CHC Compliance Risk Assessments 4 — Questions and Answers
Question 1: A compliance officer wants to distinguish between risks the organization can tolerate and those requiring immediate action. Which concept guides this decision?
- Risk capacity
- Risk appetite
- Risk transfer
- Risk tolerance threshold (Correct answer)
Correct answer: Risk tolerance threshold
A risk tolerance threshold defines the acceptable level of risk beyond which the organization must act, separating tolerable risks from those requiring intervention.
Question 2: Which data source is LEAST useful when identifying compliance risks in a physician practice?
- Claims denial patterns from payers
- Employee complaint hotline reports
- Office furniture inventory logs (Correct answer)
- Patient complaint records
Correct answer: Office furniture inventory logs
Furniture inventory logs contain no information relevant to billing, coding, privacy, or other compliance risk areas for a physician practice.
Question 3: A hospital risk assessment reveals high inherent risk in physician self-referrals. Which law governs this area?
- Anti-Kickback Statute only
- Stark Law (Physician Self-Referral Law) (Correct answer)
- HIPAA Security Rule
- Emergency Medical Treatment and Labor Act (EMTALA)
Correct answer: Stark Law (Physician Self-Referral Law)
The Stark Law prohibits physicians from referring patients to entities with which they have a financial relationship unless a specific exception applies.
Question 4: When using a risk assessment survey to gather input from department managers, the compliance team should PRIMARILY ensure that:
- Questions are open-ended only, with no rating scales
- Responses are anonymous to encourage candid feedback (Correct answer)
- Surveys are completed only by the CEO and CFO
- All survey data is shared publicly with patients
Correct answer: Responses are anonymous to encourage candid feedback
Anonymity encourages honest reporting of risks and concerns that employees might otherwise fear disclosing to leadership.
Question 5: A compliance officer at a large health system is tasked with risk-stratifying 50 identified compliance risks. Which criterion should be applied FIRST to triage the list?
- Alphabetical order of the risk description
- Whether the risk was identified by internal or external sources
- Combined score of likelihood and potential impact (Correct answer)
- Date the risk was originally identified
Correct answer: Combined score of likelihood and potential impact
Combining likelihood and impact produces a risk score that objectively ranks risks, enabling the compliance team to direct resources toward the most critical exposures first.
Question 6: Which of the following scenarios represents a 'trigger event' that should prompt an unscheduled compliance risk assessment update?
- Routine quarterly board meeting
- Acquisition of a new hospital or practice (Correct answer)
- Annual open enrollment period for employee benefits
- Filing of the organization's annual tax return
Correct answer: Acquisition of a new hospital or practice
An acquisition introduces new processes, staff, systems, and regulatory exposures that must be assessed before they are fully integrated.
Question 7: What role does the compliance risk assessment play within the broader framework of an effective compliance program?
- It replaces the need for a code of conduct
- It serves as the foundation for directing compliance resources, training, and audit priorities (Correct answer)
- It eliminates all identified compliance risks permanently
- It substitutes for mandatory government reporting
Correct answer: It serves as the foundation for directing compliance resources, training, and audit priorities
The risk assessment informs where the compliance program should focus its limited resources, including audits, training, and policy development.
A compliance officer wants to distinguish between risks the organization can tolerate and those requiring immediate action.
Which concept guides this decision?