CHC Standards, Policies, and Procedures 4 — Questions and Answers
Question 1: When developing a new compliance policy, stakeholder input should be gathered PRIMARILY from:
- External auditors only, to ensure objectivity
- Subject matter experts, operational staff, legal counsel, and leadership (Correct answer)
- The compliance department in isolation to maintain independence
- Only the C-suite to ensure strategic alignment
Correct answer: Subject matter experts, operational staff, legal counsel, and leadership
Effective policies reflect operational realities and regulatory requirements, requiring input from those who implement the policy, legal counsel, and organizational leadership.
Question 2: Which of the following BEST characterizes an effective policy exception process?
- Exceptions should be discouraged and never formally documented
- Exceptions require documented justification, risk assessment, and approval by authorized leadership (Correct answer)
- Any manager can grant an exception verbally without documentation
- Exceptions are only permitted for processes not covered by federal law
Correct answer: Exceptions require documented justification, risk assessment, and approval by authorized leadership
A formal exception process requires written justification, risk assessment, and approval from appropriate authority to maintain accountability and auditability.
Question 3: A compliance audit reveals that staff in one department are unaware of the organization's conflict-of-interest policy. This finding MOST directly indicates a failure in:
- Policy drafting quality
- Training and communication mechanisms (Correct answer)
- External regulatory oversight
- The board's fiduciary duties
Correct answer: Training and communication mechanisms
Staff unawareness of an existing policy signals a breakdown in training, communication, or distribution channels rather than a policy drafting problem.
Question 4: The OIG's Corporate Integrity Agreements (CIAs) typically require organizations to:
- Immediately terminate all federal program participation
- Implement specific compliance program elements, reporting, and independent review (Correct answer)
- Adopt voluntary self-disclosure as a permanent compliance strategy
- Replace their board of directors with government-appointed overseers
Correct answer: Implement specific compliance program elements, reporting, and independent review
CIAs obligate organizations to implement OIG-specified compliance enhancements, annual certifications, and often independent review organization (IRO) monitoring.
Question 5: Which approach BEST supports consistent application of compliance policies across multiple facilities within a health system?
- Allowing each facility to develop its own independent compliance policies
- Establishing system-wide policies with facility-specific addenda addressing local variations (Correct answer)
- Requiring all facilities to follow only the most restrictive state's regulations
- Publishing policies exclusively on the corporate intranet without local distribution
Correct answer: Establishing system-wide policies with facility-specific addenda addressing local variations
System-wide policies ensure consistency while facility-specific addenda allow for legitimate local operational or regulatory differences.
Question 6: Under HIPAA, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:
- Only upon a patient's written request
- No later than the first service delivery after April 14, 2003 (Correct answer)
- Annually regardless of whether the patient has received care
- Only when the covered entity changes its privacy practices
Correct answer: No later than the first service delivery after April 14, 2003
HIPAA requires covered entities to provide the NPP no later than the date of first service delivery and to make good-faith efforts to obtain written acknowledgment of receipt.
Question 7: A hospital's policy prohibits employees from accepting gifts valued at more than $25 from vendors. An employee receives a $50 vendor gift but returns it immediately. According to compliance best practices, the employee should NEXT:
- Take no further action since the gift was returned
- Report the offer to the compliance department per policy (Correct answer)
- Notify the vendor's sales manager directly
- Document the incident in their personal records only
Correct answer: Report the offer to the compliance department per policy
Best practice requires reporting gift offers that exceed the policy threshold to the compliance department, even when the gift is returned, to enable tracking and monitoring of vendor relationships.
When developing a new compliance policy, stakeholder input should be gathered PRIMARILY from: