CCCP Regulatory Compliance & Legal Frameworks 3 — Questions and Answers
Question 1: A pharmaceutical company is under investigation for potential violations of the Anti-Kickback Statute (AKS). Which element must prosecutors prove to establish criminal liability under the AKS?
- The company caused measurable harm to Medicare patients
- The defendant knowingly and willfully offered or paid remuneration to induce referrals (Correct answer)
- The remuneration exceeded $10,000 in value
- The improper payments were concealed in the company's financial statements
Correct answer: The defendant knowingly and willfully offered or paid remuneration to induce referrals
The AKS requires proof that the defendant knowingly and willfully offered, paid, solicited, or received remuneration to induce or reward referrals of items or services covered by federal health care programs.
Question 2: Under the False Claims Act, what is the key legal standard that distinguishes a qui tam lawsuit from a standard government enforcement action?
- Qui tam suits can only be filed by former employees of the defendant company
- A private individual (relator) files the suit on behalf of the government and may share in any recovery (Correct answer)
- Qui tam actions require prior approval from the Department of Justice before filing
- The relator must have suffered personal financial harm from the fraud
Correct answer: A private individual (relator) files the suit on behalf of the government and may share in any recovery
The False Claims Act's qui tam provision allows private individuals (relators) to file lawsuits on the government's behalf and receive 15–30% of any recovered proceeds if the government intervenes.
Question 3: Which defense is most likely to succeed for a company facing criminal prosecution under the doctrine of respondeat superior for an employee's unauthorized illegal act?
- The company had an effective compliance program and the employee acted against explicit policy (Correct answer)
- The illegal act was committed outside normal business hours
- The employee was a low-level worker with no supervisory authority
- The company self-reported the violation within 90 days of discovery
Correct answer: The company had an effective compliance program and the employee acted against explicit policy
While respondeat superior can hold a company liable for employee acts within the scope of employment, evidence of a robust compliance program and clear policy violations can be a significant mitigating factor in prosecutorial discretion.
Question 4: Under OFAC regulations, what is the legal standard applied when determining whether a transaction with a sanctioned party violates US sanctions laws?
- Strict liability — knowledge of the violation is irrelevant to civil penalties (Correct answer)
- Negligence — the company must have known or should have known of the sanction
- Intentional misconduct — willful evasion must be proven beyond a reasonable doubt
- Recklessness — the company disregarded a substantial risk of violation
Correct answer: Strict liability — knowledge of the violation is irrelevant to civil penalties
OFAC civil penalties are strict liability offenses, meaning a party can be held liable even if it did not know it was dealing with a sanctioned person; however, knowledge affects penalty severity.
Question 5: A US bank discovers it processed wire transfers for a customer later designated as a Specially Designated National (SDN) by OFAC. The transactions occurred before the designation. What is the bank's primary obligation?
- File a Suspicious Activity Report (SAR) with FinCEN and block future transactions
- Reverse all prior transactions retroactively and notify the affected customer
- Immediately freeze all accounts and report to OFAC within 10 business days (Correct answer)
- Terminate the customer relationship without any reporting obligation
Correct answer: Immediately freeze all accounts and report to OFAC within 10 business days
Upon discovering that a customer has been designated as an SDN, US financial institutions must block the account, reject future transactions, and report to OFAC within 10 business days.
Question 6: The Health Insurance Portability and Accountability Act (HIPAA) Security Rule applies to which category of information?
- All personally identifiable information held by healthcare providers
- Electronic protected health information (ePHI) created, received, maintained, or transmitted by covered entities (Correct answer)
- Protected health information stored in paper records only
- All health data processed by any US company with more than 50 employees
Correct answer: Electronic protected health information (ePHI) created, received, maintained, or transmitted by covered entities
The HIPAA Security Rule specifically addresses electronic protected health information (ePHI) and requires covered entities and their business associates to implement administrative, physical, and technical safeguards.
Question 7: Under the Bank Secrecy Act (BSA), financial institutions are required to file Currency Transaction Reports (CTRs) for which transactions?
- All wire transfers exceeding $5,000 regardless of currency type
- Cash transactions exceeding $10,000 in a single business day by or on behalf of the same person (Correct answer)
- All foreign currency exchanges exceeding $3,000
- Suspicious transactions of any amount that may involve money laundering
Correct answer: Cash transactions exceeding $10,000 in a single business day by or on behalf of the same person
The BSA requires financial institutions to file CTRs for cash transactions over $10,000 conducted by or on behalf of the same person in a single business day, whether in one or multiple transactions.
A pharmaceutical company is under investigation for potential violations of the Anti-Kickback Statute (AKS).
Which element must prosecutors prove to establish criminal liability under the AKS?