CHAP Compliance & Regulatory Requirements 3 — Questions and Answers
Question 1: The Stark Law (Physician Self-Referral Law) prohibits physicians from referring Medicare patients to entities for designated health services when:
- The physician has a financial relationship with that entity, unless an exception applies (Correct answer)
- The entity is located more than 25 miles from the referring physician's office
- The referral is for a non-emergency service
- The patient has secondary insurance that would cover the service
Correct answer: The physician has a financial relationship with that entity, unless an exception applies
Stark Law prohibits physician self-referrals to entities with which they have a financial relationship unless a specific statutory or regulatory exception applies.
Question 2: Under OSHA's Bloodborne Pathogens Standard, employers must offer hepatitis B vaccination to:
- All employees regardless of job function
- Employees with occupational exposure to blood or other potentially infectious materials (Correct answer)
- Only employees in clinical departments
- New hires within 30 days of employment in any role
Correct answer: Employees with occupational exposure to blood or other potentially infectious materials
OSHA requires employers to offer hepatitis B vaccination at no cost to employees who have occupational exposure to blood or other potentially infectious materials.
Question 3: A Notice of Privacy Practices (NPP) under HIPAA must be provided to patients:
- Only upon request by the patient or their representative
- No later than the date of first service delivery (Correct answer)
- Annually, regardless of whether services are provided
- Only when PHI will be disclosed to a third party
Correct answer: No later than the date of first service delivery
HIPAA requires covered entities to provide the NPP no later than the date of first service delivery and make good-faith efforts to obtain written acknowledgment.
Question 4: Which government agency is responsible for enforcing HIPAA Privacy and Security Rules?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Office of Inspector General (OIG)
- Federal Trade Commission (FTC)
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for investigating HIPAA complaints and enforcing Privacy and Security Rules.
Question 5: An excluded individual under the OIG exclusion program:
- May work in non-clinical roles for healthcare organizations receiving federal funds
- Cannot participate in any capacity in federal healthcare programs (Correct answer)
- Is banned only from billing Medicare directly
- Must reapply for licensure through their state board
Correct answer: Cannot participate in any capacity in federal healthcare programs
OIG-excluded individuals are prohibited from participating in any capacity in federal healthcare programs, including in administrative or non-clinical roles.
Question 6: The Emergency Medical Treatment and Labor Act (EMTALA) requires hospital emergency departments to:
- Provide free care to all uninsured patients who present for treatment
- Provide a medical screening examination and stabilizing treatment regardless of ability to pay (Correct answer)
- Transfer patients to county hospitals if they lack insurance before treatment begins
- Obtain insurance verification before initiating a medical screening examination
Correct answer: Provide a medical screening examination and stabilizing treatment regardless of ability to pay
EMTALA mandates that hospitals with emergency departments provide a medical screening exam and stabilizing treatment to anyone who presents, regardless of ability to pay.
Question 7: Under the HITECH Act, which type of breach notification must be submitted to HHS and posted on the covered entity's website?
- Any breach affecting even a single individual's PHI
- Breaches affecting 500 or more individuals in a state or jurisdiction (Correct answer)
- All breaches discovered during an annual security risk assessment
- Breaches involving business associates only
Correct answer: Breaches affecting 500 or more individuals in a state or jurisdiction
HITECH requires covered entities to notify HHS and post a public notice on their website for breaches affecting 500 or more individuals in the same state or jurisdiction.
The Stark Law (Physician Self-Referral Law) prohibits physicians from referring Medicare patients to entities for designated health services when: