PCE Industry Regulations 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a covered entity required to comply with privacy regulations?
- A physical therapy private practice billing insurance (Correct answer)
- A gym offering personal training services
- A medical equipment retail store with no insurance billing
- A wellness app with no healthcare provider affiliation
Correct answer: A physical therapy private practice billing insurance
Healthcare providers who transmit health information electronically in connection with covered transactions are considered covered entities under HIPAA.
Question 2: A physiotherapist discovers that a colleague has been billing for services not rendered. The MOST appropriate first action is to:
- Report the issue through the facility's compliance or ethics reporting process (Correct answer)
- Confront the colleague directly and demand they stop
- Ignore it unless a patient complains
- Report immediately to law enforcement
Correct answer: Report the issue through the facility's compliance or ethics reporting process
Suspected fraud should first be reported internally through established compliance channels, which then determines escalation steps.
Question 3: Which federal act primarily governs workplace safety standards relevant to physiotherapy clinic settings in the US?
- Occupational Safety and Health Act (OSHA) (Correct answer)
- Americans with Disabilities Act (ADA)
- Health Insurance Portability and Accountability Act (HIPAA)
- Stark Law
Correct answer: Occupational Safety and Health Act (OSHA)
OSHA establishes and enforces workplace safety and health standards, including those applicable to healthcare settings.
Question 4: The Stark Law (Physician Self-Referral Law) primarily prohibits:
- Physicians referring Medicare patients to entities in which they have a financial relationship (Correct answer)
- Physical therapists treating patients without physician referral
- Insurance companies denying physical therapy coverage
- Clinics hiring unlicensed aides for patient care
Correct answer: Physicians referring Medicare patients to entities in which they have a financial relationship
The Stark Law bans physician self-referrals to designated health services providers, including physical therapy, where a financial relationship exists.
Question 5: A patient requests a copy of their medical records. Under HIPAA, the covered entity must generally provide access within:
- 30 days, with one 30-day extension if needed (Correct answer)
- 7 business days with no extensions
- 60 days with no extensions allowed
- 24 hours for urgent requests only
Correct answer: 30 days, with one 30-day extension if needed
HIPAA requires covered entities to provide access to records within 30 days, with a single 30-day extension permitted if the entity notifies the patient.
Question 6: Which of the following best describes 'upcoding' in the context of physical therapy billing?
- Billing for a higher-complexity service than was actually provided (Correct answer)
- Using outdated CPT codes on a claim
- Submitting a claim without a physician's referral
- Providing a service not covered by the patient's insurance
Correct answer: Billing for a higher-complexity service than was actually provided
Upcoding is fraudulent billing that involves submitting codes for more intensive or expensive services than those actually delivered.
Question 7: State practice acts for physiotherapy primarily serve to:
- Define the legal scope of practice and licensure requirements within the state (Correct answer)
- Set federal reimbursement rates for PT services
- Regulate which insurance companies must cover physical therapy
- Establish continuing education requirements mandated by the federal government
Correct answer: Define the legal scope of practice and licensure requirements within the state
State practice acts are laws enacted by state legislatures that define who can practice physiotherapy and what they are legally permitted to do.
Under HIPAA, which of the following is considered a covered entity required to comply with privacy regulations?