CMAS Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under the Anti-Kickback Statute, which of the following arrangements is MOST likely to be considered a safe harbor?
- A physician referring patients to a lab in which they have an ownership interest
- A vendor providing free office supplies to a practice in exchange for referrals
- A rental agreement between a hospital and a physician at fair market value for legitimate space (Correct answer)
- A hospital paying bonuses to physicians based solely on the volume of referrals
Correct answer: A rental agreement between a hospital and a physician at fair market value for legitimate space
Safe harbors under the Anti-Kickback Statute include space rental agreements set at fair market value that are not based on referral volume.
Question 2: The Stark Law primarily governs which type of prohibited conduct in healthcare?
- Physicians submitting false claims to Medicare
- Physicians self-referring patients to entities in which they have a financial relationship for designated health services (Correct answer)
- Hospitals engaging in deceptive billing practices
- Patients filing fraudulent insurance claims
Correct answer: Physicians self-referring patients to entities in which they have a financial relationship for designated health services
The Stark Law (Physician Self-Referral Law) prohibits physicians from referring Medicare/Medicaid patients to entities where the physician or an immediate family member has a financial relationship, unless an exception applies.
Question 3: A covered entity under HIPAA discovers a breach affecting 600 patients. Which notification steps are required?
- Notify patients only, no federal reporting needed
- Notify affected individuals and the HHS Secretary; media notice required if over 500 in one state (Correct answer)
- Notify only the HHS Secretary within 60 days
- No notification is required if the data was encrypted
Correct answer: Notify affected individuals and the HHS Secretary; media notice required if over 500 in one state
Breaches affecting 500 or more individuals in a single state require notification to affected individuals, the HHS Secretary, and prominent local media outlets.
Question 4: Which federal law requires employers to maintain a safe and healthful workplace, including exposure controls for bloodborne pathogens in medical settings?
- HIPAA
- CLIA
- OSHA (Correct answer)
- EMTALA
Correct answer: OSHA
OSHA (Occupational Safety and Health Administration) enforces workplace safety standards, including the Bloodborne Pathogens Standard applicable to healthcare settings.
Question 5: Under CLIA (Clinical Laboratory Improvement Amendments), laboratories performing moderate-complexity testing must meet which requirement?
- No certification is required for moderate-complexity tests
- Must obtain a CLIA certificate of waiver
- Must meet personnel, quality control, and proficiency testing standards (Correct answer)
- Are only regulated by individual state laws
Correct answer: Must meet personnel, quality control, and proficiency testing standards
Moderate-complexity labs under CLIA must comply with specific personnel qualifications, quality control procedures, and proficiency testing requirements.
Question 6: The HITECH Act expanded HIPAA enforcement by:
- Eliminating civil monetary penalties for HIPAA violations
- Extending HIPAA Privacy and Security Rules to business associates and increasing penalty tiers (Correct answer)
- Requiring all healthcare providers to adopt electronic health records immediately
- Reducing patient rights regarding access to their medical records
Correct answer: Extending HIPAA Privacy and Security Rules to business associates and increasing penalty tiers
HITECH directly extended HIPAA obligations to business associates and introduced a tiered civil monetary penalty structure based on culpability.
Question 7: A medical administrative specialist receives a subpoena duces tecum for a patient's records. What is the appropriate action?
- Immediately release all records to the requesting party without any review
- Consult with the healthcare provider or legal counsel before releasing records, as a court order may be required (Correct answer)
- Destroy the records to protect patient privacy
- Refuse to comply because HIPAA prohibits all disclosures in legal proceedings
Correct answer: Consult with the healthcare provider or legal counsel before releasing records, as a court order may be required
A subpoena duces tecum requires careful review; legal counsel should be consulted to determine whether patient authorization or a court order is needed before releasing protected health information.
Under the Anti-Kickback Statute, which of the following arrangements is MOST likely to be considered a safe harbor?