CSLB General Building (B) — All Questions
← Back to practice20 questions
The HIPAA Privacy Rule primarily protects:
- a.Only electronic billing software
- b.The privacy of individually identifiable health information (protected health information)✓
- c.A provider's business financial records only
- d.The design of insurance ID cards
The HIPAA Privacy Rule sets national standards protecting individuals' protected health information (PHI) held or transmitted by covered entities and their business associates. It limits how PHI may be used and disclosed and grants patients rights over their information. Billing staff must safeguard PHI and disclose only the minimum necessary.HIPAA
The HIPAA 'minimum necessary' standard requires that covered entities:
- a.Disclose all available patient information on every request
- b.Never share information even for treatment
- c.Limit the use and disclosure of PHI to the least amount needed to accomplish the intended purpose✓
- d.Encrypt only paper records
The minimum necessary standard directs that when using or disclosing PHI, or requesting it, covered entities limit the information to what is reasonably needed for the specific purpose. It does not apply to disclosures for treatment or those authorized by the patient. Applying it in billing means sharing only the data a payer needs to adjudicate a claim.HIPAA
The HIPAA Security Rule specifically addresses the protection of:
- a.Electronic protected health information through administrative, physical, and technical safeguards✓
- b.Paper records stored in a basement only
- c.Employee salary information
- d.The provider's marketing materials
The HIPAA Security Rule establishes standards for safeguarding electronic protected health information (ePHI), requiring administrative, physical, and technical safeguards such as access controls, encryption where appropriate, and audit controls. It complements the Privacy Rule, which covers PHI in all forms. Billing systems that store ePHI must meet these safeguards.HIPAA
A 'business associate' under HIPAA is:
- a.A patient's family member
- b.A competing medical practice
- c.Any employee of the covered entity
- d.A person or entity that performs functions involving PHI on behalf of a covered entity, such as a billing company✓
A business associate is an outside person or organization that creates, receives, maintains, or transmits PHI to perform services for a covered entity, such as a third-party billing service or clearinghouse. HIPAA requires a written business associate agreement defining safeguards. Business associates are directly liable for certain HIPAA obligations.HIPAA
Under HIPAA, a patient generally has the right to:
- a.Prevent all billing to their insurance
- b.Access and request a copy of their own medical records✓
- c.Demand that the provider delete all records permanently
- d.Set the provider's fee schedule
HIPAA grants individuals the right to access and obtain copies of their protected health information held in a designated record set, subject to limited exceptions. Patients may also request amendments and an accounting of certain disclosures. Providers must respond within the timeframes the rule specifies.HIPAA
The HIPAA transactions and code sets standards were established to:
- a.Set physician salaries
- b.Determine which drugs are covered
- c.Standardize the electronic exchange of health care data, such as claims, using uniform formats and code sets✓
- d.Replace the need for medical records
HIPAA's transactions and code sets standards require covered entities to use uniform electronic formats, such as the 837 claim and 835 remittance, and standard code sets like ICD-10-CM, CPT, and HCPCS. Standardization streamlines electronic data interchange between providers and payers. It reduces the administrative burden of differing payer formats.HIPAA
The federal False Claims Act imposes liability primarily on those who:
- a.Knowingly submit, or cause to be submitted, false or fraudulent claims for payment to the government✓
- b.Submit any claim that is later denied
- c.Charge a patient a copayment
- d.Use an outdated fax machine
The False Claims Act creates liability for knowingly presenting false or fraudulent claims to federal programs such as Medicare and Medicaid, including billing for services not rendered or upcoding. 'Knowingly' includes acting with reckless disregard or deliberate ignorance, not just actual knowledge. Penalties can include substantial fines and multiplied damages.False Claims Act
A 'qui tam' provision under the False Claims Act allows:
- a.Providers to appeal any denial
- b.Patients to change their diagnosis
- c.Payers to set fee schedules
- d.A private individual (a whistleblower) to file suit on behalf of the government and potentially share in any recovery✓
The qui tam provision lets a private person, often an employee who discovers fraud, bring a lawsuit on the government's behalf and receive a portion of amounts recovered. This encourages insiders to report false claims. The law also protects such whistleblowers from retaliation.False Claims Act
The federal Anti-Kickback Statute prohibits:
- a.Billing a patient's secondary insurance
- b.Knowingly offering, paying, soliciting, or receiving anything of value to induce referrals of federal health program business✓
- c.Providing free educational pamphlets to patients
- d.Accepting Medicare assignment
The Anti-Kickback Statute makes it a crime to knowingly and willfully exchange, or offer to exchange, remuneration to induce or reward referrals of items or services payable by a federal health care program. Violations can bring criminal, civil, and administrative penalties. Certain safe harbors protect specified legitimate business arrangements.Anti-Kickback Statute
The physician self-referral law (the Stark Law) generally prohibits a physician from:
- a.Referring any patient to a specialist
- b.Billing Medicare for office visits
- c.Referring Medicare patients for certain designated health services to an entity with which the physician has a financial relationship, unless an exception applies✓
- d.Accepting insurance
The Stark Law bars physicians from referring Medicare patients for specific designated health services to entities in which the physician or an immediate family member has a financial interest, absent a qualifying exception. Unlike the Anti-Kickback Statute, Stark is a strict-liability civil law that does not require intent. Claims resulting from prohibited referrals are not payable.CMS
The Office of Inspector General (OIG) of the Department of Health and Human Services is primarily responsible for:
- a.Detecting and preventing fraud, waste, and abuse in federal health care programs✓
- b.Setting physician office hours
- c.Assigning CPT codes
- d.Selling insurance policies
The OIG protects the integrity of HHS programs, including Medicare and Medicaid, by investigating fraud and abuse, conducting audits, and issuing compliance guidance. It maintains a list of individuals and entities excluded from federal health programs. Providers check this exclusion list to avoid employing or contracting with excluded parties.CMS
An Advance Beneficiary Notice of Noncoverage (ABN) is given to a Medicare patient to:
- a.Guarantee that Medicare will pay
- b.Collect the copay in advance for all visits
- c.Serve as the patient's insurance card
- d.Inform the patient in advance that Medicare may not pay for a service so the patient can decide whether to accept financial responsibility✓
An ABN notifies a Medicare beneficiary before a service is provided that Medicare is likely to deny payment, allowing the patient to choose whether to receive the service and accept liability. Without a properly executed ABN, the provider generally cannot bill the patient for the denied amount. It must be given in advance and clearly explain the reason coverage may be denied.CMS
The National Provider Identifier (NPI) is required under HIPAA to:
- a.Track patient diagnoses
- b.Uniquely identify covered health care providers in standard transactions✓
- c.Determine patient copayments
- d.Set the Medicare conversion factor
The NPI is a unique ten-digit identifier assigned to covered health care providers and required on HIPAA standard transactions such as claims. It standardizes provider identification across payers, replacing legacy identifiers. Accurate NPI reporting is essential to avoid claim rejections.
Accurate and complete medical record documentation is important for billing because:
- a.It sets the provider's tax rate
- b.It replaces the need for coding
- c.It supports the codes billed and demonstrates the medical necessity of services✓
- d.It determines the patient's premium
Documentation in the medical record must support every code reported and justify that services were medically necessary; the principle is that if it was not documented, it was not done. Insufficient documentation is a leading cause of denials and audit findings. Coders should assign codes based only on what the record supports.
If a billing staff member accesses a patient's record out of curiosity, with no job-related reason, this is:
- a.An impermissible use of PHI that violates HIPAA✓
- b.Always permitted because the staff works there
- c.Allowed if the patient is famous
- d.Required by the minimum necessary rule
Accessing PHI without a legitimate work-related purpose, sometimes called snooping, is an impermissible use that violates the HIPAA Privacy Rule and the minimum necessary standard. Covered entities must limit access to what each role requires and may discipline violators. Such breaches can trigger penalties for both the individual and the organization.HIPAA
A compliance program in a medical practice is designed to:
- a.Increase the number of claims denied
- b.Eliminate the need for documentation
- c.Set higher charges than competitors
- d.Prevent and detect violations of law and promote ethical, accurate billing practices✓
An effective compliance program establishes policies, training, auditing, and reporting mechanisms to help a practice follow coding, billing, and privacy laws and catch problems early. The OIG has published guidance outlining key elements of such programs. A strong compliance culture reduces the risk of fraud, abuse, and penalties.
A breach of unsecured protected health information under HIPAA generally requires the covered entity to:
- a.Ignore it if fewer than 100 records are involved
- b.Notify affected individuals, and in some cases HHS and the media, within required timeframes✓
- c.Immediately delete all patient records
- d.Charge the affected patients a fee
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, and depending on the breach's size, HHS and sometimes the media, within specified timeframes after discovering a breach of unsecured PHI. Business associates must notify the covered entity of breaches. Timely, proper notification is a legal obligation, not optional.HIPAA
Medical record retention requirements are generally set by:
- a.The patient's preference alone
- b.The provider's mood
- c.Federal and state laws and payer requirements, which specify minimum retention periods✓
- d.The number of pages in the record
How long medical and billing records must be kept is governed by a combination of federal rules, state laws, and payer contracts, with retention periods that vary by record type and jurisdiction. Practices should follow the most stringent applicable requirement. Proper retention supports audits, appeals, and legal defense.
Obtaining a patient's signed authorization is generally required before a provider may:
- a.Disclose PHI for purposes not otherwise permitted, such as many marketing uses✓
- b.Submit a claim to the patient's insurer for treatment
- c.Share information with another treating provider for care
- d.Report a communicable disease as required by law
HIPAA permits certain uses and disclosures of PHI without authorization, including for treatment, payment, and health care operations, and for legally required public-health reporting. However, disclosures outside these permitted purposes, such as most marketing or the sale of PHI, require the patient's written authorization. Billing staff should know which activities need a signed authorization.
A Notice of Privacy Practices (NPP) is a document that a covered entity must:
- a.Send only to insurance companies
- b.Keep hidden from patients
- c.Provide to patients describing how their PHI may be used and disclosed and their privacy rights✓
- d.Use to set the fee schedule
HIPAA requires covered entities to give patients a Notice of Privacy Practices explaining how the practice may use and disclose PHI and outlining patients' rights regarding their information. Providers with a direct treatment relationship must make a good-faith effort to obtain acknowledgment of receipt. The notice promotes transparency about privacy practices.HIPAA