CHC Compliance Risk Assessments 5 — Questions and Answers
Question 1: A compliance officer interviews department heads and finds conflicting opinions on the severity of a billing risk. What is the BEST approach to resolve this?
- Accept the most senior leader's opinion
- Triangulate findings using claims data, audit results, and regulatory guidance (Correct answer)
- Remove the risk from the assessment
- Assign the lowest possible risk score to avoid alarm
Correct answer: Triangulate findings using claims data, audit results, and regulatory guidance
Triangulating multiple data sources provides an objective, evidence-based risk rating that is more reliable than any single opinion.
Question 2: Under the HITECH Act, which type of organization is required to conduct a security risk analysis as part of compliance?
- Any organization with more than 500 employees
- Covered entities and business associates handling electronic protected health information (Correct answer)
- Only federally funded hospitals
- All publicly traded healthcare companies
Correct answer: Covered entities and business associates handling electronic protected health information
HITECH expanded HIPAA requirements to business associates, making both covered entities and their business associates responsible for conducting security risk analyses.
Question 3: A compliance risk assessment at a behavioral health clinic identifies high risk in medical record documentation. Which next step is MOST appropriate?
- Report the finding directly to the state attorney general
- Design and implement a targeted audit and corrective action plan for documentation practices (Correct answer)
- Dismiss the finding because documentation is a clinical not a compliance issue
- Wait for the next annual assessment cycle to address the risk
Correct answer: Design and implement a targeted audit and corrective action plan for documentation practices
High-priority findings from a risk assessment must be addressed through targeted audits and corrective action plans, not deferred or ignored.
Question 4: Which component of a compliance risk assessment ensures that responsibilities for mitigating each identified risk are clearly assigned?
- Risk scoring matrix
- Risk ownership assignment (Correct answer)
- Likelihood estimation model
- Control design checklist
Correct answer: Risk ownership assignment
Assigning a specific risk owner to each identified risk ensures accountability and drives follow-through on mitigation efforts.
Question 5: A compliance officer is presenting risk assessment findings to the board of directors. Which format is MOST effective for communicating the overall risk landscape?
- A 50-page technical narrative report
- A color-coded risk heat map with a summary of top 10 risks and proposed mitigations (Correct answer)
- A raw spreadsheet of all 200 individual risk items
- A verbal briefing with no supporting documentation
Correct answer: A color-coded risk heat map with a summary of top 10 risks and proposed mitigations
A heat map with a top-risk summary gives board members a clear, actionable picture of priorities without overwhelming them with granular detail.
Question 6: In third-party vendor management, why is it important to include vendors in a healthcare compliance risk assessment?
- Vendors are legally required to pay for the cost of the assessment
- Vendors handling PHI or performing regulated functions create compliance exposure for the covered entity (Correct answer)
- Vendor contracts eliminate all compliance liability
- Vendors are exempt from HIPAA obligations
Correct answer: Vendors handling PHI or performing regulated functions create compliance exposure for the covered entity
Under HIPAA and the False Claims Act, covered entities can face liability for compliance failures occurring through their vendors, making vendor risk a key assessment area.
Question 7: A compliance team wants to validate that their risk assessment methodology is consistent with industry standards. Which resource BEST supports this?
- IRS Publication 15 (Employer Tax Guide)
- OIG Compliance Program Guidance and the COSO Enterprise Risk Management Framework (Correct answer)
- CMS Medicare Advantage marketing guidelines only
- Joint Commission National Patient Safety Goals
Correct answer: OIG Compliance Program Guidance and the COSO Enterprise Risk Management Framework
The OIG compliance program guidance and the COSO ERM framework together provide the most authoritative and widely accepted standards for healthcare compliance risk assessment methodology.
A compliance officer interviews department heads and finds conflicting opinions on the severity of a billing risk.
What is the BEST approach to resolve this?