CHC Cheat Sheet 2026
The 30 highest-yield CHC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
180 min time limit
70% to pass
- Under the False Claims Act, what is the minimum per-claim civil penalty range (approximately) for a false claim submitted to the government? → $13,000 to $27,000
- Under an effective compliance program, who typically bears primary oversight responsibility for the compliance hotline? → The Chief Compliance Officer
- A compliance audit of E/M coding reveals that 80% of visits are coded at the highest level of service. What is the MOST likely compliance concern? → Upcoding, where services are billed at a higher complexity level than documented
- Which HIPAA standard governs the electronic exchange of health information for claims and remittance advice? → The Transactions and Code Sets Rule
- Under the Affordable Care Act, providers must report and return Medicare overpayments within how many days of identifying the overpayment? → 60 days
- Which of the following is the PRIMARY purpose of a healthcare organization's document retention policy? → To ensure records are retained for legally required periods and disposed of securely
- When developing a compliance training program, which population should receive the MOST specialized and detailed training content? → High-risk employees whose job functions directly involve regulated activities
- The False Claims Act (FCA) imposes liability on healthcare organizations that submit claims that are: → Knowingly false or fraudulent to government payers
- A hospital discovers that a physician has been receiving free office space from the hospital in exchange for referrals. This most likely violates which law? → Anti-Kickback Statute
- Which document BEST establishes the authority and methodology for a healthcare compliance investigation? → A formal investigation charter or mandate signed by appropriate leadership
- A compliance officer is updating a policy on medical necessity documentation. Which external source should be consulted FIRST to ensure regulatory alignment? → CMS Local Coverage Determinations (LCDs) and National Coverage Determinations (NCDs)
- What is the PRIMARY purpose of benchmarking against OIG Work Plans during a compliance risk assessment? → To identify areas regulators are actively scrutinizing for potential fraud and abuse
- Which of the OIG's seven elements of an effective compliance program specifically addresses reporting mechanisms? → Element 4: Open lines of communication
- The 'two-midnight rule' in Medicare billing primarily governs which type of admission? → Inpatient hospital admissions and whether they meet criteria for Part A payment
- Under OIG guidance, which of the following is a core element that an effective compliance training program must include? → Training on applicable laws, regulations, and organizational policies
- A compliance officer discovers a pattern of upcoding in physician billing. Which type of audit should be initiated first? → Reactive focused audit
- Which of the following training topics is MOST critical for healthcare billing staff to receive annually? → Proper documentation requirements and coding compliance under federal billing rules
- A compliance officer interviews department heads and finds conflicting opinions on the severity of a billing risk. What is the BEST approach to resolve this? → Triangulate findings using claims data, audit results, and regulatory guidance
- Which of the following is an example of a 'corrective action plan' element following an internal compliance investigation? → Implementing mandatory retraining and enhanced monitoring for the implicated process
- Which element distinguishes the Stark Law from the Anti-Kickback Statute with respect to intent? → Stark is strict liability; AKS requires proof of knowing and willful intent
- What is the statute of limitations for the government to bring a False Claims Act civil suit not involving a qui tam relator? → 6 years
- Under the OIG's Seven Elements of an Effective Compliance Program, policies and procedures should be reviewed at minimum: → Annually or when significant regulatory changes occur
- Which Stark Law exception applies when a hospital employs a physician and pays fair market value compensation for identifiable services? → Bona fide employment exception
- Which agency operates the primary federal hotline (1-800-HHS-TIPS) for reporting Medicare and Medicaid fraud? → Office of Inspector General (OIG)
- A compliance risk assessment should inform policy development by: → Identifying high-risk areas where robust policy controls are most needed
- A compliance officer is rating risks on a 1-5 scale for both likelihood and impact. What does this technique produce? → A risk score used to rank and prioritize risks
- A compliance officer learns that a manager discouraged an employee from using the compliance hotline. Which compliance program element has most directly failed? → Non-intimidation and non-retaliation protections
- Which of the following is NOT one of the OIG's seven elements of an effective compliance program? → Requiring a board-approved annual compliance audit by external counsel
- What is a Recovery Audit Contractor (RAC) and what is its role in billing compliance? → A CMS-contracted auditor that identifies and recovers improper Medicare payments
- Under HIPAA's Security Rule, which implementation specification is 'required' versus 'addressable' for the Workstation Use standard? → Workstation Use is required; covered entities must implement it
Turn these facts into recall:
Was this helpful?