CPC Compliance and Regulatory Rules 3 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- Patient's date of birth linked to a diagnosis
- De-identified health information (Correct answer)
- Patient's ZIP code combined with treatment records
- Patient's name on a prescription
Correct answer: De-identified health information
De-identified health information that has been properly stripped of all 18 HIPAA identifiers is not considered PHI.
Question 2: A physician self-refers a Medicare patient for physical therapy services at a physical therapy clinic in which the physician has a financial interest. This likely violates:
- The False Claims Act
- The Anti-Kickback Statute only
- The Stark Law (Physician Self-Referral Law) (Correct answer)
- HIPAA Security Rule
Correct answer: The Stark Law (Physician Self-Referral Law)
The Stark Law prohibits physicians from referring patients to entities providing designated health services in which the physician has a financial relationship.
Question 3: Which type of Medicare audit is conducted by Recovery Audit Contractors (RACs) to identify and correct improper payments?
- Prepayment review
- Post-payment review (Correct answer)
- Probe and educate review
- Comprehensive error rate testing
Correct answer: Post-payment review
RAC audits are post-payment reviews that look back at claims already paid by Medicare to identify overpayments and underpayments.
Question 4: When a provider bills for services that were never rendered to the patient, this is classified as:
- Upcoding
- Unbundling
- Phantom billing (Correct answer)
- Duplicate billing
Correct answer: Phantom billing
Phantom billing (also called billing for services not rendered) is submitting claims for services that were never actually provided to the patient.
Question 5: The OIG Work Plan is published annually to indicate which areas are under scrutiny for potential fraud and abuse. Who publishes the OIG Work Plan?
- Centers for Medicare & Medicaid Services (CMS)
- Department of Justice (DOJ)
- Office of Inspector General (OIG) of HHS (Correct answer)
- American Medical Association (AMA)
Correct answer: Office of Inspector General (OIG) of HHS
The OIG Work Plan is published by the HHS Office of Inspector General and outlines planned audits and investigations for the coming year.
Question 6: A compliance officer discovers that a coder has been consistently assigning higher-level E/M codes without supporting documentation. The FIRST step should be to:
- Terminate the coder immediately
- Report the coder to law enforcement
- Conduct an internal investigation and education (Correct answer)
- Refund all overpayments immediately without investigation
Correct answer: Conduct an internal investigation and education
The first step in addressing potential compliance issues is to conduct an internal investigation and provide education before taking more drastic action.
Question 7: Which Medicare program requires providers to report and return overpayments within 60 days of identification?
- Medicare Advantage
- Medicare Fee-for-Service (Correct answer)
- Medicaid
- CHIP
Correct answer: Medicare Fee-for-Service
Under the ACA's '60-day rule,' Medicare FFS providers must report and return identified overpayments within 60 days or face False Claims Act liability.
Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?