CPC Compliance, Regulatory & Legal Guidelines 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a covered entity?
- A medical billing company that only processes claims
- A health plan that pays for medical care (Correct answer)
- A software vendor that sells EHR systems
- A janitorial service that cleans a clinic
Correct answer: A health plan that pays for medical care
Health plans that pay for medical care are covered entities under HIPAA, along with healthcare providers and healthcare clearinghouses.
Question 2: Which federal act established the national do-not-pay list and requires providers to screen employees against exclusion databases?
- HITECH Act
- False Claims Act
- Social Security Act Section 1128 (Correct answer)
- Deficit Reduction Act
Correct answer: Social Security Act Section 1128
Section 1128 of the Social Security Act grants the OIG authority to exclude individuals and entities from federal healthcare programs and maintain the exclusion database.
Question 3: A coder discovers that a physician consistently documents 'chest pain' after the fact when the actual presenting complaint was a cough. This practice is best described as:
- Upcoding
- Unbundling
- Fraudulent documentation (Correct answer)
- Query clarification
Correct answer: Fraudulent documentation
Altering documentation to reflect conditions not present at the time of the encounter constitutes fraudulent documentation.
Question 4: The Physician Self-Referral Law (Stark Law) prohibits physicians from referring Medicare patients to entities where the physician has a financial relationship unless:
- The physician discloses the relationship to the patient
- A specific exception applies (Correct answer)
- The referral is for non-surgical services
- The entity is in the same medical group
Correct answer: A specific exception applies
Stark Law violations are strict liability but specific statutory and regulatory exceptions allow certain arrangements when strict criteria are met.
Question 5: Which type of audit is conducted by an outside organization to assess a facility's compliance program objectively?
- Internal audit
- Prospective audit
- External audit (Correct answer)
- Concurrent audit
Correct answer: External audit
An external audit is performed by an independent third party to provide an objective evaluation of coding accuracy and compliance.
Question 6: What is the primary purpose of a Corporate Integrity Agreement (CIA)?
- To permanently bar a provider from Medicare participation
- To outline corrective actions a provider must take to remain in federal programs (Correct answer)
- To establish coding benchmarks for a specialty
- To define billing rates for new procedures
Correct answer: To outline corrective actions a provider must take to remain in federal programs
A CIA is a negotiated agreement with the OIG requiring a provider to implement specific compliance measures in exchange for continued participation in federal healthcare programs.
Question 7: Under the False Claims Act, qui tam provisions allow:
- CMS to audit providers without notice
- Private individuals to file lawsuits on behalf of the government and share in any recovery (Correct answer)
- Coders to report fraud anonymously without legal standing
- Providers to self-disclose errors to avoid penalties
Correct answer: Private individuals to file lawsuits on behalf of the government and share in any recovery
Qui tam provisions permit private individuals (relators/whistleblowers) to sue on the government's behalf and receive a portion of the recovered funds.
Under HIPAA, which of the following is considered a covered entity?