CBCS - Certified Billing and Coding Specialist Regulatory Compliance and HIPAA Questions and Answers 1 — Questions and Answers
Question 1: A billing specialist notices a pattern of a specific provider consistently using a higher-level evaluation and management (E/M) code for routine office visits, which is not supported by the medical documentation. Under which federal law could this practice be considered fraudulent?
- The Stark Law
- The Health Insurance Portability and Accountability Act (HIPAA)
- The False Claims Act (FCA) (Correct answer)
- The Anti-Kickback Statute (AKS)
Correct answer: The False Claims Act (FCA)
The False Claims Act (FCA) makes it illegal to knowingly submit false or fraudulent claims to a government healthcare program. Consistently billing at a higher code level than what is supported by the documentation, a practice known as 'upcoding,' is a classic example of a false claim because it seeks reimbursement for services that were not medically necessary at that level or not actually performed to that extent.
Question 2: A business associate of a covered entity discovers a breach of unsecured protected health information (PHI) affecting 600 individuals. According to the HIPAA Breach Notification Rule, what is the business associate's primary and most immediate responsibility?
- Notify the local media via a press release within 60 days.
- Notify each of the 600 affected individuals directly by mail.
- Notify the Secretary of Health and Human Services (HHS) immediately.
- Notify the covered entity of the breach without unreasonable delay. (Correct answer)
Correct answer: Notify the covered entity of the breach without unreasonable delay.
The HIPAA Breach Notification Rule requires a business associate to notify the covered entity after discovering a breach of unsecured PHI. This notification must happen 'without unreasonable delay and in no case later than 60 days' following the discovery. It is then the covered entity's responsibility to notify the affected individuals, HHS, and potentially the media.
Question 3: Which of the following is an example of a 'technical safeguard' under the HIPAA Security Rule?
- Developing a contingency plan for data recovery.
- Positioning computer monitors to prevent public viewing of PHI.
- Implementing unique user IDs and password requirements for EHR access. (Correct answer)
- Conducting annual security risk assessments.
Correct answer: Implementing unique user IDs and password requirements for EHR access.
The HIPAA Security Rule mandates three types of safeguards: administrative, physical, and technical. Technical safeguards are technology-based and relate to the policies and procedures for its use that protect electronic PHI (ePHI) and control access to it. Implementing unique user IDs, passwords, and other access controls is a core requirement of the technical safeguards.
Question 4: A hospital owns a diagnostic imaging center. A physician employed by the hospital routinely refers their Medicare patients to this imaging center for services. This arrangement could potentially violate which of the following laws if no exception is met?
- HIPAA Privacy Rule
- The Stark Law (Correct answer)
- The False Claims Act
- The Breach Notification Rule
Correct answer: The Stark Law
The Stark Law, also known as the Physician Self-Referral Law, prohibits physicians from referring Medicare or Medicaid patients for 'designated health services' (DHS) to an entity with which the physician or an immediate family member has a financial relationship, unless an exception applies. In this scenario, the physician has a financial relationship (employment) with the hospital, which owns the imaging center (a provider of DHS).
Question 5: A patient's friend calls the billing office to ask about the details of a recent bill. The billing specialist, wanting to be helpful, confirms the patient's recent surgery date and the outstanding balance. This action is a violation of which HIPAA principle?
- The Security Rule
- The Minimum Necessary Standard (Correct answer)
- The Breach Notification Rule
- The Pre-authorization Requirement
Correct answer: The Minimum Necessary Standard
The HIPAA Privacy Rule establishes the principle of 'minimum necessary,' which requires covered entities to make reasonable efforts to limit the use or disclosure of Protected Health Information (PHI) to the minimum necessary to accomplish the intended purpose. Disclosing details of a patient's bill and surgery to an unauthorized individual, like a friend, without the patient's explicit consent is a violation of their privacy and goes against this standard.
Question 6: A covered entity must notify the Secretary of HHS of a breach of unsecured PHI. If the breach affects fewer than 500 individuals, when must this notification be provided?
- Within 10 business days of discovering the breach.
- No later than 60 days from the end of the calendar year in which the breach was discovered. (Correct answer)
- Immediately upon discovery, but no later than 24 hours.
- Within 60 days of the discovery of the breach.
Correct answer: No later than 60 days from the end of the calendar year in which the breach was discovered.
According to the HIPAA Breach Notification Rule, if a breach of unsecured PHI affects fewer than 500 individuals, the covered entity may notify the Secretary of HHS on an annual basis. These notifications must be submitted no later than 60 days after the end of the calendar year in which the breaches were discovered.
A billing specialist notices a pattern of a specific provider consistently using a higher-level evaluation and management (E/M) code for routine office visits, which is not supported by the medical documentation.
Under which federal law could this practice be considered fraudulent?