第 3 章,共 4 章20% 占考试比重

Compliance and Regulatory Standards

Billing specialists operate under federal privacy, security, and fraud-and-abuse laws. Understanding HIPAA, the False Claims Act, the Anti-Kickback Statute, and documentation rules protects patients and shields the practice from penalties.

HIPAA Privacy and Security

HIPAA, the Health Insurance Portability and Accountability Act of 1996, sets the federal floor for protecting patient information. The Privacy Rule governs protected health information (PHI), which is individually identifiable health information in any form, whether spoken, written, or electronic. It defines when covered entities, meaning health plans, clearinghouses, and providers who transmit standard transactions, and their business associates, may use and disclose PHI, and it grants patients rights that include the right to access and obtain a copy of their records, to request amendments, and to receive an accounting of certain disclosures. The Security Rule applies specifically to electronic PHI (ePHI) and requires three kinds of safeguards. Administrative safeguards include risk analysis, workforce training, and access-management policies. Physical safeguards protect facilities and devices through locked areas, workstation security, and controls on media disposal. Technical safeguards include access controls, unique user IDs, audit logs, and encryption of ePHI in transit and at rest. Together these safeguards protect the confidentiality, integrity, and availability of health information. The minimum necessary standard is a recurring exam concept: when using, disclosing, or requesting PHI, a workforce member should limit the information to the least amount needed to accomplish the purpose. Important exceptions exist, because the standard does not apply to disclosures for treatment, to the individual who is the subject of the information, to disclosures the patient has authorized, or to those required by law. This is why a physician treating a patient may see the whole record, while a biller needs only the data required to submit and follow up on the claim. Snooping, meaning accessing records without a legitimate work-related reason such as looking up a neighbor, a celebrity, or a family member out of curiosity, is an impermissible use and a clear HIPAA violation even if nothing is disclosed further. Enforcement carries civil and, for willful misuse, criminal penalties, so for a billing specialist compliance is a daily discipline: access only what the job requires, and protect it.

The Privacy Rule protects individually identifiable health information (PHI) in all forms and grants patients rights to access their records.
The Security Rule protects electronic PHI through administrative, physical, and technical safeguards.
The minimum necessary standard limits use and disclosure of PHI to what is needed, except for treatment and patient-authorized disclosures.
Accessing records without a work-related reason (snooping) is an impermissible use that violates HIPAA.

HIPAA Transactions, Notices, and Breaches

Beyond privacy and security, HIPAA's Administrative Simplification provisions standardize the electronic business of health care so that every covered entity speaks the same data language. The rules mandate standard transaction formats and code sets: the ASC X12 837 for claims, the 835 for remittance and payment, the 270 and 271 for eligibility inquiry and response, the 276 and 277 for claim status, and the 278 for prior authorization. The adopted medical code sets include ICD-10-CM and ICD-10-PCS, CPT, and HCPCS. Standardizing these transactions is what lets a clearinghouse route a claim from any provider to any payer, and it is why the biller must use current, valid codes. The Notice of Privacy Practices (NPP) is the document a covered entity must give patients describing how their PHI may be used and disclosed, the patient's rights, and the entity's duties. Providers with a direct treatment relationship generally must provide the NPP at the first service encounter and make a good-faith effort to obtain the patient's written acknowledgment of receipt. The Breach Notification Rule governs what happens when unsecured PHI is compromised. A breach is an impermissible use or disclosure that compromises the security or privacy of PHI, and it is presumed reportable unless a risk assessment shows a low probability that the information was compromised. Covered entities must notify each affected individual without unreasonable delay and no later than 60 days after discovery. They must also notify the Department of Health and Human Services (HHS): breaches affecting 500 or more individuals are reported to HHS and to prominent media without unreasonable delay within that 60-day window, while smaller breaches may be logged and reported to HHS annually. The HITECH Act strengthened these requirements and extended direct liability to business associates. For the billing specialist, the practical takeaways are to use standard transactions and current code sets, honor the NPP, and report any suspected breach promptly through the practice's compliance channel.

HIPAA standardizes electronic transactions and code sets, such as the 837 claim and 835 remittance.
A Notice of Privacy Practices tells patients how their PHI is used and disclosed and describes their rights.
The Breach Notification Rule requires notifying affected individuals, and sometimes HHS and the media, within required timeframes after a breach of unsecured PHI.

Fraud and Abuse Laws

Federal fraud-and-abuse laws set the boundaries that billing decisions must respect, and the exam expects you to tell them apart. Fraud is knowingly submitting false information to obtain a payment to which one is not entitled; abuse is practices that are inconsistent with sound fiscal or medical norms and result in unnecessary cost, often without the intent that fraud requires. The distinguishing factor is intent, but both expose a practice to serious liability. The False Claims Act (FCA) imposes civil liability on anyone who knowingly presents, or causes to be presented, a false or fraudulent claim to a federal program such as Medicare or Medicaid. Knowingly includes actual knowledge, deliberate ignorance, and reckless disregard, so a biller cannot avoid liability by choosing not to look. The FCA carries steep per-claim penalties plus treble damages and includes qui tam provisions that let a whistleblower, often an employee, file suit on the government's behalf and share in any recovery. The Anti-Kickback Statute (AKS) is a criminal law prohibiting knowingly and willfully offering, paying, soliciting, or receiving any remuneration to induce or reward referrals of items or services reimbursable by a federal health care program. Because it requires intent, even one purpose to induce referrals can trigger liability, and statutory exceptions and regulatory safe harbors protect specific arrangements. The Stark Law, the physician self-referral law, is different in kind: it is a strict-liability civil statute that prohibits a physician from referring Medicare patients for designated health services to an entity with which the physician or an immediate family member has a financial relationship, unless a specific exception is met. Because Stark is strict liability, intent does not matter; a technical violation is still a violation. A useful contrast for the exam is that AKS is criminal and intent-based and applies to anyone, while Stark is civil, strict-liability, and covers physician self-referral for designated health services. Recognizing which law a scenario describes is the skill being tested.

The False Claims Act imposes liability for knowingly submitting false claims to federal programs and includes qui tam whistleblower provisions.
The Anti-Kickback Statute prohibits offering or receiving remuneration to induce referrals of federal health care business.
The Stark Law bars physician self-referral for designated health services to entities with which the physician has a financial relationship, unless an exception applies.

Oversight and the ABN

Several bodies and tools keep billing honest. The Office of Inspector General (OIG) within HHS is the primary watchdog for fraud, waste, and abuse in federal health programs. It audits and investigates, publishes an annual Work Plan signaling its focus areas, issues compliance guidance, and maintains the List of Excluded Individuals and Entities (LEIE). Checking the LEIE matters directly to billing, because a practice may not bill federal programs for items or services furnished or ordered by an excluded party, so employers screen staff and referring providers against the list. The Centers for Medicare and Medicaid Services (CMS) administers the programs and uses contractors: MACs process claims, while RACs and other auditors review paid claims for improper payments and recoup overpayments. The Advance Beneficiary Notice of Noncoverage (ABN, form CMS-R-131) is a Medicare tool that protects both patient and provider. When a provider believes Medicare may deny a specific item or service as not reasonable and necessary, the ABN is given to the patient before the service so the patient can make an informed choice to accept or decline it and to accept financial responsibility if Medicare does not pay. A valid ABN must identify the service, state the reason payment may be denied, and give an estimated cost; it must be delivered in advance, not routinely for every service and not after the fact. When an ABN is on file, specific modifiers such as GA communicate its status on the claim, and without a proper ABN the provider generally cannot bill the patient for the denied amount. A compliance program ties these pieces together. The recognized elements, which include written standards and policies, a designated compliance officer, training, auditing and monitoring, responding to detected problems, open lines of communication, and consistent enforcement, help a practice prevent violations and demonstrate good faith if a problem occurs. For the specialist, oversight is not abstract; it dictates daily habits like exclusion screening and correct ABN use.

The Office of Inspector General detects fraud, waste, and abuse and maintains the list of excluded parties.
An Advance Beneficiary Notice of Noncoverage warns a Medicare patient in advance that a service may be denied so the patient can accept financial responsibility.
A compliance program uses policies, training, and auditing to prevent and detect violations.

Documentation, NPI, and Retention

Three practical compliance duties round out the domain. First, documentation supports everything billed. The governing principle is that the medical record must justify each code reported and demonstrate medical necessity: if a service was not documented, then for billing and audit purposes it is treated as though it was not done. Codes must reflect what the provider actually documented, not what would pay best, and the biller's role includes querying the provider when documentation is missing or ambiguous rather than assuming a diagnosis or upcoding. Auditors compare the codes on the claim to the record, and a gap between them is where recoupments and penalties begin. Second, the National Provider Identifier (NPI) uniquely and permanently identifies covered health care providers in HIPAA standard transactions. It is a ten-digit number with no embedded meaning about specialty or location, which is why it stays constant even when a provider moves or changes practices. Type 1 NPIs identify individual providers, while Type 2 NPIs identify organizations such as group practices and hospitals. Accurate NPIs on every claim are a precondition for both payment and clean data. Third, record retention follows a layered set of rules. Federal requirements such as Medicare's, state laws, and payer contracts each set minimum periods for keeping medical and billing records, and the retention clock for minors often runs from the age of majority rather than the date of service. When these rules conflict, the compliant approach is to follow the most stringent applicable requirement, meaning the longest period and the strictest safeguards, so that records exist if an audit, appeal, or legal action arises years later. Records must be retained securely, protected as PHI throughout their life, and disposed of properly at the end, for example by shredding paper and sanitizing electronic media. Together, honest documentation, correct identifiers, and disciplined retention form the everyday backbone of a compliant billing operation and keep the practice audit-ready.

Documentation must support every code billed and demonstrate medical necessity; if it was not documented, it is treated as not done.
The NPI uniquely identifies covered providers in HIPAA standard transactions.
Record retention periods are set by federal and state laws and payer requirements; follow the most stringent applicable rule.
测试你的知识
练习 Compliance and Regulatory Standards 的相关题目
立即练习 →

Last updated: September 2026

想按顺序系统学?

练习一直免费。完整的 Medical Billing & Coding (CBCS) 学习指南是知识本身,从头到尾讲清楚 —— 可下载的 PDF + EPUB,永久归你。

获取本书 —— $14.99
反馈