CHAP Compliance & Regulatory Requirements 2 — Questions and Answers
Question 1: Under HIPAA's Minimum Necessary Standard, a covered entity sharing PHI must disclose:
- The entire medical record to ensure completeness
- Only the information reasonably needed to accomplish the intended purpose (Correct answer)
- All information the requesting party asks for
- PHI only after obtaining written authorization regardless of purpose
Correct answer: Only the information reasonably needed to accomplish the intended purpose
HIPAA's Minimum Necessary Standard requires covered entities to limit PHI disclosures to only what is needed for the specific purpose.
Question 2: Which federal law established the Anti-Kickback Statute (AKS) to combat healthcare fraud?
- Health Insurance Portability and Accountability Act (HIPAA)
- Social Security Act (Correct answer)
- False Claims Act
- Stark Law
Correct answer: Social Security Act
The Anti-Kickback Statute is codified under the Social Security Act and prohibits offering or accepting remuneration to induce referrals for federally funded healthcare services.
Question 3: A patient requests an amendment to their medical record under HIPAA. The covered entity may deny the request if:
- The record was created more than 6 months ago
- The record was not created by the covered entity (Correct answer)
- The patient does not provide a reason for the amendment
- The amendment would require deleting existing documentation
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if it did not create the record and the originating provider is available to act on the request.
Question 4: CMS Conditions of Participation (CoPs) apply primarily to:
- Private pay patients only
- Healthcare facilities participating in Medicare and Medicaid (Correct answer)
- Outpatient clinics with more than 50 employees
- Facilities accredited by The Joint Commission
Correct answer: Healthcare facilities participating in Medicare and Medicaid
CoPs are federal requirements that healthcare organizations must meet to participate in and receive payment from Medicare and Medicaid programs.
Question 5: The OIG Compliance Program Guidance recommends which element as the foundation of an effective compliance program?
- Mandatory employee bonuses tied to compliance metrics
- Written policies and procedures governing compliance activities (Correct answer)
- Annual external audits by a third-party firm
- A separate compliance department with no ties to administration
Correct answer: Written policies and procedures governing compliance activities
The OIG identifies written standards, policies, and procedures as the foundational element that guides all other compliance program components.
Question 6: Under the False Claims Act, 'qui tam' provisions allow:
- Government attorneys to file sealed complaints against providers
- Private individuals to file lawsuits on behalf of the government and share in any recovery (Correct answer)
- Medicare contractors to suspend payments during an investigation
- Physicians to report compliance violations anonymously to CMS
Correct answer: Private individuals to file lawsuits on behalf of the government and share in any recovery
Qui tam provisions of the False Claims Act allow whistleblowers (relators) to file suit on behalf of the government and receive a portion of any recovered funds.
Question 7: Which accreditation body uses the tracer methodology to evaluate a healthcare organization's compliance?
- National Committee for Quality Assurance (NCQA)
- The Joint Commission (TJC) (Correct answer)
- Utilization Review Accreditation Commission (URAC)
- Accreditation Association for Ambulatory Health Care (AAAHC)
Correct answer: The Joint Commission (TJC)
The Joint Commission uses tracer methodology, following individual patients through their care experience, to assess how well a facility's systems function together.
Under HIPAA's Minimum Necessary Standard, a covered entity sharing PHI must disclose: