94 questions

Compliance & Regulatory

The HIPAA Privacy Rule primarily protects:

  • a.Only electronic billing software
  • b.A provider's business financial records only
  • c.The design of insurance ID cards
  • d.The privacy of individually identifiable health information (protected health information)

The HIPAA Privacy Rule sets national standards protecting individuals' protected health information (PHI) held or transmitted by covered entities and their business associates. It limits how PHI may be used and disclosed and grants patients rights over their information. Billing staff must safeguard PHI and disclose only the minimum necessary.HIPAA

Compliance & Regulatory

The HIPAA 'minimum necessary' standard requires that covered entities:

  • a.Never share information even for treatment
  • b.Disclose all available patient information on every request
  • c.Limit the use and disclosure of PHI to the least amount needed to accomplish the intended purpose
  • d.Encrypt only paper records

The minimum necessary standard directs that when using or disclosing PHI, or requesting it, covered entities limit the information to what is reasonably needed for the specific purpose. It does not apply to disclosures for treatment or those authorized by the patient. Applying it in billing means sharing only the data a payer needs to adjudicate a claim.HIPAA

Compliance & Regulatory

The HIPAA Security Rule specifically addresses the protection of:

  • a.The provider's marketing materials
  • b.Electronic protected health information through administrative, physical, and technical safeguards
  • c.Paper records stored in a basement only
  • d.Employee salary information

The HIPAA Security Rule establishes standards for safeguarding electronic protected health information (ePHI), requiring administrative, physical, and technical safeguards such as access controls, encryption where appropriate, and audit controls. It complements the Privacy Rule, which covers PHI in all forms. Billing systems that store ePHI must meet these safeguards.HIPAA

Compliance & Regulatory

A 'business associate' under HIPAA is:

  • a.Any employee of the covered entity
  • b.A patient's family member
  • c.A competing medical practice
  • d.A person or entity that performs functions involving PHI on behalf of a covered entity, such as a billing company

A business associate is an outside person or organization that creates, receives, maintains, or transmits PHI to perform services for a covered entity, such as a third-party billing service or clearinghouse. HIPAA requires a written business associate agreement defining safeguards. Business associates are directly liable for certain HIPAA obligations.HIPAA

Compliance & Regulatory

Under HIPAA, a patient generally has the right to:

  • a.Demand that the provider delete all records permanently
  • b.Prevent all billing to their insurance
  • c.Set the provider's fee schedule
  • d.Access and request a copy of their own medical records

HIPAA grants individuals the right to access and obtain copies of their protected health information held in a designated record set, subject to limited exceptions. Patients may also request amendments and an accounting of certain disclosures. Providers must respond within the timeframes the rule specifies.HIPAA

Compliance & Regulatory

The HIPAA transactions and code sets standards were established to:

  • a.Replace the need for medical records
  • b.Standardize the electronic exchange of health care data, such as claims, using uniform formats and code sets
  • c.Set physician salaries
  • d.Determine which drugs are covered

HIPAA's transactions and code sets standards require covered entities to use uniform electronic formats, such as the 837 claim and 835 remittance, and standard code sets like ICD-10-CM, CPT, and HCPCS. Standardization streamlines electronic data interchange between providers and payers. It reduces the administrative burden of differing payer formats.HIPAA

Compliance & Regulatory

The federal False Claims Act imposes liability primarily on those who:

  • a.Charge a patient a copayment
  • b.Submit any claim that is later denied
  • c.Knowingly submit, or cause to be submitted, false or fraudulent claims for payment to the government
  • d.Use an outdated fax machine

The False Claims Act creates liability for knowingly presenting false or fraudulent claims to federal programs such as Medicare and Medicaid, including billing for services not rendered or upcoding. 'Knowingly' includes acting with reckless disregard or deliberate ignorance, not just actual knowledge. Penalties can include substantial fines and multiplied damages.False Claims Act

Compliance & Regulatory

A 'qui tam' provision under the False Claims Act allows:

  • a.A private individual (a whistleblower) to file suit on behalf of the government and potentially share in any recovery
  • b.Patients to change their diagnosis
  • c.Payers to set fee schedules
  • d.Providers to appeal any denial

The qui tam provision lets a private person, often an employee who discovers fraud, bring a lawsuit on the government's behalf and receive a portion of amounts recovered. This encourages insiders to report false claims. The law also protects such whistleblowers from retaliation.False Claims Act

Compliance & Regulatory

The federal Anti-Kickback Statute prohibits:

  • a.Knowingly offering, paying, soliciting, or receiving anything of value to induce referrals of federal health program business
  • b.Accepting Medicare assignment
  • c.Providing free educational pamphlets to patients
  • d.Billing a patient's secondary insurance

The Anti-Kickback Statute makes it a crime to knowingly and willfully exchange, or offer to exchange, remuneration to induce or reward referrals of items or services payable by a federal health care program. Violations can bring criminal, civil, and administrative penalties. Certain safe harbors protect specified legitimate business arrangements.Anti-Kickback Statute

Compliance & Regulatory

The physician self-referral law (the Stark Law) generally prohibits a physician from:

  • a.Referring any patient to a specialist
  • b.Billing Medicare for office visits
  • c.Accepting insurance
  • d.Referring Medicare patients for certain designated health services to an entity with which the physician has a financial relationship, unless an exception applies

The Stark Law bars physicians from referring Medicare patients for specific designated health services to entities in which the physician or an immediate family member has a financial interest, absent a qualifying exception. Unlike the Anti-Kickback Statute, Stark is a strict-liability civil law that does not require intent. Claims resulting from prohibited referrals are not payable.CMS

Compliance & Regulatory

The Office of Inspector General (OIG) of the Department of Health and Human Services is primarily responsible for:

  • a.Setting physician office hours
  • b.Selling insurance policies
  • c.Detecting and preventing fraud, waste, and abuse in federal health care programs
  • d.Assigning CPT codes

