HAC Healthcare Analyst Risk Assessment & Compliance 3 — Questions and Answers
Question 1: A healthcare analyst is performing a HIPAA risk analysis. Which NIST publication provides the most widely used framework for this process?
- NIST SP 800-53
- NIST SP 800-30
- NIST SP 800-66 (Correct answer)
- NIST SP 800-171
Correct answer: NIST SP 800-66
NIST SP 800-66 (An Introductory Resource Guide for Implementing the HIPAA Security Rule) is specifically tailored to help organizations conduct HIPAA security risk assessments.
Question 2: Which type of healthcare fraud involves billing for services at a higher complexity level than was actually provided?
- Unbundling
- Upcoding (Correct answer)
- Phantom billing
- Double billing
Correct answer: Upcoding
Upcoding is the practice of submitting claims for more complex or expensive services than were actually rendered, inflating reimbursement from payers.
Question 3: A hospital's compliance audit finds that certain CPT codes are routinely billed separately when they should be billed together under one code. This is an example of:
- Upcoding
- Unbundling (Correct answer)
- Churning
- Waiver of cost-sharing
Correct answer: Unbundling
Unbundling involves separately billing individual components of a procedure that should be billed together under a single bundled CPT code, resulting in higher reimbursement.
Question 4: In a healthcare risk matrix, what two dimensions are typically used to assess and prioritize risks?
- Cost and duration
- Likelihood and impact (Correct answer)
- Frequency and severity of past incidents
- Regulatory citation rate and penalty amount
Correct answer: Likelihood and impact
A standard risk matrix plots risks on the axes of likelihood (probability of occurrence) and impact (severity of consequences) to prioritize mitigation efforts.
Question 5: What is the primary purpose of a healthcare organization's Internal Audit function in relation to compliance?
- To negotiate contracts with payers
- To independently assess the effectiveness of internal controls and compliance processes (Correct answer)
- To approve all clinical protocols
- To manage the revenue cycle billing team
Correct answer: To independently assess the effectiveness of internal controls and compliance processes
Internal Audit provides independent, objective assurance that compliance controls are functioning effectively and that identified risks are being appropriately managed.
Question 6: The False Claims Act's 'qui tam' provision allows:
- CMS to audit claims without prior notice
- Private individuals to file lawsuits on behalf of the government and share in any recovery (Correct answer)
- Physicians to self-report overpayments without penalty
- State attorneys general to prosecute Medicare fraud
Correct answer: Private individuals to file lawsuits on behalf of the government and share in any recovery
The qui tam provision of the False Claims Act empowers whistleblowers (relators) to file suit on the government's behalf and receive 15–30% of the recovered funds.
Question 7: Which regulation requires healthcare organizations to report and return Medicare and Medicaid overpayments within 60 days of identification?
- HIPAA Privacy Rule
- Affordable Care Act Section 6402 (Correct answer)
- Stark Law Safe Harbor
- Anti-Kickback Statute exception
Correct answer: Affordable Care Act Section 6402
ACA Section 6402 (the '60-day rule') requires providers to report and return identified overpayments within 60 days, or they face False Claims Act liability.
A healthcare analyst is performing a HIPAA risk analysis.
Which NIST publication provides the most widely used framework for this process?