โ† All RELIAS Flashcard Decks

Compliance and Regulatory Training Flashcards

7 cards from real RELIAS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance and Regulatory Training flashcards as text
  1. A patient requests access to their medical records under HIPAA. The covered entity must respond within:

    Answer: 30 calendar days, with a possible 30-day extension

    HIPAA requires covered entities to act on access requests within 30 calendar days, with one 30-day extension permitted if needed.

  2. Which of the following is an example of a HIPAA-permitted disclosure without patient authorization?

    Answer: Disclosing PHI to public health authorities for disease surveillance

    HIPAA permits disclosures to public health authorities for activities such as disease reporting, which serves a recognized public interest.

  3. The Corporate Integrity Agreement (CIA) is typically negotiated between a healthcare provider and:

    Answer: The HHS Office of Inspector General (OIG)

    CIAs are agreements between the OIG and healthcare entities that have engaged in fraud, requiring enhanced compliance oversight as an alternative to exclusion.

  4. Under the CMS Conditions of Participation, which of the following is required for patient rights?

    Answer: Patients must be informed of their rights in advance of or at admission

    CMS Conditions of Participation require hospitals to inform patients of their rights in advance of or at the time of admission.

  5. What does 'downstream risk' mean in the context of a healthcare compliance program?

    Answer: Compliance risks that flow to subcontractors and vendors from the primary organization's non-compliance

    Downstream risk refers to compliance obligations and potential liability that organizations pass on to their contractors, vendors, and business associates.

  6. A healthcare worker accidentally sends an email with PHI to the wrong recipient. Under HIPAA, this is classified as:

    Answer: A potential breach requiring a risk assessment to determine notification obligations

    Accidental disclosures must be assessed under the four-factor breach risk assessment to determine whether notification is required.

  7. Which federal program provides 'safe harbor' protections allowing certain healthcare financial arrangements that would otherwise violate the Anti-Kickback Statute?

    Answer: The OIG Safe Harbor Regulations

    The OIG has established safe harbor regulations that define specific financial arrangements that are protected from Anti-Kickback Statute prosecution.