Healthcare Compliance & HIPAA Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Healthcare Compliance & HIPAA flashcards as text
The '60-day rule' in healthcare compliance, established by the Affordable Care Act, requires providers to:
Answer: Report and return identified Medicare/Medicaid overpayments within 60 days of identification
The ACA requires providers to report and return identified Medicare/Medicaid overpayments within 60 days of identification to avoid False Claims Act liability.
Under HIPAA's Privacy Rule, which of the following constitutes a 'use' of PHI (as distinct from a 'disclosure')?
Answer: A billing clerk within the hospital views a patient's diagnosis to process a claim
A 'use' occurs when PHI is shared, examined, or applied within the covered entity itself, whereas 'disclosure' involves releasing PHI outside the entity.
A healthcare compliance risk assessment should be conducted:
Answer: Periodically and whenever significant operational or regulatory changes occur
Effective compliance programs require periodic risk assessments that are also triggered by material changes in operations, laws, or enforcement priorities.
Which HIPAA provision allows a covered entity to disclose PHI to a public health authority without patient authorization for the purpose of preventing or controlling disease?
Answer: The public health activities exception under 45 CFR § 164.512(b)
45 CFR § 164.512(b) permits disclosure of PHI to public health authorities authorized to collect data for preventing or controlling disease without patient authorization.
A compliance officer at a hospital system wants to assess whether clinical documentation supports the billing codes submitted. The most appropriate internal audit methodology would be:
Answer: Random sampling of claims followed by medical record review against billing data
Random sampling of claims with corresponding medical record review is the standard methodology for assessing coding accuracy and documentation compliance.
Under HIPAA, a 'hybrid entity' is best defined as:
Answer: An entity that performs both covered and non-covered functions, with HIPAA applying only to its healthcare component
A hybrid entity conducts both covered healthcare functions and non-covered business functions, and may designate only the healthcare component as subject to HIPAA.
The primary purpose of the OIG's Annual Work Plan in the context of healthcare compliance is to:
Answer: Signal areas of heightened audit and enforcement focus that providers should proactively review
The OIG Work Plan identifies specific billing, coding, and operational areas that OIG will scrutinize, enabling proactive internal audit prioritization.