Chapter 3 of 420% of exam
Compliance and Regulatory Standards
Billing specialists operate under federal privacy, security, and fraud-and-abuse laws. Understanding HIPAA, the False Claims Act, the Anti-Kickback Statute, and documentation rules protects patients and shields the practice from penalties.
HIPAA Privacy and Security
The Privacy Rule protects individually identifiable health information (PHI) in all forms and grants patients rights to access their records.
The Security Rule protects electronic PHI through administrative, physical, and technical safeguards.
The minimum necessary standard limits use and disclosure of PHI to what is needed, except for treatment and patient-authorized disclosures.
Accessing records without a work-related reason (snooping) is an impermissible use that violates HIPAA.
HIPAA Transactions, Notices, and Breaches
HIPAA standardizes electronic transactions and code sets, such as the 837 claim and 835 remittance.
A Notice of Privacy Practices tells patients how their PHI is used and disclosed and describes their rights.
The Breach Notification Rule requires notifying affected individuals, and sometimes HHS and the media, within required timeframes after a breach of unsecured PHI.
Fraud and Abuse Laws
The False Claims Act imposes liability for knowingly submitting false claims to federal programs and includes qui tam whistleblower provisions.
The Anti-Kickback Statute prohibits offering or receiving remuneration to induce referrals of federal health care business.
The Stark Law bars physician self-referral for designated health services to entities with which the physician has a financial relationship, unless an exception applies.
Oversight and the ABN
The Office of Inspector General detects fraud, waste, and abuse and maintains the list of excluded parties.
An Advance Beneficiary Notice of Noncoverage warns a Medicare patient in advance that a service may be denied so the patient can accept financial responsibility.
A compliance program uses policies, training, and auditing to prevent and detect violations.
Documentation, NPI, and Retention
Documentation must support every code billed and demonstrate medical necessity; if it was not documented, it is treated as not done.
The NPI uniquely identifies covered providers in HIPAA standard transactions.
Record retention periods are set by federal and state laws and payer requirements; follow the most stringent applicable rule.
Test your knowledge
Practice questions on Compliance and Regulatory Standards
Last updated: July 2026