CCCP Healthcare Compliance & HIPAA 3 — Questions and Answers
Question 1: A patient requests an amendment to their medical record, claiming the information is inaccurate. Under HIPAA, a covered entity may deny the request if:
- The request is submitted verbally rather than in writing
- The PHI was not created by the covered entity (Correct answer)
- The patient cannot provide a specific legal citation supporting the amendment
- The amendment would take longer than 30 days to complete
Correct answer: The PHI was not created by the covered entity
A covered entity may deny an amendment request when the PHI at issue was not created by that entity, among other grounds listed in the Privacy Rule.
Question 2: Under the Anti-Kickback Statute (AKS), which element distinguishes a safe harbor arrangement from a prohibited kickback?
- Safe harbor arrangements require prior HHS approval
- Safe harbor arrangements must be disclosed to Medicare beneficiaries
- Safe harbor arrangements meet specific criteria that insulate them from prosecution (Correct answer)
- Safe harbor arrangements are only available to non-profit healthcare entities
Correct answer: Safe harbor arrangements meet specific criteria that insulate them from prosecution
AKS safe harbors define specific criteria under which remuneration arrangements will not be treated as kickbacks warranting prosecution.
Question 3: The Stark Law (Physician Self-Referral Law) prohibits a physician from referring Medicare patients for designated health services to an entity in which the physician has a financial relationship, unless:
- The referral is for emergency services only
- A recognized exception applies (Correct answer)
- The referring physician discloses the relationship to the patient
- The referring physician is a hospital employee
Correct answer: A recognized exception applies
The Stark Law is a strict liability statute, so the only way to make a prohibited referral permissible is to fit within a statutory or regulatory exception.
Question 4: A healthcare organization's compliance program receives an anonymous hotline tip alleging billing fraud. The FIRST step the compliance officer should take is to:
- Immediately report the allegation to OIG
- Conduct a preliminary assessment to determine whether the allegation has merit (Correct answer)
- Terminate employees named in the tip pending investigation
- Notify the board of directors before taking any other action
Correct answer: Conduct a preliminary assessment to determine whether the allegation has merit
A compliance officer should first conduct a preliminary assessment to evaluate the credibility and scope of the allegation before escalating or taking remedial action.
Question 5: Under the False Claims Act (FCA), the 'reverse false claim' theory imposes liability when a defendant:
- Files a false claim for services not rendered
- Knowingly retains an overpayment from a government health program (Correct answer)
- Submits a claim with an incorrect diagnosis code
- Causes a third party to submit a false claim
Correct answer: Knowingly retains an overpayment from a government health program
A reverse false claim arises when a party knowingly retains money owed to the government, such as a Medicare overpayment, rather than repaying it.
Question 6: Which federal program requires healthcare providers to report and return identified Medicare overpayments within 60 days of identification?
- The False Claims Act self-disclosure protocol
- The Affordable Care Act's overpayment provisions (42 U.S.C. § 1320a-7k) (Correct answer)
- The OIG's Self-Disclosure Protocol
- The RAC audit program regulations
Correct answer: The Affordable Care Act's overpayment provisions (42 U.S.C. § 1320a-7k)
The ACA's overpayment statute at 42 U.S.C. § 1320a-7k requires providers to report and return identified Medicare/Medicaid overpayments within 60 days.
Question 7: A covered entity uses a vendor to process insurance claims electronically. The vendor meets the HIPAA definition of a:
- Covered entity
- Business associate (Correct answer)
- Workforce member
- Hybrid entity
Correct answer: Business associate
A claims processing vendor that handles PHI on behalf of a covered entity qualifies as a business associate under HIPAA.
A patient requests an amendment to their medical record, claiming the information is inaccurate.
Under HIPAA, a covered entity may deny the request if: