CRCR CRCR - Certified Revenue Cycle Representative Program Healthcare Compliance and Regulations 4 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered a covered entity?
- Health plan
- Healthcare clearinghouse
- Healthcare provider that transmits health information electronically
- A self-insured employer that administers its own health plan internally without using a third-party administrator (Correct answer)
Correct answer: A self-insured employer that administers its own health plan internally without using a third-party administrator
A self-insured employer acting solely in its capacity as an employer is not a covered entity; however, if it uses a TPA to administer the plan, the TPA (not the employer) is the covered entity.
Question 2: The OIG's Work Plan is significant for revenue cycle compliance because it:
- Lists all providers currently under federal investigation
- Identifies audit areas and billing vulnerabilities OIG plans to review in the coming year (Correct answer)
- Sets Medicare reimbursement rates for the upcoming fiscal year
- Establishes new coding guidelines for CPT updates
Correct answer: Identifies audit areas and billing vulnerabilities OIG plans to review in the coming year
The OIG Work Plan outlines specific topics and billing areas OIG will audit, helping compliance teams proactively self-audit those same areas.
Question 3: A patient requests access to their Protected Health Information (PHI) under HIPAA. In most cases, the covered entity must provide access within:
- 10 business days
- 30 days, with one 30-day extension if needed (Correct answer)
- 60 days
- 90 days with written justification
Correct answer: 30 days, with one 30-day extension if needed
HIPAA requires covered entities to act on an individual's request for access to PHI within 30 days, with one 30-day extension allowed if the individual is notified in writing.
Question 4: Which of the following best describes 'upcoding' in the context of healthcare billing compliance?
- Submitting claims for services not rendered
- Billing a higher-level or more complex code than the service actually provided (Correct answer)
- Using an incorrect patient identifier on a claim
- Submitting duplicate claims for the same service
Correct answer: Billing a higher-level or more complex code than the service actually provided
Upcoding is billing a code that reflects a higher level of service or a more expensive procedure than was actually performed, which is a form of healthcare fraud.
Question 5: Under the Conditions of Participation (CoPs) for Medicare, hospitals must maintain a compliance program that includes which of the following?
- An annual external audit by a CMS-certified firm
- Written standards, training, a compliance officer, and a reporting mechanism (Correct answer)
- Board-level approval of all billing codes used
- Mandatory employee background checks every two years
Correct answer: Written standards, training, a compliance officer, and a reporting mechanism
CMS Conditions of Participation require hospitals to have a compliance program including written policies, training, a compliance officer, and a confidential reporting system.
Question 6: What is the primary purpose of the Medicare Physician Fee Schedule (MPFS) in revenue cycle management?
- To set hospital inpatient reimbursement rates
- To determine payment amounts for services rendered by physicians and other practitioners billed under Part B (Correct answer)
- To establish global surgical package definitions only
- To set premium amounts for Medicare Advantage plans
Correct answer: To determine payment amounts for services rendered by physicians and other practitioners billed under Part B
The MPFS establishes the payment rates for physician and practitioner services under Medicare Part B, based on Relative Value Units (RVUs) and a conversion factor.
Question 7: A hospital receives a Recovery Audit Contractor (RAC) audit demand letter requesting medical records for a claim submitted two years ago. What is the RAC's look-back period for most claims?
- 1 year
- 2 years
- 3 years (Correct answer)
- 5 years
Correct answer: 3 years
RACs can look back up to 3 years from the date the claim was filed when conducting post-payment reviews of Medicare and Medicaid claims.
Under HIPAA, which of the following is NOT considered a covered entity?