CHC Compliance Program Administration 4 — Questions and Answers
Question 1: A healthcare compliance officer receives an anonymous hotline report alleging that a supervisor is falsifying patient records. What is the correct FIRST step?
- Immediately terminate the supervisor
- Notify the supervisor that a complaint has been filed
- Conduct a preliminary assessment to determine if an investigation is warranted (Correct answer)
- Discard the report since it is anonymous
Correct answer: Conduct a preliminary assessment to determine if an investigation is warranted
All hotline reports, including anonymous ones, require a preliminary assessment to determine scope, severity, and whether a formal investigation is needed.
Question 2: Under the False Claims Act, what is 'qui tam' litigation?
- A government audit of Medicare claims
- A whistleblower lawsuit filed on behalf of the government by a private individual (Correct answer)
- A mandatory self-disclosure to the OIG
- A type of compliance certification
Correct answer: A whistleblower lawsuit filed on behalf of the government by a private individual
Qui tam provisions of the False Claims Act allow private individuals (relators) to sue on behalf of the government and share in any recovery.
Question 3: Which of the following is a key characteristic of an effective compliance hotline?
- It is managed exclusively by the HR department
- It allows for anonymous reporting and is available 24/7 (Correct answer)
- It only accepts reports from supervisors
- It requires reporters to provide their employee ID number
Correct answer: It allows for anonymous reporting and is available 24/7
An effective compliance hotline must allow anonymous reporting and be accessible around the clock to encourage employees to report concerns without fear.
Question 4: A compliance program's work plan should PRIMARILY be based on which of the following?
- The prior year's work plan copied verbatim
- Results of the organization's current risk assessment (Correct answer)
- Requests from department heads only
- National benchmarks with no local customization
Correct answer: Results of the organization's current risk assessment
The annual work plan should be driven by the current risk assessment to ensure compliance activities address the organization's most significant and timely risks.
Question 5: What is the primary function of compliance monitoring as distinct from compliance auditing?
- Monitoring involves one-time deep-dive reviews; auditing is ongoing
- Monitoring is ongoing and routine; auditing involves in-depth, periodic review of specific areas (Correct answer)
- Monitoring is only conducted by external parties; auditing is internal
- Monitoring and auditing are identical activities with different names
Correct answer: Monitoring is ongoing and routine; auditing involves in-depth, periodic review of specific areas
Monitoring is a continuous, routine process to detect potential issues early, while auditing is a more structured, periodic examination of specific risk areas.
Question 6: Which of the following scenarios would MOST likely require a self-disclosure to the OIG's Self-Disclosure Protocol?
- A coding error that resulted in a $50 underpayment
- Potential violations of the Anti-Kickback Statute involving physician arrangements (Correct answer)
- A minor HIPAA administrative safeguard deficiency
- A documentation issue with no financial impact
Correct answer: Potential violations of the Anti-Kickback Statute involving physician arrangements
The OIG Self-Disclosure Protocol is designed for providers who identify potential fraud violations, particularly Anti-Kickback Statute or False Claims Act issues.
Question 7: In the context of healthcare compliance, what does 'downstream risk' refer to?
- Financial risks that decrease over time
- Compliance risks passed to an organization through its business partners and vendors (Correct answer)
- Risks identified in lower-level staff positions
- Audit findings from previous fiscal years
Correct answer: Compliance risks passed to an organization through its business partners and vendors
Downstream risk refers to compliance liability that an organization may inherit from its business associates, contractors, or referral partners who engage in non-compliant behavior.
A healthcare compliance officer receives an anonymous hotline report alleging that a supervisor is falsifying patient records.
What is the correct FIRST step?