The OIG protects the integrity of HHS programs, including Medicare and Medicaid, by investigating fraud and abuse, conducting audits, and issuing compliance guidance. It maintains a list of individuals and entities excluded from federal health programs. Providers check this exclusion list to avoid employing or contracting with excluded parties.CMS

Compliance & Regulatory

An Advance Beneficiary Notice of Noncoverage (ABN) is given to a Medicare patient to:

  • a.Collect the copay in advance for all visits
  • b.Inform the patient in advance that Medicare may not pay for a service so the patient can decide whether to accept financial responsibility
  • c.Guarantee that Medicare will pay
  • d.Serve as the patient's insurance card

An ABN notifies a Medicare beneficiary before a service is provided that Medicare is likely to deny payment, allowing the patient to choose whether to receive the service and accept liability. Without a properly executed ABN, the provider generally cannot bill the patient for the denied amount. It must be given in advance and clearly explain the reason coverage may be denied.CMS

Compliance & Regulatory

The National Provider Identifier (NPI) is required under HIPAA to:

  • a.Determine patient copayments
  • b.Uniquely identify covered health care providers in standard transactions
  • c.Track patient diagnoses
  • d.Set the Medicare conversion factor

The NPI is a unique ten-digit identifier assigned to covered health care providers and required on HIPAA standard transactions such as claims. It standardizes provider identification across payers, replacing legacy identifiers. Accurate NPI reporting is essential to avoid claim rejections.

Compliance & Regulatory

Accurate and complete medical record documentation is important for billing because:

  • a.It determines the patient's premium
  • b.It replaces the need for coding
  • c.It sets the provider's tax rate
  • d.It supports the codes billed and demonstrates the medical necessity of services

Documentation in the medical record must support every code reported and justify that services were medically necessary; the principle is that if it was not documented, it was not done. Insufficient documentation is a leading cause of denials and audit findings. Coders should assign codes based only on what the record supports.

Compliance & Regulatory

If a billing staff member accesses a patient's record out of curiosity, with no job-related reason, this is:

  • a.Required by the minimum necessary rule
  • b.Always permitted because the staff works there
  • c.An impermissible use of PHI that violates HIPAA
  • d.Allowed if the patient is famous

Accessing PHI without a legitimate work-related purpose, sometimes called snooping, is an impermissible use that violates the HIPAA Privacy Rule and the minimum necessary standard. Covered entities must limit access to what each role requires and may discipline violators. Such breaches can trigger penalties for both the individual and the organization.HIPAA

Compliance & Regulatory

A compliance program in a medical practice is designed to:

  • a.Prevent and detect violations of law and promote ethical, accurate billing practices
  • b.Increase the number of claims denied
  • c.Eliminate the need for documentation
  • d.Set higher charges than competitors

An effective compliance program establishes policies, training, auditing, and reporting mechanisms to help a practice follow coding, billing, and privacy laws and catch problems early. The OIG has published guidance outlining key elements of such programs. A strong compliance culture reduces the risk of fraud, abuse, and penalties.

Compliance & Regulatory

A breach of unsecured protected health information under HIPAA generally requires the covered entity to:

  • a.Ignore it if fewer than 100 records are involved
  • b.Charge the affected patients a fee
  • c.Immediately delete all patient records
  • d.Notify affected individuals, and in some cases HHS and the media, within required timeframes

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, and depending on the breach's size, HHS and sometimes the media, within specified timeframes after discovering a breach of unsecured PHI. Business associates must notify the covered entity of breaches. Timely, proper notification is a legal obligation, not optional.HIPAA

Compliance & Regulatory

Medical record retention requirements are generally set by:

  • a.The patient's preference alone
  • b.The number of pages in the record
  • c.The provider's mood
  • d.Federal and state laws and payer requirements, which specify minimum retention periods

How long medical and billing records must be kept is governed by a combination of federal rules, state laws, and payer contracts, with retention periods that vary by record type and jurisdiction. Practices should follow the most stringent applicable requirement. Proper retention supports audits, appeals, and legal defense.

Compliance & Regulatory

Obtaining a patient's signed authorization is generally required before a provider may:

  • a.Share information with another treating provider for care
  • b.Disclose PHI for purposes not otherwise permitted, such as many marketing uses
  • c.Report a communicable disease as required by law
  • d.Submit a claim to the patient's insurer for treatment

HIPAA permits certain uses and disclosures of PHI without authorization, including for treatment, payment, and health care operations, and for legally required public-health reporting. However, disclosures outside these permitted purposes, such as most marketing or the sale of PHI, require the patient's written authorization. Billing staff should know which activities need a signed authorization.

Compliance & Regulatory

A Notice of Privacy Practices (NPP) is a document that a covered entity must:

  • a.Send only to insurance companies
  • b.Provide to patients describing how their PHI may be used and disclosed and their privacy rights
  • c.Use to set the fee schedule
  • d.Keep hidden from patients

HIPAA requires covered entities to give patients a Notice of Privacy Practices explaining how the practice may use and disclose PHI and outlining patients' rights regarding their information. Providers with a direct treatment relationship must make a good-faith effort to obtain acknowledgment of receipt. The notice promotes transparency about privacy practices.HIPAA

Compliance & Regulatory

Which agency is responsible for enforcing the HIPAA Privacy and Security Rules?

