Mixed Deck — All CCT Topics Flashcards
100 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCT Topics flashcards as text
The SEC's Whistleblower Program under Dodd-Frank requires that awards be paid only when the whistleblower's information leads to a successful enforcement action resulting in sanctions exceeding what threshold?
Answer: $1 million
SEC whistleblower awards are available only when the related enforcement action results in monetary sanctions exceeding $1 million.
Under EPA's RCRA regulations, a Conditionally Exempt Small Quantity Generator (CESQG) generates how much hazardous waste per month?
Answer: Less than 100 kg
CESQGs (now called Very Small Quantity Generators) generate less than 100 kg of hazardous waste per month and have the least stringent requirements.
A hospital receives a letter from a Recovery Audit Contractor (RAC) that requests medical records for 15 inpatient stays to validate the medical necessity of the admissions. This type of review is known as a:
Answer: Complex review
A complex review is one that requires the review of medical records or other supporting documentation to determine if an improper payment has occurred. An automated review does not involve a human review of the medical record and is based on analyzing claims data for clear policy violations. A pre-payment review happens before the claim is paid, whereas RAC reviews are post-payment. A CERT review is part of a program to measure the overall Medicare error rate, not to recover specific overpayments.
Which program allows states to bring fraud and abuse actions against Medicaid providers under the authority of the Social Security Act?
Answer: Medicaid Fraud Control Units (MFCUs)
Medicaid Fraud Control Units (MFCUs) are state agencies that investigate and prosecute Medicaid provider fraud and patient abuse, operating under federal oversight and receiving 75% federal funding.
Under HIPAA, what is the maximum annual penalty for violations in the 'willful neglect - not corrected' category?
Answer: $1,900,000
HIPAA's penalty tier for willful neglect violations not corrected within 30 days carries a maximum of $1,900,000 per violation category per year.
What is the primary purpose of a 'corrective action plan' (CAP) following a compliance monitoring finding?
Answer: To specify remediation steps, responsible parties, and deadlines to resolve identified deficiencies
A CAP formalizes the remediation response by assigning ownership, defining specific remediation steps, and setting target completion dates for each finding.
OIG guidance recommends that compliance programs conduct regular internal monitoring and auditing primarily to:
Answer: Detect and correct compliance problems before they escalate or are discovered externally
Ongoing monitoring and auditing allow organizations to identify and self-correct issues proactively, reducing exposure and demonstrating a commitment to compliance.
Which of the following is the correct hierarchy of HIPAA civil monetary penalty tiers (lowest to highest culpability)?
Answer: Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected
HIPAA penalty tiers escalate from unknowing violations, to reasonable cause, to willful neglect that is corrected, to willful neglect that is not corrected.
What is the PRIMARY purpose of maintaining a compliance issue log or tracking system?
Answer: To record identified compliance issues, investigations, corrective actions, and resolutions
An issue log documents the lifecycle of compliance problems from identification through resolution, demonstrating program responsiveness.
Which safe harbor under the Anti-Kickback Statute protects properly structured investment interests?
Answer: The investment interests safe harbor
The investment interests safe harbor protects returns on equity investments when certain criteria—such as investment terms not being based on referral volume—are met.
Which of the following is an example of a preventive control?
Answer: Physical security measures such as locked doors
Physical security measures, such as locked doors, are a prime example of a preventive control. Preventive controls are designed to stop undesirable events or errors from occurring in the first place. By restricting unauthorized access, locked doors directly prevent theft or damage to assets, thereby mitigating risks proactively.
During a compliance audit, it is discovered that 40% of staff have never completed compliance training. Which of the Seven Elements is most clearly deficient?
Answer: Effective training and education
The third element—effective training and education—requires that all relevant personnel complete compliance training, so a 40% gap signals a major deficiency.
Environmental compliance with the Clean Air Act is enforced at the federal level by which agency?
Answer: EPA
The Environmental Protection Agency (EPA) enforces the Clean Air Act, setting and enforcing national air quality standards.
Which of the following is an example of a preventive control designed to reduce compliance risk?
Answer: Requiring management approval before a new vendor is onboarded
Preventive controls act before a risk event occurs; requiring approval before onboarding a vendor stops noncompliant vendors from entering the system.
A compliance officer at a publicly traded company notices that their audit committee has a member who may not qualify as 'financially literate' under SOX. Which agency's rules define audit committee independence requirements for listed companies?
Answer: SEC
The SEC implemented SOX Section 301 audit committee requirements, and stock exchanges impose additional independence and financial literacy standards under SEC-approved listing rules.
A large-scale, multi-state investigation into a complex criminal healthcare fraud enterprise is underway. While the HHS OIG provides investigative expertise, which government agency is primarily responsible for leading the criminal prosecution and bringing charges against the defendants?
Answer: Department of Justice (DOJ)
The Department of Justice (DOJ), through its Criminal Division's Health Care Fraud Unit and various U.S. Attorneys' Offices, is the primary federal agency responsible for prosecuting criminal violations of healthcare laws. While the OIG investigates and can impose civil penalties and exclusions, and the FBI investigates federal crimes, the DOJ leads the ultimate criminal prosecution in court.
Which training delivery format is MOST appropriate for reaching large numbers of geographically dispersed employees?
Answer: Online or e-learning modules
Online e-learning modules allow consistent, trackable compliance training delivery across multiple locations simultaneously.
Under the COSO framework, the 'control environment' component is best described as:
Answer: The foundation of internal control, shaped by management's integrity, ethics, and governance structure
The control environment sets the overall tone of the organization and is the foundation upon which all other components of internal control rest.
Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
Answer: Law firms that advise hospitals
Law firms that advise healthcare entities are business associates, not covered entities; covered entities are providers, health plans, and clearinghouses.
What is a 'remittance advice' (RA) in medical billing?
Answer: A notice from a payer explaining how a claim was processed, including payment amounts or denial reasons
A remittance advice is issued by a payer to a provider after claim adjudication, detailing any payment made, contractual adjustments applied, patient responsibility amounts, and the reason codes for any denials.