CHC - Certified in Healthcare Compliance Standards, Policies, and Procedures Questions and Answers — Questions and Answers
Question 1: A healthcare organization is developing its compliance program. Which of the following BEST distinguishes between policies and procedures?
- Policies are detailed, step-by-step instructions for specific tasks, while procedures are high-level statements of intent.
- Policies are high-level statements of management's intent and values, while procedures provide mandatory, step-by-step instructions to implement those policies. (Correct answer)
- Policies are optional guidelines, whereas procedures are mandatory regulations enforced by government agencies.
- Policies apply only to clinical staff, while procedures apply to all employees and contractors.
Correct answer: Policies are high-level statements of management's intent and values, while procedures provide mandatory, step-by-step instructions to implement those policies.
Policies are broad, high-level statements that communicate management's intent, goals, and the organization's values. Procedures are the detailed, mandatory, step-by-step instructions that describe how to carry out a policy. For example, a policy might state that the organization will protect patient information, while a procedure would outline the specific steps for accessing, sharing, and destroying PHI.
Question 2: When implementing new and revised compliance policies, which of the following is the MOST critical initial step to ensure effectiveness and adoption by staff?
- Conducting a detailed cost-benefit analysis of the new policy.
- Distributing the policy document via email to all employees.
- Developing a clear communication and training plan tailored to different audiences. (Correct answer)
- Immediately implementing disciplinary action for non-adherence.
Correct answer: Developing a clear communication and training plan tailored to different audiences.
Effective implementation hinges on ensuring staff understand the new policies and their importance. A clear communication and training plan is the most critical first step to achieve this understanding. While distribution is part of communication, a comprehensive plan includes training, opportunities for questions, and explaining the 'why' behind the policy, which is essential for buy-in and adherence.
Question 3: A compliance officer at a large hospital system discovers that a recently implemented billing procedure conflicts with a long-standing coding policy, leading to claim submission errors. What is the BEST course of action for the compliance officer?
- Immediately halt all billing until the procedure can be rewritten.
- Discipline the department manager responsible for implementing the conflicting procedure.
- Report the issue to the OIG without first attempting internal resolution.
- Convene relevant stakeholders to review the conflict, revise the documents for consistency, and provide education on the corrected process. (Correct answer)
Correct answer: Convene relevant stakeholders to review the conflict, revise the documents for consistency, and provide education on the corrected process.
The best course of action is to address the problem systematically. This involves bringing together the relevant parties (e.g., from billing, coding, and compliance) to understand the discrepancy, revise the policy and/or procedure to ensure they are aligned and compliant, and then re-educate the staff on the correct, harmonized process. This approach corrects the root cause and prevents future errors.
Question 4: According to the OIG's Seven Elements of an Effective Compliance Program, written policies and procedures should be developed to address which of the following?
- Only the specific regulations cited in the most recent OIG Work Plan.
- The high-risk areas identified through the organization's specific risk assessment process. (Correct answer)
- A standard set of templates provided by the American Hospital Association.
- Primarily the organization's human resources and employee conduct guidelines.
Correct answer: The high-risk areas identified through the organization's specific risk assessment process.
An effective compliance program's policies and procedures must be tailored to the organization. This involves conducting a risk assessment to identify specific areas of vulnerability and high risk (e.g., billing, physician relationships, data privacy) and then developing policies and procedures to mitigate those identified risks.
Question 5: Which of the following is a key requirement for the ongoing management of compliance policies and procedures?
- A process for certifying that every employee has memorized all key policies.
- A system for annual review and updates to reflect changes in laws, regulations, and business operations. (Correct answer)
- Archiving all policies that are more than three years old, regardless of their current relevance.
- Ensuring all policies are written exclusively by external legal counsel to guarantee compliance.
Correct answer: A system for annual review and updates to reflect changes in laws, regulations, and business operations.
Compliance policies and procedures are not static documents. An essential component of an effective compliance program is to have a system in place for their periodic (at least annual) review and update. This ensures they remain current with changing laws, regulations, and the organization's own operational realities.
Question 6: In the hierarchy of compliance documentation, what is the role of a 'Standard'?
- A high-level statement of management intent that guides decisions.
- A step-by-step guide on how to perform a specific task.
- A formally-established, mandatory requirement that provides quantifiable metrics to enforce a policy. (Correct answer)
- A general recommendation or best practice that is not mandatory.
Correct answer: A formally-established, mandatory requirement that provides quantifiable metrics to enforce a policy.
In the common GRC (Governance, Risk, and Compliance) hierarchy, a policy sets the high-level intent. A standard provides the specific, mandatory, and quantifiable requirements needed to meet that policy (e.g., 'Passwords must be at least 12 characters'). A procedure then details the steps to meet the standard. Guidelines are typically non-mandatory recommendations.
A healthcare organization is developing its compliance program.
Which of the following BEST distinguishes between policies and procedures?