  • a.The HHS Office for Civil Rights (OCR)
  • b.The Internal Revenue Service
  • c.The Office of Inspector General
  • d.The Federal Trade Commission

The HHS Office for Civil Rights investigates HIPAA complaints and can impose penalties for violations. The OIG focuses on fraud, waste, and abuse in federal health programs. Knowing the enforcer helps staff understand HIPAA accountability.HIPAA

Compliance & Regulatory

Under HIPAA, PHI may be used or disclosed WITHOUT patient authorization for:

  • a.Treatment, payment, and health care operations
  • b.Any purpose the staff member chooses
  • c.Selling patient lists to outside marketers
  • d.Posting patient cases on social media

HIPAA permits use and disclosure for treatment, payment, and health care operations (TPO) without authorization. Most other uses, such as marketing or sale of PHI, require the patient's written authorization. Billing falls under the permitted payment purpose.HIPAA

Compliance & Regulatory

Health information that has been properly de-identified under HIPAA:

  • a.Can never be used for any research purpose
  • b.Must be reported to the Office for Civil Rights
  • c.Still requires a signed business associate agreement
  • d.Is no longer PHI subject to the Privacy Rule

Properly de-identified data, using Safe Harbor removal of the 18 identifiers or expert determination, is not PHI and is not subject to Privacy Rule limits. Re-identification would restore protection. De-identification enables broader analytic use.HIPAA

Compliance & Regulatory

Protected health information (PHI) under HIPAA includes identifiable health information that is:

  • a.Oral, paper, or electronic
  • b.Only information written on paper charts
  • c.Only information stored in electronic systems
  • d.Only information that is spoken aloud

PHI covers individually identifiable health information in any form, including spoken, written, and electronic. The Security Rule adds specific safeguards for electronic PHI (ePHI). Staff must protect PHI regardless of its format.HIPAA

Compliance & Regulatory

If a patient pays in full out of pocket and asks the provider not to disclose that service to the health plan, HIPAA requires the provider to:

  • a.Refuse the patient's request and bill the plan anyway
  • b.Honor the restriction and withhold it from the plan
  • c.Charge the patient an additional penalty
  • d.Report the patient's request to Medicare

Under HITECH-era rules, a provider must grant a requested restriction when the patient pays in full out of pocket for the service. This is one restriction request the provider cannot decline. It gives patients control over disclosures to their plan.HIPAA

Compliance & Regulatory

The HIPAA right to an 'accounting of disclosures' allows a patient to:

  • a.View other patients' medical records
  • b.Set the provider's fee schedule
  • c.Request a list of certain disclosures of their PHI
  • d.Demand the practice's internal financial statements

Patients may request an accounting of specified disclosures of their PHI over a defined period, generally excluding routine TPO disclosures. It is one of several patient rights under the Privacy Rule. The practice must respond within required timeframes.HIPAA

Compliance & Regulatory

An 'incidental' disclosure of PHI, such as a patient overhearing a name at a counter, is permitted under HIPAA when the covered entity has:

  • a.Notified both the Office for Civil Rights and the patient beforehand
  • b.Applied reasonable safeguards and the minimum necessary standard
  • c.Obtained a court order in advance
  • d.Charged the patient a disclosure fee

Incidental disclosures are not violations when reasonable safeguards and the minimum necessary standard are already in place. Speaking quietly and limiting information are examples of such safeguards. HIPAA does not require eliminating every incidental exposure.HIPAA

Compliance & Regulatory

HIPAA permits disclosing relevant PHI to a family member involved in a patient's care when:

  • a.The family member simply asks for it
  • b.The patient agrees or does not object
  • c.The information is already public
  • d.The information concerns anyone's care

Disclosure to those involved in a patient's care is allowed with the patient's agreement, when the patient does not object, or based on professional judgment if the patient is not present. Only relevant information should be shared. Minimum necessary still applies.HIPAA

Compliance & Regulatory

Under HIPAA, psychotherapy notes receive special protection and generally:

  • a.Are never considered PHI at all
  • b.May be shared like any other part of the record
  • c.Require a specific authorization to disclose
  • d.Must be posted in the waiting room

Psychotherapy notes are held to a higher standard, and most disclosures require a separate, specific authorization. They are kept apart from the general medical record. This extra protection reflects their sensitivity.HIPAA

Compliance & Regulatory

HIPAA gives patients the right to request that a covered entity:

  • a.Delete all of their medical records from the system permanently
  • b.Waive the plan deductible
  • c.Change a diagnosis to lower their bill
  • d.Amend PHI they believe is inaccurate or incomplete

Patients may request an amendment to PHI they believe is wrong or incomplete. The provider may deny the request under defined conditions but must document the decision. The original entry is not erased when an amendment is made.HIPAA

Compliance & Regulatory

The HIPAA 'minimum necessary' standard does NOT apply to disclosures:

  • a.Shared with a business associate
  • b.Made to the patient or for treatment purposes
  • c.Made to a payer in order to adjudicate a submitted claim
  • d.Sent to an outside marketing vendor

Minimum necessary does not restrict disclosures to the individual, for treatment, or those made under the patient's authorization. It does apply to routine payment and operations disclosures. This ensures clinicians can share what treatment requires.HIPAA

Compliance & Regulatory

Which of the following is a HIPAA 'covered entity'?

  • a.A health care clearinghouse that processes claims
  • b.A patient receiving medical care
  • c.A software vendor that never handles any PHI at all
  • d.A newspaper reporter writing a story

Covered entities are health plans, health care clearinghouses, and providers who transmit health information in standard electronic transactions. Patients and unrelated third parties are not covered entities. Business associates are separately regulated.HIPAA

Compliance & Regulatory

Before a medical practice shares PHI with an outside billing company, HIPAA requires:

  • a.A signed business associate agreement (BAA)
  • b.Approval from the patient's employer
  • c.A public press release to the community
  • d.A copy of the patient's insurance ID card

A business associate agreement obligates the outside vendor to safeguard PHI and use it only as permitted. It must be in place before PHI is disclosed for services. Business associates are directly liable for certain HIPAA requirements.HIPAA

Compliance & Regulatory

The HITECH Act strengthened HIPAA mainly by:

  • a.Raising penalties and extending liability to business associates
  • b.Removing the breach-notification requirements that apply to business associates
  • c.Eliminating the Privacy Rule entirely
  • d.Making PHI freely shareable with anyone

HITECH boosted HIPAA enforcement, raised penalty amounts, added breach-notification duties, and made business associates directly liable. It also promoted electronic health record adoption. These changes tightened protection of health information.HITECH

Compliance & Regulatory

HIPAA civil monetary penalties are tiered primarily according to:

  • a.The medical specialty of the provider
  • b.The number of employees at the practice
  • c.The dollar size of the patient's medical bill
  • d.The covered entity's level of culpability

Penalty tiers rise with culpability, from unknowing violations up to willful neglect that is not corrected. Higher culpability carries larger per-violation penalties. Prompt correction can reduce exposure.HIPAA

Compliance & Regulatory

Following discovery of a breach of unsecured PHI, HIPAA generally requires that affected individuals be notified without unreasonable delay and no later than:

  • a.1 year after discovery
  • b.60 days after discovery of the breach
  • c.24 hours after discovery
  • d.The end of the following calendar quarter

Individuals must be notified within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500 or more individuals also require prompt notice to HHS and the media. Timely notification is a legal obligation.HIPAA

Compliance & Regulatory

A breach of unsecured PHI affecting 500 or more individuals additionally requires the covered entity to notify:

  • a.No one, as long as the data was on paper
  • b.Only the affected patients, and no one else
  • c.HHS and prominent media in the affected area
  • d.The patient's current employer

Large breaches of 500 or more individuals trigger prompt notification to HHS and to prominent media in the area. Smaller breaches are logged and reported to HHS annually. The size of the breach drives the notification requirements.HIPAA

Compliance & Regulatory

A required administrative safeguard under the HIPAA Security Rule is:

  • a.Sharing a single password among all staff
  • b.Conducting a security risk analysis of ePHI
  • c.Encrypting the office's marketing brochures
  • d.Publishing patient names on a public website

A security risk analysis is a required administrative safeguard that drives other protections. Administrative safeguards also include workforce training and sanction policies. Physical and technical safeguards address facilities and systems.HIPAA

Compliance & Regulatory

Which is an example of a HIPAA Security Rule PHYSICAL safeguard?

  • a.Assigning unique user login IDs
  • b.Conducting workforce sanction and disciplinary policies
  • c.Encrypting data during transmission
  • d.Facility access controls and workstation security

Physical safeguards cover facility access controls, workstation use and security, and device and media controls. Encryption and unique IDs are technical safeguards, and sanction policies are administrative. Each category protects ePHI in a different way.HIPAA

Compliance & Regulatory

Which is a HIPAA Security Rule TECHNICAL safeguard for electronic PHI?

  • a.Training staff on privacy policies
  • b.Shredding old paper records
  • c.Access controls, audit logs, and encryption
  • d.Locking the medical-record file room

Technical safeguards include access control, audit controls, integrity controls, authentication, and transmission security such as encryption. Locking rooms is a physical safeguard and training is administrative. Together they protect ePHI.HIPAA

Compliance & Regulatory

An 'addressable' implementation specification under the HIPAA Security Rule means the covered entity must:

  • a.Assess it and implement it or a documented equivalent
  • b.Ignore the specification entirely
  • c.Obtain written permission from the Office for Civil Rights before acting
  • d.Always skip it to reduce costs

Addressable does not mean optional; the entity must evaluate the specification and either implement it, adopt an equivalent measure, or document why it is not reasonable. Required specifications must always be implemented. Both types protect ePHI.HIPAA

Compliance & Regulatory

Assigning each staff member a unique login and prohibiting password sharing supports HIPAA by:

  • a.Enabling audit trails that trace activity to individuals
  • b.Increasing the payer's allowed amount
  • c.Speeding up insurance claim payment
  • d.Replacing the need for a business associate agreement

Unique user IDs and audit controls are technical safeguards that let a practice trace who accessed ePHI. Shared logins defeat accountability and audit trails. This supports both security and investigation of misuse.HIPAA

Compliance & Regulatory

Proper disposal of paper records containing PHI requires that they be:

  • a.Recycled along with general office paper
  • b.Mailed back to the insurance payer
  • c.Left in an unlocked collection bin
  • d.Shredded or otherwise rendered unreadable

PHI must be destroyed so it cannot be read or reconstructed, typically by shredding. Tossing PHI in regular trash is a common breach source. Proper disposal is part of reasonable safeguards.HIPAA

Compliance & Regulatory

When emailing PHI to an external party, a reasonable HIPAA safeguard is to:

  • a.Post it to a publicly shared folder
  • b.Send it from a personal webmail account
  • c.Include the entire record for convenience
  • d.Use encryption and verify the recipient address

Encrypting the message and confirming the recipient reduces the risk of an impermissible disclosure. Minimum necessary still applies, so only needed information should be sent. These safeguards help prevent email breaches.HIPAA

Compliance & Regulatory

A staff member posting a patient's identifiable information on social media is:

  • a.Allowed when the patient is well known
  • b.A HIPAA violation and a reportable breach of PHI
  • c.Permitted as long as the post is later deleted quickly
  • d.Required as part of marketing

Posting identifiable PHI without authorization is an impermissible disclosure and a reportable breach, regardless of intent or how briefly it appears. Fame does not remove HIPAA protection. Such conduct can lead to penalties and discipline.HIPAA

Compliance & Regulatory

The HIPAA standard transactions for an electronic eligibility inquiry and its response are the:

  • a.270 and 271
  • b.276 and 277
  • c.278 and 275
  • d.837 and 835

The 270 is the eligibility inquiry and the 271 is the response. The 276/277 pair handles claim status and the 278 handles prior authorization. Standard transactions streamline electronic exchange with payers.HIPAA

Compliance & Regulatory

The HIPAA standard transaction used to request prior authorization or referral certification is the:

  • a.835
  • b.837I
  • c.278
  • d.271

The 278 is the services review transaction used for prior authorization and referral requests and responses. The 837 is the claim and the 835 is the remittance advice. Standardizing these exchanges reduces administrative burden.HIPAA

Compliance & Regulatory

Under HIPAA, the required code set for reporting diagnoses is:

  • a.HCPCS Level II
  • b.ICD-10-CM
  • c.ICD-10-PCS
  • d.CPT Category I

ICD-10-CM is the adopted code set for diagnoses. ICD-10-PCS is for hospital inpatient procedures, and CPT and HCPCS report services and supplies. Using the correct code set is required for standard transactions.HIPAA

Compliance & Regulatory

The HIPAA-adopted code set for reporting hospital INPATIENT procedures is:

  • a.ICD-10-CM
  • b.CPT Category I
  • c.National Drug Codes
  • d.ICD-10-PCS

ICD-10-PCS codes hospital inpatient procedures, while CPT is used for physician and outpatient procedures. ICD-10-CM reports diagnoses, not procedures. Selecting the right set depends on the setting.HIPAA

Compliance & Regulatory

The National Drug Code (NDC) is the HIPAA-adopted code set used to identify:

  • a.Patient diagnoses
  • b.Physician work RVUs
  • c.Drugs and biologics
  • d.Places of service

The NDC identifies specific drug products by manufacturer, product, and package. It is often required on drug claims alongside HCPCS J-codes. Correct NDC reporting supports accurate drug reimbursement.HIPAA

Compliance & Regulatory

The HIPAA standard national identifier for employers used in transactions is the:

  • a.Employer Identification Number (EIN)
  • b.National Provider Identifier
  • c.Patient's Social Security Number
  • d.Medicare Beneficiary Identifier

HIPAA adopted the EIN as the standard employer identifier and the NPI as the provider identifier. Standard identifiers make electronic transactions consistent across payers. Correct identifiers help prevent rejections.HIPAA

Compliance & Regulatory

The key difference between health care 'fraud' and 'abuse' is that fraud:

  • a.Involves knowing intent to deceive, unlike abuse
  • b.Is always purely accidental
  • c.Never involves federal programs or the beneficiaries they cover
  • d.Cannot result in any penalties

Fraud is intentional deception or misrepresentation for gain, while abuse involves practices inconsistent with sound fiscal or medical norms that may lack intent. Both waste program dollars and can carry penalties. Intent is the distinguishing factor.

Compliance & Regulatory

Which of the following is an example of health care FRAUD?

  • a.Appealing a denial with medical records
  • b.Collecting the correct patient copay
  • c.Billing Medicare for a service that was never provided
  • d.Submitting a properly coded claim that is later denied by the payer

Billing for services never rendered is classic fraud, as are upcoding and deliberate unbundling to gain payment. A denied claim or a proper appeal is not fraud. Fraud requires intent to obtain unearned payment.

Compliance & Regulatory

Which situation best illustrates 'abuse' rather than outright fraud?

  • a.Creating entirely fake patient encounters
  • b.Forging a physician's signature on a note
  • c.Billing inconsistent with accepted practices, without proven intent
  • d.Deliberately falsifying a diagnosis on the claim in order to be paid a higher amount

Abuse involves improper practices that waste resources without established intent to deceive. Deliberate falsification, forgery, and fabricated encounters are fraud because intent is present. The line between them is the presence of intent.

Compliance & Regulatory

Selecting a higher-level evaluation and management code than the documentation supports, to increase payment, is:

  • a.Upcoding, a form of fraudulent billing
  • b.Downcoding, which payers require
  • c.A routine contractual adjustment
  • d.A permitted rounding practice

Upcoding misrepresents the level of service to obtain higher payment and is fraudulent. Codes must match what the record documents. Both upcoding and its opposite, deliberate downcoding, distort accurate billing.

Compliance & Regulatory

Reporting the separate components of a procedure that has a single comprehensive code, in order to increase payment, is called:

  • a.Bundling
  • b.Unbundling
  • c.Sequencing
  • d.Crosswalking

Unbundling fragments a comprehensive procedure into separate codes to raise reimbursement. NCCI edits are designed to detect it. When done to gain higher pay, unbundling is abusive or fraudulent.

Compliance & Regulatory

Beyond repaying the claim, the federal False Claims Act can impose:

  • a.A reduction in the Medicare conversion factor for the year
  • b.Automatic loss of the patient's coverage
  • c.A simple warning letter only
  • d.Civil penalties per claim plus multiple (treble) damages

The False Claims Act allows per-claim civil penalties and up to treble (three times) the government's damages. It is a powerful tool against health care fraud. Liability attaches to knowingly submitting false claims.False Claims Act

Compliance & Regulatory

The Civil Monetary Penalties Law (CMPL) allows the government to:

  • a.Impose penalties for specified improper billing conduct
  • b.Approve the prior authorization requests that providers submit to payers
  • c.Set physician fee schedules
  • d.License new health care providers

The CMPL authorizes financial penalties and assessments for conduct such as false claims, kickbacks, and employing excluded individuals. It complements other fraud and abuse laws. Penalties can be substantial per violation.CMS

Compliance & Regulatory

The OIG List of Excluded Individuals and Entities (LEIE) is checked by employers to ensure they do not:

  • a.Exceed the Medicare limiting charge on a submitted claim
  • b.Overpay their own staff
  • c.Employ parties barred from federal health programs
  • d.Miss a timely-filing deadline

Paying an excluded individual or entity with federal health care funds can trigger civil monetary penalties. Employers screen the LEIE before hiring or contracting and periodically thereafter. Exclusion screening is a compliance safeguard.CMS

Compliance & Regulatory

Compared with the Stark Law, the Anti-Kickback Statute is distinctive because it:

  • a.Is a strict-liability civil law that contains no intent element at all
  • b.Governs medical-record retention periods
  • c.Applies only to dental services
  • d.Requires knowing and willful intent and can carry criminal penalties

The Anti-Kickback Statute requires knowing and willful intent and can bring criminal, civil, and administrative penalties. The Stark Law, by contrast, is strict-liability and civil. Both target improper financial arrangements tied to referrals.Anti-Kickback Statute

Compliance & Regulatory

'Safe harbors' under the Anti-Kickback Statute are:

  • a.Penalties assessed for late claims
  • b.Loopholes in the statute that permit any kickback arrangement so long as it is disclosed
  • c.Arrangements protected from prosecution if all conditions are met
  • d.Codes entered on the CMS-1500 form

Safe harbors describe specific arrangements that, when every condition is satisfied, are shielded from Anti-Kickback prosecution. Failing to fit a safe harbor is not automatically illegal but loses that protection. They guide lawful business relationships.Anti-Kickback Statute

Compliance & Regulatory

A distinguishing feature of the Stark Law is that it:

  • a.Requires proof of criminal intent to violate
  • b.Applies only to private-pay cosmetic patients
  • c.Sets the OPPS payment rates
  • d.Imposes liability even without proof of intent

The Stark Law is a strict-liability civil statute, so a prohibited self-referral can violate it regardless of intent. Claims from prohibited referrals are not payable. This differs from the intent-based Anti-Kickback Statute.CMS

Compliance & Regulatory

The Stark Law restricts physician self-referral specifically for:

  • a.Certain designated health services under Medicare
  • b.All cash-pay cosmetic procedures performed in a physician office
  • c.Any referral to any specialist
  • d.Employee wage decisions

Stark applies when a physician refers Medicare patients for designated health services to an entity with which the physician has a financial relationship, unless an exception applies. It does not bar all referrals. Designated services include labs, imaging, and therapy.CMS

Compliance & Regulatory

The OIG's guidance on an effective compliance program includes designating a compliance officer, training, auditing, and:

  • a.Eliminating clinical documentation
  • b.Corrective action for detected offenses
  • c.Waiving all patient cost-sharing
  • d.Maximizing every claim's payment

The seven elements include written standards, a compliance officer, training, open lines of communication, auditing and monitoring, enforcement, and prompt corrective action for detected problems. These reduce fraud and abuse risk. Corrective action closes the loop.CMS

Compliance & Regulatory

A designated compliance officer in a practice is primarily responsible for:

  • a.Approving prior authorization requests
  • b.Setting the chargemaster prices
  • c.Overseeing the compliance program
  • d.Negotiating the Medicare conversion factor

The compliance officer implements policies, coordinates training and auditing, and responds to reported issues. This role is a core element of an effective compliance program. It supports a culture of accurate, lawful billing.CMS

Compliance & Regulatory

A Corporate Integrity Agreement (CIA) is typically entered when a provider:

  • a.Wants to raise its contracted fee schedule
  • b.Applies for a new National Provider Identifier to use for billing
  • c.Settles fraud allegations and accepts compliance obligations
  • d.Requests faster claim payment

A CIA imposes detailed compliance obligations, monitoring, and reporting after a fraud settlement, often as an alternative to program exclusion. It lets the provider continue participating under oversight. Breaching a CIA can lead to penalties or exclusion.CMS

Compliance & Regulatory

Medicare Recovery Audit Contractors (RACs) are hired to:

  • a.Identify and recover improper Medicare payments
  • b.Assign diagnosis codes on behalf of providers
  • c.Set each patient's deductible amount
  • d.Sell Medicare Advantage plans to beneficiaries

RACs review claims after payment to detect and correct improper payments, which can require repayment or, less often, additional payment. Providers may appeal RAC findings. The program protects Medicare trust funds.CMS

Compliance & Regulatory

The Comprehensive Error Rate Testing (CERT) program measures:

  • a.Average physician office wait times experienced by patients
  • b.The number of NPIs issued each year
  • c.Patient satisfaction survey scores
  • d.The Medicare fee-for-service improper payment rate

CERT samples Medicare fee-for-service claims to estimate the improper payment rate and identify common error causes. Findings inform education and program-integrity efforts. It is a measurement, not an enforcement, program.CMS

Compliance & Regulatory

Medical necessity for a billed service is primarily demonstrated by:

  • a.The provider's specialty alone
  • b.The overall size of the practice
  • c.A diagnosis that supports the procedure performed
  • d.The patient's own personal request for the service

Payment for a covered service requires that the diagnosis support the procedure and that the record document the clinical need. Services lacking medical necessity are denied even when coded correctly. Diagnosis-to-procedure linkage is key.

Compliance & Regulatory

A Local Coverage Determination (LCD) differs from a National Coverage Determination (NCD) in that an LCD:

  • a.Is set by a regional contractor for its jurisdiction
  • b.Applies nationwide to every Medicare contractor equally
  • c.Overrides all federal statutes
  • d.Is written by the patient's employer

NCDs apply nationally, while LCDs are issued by Medicare Administrative Contractors for their regions when no NCD governs. Coverage can therefore vary by locality. Checking the applicable determination supports medical-necessity decisions.CMS

Compliance & Regulatory

An Advance Beneficiary Notice (ABN) is generally NOT appropriate to give a Medicare patient when:

  • a.The provider expects the service to be non-covered
  • b.Medicare is likely to deny the service as not medically necessary
  • c.A screening test exceeds Medicare's frequency limit
  • d.The service is being furnished in a genuine emergency

An ABN must be given in advance and never under duress, so it is not appropriate during a true emergency. It is used when denial is expected for lack of medical necessity or frequency limits. The patient must be able to make an informed choice.CMS

Compliance & Regulatory

Modifier GA on a Medicare claim indicates that:

  • a.The provider forgot to issue an ABN
  • b.A required Advance Beneficiary Notice is on file for the service
  • c.The service is statutorily excluded from all Medicare coverage
  • d.The claim is for a bilateral procedure

Modifier GA signals that a required ABN was properly issued and is on file when a denial is expected. GZ indicates no ABN was obtained, and GY indicates a statutorily excluded service. Correct ABN modifiers determine who is liable for a denied charge.CMS

Compliance & Regulatory

Modifier GZ is reported when a service is expected to be denied as not reasonable and necessary and:

  • a.The patient has no Medicare coverage
  • b.No ABN was obtained from the patient
  • c.The service is always fully covered
  • d.An ABN is properly on file for the service

GZ marks an expected denial for which no ABN was obtained, meaning the provider generally cannot bill the patient for the denied amount. Had an ABN been issued, GA would apply. It flags a likely non-billable denial.CMS

Compliance & Regulatory

Modifier GY indicates that an item or service is:

  • a.Covered but pending medical review
  • b.Subject to a 50 percent payment reduction
  • c.Bundled into a surgical global package
  • d.Statutorily excluded and not a Medicare benefit

GY identifies a service that is statutorily excluded or not a Medicare benefit, often used to obtain a denial for secondary billing. The patient is liable for such non-covered services. It differs from GA and GZ, which involve medical-necessity ABNs.CMS

Compliance & Regulatory

The billing principle 'if it was not documented, it was not done' means that:

  • a.Verbal orders never need to be recorded
  • b.Only the busiest visits require any notes
  • c.Services must be supported by the medical record to be billable
  • d.Documentation may be added at any later time without dating it

A service that is not documented is treated as not performed and is not billable. The record is the basis for code assignment and survives audits. Complete, contemporaneous documentation supports the codes reported.

Compliance & Regulatory

A proper amendment or late entry in a medical record must:

  • a.Be backdated to the visit date
  • b.Be labeled, dated, and signed, keeping the original
  • c.Be made anonymously by any available staff member on duty
  • d.Erase the original text entirely

Amendments and late entries must be identifiable, dated, signed, and must preserve the original entry. Backdating or altering records improperly can constitute fraud. Proper documentation practices protect both patient and provider.

Compliance & Regulatory

'Cloned' documentation, where notes are copied identically across visits, is a compliance concern because it:

  • a.Removes the need for provider signatures
  • b.May misrepresent the services at each visit
  • c.Is specifically required by Medicare
  • d.Always improves coding accuracy

Cloned or copy-forward notes can misrepresent what happened at each encounter and are a frequent audit target. Each visit needs individualized documentation. Overreliance on cloning can lead to denials and fraud findings.

Compliance & Regulatory

Medicare generally requires that services in the medical record be:

  • a.Authenticated by a legible or valid electronic signature
  • b.Left unsigned to save time
  • c.Signed only by the billing clerk
  • d.Approved and countersigned by the patient before any claim is billed

Entries must be authenticated by the rendering provider through a legible handwritten or valid electronic signature. Missing or illegible signatures are a common cause of audit denials. Authentication confirms who performed and documented the service.CMS

Compliance & Regulatory

National Correct Coding Initiative (NCCI) Procedure-to-Procedure (PTP) edits identify:

  • a.Which diagnoses a plan will cover
  • b.The maximum number of units of a single code that are allowed per day
  • c.The patient's remaining deductible
  • d.Code pairs that should not be reported together the same day

PTP edits flag code pairs that generally should not be billed together, using column one and column two logic. A supporting modifier may override the edit when a distinct service is documented. They help prevent improper unbundling.CMS

Compliance & Regulatory

A Medically Unlikely Edit (MUE) sets:

  • a.The maximum units billable per patient per day
  • b.The provider's contracted fee-schedule amount
  • c.The minimum charge for a service
  • d.The list of covered diagnoses

MUEs cap the units of a HCPCS or CPT code reportable for one patient on one day to catch errors and abuse. Units above the limit may be denied. MUEs complement the PTP edits within NCCI.CMS

Compliance & Regulatory

When an NCCI Procedure-to-Procedure edit has a modifier indicator of '1', it means:

  • a.No modifier can ever bypass the edit
  • b.A modifier may bypass the edit when documented
  • c.The two codes must always be billed together
  • d.The edit does not apply to Medicare claims

A modifier indicator of 1 allows a supporting modifier to override the edit when the services are truly distinct. An indicator of 0 means no modifier can bypass the edit. Documentation must justify any modifier used.CMS

Compliance & Regulatory

Reviewing electronic health record access logs helps a practice:

  • a.Increase the payer's allowed amount
  • b.Set the timely-filing deadline
  • c.Assign procedure codes automatically and set the payer timely-filing deadline
  • d.Detect impermissible access to PHI, such as staff snooping

Audit controls and access logs are technical safeguards that reveal snooping and other impermissible access. Reviewing them supports HIPAA compliance and appropriate sanctions. Monitoring deters misuse of PHI.HIPAA

Compliance & Regulatory

A HIPAA-required 'sanction policy' means the covered entity must:

  • a.Report every submitted claim to the Office for Civil Rights
  • b.Waive penalties for managers
  • c.Discipline staff who violate privacy or security policies
  • d.Reward staff for accessing more records

A sanction policy, an administrative safeguard, requires consistent discipline for workforce HIPAA violations. It reinforces accountability and deters misconduct. Applying it uniformly is part of an effective program.HIPAA

Compliance & Regulatory

Under the False Claims Act, an employee who reports suspected fraud in good faith is:

  • a.Automatically terminated from employment
  • b.Barred from sharing in any recovery
  • c.Required to pay the resulting penalties
  • d.Protected from employer retaliation

The False Claims Act includes anti-retaliation protections for good-faith whistleblowers, who may also share in qui tam recoveries. Retaliation can create additional liability for the employer. These protections encourage reporting of fraud.False Claims Act

Compliance & Regulatory

HIPAA requires covered entities to retain required HIPAA documentation, such as policies and the Notice of Privacy Practices, for at least:

  • a.6 years from creation or last effective date
  • b.1 year after creation
  • c.30 days after creation
  • d.At least 100 years, the same period required for medical records

The Privacy and Security Rules require HIPAA compliance documentation to be kept for six years. This is separate from medical-record retention, which is set by state and other law. Retaining documentation supports audits and investigations.HIPAA

Compliance & Regulatory

CMS requires records related to Medicare Advantage (Part C) and Part D to be retained for at least:

  • a.2 years
  • b.10 years
  • c.6 months
  • d.No set period under HIPAA

CMS mandates a 10-year retention period for Medicare Advantage and Part D records. Retention requirements vary by program and by state law. Practices should follow the most stringent applicable rule.CMS

Compliance & Regulatory

When federal HIPAA and a state privacy law both apply and the state law is MORE protective of the patient, the practice should generally:

  • a.Follow whichever rule is easier
  • b.Ignore the state law entirely
  • c.Follow the more stringent state law
  • d.Apply neither requirement

HIPAA sets a federal floor, and more protective state privacy laws are generally not preempted. The practice must follow the stricter requirement. This ensures patients receive the greater protection.HIPAA

Compliance & Regulatory

Before disclosing PHI over the phone to a caller who claims to be the patient, staff should:

  • a.Ask the caller for a credit card number in order to confirm the account
  • b.Release all information immediately
  • c.Refuse to speak with any patient
  • d.Verify the caller's identity before releasing information

Verifying identity is a reasonable safeguard that prevents improper disclosure to an impostor. Only the minimum necessary information should then be shared. Identity verification protects the patient's PHI.HIPAA

Compliance & Regulatory

A valid HIPAA authorization to disclose PHI for a non-routine purpose must:

  • a.Be signed by the payer or a family member instead of the patient, with no description of the information or an expiration date
  • b.Omit any expiration date
  • c.Describe the information, the recipient, the purpose, and an expiration, and be signed
  • d.Be verbal and undocumented

A valid authorization contains core elements: a specific description of the information, who may disclose and receive it, the purpose, an expiration, the patient's signature, and the right to revoke. It is required for uses beyond treatment, payment, and operations. Missing elements make it invalid.HIPAA

Compliance & Regulatory

A patient who has signed a HIPAA authorization to release PHI generally may:

  • a.Revoke it only with a court order
  • b.Never revoke it once it is signed
  • c.Revoke it in order to undo disclosures already made
  • d.Revoke it in writing, but only going forward

Authorizations are revocable in writing, but the revocation is prospective and does not undo disclosures already made in reliance on it. Patients retain control going forward. The right to revoke must be stated in the authorization.HIPAA

Compliance & Regulatory

A periodic internal coding and billing audit is a compliance activity that primarily:

  • a.Guarantees higher reimbursement on every claim
  • b.Replaces the need for clinical documentation
  • c.Identifies coding errors and overpayment risks
  • d.Sets the payer's fee schedule

Proactive auditing and monitoring is a core compliance-program element that finds and corrects errors before they grow. It reduces fraud and abuse exposure and supports accurate billing. Self-identified overpayments should be refunded promptly.CMS

Compliance & Regulatory

Knowingly retaining a Medicare overpayment beyond the deadline to return it can create liability under the:

  • a.False Claims Act
  • b.Fair Debt Collection Practices Act
  • c.Truth in Lending Act
  • d.HIPAA Security Rule

The Affordable Care Act made retaining an identified overpayment past the 60-day deadline a potential reverse false claim under the False Claims Act. Timely refunds avoid this exposure. It links overpayment handling to fraud enforcement.False Claims Act

Compliance & Regulatory

HIPAA permits disclosure of PHI WITHOUT patient authorization for:

  • a.Legally required public health reporting
  • b.Sharing with an employer for hiring decisions
  • c.Posting patient outcomes on the internet
  • d.Selling the information to a marketer

HIPAA allows specified disclosures without authorization, including required public health reporting and certain oversight and law-enforcement purposes. Marketing and sale of PHI require authorization. Knowing the permitted disclosures guides lawful sharing.HIPAA

Compliance & Regulatory

When documentation is ambiguous or conflicting, the compliant action for a coder is to:

  • a.Leave the encounter permanently unbilled
  • b.Query the provider rather than assume a code
  • c.Assign the highest-paying plausible code
  • d.Guess based on the patient's history

A non-leading provider query resolves ambiguous or conflicting documentation before coding. Codes must reflect the clarified record, never assumptions made to increase payment. Querying supports both accuracy and compliance.

¿Qué tan difícil es el examen?

El NHA CBCS (Certified Billing and Coding Specialist) tiene 120 preguntas (100 calificadas más 20 de prueba) en 2 horas 40 minutos. La tarifa es $119. Los especialistas en registros médicos ganan una mediana de unos $50,250 al año (BLS, mayo 2024).

Horas de estudio recomendadas
50-90 horas para la mayoría — las secciones de codificación ICD-10-CM y CPT necesitan más práctica.
Tasa de aprobación publicada
73.82% de todos los exámenes administrados (quien se examina dos veces cuenta dos veces) (n = 6,905) — NHA, 2024.Fuente: NHA — Pass Rates for NHA Examinations Administered in 2024 (PDF)
Por dónde empezar
La Codificación es el área mayor con 45% — codificación de diagnósticos ICD-10-CM y codificación de procedimientos CPT/HCPCS.

Las tarifas y los salarios son aproximados y cambian con el tiempo. La tasa de aprobación de arriba se cita de la fuente enlazada junto a ella, para el periodo que esa fuente cubre; cuando no hemos verificado una fuente, lo decimos y no damos ninguna cifra.

Reportar