CCCP Healthcare Compliance & HIPAA 5 — Questions and Answers
Question 1: The '60-day rule' in healthcare compliance, established by the Affordable Care Act, requires providers to:
- Investigate all compliance hotline tips within 60 days
- Report and return identified Medicare/Medicaid overpayments within 60 days of identification (Correct answer)
- Respond to OIG audit requests within 60 days of receipt
- Complete annual compliance training within 60 days of the program year start
Correct answer: Report and return identified Medicare/Medicaid overpayments within 60 days of identification
The ACA requires providers to report and return identified Medicare/Medicaid overpayments within 60 days of identification to avoid False Claims Act liability.
Question 2: Under HIPAA's Privacy Rule, which of the following constitutes a 'use' of PHI (as distinct from a 'disclosure')?
- A hospital shares a patient's records with a treating specialist outside the hospital
- A billing clerk within the hospital views a patient's diagnosis to process a claim (Correct answer)
- A hospital responds to a subpoena for patient records
- A health plan sends an Explanation of Benefits to a patient's employer
Correct answer: A billing clerk within the hospital views a patient's diagnosis to process a claim
A 'use' occurs when PHI is shared, examined, or applied within the covered entity itself, whereas 'disclosure' involves releasing PHI outside the entity.
Question 3: A healthcare compliance risk assessment should be conducted:
- Once at program inception and never again unless a breach occurs
- Periodically and whenever significant operational or regulatory changes occur (Correct answer)
- Only when required by an active OIG Corporate Integrity Agreement
- Exclusively by external auditors to ensure independence
Correct answer: Periodically and whenever significant operational or regulatory changes occur
Effective compliance programs require periodic risk assessments that are also triggered by material changes in operations, laws, or enforcement priorities.
Question 4: Which HIPAA provision allows a covered entity to disclose PHI to a public health authority without patient authorization for the purpose of preventing or controlling disease?
- The Treatment, Payment, and Operations (TPO) exception
- The public health activities exception under 45 CFR § 164.512(b) (Correct answer)
- The emergency preparedness waiver
- The national security disclosure provision
Correct answer: The public health activities exception under 45 CFR § 164.512(b)
45 CFR § 164.512(b) permits disclosure of PHI to public health authorities authorized to collect data for preventing or controlling disease without patient authorization.
Question 5: A compliance officer at a hospital system wants to assess whether clinical documentation supports the billing codes submitted. The most appropriate internal audit methodology would be:
- Random sampling of claims followed by medical record review against billing data (Correct answer)
- Reviewing only claims that were denied by payers
- Auditing exclusively claims flagged by the OIG Work Plan
- Conducting patient satisfaction surveys to identify billing concerns
Correct answer: Random sampling of claims followed by medical record review against billing data
Random sampling of claims with corresponding medical record review is the standard methodology for assessing coding accuracy and documentation compliance.
Question 6: Under HIPAA, a 'hybrid entity' is best defined as:
- An entity that is both a covered entity and a business associate simultaneously
- An entity that performs both covered and non-covered functions, with HIPAA applying only to its healthcare component (Correct answer)
- A government agency that is exempt from HIPAA's Privacy Rule
- An entity that uses both paper and electronic health records
Correct answer: An entity that performs both covered and non-covered functions, with HIPAA applying only to its healthcare component
A hybrid entity conducts both covered healthcare functions and non-covered business functions, and may designate only the healthcare component as subject to HIPAA.
Question 7: The primary purpose of the OIG's Annual Work Plan in the context of healthcare compliance is to:
- Set Medicare reimbursement rates for the upcoming fiscal year
- Signal areas of heightened audit and enforcement focus that providers should proactively review (Correct answer)
- Establish mandatory compliance program requirements for all providers
- Define criminal penalty ranges for healthcare fraud convictions
Correct answer: Signal areas of heightened audit and enforcement focus that providers should proactively review
The OIG Work Plan identifies specific billing, coding, and operational areas that OIG will scrutinize, enabling proactive internal audit prioritization.
The '60-day rule' in healthcare compliance, established by the Affordable Care Act, requires providers to: