Healthcare Compliance and Regulations Flashcards
7 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Healthcare Compliance and Regulations flashcards as text
A facility discovers that an employee accessed the electronic health records of a celebrity patient out of curiosity, without a treatment relationship. Under HIPAA, this is classified as:
Answer: An impermissible use resulting in a presumed breach, unless a low probability of compromise analysis clears it
Unauthorized snooping by a workforce member is an impermissible use that is presumed to be a breach unless a four-factor risk assessment demonstrates low probability of compromise.
The Genetic Information Nondiscrimination Act (GINA) Title II prohibits employers from using genetic information in employment decisions. In the context of HIPAA, genetic information is classified as:
Answer: A type of PHI that is generally prohibited from use for underwriting purposes by health plans
HIPAA, as amended by GINA, prohibits health plans from using genetic information for underwriting and treats it as a type of PHI.
A release of information specialist receives a request for records from a patient's attorney. Which document is essential before releasing records in a non-litigation context?
Answer: A valid written HIPAA-compliant authorization signed by the patient
Without a court order or subpoena, a valid patient authorization is required to release records to an attorney.
Which type of Medicare audit uses sophisticated data analysis to identify providers with unusual billing patterns before conducting a review?
Answer: Zone Program Integrity Contractor (ZPIC) data analysis
ZPICs (now unified under UPICs) use data analysis and statistical modeling to detect fraud patterns before initiating field investigations.
A state law grants patients broader access rights to their mental health records than HIPAA provides. Under the principle of federal preemption, which standard applies?
Answer: The state law applies because it provides greater patient protections
HIPAA establishes a floor, not a ceiling; state laws providing greater privacy protections or patient rights are not preempted and must be followed.
Under the Health Care Quality Improvement Act (HCQIA), the National Practitioner Data Bank (NPDB) must be queried by hospitals when:
Answer: Any physician applies for medical staff privileges and at least every two years thereafter
HCQIA requires hospitals to query the NPDB when practitioners apply for clinical privileges and at least every two years for ongoing credentialing.
Which of the following BEST describes the purpose of a Corporate Integrity Agreement (CIA) negotiated between a healthcare provider and the OIG?
Answer: It establishes compliance obligations a provider must fulfill as part of a settlement to avoid exclusion from federal programs
A CIA is a settlement tool requiring a provider to implement specific compliance measures in exchange for remaining eligible to participate in Medicare and Medicaid.