpayment estimations?
  • Which of the following statements is true about the Sarbanes-Oxley Act?
  • In relation to compliance, what is a critical function of leadership within an organization?
  • What is the primary purpose of a privacy exit interview?
  • Who is primarily responsible for carrying out discipline within a healthcare organization?
  • True or False: Conducting a Controlled Self-Assessment contributes to increasing the awareness and targeting of audit work.
  • What type of law is the False Claims Act categorized as?
  • What is the outcome of failing to adhere to compliance programs?
  • If a whistleblower identifies fraudulent claims, what could be a true statement regarding potential rewards?
  • What does a preventive internal control involve?
  • When assisting IT with data privacy controls, which of the following is an employee-related control?
  • When resolving compliance issues, which aspect is emphasized as the most critical line of defense?
  • Which document is used to assist employees in carrying out daily responsibilities within an appropriate legal standard?
  • Which of the following is NOT a characteristic of a Corporate Integrity Agreement (CIA)?
  • What type of safeguard is NOT included in the HIPAA Security Rule?
  • Which of the following is one objective of a baseline audit?
  • What is one of the seven elements emphasized in OIG CPG guidance for hospitals?
  • Who holds the primary responsibility for the monitoring component of internal controls?
  • What does the General Services Administration (GSA) manage?
  • True or False: An excluded individual is automatically reinstated at the end of an exclusion term.
  • Which act imposes penalties for knowingly submitting false claims to Medicare?
  • Which of the following is NOT required for an effective compliance program?
  • Which act requires providers to be permanently excluded from federal health care programs after being found guilty of fraud three times?
  • What is ensured by contract provisions for background checks of vendor employees?
  • What does EMTALA require from participating hospitals regarding patient transfers?
  • In compliance, what does "education and training" primarily aim to achieve?
  • When determining the extent of research monitoring activities, which factor is critical to consider?
  • What is one function of safety data sheets in a hazard communication program?
  • What is the process to assess if an "impermissible" use of protected health information is a breach?
  • The ACA requires that all providers adopt a compliance plan as a condition of enrollment with Medicare, Medicaid, and CHIP. Is this statement true or false?
  • In a compliance program, what does auditing and monitoring help ensure?
  • Does a Compliance Officer impose disciplinary actions within an organization?
  • Which of the following is a valid example of PHI use beyond TPO?
  • What is a common objective of an effective compliance program?
  • Which scenario violates the Stark Law?
  • What is the minimum number of units to be sampled for a full statistical audit?
  • What is the significance of documenting how a complaint was handled?
  • What is the penalty for a HIPAA violation committed under false pretenses?
  • In case of a cyber-attack, what steps must an entity take?
  • What does an open door policy encourage in the workplace?
  • What is a likely consequence of the board not having a solid understanding of compliance objectives?
  • When determining the amount of a civil money penalty for HIPAA violations, which factor is NOT considered?
  • What does the Health Care Financing Administration (HCFA) encourage to promote consistency in interpretation of claims?
  • Which of the following is NOT considered a possible sanction by the OIG?
  • What does a Fiscal Intermediary do in the context of Medicare and Medicaid services?
  • Who should be contacted immediately upon discovering a significant billing error?
  • A violation of PHI is considered a breach when:
  • How is Medicaid primarily administered in the United States?
  • What does risk assessment involve within an organization?
  • Which acronym refers to legal protections between a lawyer and a client?
  • What are the seven basic elements for a fundamental compliance program?
  • A Compliance Program with well-written policies will not be successful without what?
  • When is it necessary to hire an outside consultant or legal counsel?
  • Which of the following levels of confidentiality is considered when handling personal health information (PHI)?
  • Which of the following should be reflected in a billing company's written policies and procedures?
  • What does P-D-F stand for in the context of audits and investigations?
  • Which method is preferred for monitoring and auditing compliance effectively?
  • What does the term "Duty of Care" refer to for a Board of Directors (BOD)?
  • If there are inconsistencies in PHI policies, what should the Compliance Officer do?
  • What aspect of healthcare does HITECH Subtitle D focus on?
  • How can a 100% confidence level in an audit be obtained?
  • What is NOT a feature of CMS programs?
  • What type of information does the CMS Open Payments Program provide to the public?
  • In healthcare compliance, why is effective education and training emphasized as a key element?
  • How can organizations effectively perform community service in the context of probation?
  • Which term represents the process of identifying and dealing with risks in a compliance program?
  • RAT-STATS is best described as:
  • Which of the following is not one of the key objectives of internal controls?
  • What does LoProCo stand for in the context of HIPAA compliance?
  • What is true regarding contemporaneous reviews in a compliance setting?
  • Which of the following is a key requirement of the Sunshine Act?
  • In which scenario should a compliance professional establish attorney-client privilege?
  • Under FERA, what may happen if overpayments are not returned in time?
  • What type of communication is NOT considered PHI?
  • What is the acceptable extrapolation of the review results for the Observation Room charges?
  • In a research study involving adolescents, what document must an adolescent subject sign?
  • Which type of safeguards are fundamental for protecting physical systems and data from environmental hazards?
  • What is a penalty for willful neglect if the violation is corrected in 30 days?
  • What does the OIG's voluntary self-disclosure protocol require providers to report?
  • Which area is identified by the OIG as most prone to fraud, waste, and abuse in home health agencies?
  • What does the Family Educational Rights and Privacy Act (FERPA) protect?
  • What element should a privacy professional consider first when presenting to the board about a privacy program?
  • One benefit of having an effective compliance program is to help create which of the following?
  • What must a healthcare provider set up to become a Medicare biller?
  • Which agency has enforcement authority for HIPAA privacy regulations?
  • What is one way to prevent duplication of auditing efforts in an organization?
  • What is considered an appropriate start to implementing an effective compliance program for small physician group practices with limited resources?
  • Which statement about breaches is correct?
  • What type of testing requires a laboratory to enroll in the CLIA program?
  • What is one of the requirements of the Gramm-Leach-Bliley Act concerning financial institutions?
  • What can be a potential penalty under the False Claims Act?
  • Which of the following comprises the entirety of a compliance program?
  • Which of the following is NOT listed as an obstacle to effective compliance program implementation?
  • What is prohibited by the Omnibus Budget Reconciliation Act of 1987 (OBRA)?
  • What right is NOT typically included in the Notice of Privacy Practices?
  • Which federal agency's guidance includes criteria on unbiased judgment and independence for IROs?
  • Which compliance program guideline focuses on evaluating corporate compliance?
  • What is the maximum prison sentence for committing a HIPAA offense knowingly?
  • What is the main purpose of general compliance training?
  • What element is significant for a compliance program in relation to healthcare fraud?
  • When training physicians and providers, which aspects should be covered?
  • What is a formal statement outlining a plan for a specified subject area, usually citing state and/or federal required actions or standards?
  • What is considered the primary means of minimizing employee exposure to hazards in the workplace?
  • What is one significant benefit of maintaining communication lines open in a compliance program?
  • In which scenario can a probe sample be used?
  • In the context of healthcare compliance, what characterizes 'waste'?
  • What could happen to a physician who fails to respond to an emergency while on call?
  • What recent addition to compliance programs does the updated DOJ ECCP emphasize regarding new technologies?
  • What defines the monetary gain for whistleblowers under the DOJ when it chooses to decline a case?
  • What does the phrase "Res Ipsa Loquitur" mean in legal terms?
  • Why is developing a variety of educational materials important?
  • What is a primary benefit of conducting a contemporaneous review?
  • What is the role of the Office for Human Research Protections?
  • Incentive programs based on employee performance may be tied to increases in what?
  • What does the Medicaid - Deficit Reduction Act of 2005 allow states to do?
  • Which question is considered the most effective to include in an employee exit interview?
  • What is a fundamental principle of the Privacy Rule?
  • What principle is emphasized in the Code of Ethics for Healthcare Compliance Professionals?
  • Which of the following is not an aggravating factor to a culpability score?
  • Are physicians allowed to offer cash discounts?
  • What kind of safeguards might include the use of visitor badges and surveillance cameras?
  • What is the role of proper documentation in compliance, according to HHS-OIG?
  • What is one of the main purposes of the Code of Conduct?
  • A compliance audit typically aims to do which of the following?
  • Which practice promotes a culture of compliance within healthcare organizations?
  • What does the False Claims Act primarily address?
  • What should you do if you discover a minor inventory discrepancy in controlled substances?
  • What significant reforms did the Balance Budget Act of 1997 introduce concerning Medicare and Medicaid?
  • According to Stark Law, financial relationships are scrutinized if they exist between which of the following?
  • What consequence can result from violations of the Anti-Kickback Statute?
  • Which Act requires providers to repay identified overpayments to Medicare and Medicaid within 60 days?
  • What role does Compliance play in a disciplinary action?
  • According to HIPAA, can pharmacists provide advice about over-the-counter medicines without restriction?
  • What must be included in a covered entity’s Notice of Privacy Practices?
  • Which statement regarding signed authorizations for release of information is correct?
  • Under HIPAA's Privacy Rule, who constitutes the covered entity's workforce?
  • What is a key component that should be included in a compliance program according to the 2023 OIG guidance?
  • What does the term "condoned" refer to in a compliance context?
  • Which of the following is a method for collecting compliance data?
  • For what reason might education not be labeled as punishment?
  • What is a significant obstacle to effective compliance implementation?
  • What is the illegal practice of submitting separate claims for maximum reimbursement known as?
  • What is the purpose of root cause analysis in healthcare compliance investigations?
  • How do patients typically learn about their privacy rights under HIPAA?
  • How are minor unintentional non-compliance infractions typically addressed?
  • What is one of the main benefits of a Compliance Program?
  • According to HIPAA, a healthcare provider or its business associate may disclose PHI when authorized to do so, but only to the extent necessary. This is known as:
  • What should a compliance professional do first upon receiving a complaint about unfair discipline?
  • When monitoring a high-risk area shows it was never implemented, what should the compliance professional do FIRST?
  • What are Limited Data Sets used for within HIPAA guidelines?
  • In the course of an audit, what is the first course of action if disciplinary actions against certain individuals are found to be unfair?
  • What should be considered when evaluating a potential conflict of interest?
  • What does "Willfully Ignorant of the Offense" imply?
  • In dealing with medical necessity issues, whom should the compliance professional collaborate with?
  • Which of the following is part of preventive measures in compliance?
  • If a compliance professional discovers non-compliance, what is the FIRST step they should take?
  • What year did OSHA establish the Bloodborne Pathogens Standard?
  • Which of the following is NOT a legal requirement under the Equal Employment Opportunity law?
  • Routine waiver of co-pays would violate which law?
  • What does PHI stand for?
  • What is the significance of the FSG Culpability Score?
  • Which of the following is NOT a part of the Code of Conduct content checklist?
  • What is the first step in the monitoring and auditing two-step process?
  • What should be taken into consideration when developing an audit agenda?
  • What is the significance of implementing the False Claims Act during the Civil War?
  • Which of the following is NOT a category of obligations in the HCCA Code of Ethics?
  • What is a critical element to address when preparing a compliance plan for the year?
  • What should a research compliance professional do NEXT after discovering device and serial numbers included in reporting data during a HIPAA audit?
  • Which of the following is an administrative safeguard?
  • One of the benefits of a Compliance Program is to:
  • Which Compliance Program Element is emphasized by the statement "the only thing worse than not having a policy is having a policy and not following it"?
  • What does IACUC stand for?
  • True or False: A self-audit can help providers reduce chances of non-compliance.
  • Which type of internal control is intended to signal the presence of a problem?
  • Which action is essential once compliance violations are identified?
  • Under what circumstances can PHI be disclosed without patient authorization?
  • What should the approach to penalties be based on?
  • What is a common measure to mitigate privacy risk when sharing patient information?
  • Which of the following statements accurately reflects the attitude of ACA regarding statistical sampling?
  • What statement is true regarding the updating of a compliance program due to changing healthcare regulations?
  • Which standard component is NOT typically included in codes of conduct?
  • What does the term 'Code of Conduct' encapsulate in a healthcare organization?
  • How can auditing be distinguished from monitoring in a compliance context?
  • What are the two primary objectives of a Board of Directors (BOD)?
  • What is an example of a contingency planning safeguard?
  • What is one of the main responsibilities of a Compliance Officer?
  • What is essential for a privacy professional to maintain in order to keep up with industry standards?
  • Which agency emphasized that compliance and ethics programs should be designed to prevent and detect criminal conduct?
  • Which of these is NOT considered a common trigger for a compliance audit?
  • What is a key feature of a Non-Statistical Sample?
  • Which of the following is not required in a written hazard communication program?
  • Which of the following describes an organization with an effective compliance program?
  • During a corporate compliance investigation, which statement is false regarding Attorney-Client Privilege considerations?
  • What should be done in response to suspected misconduct or wrongdoing?
  • If there is a detection of serious wrongdoing, what is the first step for the compliance professional?
  • According to the Federal Sentencing Guidelines, which factor could increase an organization's punishment?
  • Which of the following best describes the watchwords for enforcing standards of conduct in compliance?
  • According to the OIG, what is equally important to the successful implementation of a compliance program?
  • When is the HIPAA Privacy Rule retraining of the workforce required?
  • What is the main objective of conducting compliance reviews in healthcare billing?
  • What is a key difference between the Anti-Kickback Statute and Stark Law?
  • Which of the following is NOT typically included in codes of conduct?
  • Which action does NOT support a robust compliance program?
  • In-kind payments as restitution may include which of the following?
  • What is considered the most important aspect of a compliance program?
  • What identification is essential for employees in a compliance program?
  • What destruction method is used for magnetic tape medical records?
  • What defines a breach in the context of healthcare compliance?
  • Can the same individual serve as both the designated privacy and security official under HIPAA?
  • How many identifiers are listed in the HIPAA Privacy Rules?
  • Which term describes the 'provision, coordination, or management of health care and related services'?
  • What is a critical first step in the compliance auditing process?
  • What should a compliance professional do to prevent a billing error from recurring after it has been identified?
  • In what year was the Equal Employment Opportunity Commission created?
  • What is the correct term for physicians billing for services performed by residents in teaching hospitals?
  • The FSG - Culpability Score is used to determine what?
  • How long is a corporate integrity agreement typically enforced?
  • Which of the following would be classified as a technical safeguard?
  • What does the acronym OHCA stand for?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy