Medical Billing Software Risk Assessment & Management 3 — Questions and Answers
Question 1: A billing manager receives an email appearing to be from a payer requesting updated EFT bank routing information. What type of attack is this?
- Business Email Compromise (BEC) / phishing targeting payment redirection (Correct answer)
- A legitimate payer update process
- A ransomware deployment attempt
- A denial-of-service attack
Correct answer: Business Email Compromise (BEC) / phishing targeting payment redirection
Redirecting EFT payments via fraudulent emails is a Business Email Compromise scheme, one of the highest-cost fraud types in healthcare billing.
Question 2: Which metric best measures the financial impact of billing software downtime on a medical practice?
- Revenue at Risk per hour, calculated from average daily collections divided by operating hours (Correct answer)
- Number of patient records stored in the system
- The vendor's SLA uptime percentage alone
- Total number of user licenses purchased
Correct answer: Revenue at Risk per hour, calculated from average daily collections divided by operating hours
Revenue at Risk per hour quantifies the direct financial exposure of downtime and drives decisions about acceptable recovery time objectives.
Question 3: A practice's risk register shows 'payer audit of E&M coding' as HIGH likelihood and HIGH impact. What action is most appropriate?
- Implement immediate corrective action: internal coding audit, staff training, and prospective review (Correct answer)
- Accept the risk because payer audits are routine
- Transfer the risk by purchasing malpractice insurance
- Avoid the risk by stopping E&M billing
Correct answer: Implement immediate corrective action: internal coding audit, staff training, and prospective review
High-likelihood, high-impact risks require proactive mitigation through audits, training, and process controls, not acceptance or avoidance.
Question 4: Under the OIG Work Plan, which billing practice is flagged as a recurring risk area for outpatient facilities?
- Upcoding evaluation and management (E&M) services to higher complexity levels than documented (Correct answer)
- Submitting claims electronically instead of on paper
- Using clearinghouses to route claims
- Enrolling providers in the PECOS system
Correct answer: Upcoding evaluation and management (E&M) services to higher complexity levels than documented
E&M upcoding is a perennial OIG Work Plan target because documentation often does not support the higher-level codes billed.
Question 5: What does a 'probability × impact' matrix produce in a risk assessment?
- A risk score used to prioritize which risks require the most urgent mitigation (Correct answer)
- A guaranteed prediction of future losses
- A list of all HIPAA violations
- A vendor performance scorecard
Correct answer: A risk score used to prioritize which risks require the most urgent mitigation
Multiplying probability by impact yields a risk score that allows organizations to rank and prioritize risks for mitigation planning.
Question 6: A clearinghouse that routes your claims experiences a data breach exposing 50,000 patient records. Who bears primary HIPAA notification responsibility to affected patients?
- The covered entity (the medical practice), not the clearinghouse acting as its Business Associate (Correct answer)
- The clearinghouse exclusively, because it holds the data
- The payers who received the claims
- HHS Office for Civil Rights directly notifies patients
Correct answer: The covered entity (the medical practice), not the clearinghouse acting as its Business Associate
Under HIPAA Breach Notification Rule, covered entities must notify affected individuals even when the breach occurs at a Business Associate.
Question 7: Which scenario represents an inherent risk in medical billing software rather than a residual risk?
- The possibility of coding errors before any internal audit controls are applied (Correct answer)
- The coding error rate remaining after internal audits are performed
- The number of claims denied after a scrubbing tool is implemented
- The downtime remaining after a redundant server is installed
Correct answer: The possibility of coding errors before any internal audit controls are applied
Inherent risk is the raw risk before controls are applied; residual risk is what remains after controls are in place.
A billing manager receives an email appearing to be from a payer requesting updated EFT bank routing information.
What type of attack is this?