CBCS Ethics and Professionalism 2 — Questions and Answers
Question 1: What is upcoding in medical billing?
- Assigning a higher-level code than documented to receive greater reimbursement (Correct answer)
- Using outdated codes from a previous year's code set
- Coding a service that was never performed
- Combining multiple codes into a single bundled code
Correct answer: Assigning a higher-level code than documented to receive greater reimbursement
Upcoding is a fraudulent practice where a provider bills for a higher-level service than what was actually documented or performed, resulting in inflated reimbursement.
Upcoding violates the False Claims Act and can result in civil monetary penalties, exclusion from Medicare/Medicaid, and criminal prosecution. An example is billing a Level 4 office visit (99214) when documentation only supports a Level 3 (99213). The OIG monitors upcoding patterns through data analysis, and providers with statistically unusual billing profiles may be audited. Billers and coders have a professional obligation to code only what is documented.
Question 2: Under HIPAA, which of the following is considered a covered entity?
- A medical billing software vendor
- A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically (Correct answer)
- A pharmaceutical manufacturer
- An employer providing workers' compensation benefits
Correct answer: A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically
HIPAA covered entities are health plans, healthcare clearinghouses, and healthcare providers that conduct covered transactions electronically. Business associates that work with covered entities also have HIPAA obligations.
Under 45 CFR Parts 160 and 164, covered entities include: (1) Health plans (e.g., insurance companies, HMOs, Medicare), (2) Healthcare clearinghouses (entities that process nonstandard health information to/from standard formats), and (3) Healthcare providers who transmit health information electronically in connection with covered transactions. Billing software vendors are typically business associates, not covered entities themselves.
Question 3: What is the primary purpose of the AHIMA and AAPC codes of ethics for medical coders?
- To set billing rates for coding services
- To guide professional conduct, ensure accurate coding, and protect patient privacy (Correct answer)
- To determine which coding credentials are most valuable
- To establish continuing education requirements
Correct answer: To guide professional conduct, ensure accurate coding, and protect patient privacy
Professional codes of ethics for coders emphasize accurate and complete coding, protecting patient confidentiality, avoiding fraud, and maintaining professional competence.
AHIMA's Standards of Ethical Coding and AAPC's Code of Ethics both require coders to: report accurately what is documented, avoid upcoding/undercoding, protect patient privacy, report compliance concerns, maintain competency through continued education, and refuse to participate in fraudulent activities. Violations can result in loss of credentials. These standards form the ethical foundation of the coding profession.
Question 4: A patient calls requesting a copy of their medical records. Under HIPAA, the covered entity must provide access within:
- 7 calendar days
- 30 calendar days (with a possible 30-day extension) (Correct answer)
- 60 calendar days
- 10 business days
Correct answer: 30 calendar days (with a possible 30-day extension)
Under HIPAA's Privacy Rule, covered entities must act on a request for access to PHI within 30 calendar days, with one possible 30-day extension if the entity provides written notice.
45 CFR 164.524 establishes the patient's right of access to PHI. Covered entities must provide access within 30 days of receiving a request. A single 30-day extension is allowed with written notice stating the reason and new expected date. Access may be in the requested format (electronic or paper). Fees for copies must be reasonable and cost-based. Denying access without valid grounds is a HIPAA violation.
Question 5: What is the False Claims Act (FCA) primarily designed to prevent?
- Identity theft in healthcare settings
- Fraudulent billing to federal healthcare programs like Medicare and Medicaid (Correct answer)
- Unauthorized use of protected health information
- Improper coding of diagnoses for research purposes
Correct answer: Fraudulent billing to federal healthcare programs like Medicare and Medicaid
The False Claims Act prohibits submitting false or fraudulent claims for payment to federal programs. It includes qui tam provisions allowing whistleblowers to file suit on behalf of the government.
The False Claims Act (31 U.S.C. §§ 3729–3733) imposes civil liability on persons who knowingly submit false claims to the federal government. In healthcare, violations include billing for services not rendered, upcoding, unbundling, kickback arrangements, and billing for excluded providers. Penalties include $13,000–$27,000 per false claim plus treble damages. The qui tam (whistleblower) provision allows private individuals to sue on the government's behalf and receive 15–30% of recovered funds.
Question 6: Which of the following best describes the concept of 'minimum necessary' under HIPAA?
- Covered entities must use or disclose only the minimum amount of PHI needed to accomplish the intended purpose (Correct answer)
- Healthcare providers must collect the least amount of patient information possible at registration
- Insurance companies must pay at least the minimum required reimbursement
- Patients must provide only the minimum required consent for treatment
Correct answer: Covered entities must use or disclose only the minimum amount of PHI needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use and disclosure to what is necessary to accomplish the intended purpose.
Under 45 CFR 164.502(b), the minimum necessary standard applies to most uses and disclosures of PHI (except for treatment purposes, which are exempt). For example, a billing department only needs diagnosis and procedure codes — not the full clinical notes — to process a claim. Staff access to PHI should be role-based and limited to what is needed for their specific job functions. Violations of this standard can result in HIPAA penalties.
What is upcoding in medical billing?