NHA Medical Billing & Coding (CBCS) — All Questions
Sở hữu trọn bộ hướng dẫn Medical Billing & Coding (CBCS) — PDF + EPUB, $14.99 →
← Back to practice94 questions
The HIPAA Privacy Rule primarily protects:
- a.Only electronic billing software
- b.A provider's business financial records only
- c.The design of insurance ID cards
- d.The privacy of individually identifiable health information (protected health information)✓
The HIPAA Privacy Rule sets national standards protecting individuals' protected health information (PHI) held or transmitted by covered entities and their business associates. It limits how PHI may be used and disclosed and grants patients rights over their information. Billing staff must safeguard PHI and disclose only the minimum necessary.HIPAA
The HIPAA 'minimum necessary' standard requires that covered entities:
- a.Never share information even for treatment
- b.Disclose all available patient information on every request
- c.Limit the use and disclosure of PHI to the least amount needed to accomplish the intended purpose✓
- d.Encrypt only paper records
The minimum necessary standard directs that when using or disclosing PHI, or requesting it, covered entities limit the information to what is reasonably needed for the specific purpose. It does not apply to disclosures for treatment or those authorized by the patient. Applying it in billing means sharing only the data a payer needs to adjudicate a claim.HIPAA
The HIPAA Security Rule specifically addresses the protection of:
- a.The provider's marketing materials
- b.Electronic protected health information through administrative, physical, and technical safeguards✓
- c.Paper records stored in a basement only
- d.Employee salary information
The HIPAA Security Rule establishes standards for safeguarding electronic protected health information (ePHI), requiring administrative, physical, and technical safeguards such as access controls, encryption where appropriate, and audit controls. It complements the Privacy Rule, which covers PHI in all forms. Billing systems that store ePHI must meet these safeguards.HIPAA
A 'business associate' under HIPAA is:
- a.Any employee of the covered entity
- b.A patient's family member
- c.A competing medical practice
- d.A person or entity that performs functions involving PHI on behalf of a covered entity, such as a billing company✓
A business associate is an outside person or organization that creates, receives, maintains, or transmits PHI to perform services for a covered entity, such as a third-party billing service or clearinghouse. HIPAA requires a written business associate agreement defining safeguards. Business associates are directly liable for certain HIPAA obligations.HIPAA
Under HIPAA, a patient generally has the right to:
- a.Demand that the provider delete all records permanently
- b.Prevent all billing to their insurance
- c.Set the provider's fee schedule
- d.Access and request a copy of their own medical records✓
HIPAA grants individuals the right to access and obtain copies of their protected health information held in a designated record set, subject to limited exceptions. Patients may also request amendments and an accounting of certain disclosures. Providers must respond within the timeframes the rule specifies.HIPAA
The HIPAA transactions and code sets standards were established to:
- a.Replace the need for medical records
- b.Standardize the electronic exchange of health care data, such as claims, using uniform formats and code sets✓
- c.Set physician salaries
- d.Determine which drugs are covered
HIPAA's transactions and code sets standards require covered entities to use uniform electronic formats, such as the 837 claim and 835 remittance, and standard code sets like ICD-10-CM, CPT, and HCPCS. Standardization streamlines electronic data interchange between providers and payers. It reduces the administrative burden of differing payer formats.HIPAA
The federal False Claims Act imposes liability primarily on those who:
- a.Charge a patient a copayment
- b.Submit any claim that is later denied
- c.Knowingly submit, or cause to be submitted, false or fraudulent claims for payment to the government✓
- d.Use an outdated fax machine
The False Claims Act creates liability for knowingly presenting false or fraudulent claims to federal programs such as Medicare and Medicaid, including billing for services not rendered or upcoding. 'Knowingly' includes acting with reckless disregard or deliberate ignorance, not just actual knowledge. Penalties can include substantial fines and multiplied damages.False Claims Act
A 'qui tam' provision under the False Claims Act allows:
- a.A private individual (a whistleblower) to file suit on behalf of the government and potentially share in any recovery✓
- b.Patients to change their diagnosis
- c.Payers to set fee schedules
- d.Providers to appeal any denial
The qui tam provision lets a private person, often an employee who discovers fraud, bring a lawsuit on the government's behalf and receive a portion of amounts recovered. This encourages insiders to report false claims. The law also protects such whistleblowers from retaliation.False Claims Act
The federal Anti-Kickback Statute prohibits:
- a.Knowingly offering, paying, soliciting, or receiving anything of value to induce referrals of federal health program business✓
- b.Accepting Medicare assignment
- c.Providing free educational pamphlets to patients
- d.Billing a patient's secondary insurance
The Anti-Kickback Statute makes it a crime to knowingly and willfully exchange, or offer to exchange, remuneration to induce or reward referrals of items or services payable by a federal health care program. Violations can bring criminal, civil, and administrative penalties. Certain safe harbors protect specified legitimate business arrangements.Anti-Kickback Statute
The physician self-referral law (the Stark Law) generally prohibits a physician from:
- a.Referring any patient to a specialist
- b.Billing Medicare for office visits
- c.Accepting insurance
- d.Referring Medicare patients for certain designated health services to an entity with which the physician has a financial relationship, unless an exception applies✓
The Stark Law bars physicians from referring Medicare patients for specific designated health services to entities in which the physician or an immediate family member has a financial interest, absent a qualifying exception. Unlike the Anti-Kickback Statute, Stark is a strict-liability civil law that does not require intent. Claims resulting from prohibited referrals are not payable.CMS
The Office of Inspector General (OIG) of the Department of Health and Human Services is primarily responsible for:
- a.Setting physician office hours
- b.Selling insurance policies
- c.Detecting and preventing fraud, waste, and abuse in federal health care programs✓
- d.Assigning CPT codes
The OIG protects the integrity of HHS programs, including Medicare and Medicaid, by investigating fraud and abuse, conducting audits, and issuing compliance guidance. It maintains a list of individuals and entities excluded from federal health programs. Providers check this exclusion list to avoid employing or contracting with excluded parties.CMS
An Advance Beneficiary Notice of Noncoverage (ABN) is given to a Medicare patient to:
- a.Collect the copay in advance for all visits
- b.Inform the patient in advance that Medicare may not pay for a service so the patient can decide whether to accept financial responsibility✓
- c.Guarantee that Medicare will pay
- d.Serve as the patient's insurance card
An ABN notifies a Medicare beneficiary before a service is provided that Medicare is likely to deny payment, allowing the patient to choose whether to receive the service and accept liability. Without a properly executed ABN, the provider generally cannot bill the patient for the denied amount. It must be given in advance and clearly explain the reason coverage may be denied.CMS
The National Provider Identifier (NPI) is required under HIPAA to:
- a.Determine patient copayments
- b.Uniquely identify covered health care providers in standard transactions✓
- c.Track patient diagnoses
- d.Set the Medicare conversion factor
The NPI is a unique ten-digit identifier assigned to covered health care providers and required on HIPAA standard transactions such as claims. It standardizes provider identification across payers, replacing legacy identifiers. Accurate NPI reporting is essential to avoid claim rejections.
Accurate and complete medical record documentation is important for billing because:
- a.It determines the patient's premium
- b.It replaces the need for coding
- c.It sets the provider's tax rate
- d.It supports the codes billed and demonstrates the medical necessity of services✓
Documentation in the medical record must support every code reported and justify that services were medically necessary; the principle is that if it was not documented, it was not done. Insufficient documentation is a leading cause of denials and audit findings. Coders should assign codes based only on what the record supports.
If a billing staff member accesses a patient's record out of curiosity, with no job-related reason, this is:
- a.Required by the minimum necessary rule
- b.Always permitted because the staff works there
- c.An impermissible use of PHI that violates HIPAA✓
- d.Allowed if the patient is famous
Accessing PHI without a legitimate work-related purpose, sometimes called snooping, is an impermissible use that violates the HIPAA Privacy Rule and the minimum necessary standard. Covered entities must limit access to what each role requires and may discipline violators. Such breaches can trigger penalties for both the individual and the organization.HIPAA
A compliance program in a medical practice is designed to:
- a.Prevent and detect violations of law and promote ethical, accurate billing practices✓
- b.Increase the number of claims denied
- c.Eliminate the need for documentation
- d.Set higher charges than competitors
An effective compliance program establishes policies, training, auditing, and reporting mechanisms to help a practice follow coding, billing, and privacy laws and catch problems early. The OIG has published guidance outlining key elements of such programs. A strong compliance culture reduces the risk of fraud, abuse, and penalties.
A breach of unsecured protected health information under HIPAA generally requires the covered entity to:
- a.Ignore it if fewer than 100 records are involved
- b.Charge the affected patients a fee
- c.Immediately delete all patient records
- d.Notify affected individuals, and in some cases HHS and the media, within required timeframes✓
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, and depending on the breach's size, HHS and sometimes the media, within specified timeframes after discovering a breach of unsecured PHI. Business associates must notify the covered entity of breaches. Timely, proper notification is a legal obligation, not optional.HIPAA
Medical record retention requirements are generally set by:
- a.The patient's preference alone
- b.The number of pages in the record
- c.The provider's mood
- d.Federal and state laws and payer requirements, which specify minimum retention periods✓
How long medical and billing records must be kept is governed by a combination of federal rules, state laws, and payer contracts, with retention periods that vary by record type and jurisdiction. Practices should follow the most stringent applicable requirement. Proper retention supports audits, appeals, and legal defense.
Obtaining a patient's signed authorization is generally required before a provider may:
- a.Share information with another treating provider for care
- b.Disclose PHI for purposes not otherwise permitted, such as many marketing uses✓
- c.Report a communicable disease as required by law
- d.Submit a claim to the patient's insurer for treatment
HIPAA permits certain uses and disclosures of PHI without authorization, including for treatment, payment, and health care operations, and for legally required public-health reporting. However, disclosures outside these permitted purposes, such as most marketing or the sale of PHI, require the patient's written authorization. Billing staff should know which activities need a signed authorization.
A Notice of Privacy Practices (NPP) is a document that a covered entity must:
- a.Send only to insurance companies
- b.Provide to patients describing how their PHI may be used and disclosed and their privacy rights✓
- c.Use to set the fee schedule
- d.Keep hidden from patients
HIPAA requires covered entities to give patients a Notice of Privacy Practices explaining how the practice may use and disclose PHI and outlining patients' rights regarding their information. Providers with a direct treatment relationship must make a good-faith effort to obtain acknowledgment of receipt. The notice promotes transparency about privacy practices.HIPAA
Which agency is responsible for enforcing the HIPAA Privacy and Security Rules?
- a.The HHS Office for Civil Rights (OCR)✓
- b.The Internal Revenue Service
- c.The Office of Inspector General
- d.The Federal Trade Commission
The HHS Office for Civil Rights investigates HIPAA complaints and can impose penalties for violations. The OIG focuses on fraud, waste, and abuse in federal health programs. Knowing the enforcer helps staff understand HIPAA accountability.HIPAA
Under HIPAA, PHI may be used or disclosed WITHOUT patient authorization for:
- a.Treatment, payment, and health care operations✓
- b.Any purpose the staff member chooses
- c.Selling patient lists to outside marketers
- d.Posting patient cases on social media
HIPAA permits use and disclosure for treatment, payment, and health care operations (TPO) without authorization. Most other uses, such as marketing or sale of PHI, require the patient's written authorization. Billing falls under the permitted payment purpose.HIPAA
Health information that has been properly de-identified under HIPAA:
- a.Can never be used for any research purpose
- b.Must be reported to the Office for Civil Rights
- c.Still requires a signed business associate agreement
- d.Is no longer PHI subject to the Privacy Rule✓
Properly de-identified data, using Safe Harbor removal of the 18 identifiers or expert determination, is not PHI and is not subject to Privacy Rule limits. Re-identification would restore protection. De-identification enables broader analytic use.HIPAA
Protected health information (PHI) under HIPAA includes identifiable health information that is:
- a.Oral, paper, or electronic✓
- b.Only information written on paper charts
- c.Only information stored in electronic systems
- d.Only information that is spoken aloud
PHI covers individually identifiable health information in any form, including spoken, written, and electronic. The Security Rule adds specific safeguards for electronic PHI (ePHI). Staff must protect PHI regardless of its format.HIPAA
If a patient pays in full out of pocket and asks the provider not to disclose that service to the health plan, HIPAA requires the provider to:
- a.Refuse the patient's request and bill the plan anyway
- b.Honor the restriction and withhold it from the plan✓
- c.Charge the patient an additional penalty
- d.Report the patient's request to Medicare
Under HITECH-era rules, a provider must grant a requested restriction when the patient pays in full out of pocket for the service. This is one restriction request the provider cannot decline. It gives patients control over disclosures to their plan.HIPAA
The HIPAA right to an 'accounting of disclosures' allows a patient to:
- a.View other patients' medical records
- b.Set the provider's fee schedule
- c.Request a list of certain disclosures of their PHI✓
- d.Demand the practice's internal financial statements
Patients may request an accounting of specified disclosures of their PHI over a defined period, generally excluding routine TPO disclosures. It is one of several patient rights under the Privacy Rule. The practice must respond within required timeframes.HIPAA
An 'incidental' disclosure of PHI, such as a patient overhearing a name at a counter, is permitted under HIPAA when the covered entity has:
- a.Notified both the Office for Civil Rights and the patient beforehand
- b.Applied reasonable safeguards and the minimum necessary standard✓
- c.Obtained a court order in advance
- d.Charged the patient a disclosure fee
Incidental disclosures are not violations when reasonable safeguards and the minimum necessary standard are already in place. Speaking quietly and limiting information are examples of such safeguards. HIPAA does not require eliminating every incidental exposure.HIPAA
HIPAA permits disclosing relevant PHI to a family member involved in a patient's care when:
- a.The family member simply asks for it
- b.The patient agrees or does not object✓
- c.The information is already public
- d.The information concerns anyone's care
Disclosure to those involved in a patient's care is allowed with the patient's agreement, when the patient does not object, or based on professional judgment if the patient is not present. Only relevant information should be shared. Minimum necessary still applies.HIPAA
Under HIPAA, psychotherapy notes receive special protection and generally:
- a.Are never considered PHI at all
- b.May be shared like any other part of the record
- c.Require a specific authorization to disclose✓
- d.Must be posted in the waiting room
Psychotherapy notes are held to a higher standard, and most disclosures require a separate, specific authorization. They are kept apart from the general medical record. This extra protection reflects their sensitivity.HIPAA
HIPAA gives patients the right to request that a covered entity:
- a.Delete all of their medical records from the system permanently
- b.Waive the plan deductible
- c.Change a diagnosis to lower their bill
- d.Amend PHI they believe is inaccurate or incomplete✓
Patients may request an amendment to PHI they believe is wrong or incomplete. The provider may deny the request under defined conditions but must document the decision. The original entry is not erased when an amendment is made.HIPAA
The HIPAA 'minimum necessary' standard does NOT apply to disclosures:
- a.Shared with a business associate
- b.Made to the patient or for treatment purposes✓
- c.Made to a payer in order to adjudicate a submitted claim
- d.Sent to an outside marketing vendor
Minimum necessary does not restrict disclosures to the individual, for treatment, or those made under the patient's authorization. It does apply to routine payment and operations disclosures. This ensures clinicians can share what treatment requires.HIPAA
Which of the following is a HIPAA 'covered entity'?
- a.A health care clearinghouse that processes claims✓
- b.A patient receiving medical care
- c.A software vendor that never handles any PHI at all
- d.A newspaper reporter writing a story
Covered entities are health plans, health care clearinghouses, and providers who transmit health information in standard electronic transactions. Patients and unrelated third parties are not covered entities. Business associates are separately regulated.HIPAA
Before a medical practice shares PHI with an outside billing company, HIPAA requires:
- a.A signed business associate agreement (BAA)✓
- b.Approval from the patient's employer
- c.A public press release to the community
- d.A copy of the patient's insurance ID card
A business associate agreement obligates the outside vendor to safeguard PHI and use it only as permitted. It must be in place before PHI is disclosed for services. Business associates are directly liable for certain HIPAA requirements.HIPAA
The HITECH Act strengthened HIPAA mainly by:
- a.Raising penalties and extending liability to business associates✓
- b.Removing the breach-notification requirements that apply to business associates
- c.Eliminating the Privacy Rule entirely
- d.Making PHI freely shareable with anyone
HITECH boosted HIPAA enforcement, raised penalty amounts, added breach-notification duties, and made business associates directly liable. It also promoted electronic health record adoption. These changes tightened protection of health information.HITECH
HIPAA civil monetary penalties are tiered primarily according to:
- a.The medical specialty of the provider
- b.The number of employees at the practice
- c.The dollar size of the patient's medical bill
- d.The covered entity's level of culpability✓
Penalty tiers rise with culpability, from unknowing violations up to willful neglect that is not corrected. Higher culpability carries larger per-violation penalties. Prompt correction can reduce exposure.HIPAA
Following discovery of a breach of unsecured PHI, HIPAA generally requires that affected individuals be notified without unreasonable delay and no later than:
- a.1 year after discovery
- b.60 days after discovery of the breach✓
- c.24 hours after discovery
- d.The end of the following calendar quarter
Individuals must be notified within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500 or more individuals also require prompt notice to HHS and the media. Timely notification is a legal obligation.HIPAA
A breach of unsecured PHI affecting 500 or more individuals additionally requires the covered entity to notify:
- a.No one, as long as the data was on paper
- b.Only the affected patients, and no one else
- c.HHS and prominent media in the affected area✓
- d.The patient's current employer
Large breaches of 500 or more individuals trigger prompt notification to HHS and to prominent media in the area. Smaller breaches are logged and reported to HHS annually. The size of the breach drives the notification requirements.HIPAA
A required administrative safeguard under the HIPAA Security Rule is:
- a.Sharing a single password among all staff
- b.Conducting a security risk analysis of ePHI✓
- c.Encrypting the office's marketing brochures
- d.Publishing patient names on a public website
A security risk analysis is a required administrative safeguard that drives other protections. Administrative safeguards also include workforce training and sanction policies. Physical and technical safeguards address facilities and systems.HIPAA
Which is an example of a HIPAA Security Rule PHYSICAL safeguard?
- a.Assigning unique user login IDs
- b.Conducting workforce sanction and disciplinary policies
- c.Encrypting data during transmission
- d.Facility access controls and workstation security✓
Physical safeguards cover facility access controls, workstation use and security, and device and media controls. Encryption and unique IDs are technical safeguards, and sanction policies are administrative. Each category protects ePHI in a different way.HIPAA
Which is a HIPAA Security Rule TECHNICAL safeguard for electronic PHI?
- a.Training staff on privacy policies
- b.Shredding old paper records
- c.Access controls, audit logs, and encryption✓
- d.Locking the medical-record file room
Technical safeguards include access control, audit controls, integrity controls, authentication, and transmission security such as encryption. Locking rooms is a physical safeguard and training is administrative. Together they protect ePHI.HIPAA
An 'addressable' implementation specification under the HIPAA Security Rule means the covered entity must:
- a.Assess it and implement it or a documented equivalent✓
- b.Ignore the specification entirely
- c.Obtain written permission from the Office for Civil Rights before acting
- d.Always skip it to reduce costs
Addressable does not mean optional; the entity must evaluate the specification and either implement it, adopt an equivalent measure, or document why it is not reasonable. Required specifications must always be implemented. Both types protect ePHI.HIPAA
Assigning each staff member a unique login and prohibiting password sharing supports HIPAA by:
- a.Enabling audit trails that trace activity to individuals✓
- b.Increasing the payer's allowed amount
- c.Speeding up insurance claim payment
- d.Replacing the need for a business associate agreement
Unique user IDs and audit controls are technical safeguards that let a practice trace who accessed ePHI. Shared logins defeat accountability and audit trails. This supports both security and investigation of misuse.HIPAA
Proper disposal of paper records containing PHI requires that they be:
- a.Recycled along with general office paper
- b.Mailed back to the insurance payer
- c.Left in an unlocked collection bin
- d.Shredded or otherwise rendered unreadable✓
PHI must be destroyed so it cannot be read or reconstructed, typically by shredding. Tossing PHI in regular trash is a common breach source. Proper disposal is part of reasonable safeguards.HIPAA
When emailing PHI to an external party, a reasonable HIPAA safeguard is to:
- a.Post it to a publicly shared folder
- b.Send it from a personal webmail account
- c.Include the entire record for convenience
- d.Use encryption and verify the recipient address✓
Encrypting the message and confirming the recipient reduces the risk of an impermissible disclosure. Minimum necessary still applies, so only needed information should be sent. These safeguards help prevent email breaches.HIPAA
A staff member posting a patient's identifiable information on social media is:
- a.Allowed when the patient is well known
- b.A HIPAA violation and a reportable breach of PHI✓
- c.Permitted as long as the post is later deleted quickly
- d.Required as part of marketing
Posting identifiable PHI without authorization is an impermissible disclosure and a reportable breach, regardless of intent or how briefly it appears. Fame does not remove HIPAA protection. Such conduct can lead to penalties and discipline.HIPAA
The HIPAA standard transactions for an electronic eligibility inquiry and its response are the:
- a.270 and 271✓
- b.276 and 277
- c.278 and 275
- d.837 and 835
The 270 is the eligibility inquiry and the 271 is the response. The 276/277 pair handles claim status and the 278 handles prior authorization. Standard transactions streamline electronic exchange with payers.HIPAA
The HIPAA standard transaction used to request prior authorization or referral certification is the:
- a.835
- b.837I
- c.278✓
- d.271
The 278 is the services review transaction used for prior authorization and referral requests and responses. The 837 is the claim and the 835 is the remittance advice. Standardizing these exchanges reduces administrative burden.HIPAA
Under HIPAA, the required code set for reporting diagnoses is:
- a.HCPCS Level II
- b.ICD-10-CM✓
- c.ICD-10-PCS
- d.CPT Category I
ICD-10-CM is the adopted code set for diagnoses. ICD-10-PCS is for hospital inpatient procedures, and CPT and HCPCS report services and supplies. Using the correct code set is required for standard transactions.HIPAA
The HIPAA-adopted code set for reporting hospital INPATIENT procedures is:
- a.ICD-10-CM
- b.CPT Category I
- c.National Drug Codes
- d.ICD-10-PCS✓
ICD-10-PCS codes hospital inpatient procedures, while CPT is used for physician and outpatient procedures. ICD-10-CM reports diagnoses, not procedures. Selecting the right set depends on the setting.HIPAA
The National Drug Code (NDC) is the HIPAA-adopted code set used to identify:
- a.Patient diagnoses
- b.Physician work RVUs
- c.Drugs and biologics✓
- d.Places of service
The NDC identifies specific drug products by manufacturer, product, and package. It is often required on drug claims alongside HCPCS J-codes. Correct NDC reporting supports accurate drug reimbursement.HIPAA
The HIPAA standard national identifier for employers used in transactions is the:
- a.Employer Identification Number (EIN)✓
- b.National Provider Identifier
- c.Patient's Social Security Number
- d.Medicare Beneficiary Identifier
HIPAA adopted the EIN as the standard employer identifier and the NPI as the provider identifier. Standard identifiers make electronic transactions consistent across payers. Correct identifiers help prevent rejections.HIPAA
The key difference between health care 'fraud' and 'abuse' is that fraud:
- a.Involves knowing intent to deceive, unlike abuse✓
- b.Is always purely accidental
- c.Never involves federal programs or the beneficiaries they cover
- d.Cannot result in any penalties
Fraud is intentional deception or misrepresentation for gain, while abuse involves practices inconsistent with sound fiscal or medical norms that may lack intent. Both waste program dollars and can carry penalties. Intent is the distinguishing factor.
Which of the following is an example of health care FRAUD?
- a.Appealing a denial with medical records
- b.Collecting the correct patient copay
- c.Billing Medicare for a service that was never provided✓
- d.Submitting a properly coded claim that is later denied by the payer
Billing for services never rendered is classic fraud, as are upcoding and deliberate unbundling to gain payment. A denied claim or a proper appeal is not fraud. Fraud requires intent to obtain unearned payment.
Which situation best illustrates 'abuse' rather than outright fraud?
- a.Creating entirely fake patient encounters
- b.Forging a physician's signature on a note
- c.Billing inconsistent with accepted practices, without proven intent✓
- d.Deliberately falsifying a diagnosis on the claim in order to be paid a higher amount
Abuse involves improper practices that waste resources without established intent to deceive. Deliberate falsification, forgery, and fabricated encounters are fraud because intent is present. The line between them is the presence of intent.
Selecting a higher-level evaluation and management code than the documentation supports, to increase payment, is:
- a.Upcoding, a form of fraudulent billing✓
- b.Downcoding, which payers require
- c.A routine contractual adjustment
- d.A permitted rounding practice
Upcoding misrepresents the level of service to obtain higher payment and is fraudulent. Codes must match what the record documents. Both upcoding and its opposite, deliberate downcoding, distort accurate billing.
Reporting the separate components of a procedure that has a single comprehensive code, in order to increase payment, is called:
- a.Bundling
- b.Unbundling✓
- c.Sequencing
- d.Crosswalking
Unbundling fragments a comprehensive procedure into separate codes to raise reimbursement. NCCI edits are designed to detect it. When done to gain higher pay, unbundling is abusive or fraudulent.
Beyond repaying the claim, the federal False Claims Act can impose:
- a.A reduction in the Medicare conversion factor for the year
- b.Automatic loss of the patient's coverage
- c.A simple warning letter only
- d.Civil penalties per claim plus multiple (treble) damages✓
The False Claims Act allows per-claim civil penalties and up to treble (three times) the government's damages. It is a powerful tool against health care fraud. Liability attaches to knowingly submitting false claims.False Claims Act
The Civil Monetary Penalties Law (CMPL) allows the government to:
- a.Impose penalties for specified improper billing conduct✓
- b.Approve the prior authorization requests that providers submit to payers
- c.Set physician fee schedules
- d.License new health care providers
The CMPL authorizes financial penalties and assessments for conduct such as false claims, kickbacks, and employing excluded individuals. It complements other fraud and abuse laws. Penalties can be substantial per violation.CMS
The OIG List of Excluded Individuals and Entities (LEIE) is checked by employers to ensure they do not:
- a.Exceed the Medicare limiting charge on a submitted claim
- b.Overpay their own staff
- c.Employ parties barred from federal health programs✓
- d.Miss a timely-filing deadline
Paying an excluded individual or entity with federal health care funds can trigger civil monetary penalties. Employers screen the LEIE before hiring or contracting and periodically thereafter. Exclusion screening is a compliance safeguard.CMS
Compared with the Stark Law, the Anti-Kickback Statute is distinctive because it:
- a.Is a strict-liability civil law that contains no intent element at all
- b.Governs medical-record retention periods
- c.Applies only to dental services
- d.Requires knowing and willful intent and can carry criminal penalties✓
The Anti-Kickback Statute requires knowing and willful intent and can bring criminal, civil, and administrative penalties. The Stark Law, by contrast, is strict-liability and civil. Both target improper financial arrangements tied to referrals.Anti-Kickback Statute
'Safe harbors' under the Anti-Kickback Statute are:
- a.Penalties assessed for late claims
- b.Loopholes in the statute that permit any kickback arrangement so long as it is disclosed
- c.Arrangements protected from prosecution if all conditions are met✓
- d.Codes entered on the CMS-1500 form
Safe harbors describe specific arrangements that, when every condition is satisfied, are shielded from Anti-Kickback prosecution. Failing to fit a safe harbor is not automatically illegal but loses that protection. They guide lawful business relationships.Anti-Kickback Statute
A distinguishing feature of the Stark Law is that it:
- a.Requires proof of criminal intent to violate
- b.Applies only to private-pay cosmetic patients
- c.Sets the OPPS payment rates
- d.Imposes liability even without proof of intent✓
The Stark Law is a strict-liability civil statute, so a prohibited self-referral can violate it regardless of intent. Claims from prohibited referrals are not payable. This differs from the intent-based Anti-Kickback Statute.CMS
The Stark Law restricts physician self-referral specifically for:
- a.Certain designated health services under Medicare✓
- b.All cash-pay cosmetic procedures performed in a physician office
- c.Any referral to any specialist
- d.Employee wage decisions
Stark applies when a physician refers Medicare patients for designated health services to an entity with which the physician has a financial relationship, unless an exception applies. It does not bar all referrals. Designated services include labs, imaging, and therapy.CMS
The OIG's guidance on an effective compliance program includes designating a compliance officer, training, auditing, and:
- a.Eliminating clinical documentation
- b.Corrective action for detected offenses✓
- c.Waiving all patient cost-sharing
- d.Maximizing every claim's payment
The seven elements include written standards, a compliance officer, training, open lines of communication, auditing and monitoring, enforcement, and prompt corrective action for detected problems. These reduce fraud and abuse risk. Corrective action closes the loop.CMS
A designated compliance officer in a practice is primarily responsible for:
- a.Approving prior authorization requests
- b.Setting the chargemaster prices
- c.Overseeing the compliance program✓
- d.Negotiating the Medicare conversion factor
The compliance officer implements policies, coordinates training and auditing, and responds to reported issues. This role is a core element of an effective compliance program. It supports a culture of accurate, lawful billing.CMS
A Corporate Integrity Agreement (CIA) is typically entered when a provider:
- a.Wants to raise its contracted fee schedule
- b.Applies for a new National Provider Identifier to use for billing
- c.Settles fraud allegations and accepts compliance obligations✓
- d.Requests faster claim payment
A CIA imposes detailed compliance obligations, monitoring, and reporting after a fraud settlement, often as an alternative to program exclusion. It lets the provider continue participating under oversight. Breaching a CIA can lead to penalties or exclusion.CMS
Medicare Recovery Audit Contractors (RACs) are hired to:
- a.Identify and recover improper Medicare payments✓
- b.Assign diagnosis codes on behalf of providers
- c.Set each patient's deductible amount
- d.Sell Medicare Advantage plans to beneficiaries
RACs review claims after payment to detect and correct improper payments, which can require repayment or, less often, additional payment. Providers may appeal RAC findings. The program protects Medicare trust funds.CMS
The Comprehensive Error Rate Testing (CERT) program measures:
- a.Average physician office wait times experienced by patients
- b.The number of NPIs issued each year
- c.Patient satisfaction survey scores
- d.The Medicare fee-for-service improper payment rate✓
CERT samples Medicare fee-for-service claims to estimate the improper payment rate and identify common error causes. Findings inform education and program-integrity efforts. It is a measurement, not an enforcement, program.CMS
Medical necessity for a billed service is primarily demonstrated by:
- a.The provider's specialty alone
- b.The overall size of the practice
- c.A diagnosis that supports the procedure performed✓
- d.The patient's own personal request for the service
Payment for a covered service requires that the diagnosis support the procedure and that the record document the clinical need. Services lacking medical necessity are denied even when coded correctly. Diagnosis-to-procedure linkage is key.
A Local Coverage Determination (LCD) differs from a National Coverage Determination (NCD) in that an LCD:
- a.Is set by a regional contractor for its jurisdiction✓
- b.Applies nationwide to every Medicare contractor equally
- c.Overrides all federal statutes
- d.Is written by the patient's employer
NCDs apply nationally, while LCDs are issued by Medicare Administrative Contractors for their regions when no NCD governs. Coverage can therefore vary by locality. Checking the applicable determination supports medical-necessity decisions.CMS
An Advance Beneficiary Notice (ABN) is generally NOT appropriate to give a Medicare patient when:
- a.The provider expects the service to be non-covered
- b.Medicare is likely to deny the service as not medically necessary
- c.A screening test exceeds Medicare's frequency limit
- d.The service is being furnished in a genuine emergency✓
An ABN must be given in advance and never under duress, so it is not appropriate during a true emergency. It is used when denial is expected for lack of medical necessity or frequency limits. The patient must be able to make an informed choice.CMS
Modifier GA on a Medicare claim indicates that:
- a.The provider forgot to issue an ABN
- b.A required Advance Beneficiary Notice is on file for the service✓
- c.The service is statutorily excluded from all Medicare coverage
- d.The claim is for a bilateral procedure
Modifier GA signals that a required ABN was properly issued and is on file when a denial is expected. GZ indicates no ABN was obtained, and GY indicates a statutorily excluded service. Correct ABN modifiers determine who is liable for a denied charge.CMS
Modifier GZ is reported when a service is expected to be denied as not reasonable and necessary and:
- a.The patient has no Medicare coverage
- b.No ABN was obtained from the patient✓
- c.The service is always fully covered
- d.An ABN is properly on file for the service
GZ marks an expected denial for which no ABN was obtained, meaning the provider generally cannot bill the patient for the denied amount. Had an ABN been issued, GA would apply. It flags a likely non-billable denial.CMS
Modifier GY indicates that an item or service is:
- a.Covered but pending medical review
- b.Subject to a 50 percent payment reduction
- c.Bundled into a surgical global package
- d.Statutorily excluded and not a Medicare benefit✓
GY identifies a service that is statutorily excluded or not a Medicare benefit, often used to obtain a denial for secondary billing. The patient is liable for such non-covered services. It differs from GA and GZ, which involve medical-necessity ABNs.CMS
The billing principle 'if it was not documented, it was not done' means that:
- a.Verbal orders never need to be recorded
- b.Only the busiest visits require any notes
- c.Services must be supported by the medical record to be billable✓
- d.Documentation may be added at any later time without dating it
A service that is not documented is treated as not performed and is not billable. The record is the basis for code assignment and survives audits. Complete, contemporaneous documentation supports the codes reported.
A proper amendment or late entry in a medical record must:
- a.Be backdated to the visit date
- b.Be labeled, dated, and signed, keeping the original✓
- c.Be made anonymously by any available staff member on duty
- d.Erase the original text entirely
Amendments and late entries must be identifiable, dated, signed, and must preserve the original entry. Backdating or altering records improperly can constitute fraud. Proper documentation practices protect both patient and provider.
'Cloned' documentation, where notes are copied identically across visits, is a compliance concern because it:
- a.Removes the need for provider signatures
- b.May misrepresent the services at each visit✓
- c.Is specifically required by Medicare
- d.Always improves coding accuracy
Cloned or copy-forward notes can misrepresent what happened at each encounter and are a frequent audit target. Each visit needs individualized documentation. Overreliance on cloning can lead to denials and fraud findings.
Medicare generally requires that services in the medical record be:
- a.Authenticated by a legible or valid electronic signature✓
- b.Left unsigned to save time
- c.Signed only by the billing clerk
- d.Approved and countersigned by the patient before any claim is billed
Entries must be authenticated by the rendering provider through a legible handwritten or valid electronic signature. Missing or illegible signatures are a common cause of audit denials. Authentication confirms who performed and documented the service.CMS
National Correct Coding Initiative (NCCI) Procedure-to-Procedure (PTP) edits identify:
- a.Which diagnoses a plan will cover
- b.The maximum number of units of a single code that are allowed per day
- c.The patient's remaining deductible
- d.Code pairs that should not be reported together the same day✓
PTP edits flag code pairs that generally should not be billed together, using column one and column two logic. A supporting modifier may override the edit when a distinct service is documented. They help prevent improper unbundling.CMS
A Medically Unlikely Edit (MUE) sets:
- a.The maximum units billable per patient per day✓
- b.The provider's contracted fee-schedule amount
- c.The minimum charge for a service
- d.The list of covered diagnoses
MUEs cap the units of a HCPCS or CPT code reportable for one patient on one day to catch errors and abuse. Units above the limit may be denied. MUEs complement the PTP edits within NCCI.CMS
When an NCCI Procedure-to-Procedure edit has a modifier indicator of '1', it means:
- a.No modifier can ever bypass the edit
- b.A modifier may bypass the edit when documented✓
- c.The two codes must always be billed together
- d.The edit does not apply to Medicare claims
A modifier indicator of 1 allows a supporting modifier to override the edit when the services are truly distinct. An indicator of 0 means no modifier can bypass the edit. Documentation must justify any modifier used.CMS
Reviewing electronic health record access logs helps a practice:
- a.Increase the payer's allowed amount
- b.Set the timely-filing deadline
- c.Assign procedure codes automatically and set the payer timely-filing deadline
- d.Detect impermissible access to PHI, such as staff snooping✓
Audit controls and access logs are technical safeguards that reveal snooping and other impermissible access. Reviewing them supports HIPAA compliance and appropriate sanctions. Monitoring deters misuse of PHI.HIPAA
A HIPAA-required 'sanction policy' means the covered entity must:
- a.Report every submitted claim to the Office for Civil Rights
- b.Waive penalties for managers
- c.Discipline staff who violate privacy or security policies✓
- d.Reward staff for accessing more records
A sanction policy, an administrative safeguard, requires consistent discipline for workforce HIPAA violations. It reinforces accountability and deters misconduct. Applying it uniformly is part of an effective program.HIPAA
Under the False Claims Act, an employee who reports suspected fraud in good faith is:
- a.Automatically terminated from employment
- b.Barred from sharing in any recovery
- c.Required to pay the resulting penalties
- d.Protected from employer retaliation✓
The False Claims Act includes anti-retaliation protections for good-faith whistleblowers, who may also share in qui tam recoveries. Retaliation can create additional liability for the employer. These protections encourage reporting of fraud.False Claims Act
HIPAA requires covered entities to retain required HIPAA documentation, such as policies and the Notice of Privacy Practices, for at least:
- a.6 years from creation or last effective date✓
- b.1 year after creation
- c.30 days after creation
- d.At least 100 years, the same period required for medical records
The Privacy and Security Rules require HIPAA compliance documentation to be kept for six years. This is separate from medical-record retention, which is set by state and other law. Retaining documentation supports audits and investigations.HIPAA
CMS requires records related to Medicare Advantage (Part C) and Part D to be retained for at least:
- a.2 years
- b.10 years✓
- c.6 months
- d.No set period under HIPAA
CMS mandates a 10-year retention period for Medicare Advantage and Part D records. Retention requirements vary by program and by state law. Practices should follow the most stringent applicable rule.CMS
When federal HIPAA and a state privacy law both apply and the state law is MORE protective of the patient, the practice should generally:
- a.Follow whichever rule is easier
- b.Ignore the state law entirely
- c.Follow the more stringent state law✓
- d.Apply neither requirement
HIPAA sets a federal floor, and more protective state privacy laws are generally not preempted. The practice must follow the stricter requirement. This ensures patients receive the greater protection.HIPAA
Before disclosing PHI over the phone to a caller who claims to be the patient, staff should:
- a.Ask the caller for a credit card number in order to confirm the account
- b.Release all information immediately
- c.Refuse to speak with any patient
- d.Verify the caller's identity before releasing information✓
Verifying identity is a reasonable safeguard that prevents improper disclosure to an impostor. Only the minimum necessary information should then be shared. Identity verification protects the patient's PHI.HIPAA
A valid HIPAA authorization to disclose PHI for a non-routine purpose must:
- a.Be signed by the payer or a family member instead of the patient, with no description of the information or an expiration date
- b.Omit any expiration date
- c.Describe the information, the recipient, the purpose, and an expiration, and be signed✓
- d.Be verbal and undocumented
A valid authorization contains core elements: a specific description of the information, who may disclose and receive it, the purpose, an expiration, the patient's signature, and the right to revoke. It is required for uses beyond treatment, payment, and operations. Missing elements make it invalid.HIPAA
A patient who has signed a HIPAA authorization to release PHI generally may:
- a.Revoke it only with a court order
- b.Never revoke it once it is signed
- c.Revoke it in order to undo disclosures already made
- d.Revoke it in writing, but only going forward✓
Authorizations are revocable in writing, but the revocation is prospective and does not undo disclosures already made in reliance on it. Patients retain control going forward. The right to revoke must be stated in the authorization.HIPAA
A periodic internal coding and billing audit is a compliance activity that primarily:
- a.Guarantees higher reimbursement on every claim
- b.Replaces the need for clinical documentation
- c.Identifies coding errors and overpayment risks✓
- d.Sets the payer's fee schedule
Proactive auditing and monitoring is a core compliance-program element that finds and corrects errors before they grow. It reduces fraud and abuse exposure and supports accurate billing. Self-identified overpayments should be refunded promptly.CMS
Knowingly retaining a Medicare overpayment beyond the deadline to return it can create liability under the:
- a.False Claims Act✓
- b.Fair Debt Collection Practices Act
- c.Truth in Lending Act
- d.HIPAA Security Rule
The Affordable Care Act made retaining an identified overpayment past the 60-day deadline a potential reverse false claim under the False Claims Act. Timely refunds avoid this exposure. It links overpayment handling to fraud enforcement.False Claims Act
HIPAA permits disclosure of PHI WITHOUT patient authorization for:
- a.Legally required public health reporting✓
- b.Sharing with an employer for hiring decisions
- c.Posting patient outcomes on the internet
- d.Selling the information to a marketer
HIPAA allows specified disclosures without authorization, including required public health reporting and certain oversight and law-enforcement purposes. Marketing and sale of PHI require authorization. Knowing the permitted disclosures guides lawful sharing.HIPAA
When documentation is ambiguous or conflicting, the compliant action for a coder is to:
- a.Leave the encounter permanently unbilled
- b.Query the provider rather than assume a code✓
- c.Assign the highest-paying plausible code
- d.Guess based on the patient's history
A non-leading provider query resolves ambiguous or conflicting documentation before coding. Codes must reflect the clarified record, never assumptions made to increase payment. Querying supports both accuracy and compliance.
Kỳ thi này khó cỡ nào?
NHA CBCS (Certified Billing and Coding Specialist) gồm 120 câu (100 tính điểm cộng 20 câu thử nghiệm) trong 2 giờ 40 phút. Lệ phí thi 119 USD. Chuyên viên hồ sơ y tế có mức lương trung vị khoảng 50.250 USD/năm (BLS, tháng 5/2024).
- Số giờ học khuyến nghị
- 50-90 giờ với hầu hết mọi người — các phần mã hóa ICD-10-CM và CPT cần luyện nhiều nhất.
- Tỷ lệ đậu đã công bố
- 73.82% trên tổng số lượt thi (thi hai lần được tính hai lần) (n = 6,905) — NHA, 2024.Nguồn: NHA — Pass Rates for NHA Examinations Administered in 2024 (PDF)
- Nên ưu tiên học đâu trước
- Mã hóa (Coding) là mảng lớn nhất với 45% — mã hóa chẩn đoán ICD-10-CM và mã hóa thủ thuật CPT/HCPCS.
Lệ phí và mức lương chỉ là ước tính và thay đổi theo thời gian. Tỷ lệ đậu ở trên được trích từ nguồn có liên kết bên cạnh, cho đúng giai đoạn mà nguồn đó bao phủ — chỗ nào chúng tôi chưa kiểm chứng nguồn thì nói rõ và không nêu con số nào.