← Back

22 Compliance & Regulatory Practice Questions & Answers

Every Compliance & Regulatory practice question from the CPC Medical Coding Practice Test, with the correct answer and a short explanation.

Start practice test
  1. 1. A physician practice sends a patient's operative report to the patient's health plan so the plan can adjudicate the surgical claim. Under the HIPAA Privacy Rule, what makes this disclosure permissible without the patient's written authorization?

    • A.Health plans are not covered entities, so information sent to them falls outside the Privacy Rule
    • B.The practice obtained the patient's signed acknowledgment of its Notice of Privacy Practices, which serves as blanket authorization for any disclosure
    • C.It is a disclosure for payment, one of the treatment, payment, and health care operations purposes that does not require the patient's written authorizationAnswer
    • D.Any disclosure is permitted once the record has been stripped of the patient's account number

    The Privacy Rule expressly permits a covered entity to use and disclose protected health information for its own treatment, payment, and health care operations without authorization; submitting documentation so a plan can adjudicate a claim is a payment activity. An acknowledgment of the Notice of Privacy Practices is not an authorization, and health plans are themselves covered entities.

    Source: HIPAA Privacy Rule, 45 CFR 164.506 (uses and disclosures for treatment, payment, and health care operations)Report a problem with this question

  2. 2. A hospitalist telephones a patient's primary care physician and asks for the patient's complete chart in order to manage an acute admission. How does the HIPAA minimum necessary standard apply to that release?

    • A.It applies to every use and disclosure without exception, so the request must be refused
    • B.It applies, so only the single most recent progress note may be released
    • C.It applies unless the patient first signs an authorization permitting the full chart to be sent
    • D.It does not apply, because the minimum necessary standard expressly excludes disclosures to a health care provider for treatment purposesAnswer

    The minimum necessary standard has stated exceptions: it does not apply to disclosures to, or requests by, a health care provider for treatment, to disclosures to the individual, or to uses and disclosures required by law. Limiting clinical information during active treatment would endanger care, which is why the rule carves treatment out.

    Source: HIPAA Privacy Rule, 45 CFR 164.502(b)(2) (minimum necessary exceptions)Report a problem with this question

  3. 3. An independent billing company codes and submits claims for a physician group using the group's patient records. Under HIPAA, what is the billing company's status?

    • A.A covered entity in its own right, because it handles protected health information
    • B.Outside HIPAA's reach, because only the treating provider is regulated
    • C.A business associate, which requires a written business associate agreement and is directly liable for HIPAA complianceAnswer
    • D.Exempt while the physician group remains the legal custodian of the records

    A business associate is a person or entity that creates, receives, maintains, or transmits protected health information to perform a function on behalf of a covered entity, and billing, claims processing, and coding are named examples. The covered entity must obtain satisfactory assurances through a written business associate agreement, and since the HITECH amendments business associates are directly liable for their own HIPAA violations.

    Source: HIPAA, 45 CFR 160.103 (definition of business associate) and 45 CFR 164.502(e) (business associate contracts)Report a problem with this question

  4. 4. A practice is deciding who may open the electronic health record and is configuring unique user log-ins and audit logs. Which HIPAA rule governs those requirements?

    • A.The Security Rule, which requires administrative, physical, and technical safeguards for electronic protected health informationAnswer
    • B.The standard transaction and code set requirements, which define who may open a record
    • C.The Breach Notification Rule, which establishes system access controls
    • D.The Privacy Rule, which governs all technical controls over electronic systems

    The Privacy Rule sets the substantive limits on how protected health information in any form may be used or disclosed, while the Security Rule applies specifically to electronic protected health information and requires administrative, physical, and technical safeguards, including a risk analysis, unique user identification, and audit controls. Access rights and audit trails are technical safeguards under the Security Rule.

    Source: HIPAA Security Rule, 45 CFR 164.306 and 164.312Report a problem with this question

  5. 5. A patient asks a practice for a list showing to whom it has released her health information for purposes other than treatment, payment, and health care operations. Which patient right is she exercising?

    • A.The right of access to inspect and obtain a copy of the record
    • B.The right to an accounting of disclosuresAnswer
    • C.The right to request an amendment to the record
    • D.The right to request confidential communications

    The accounting of disclosures is the right to receive a list of certain disclosures a covered entity has made, and disclosures for treatment, payment, and health care operations are among those excluded from the accounting. Access is the right to a copy of the record itself, and amendment is the right to ask that information the patient believes is inaccurate be corrected.

    Source: HIPAA Privacy Rule, 45 CFR 164.528 (accounting of disclosures)Report a problem with this question

  6. 6. An unencrypted laptop holding patient records is stolen from a billing office, and the incident meets the definition of a breach of unsecured protected health information. Which statement reflects the Breach Notification Rule?

    • A.Reporting the theft to law enforcement satisfies the covered entity's notification duty
    • B.Notification is required only if the covered entity concludes that patients suffered financial harm
    • C.Business associates have no breach obligations, because the covered entity owns the records
    • D.Affected individuals must be notified without unreasonable delay after discovery, the Department of Health and Human Services must also be notified, and the HHS Office for Civil Rights enforces the ruleAnswer

    The Breach Notification Rule requires notice to each affected individual without unreasonable delay after discovery, notice to HHS, and, for large breaches within a state or jurisdiction, contemporaneous notice to prominent media; a business associate must notify the covered entity of a breach it discovers. Financial harm is not the trigger, and a police report does not replace notification. The HHS Office for Civil Rights enforces the Privacy, Security, and Breach Notification Rules.

    Source: HIPAA Breach Notification Rule, 45 CFR 164.404 through 164.410; enforcement by the HHS Office for Civil RightsReport a problem with this question

  7. 7. A clinic orders and bills a test far more often than accepted practice supports, driving up program cost, but there is no evidence that anyone knew the pattern was improper. How is this conduct best classified?

    • A.Fraud, because every incorrect claim submitted to a federal health care program is fraudulent by definition
    • B.Abuse, because it causes unnecessary program cost without the knowing and willful intent that defines fraudAnswer
    • C.Fraud, because intent is presumed once a pattern of claims exists
    • D.Neither, because only billing for services never rendered can be fraud or abuse

    Intent is the dividing line: fraud requires knowingly and willfully executing a scheme to obtain payment by false pretenses, while abuse covers practices inconsistent with sound fiscal, business, or medical practice that create unnecessary cost without that intent. The same conduct can move from abuse to fraud once knowledge or willfulness is shown.

    Source: HHS OIG and CMS definitions of fraud versus abuse; health care fraud statute, 18 U.S.C. 1347Report a problem with this question

  8. 8. A billing manager suspects that the practice's claims include services the records do not support, decides not to look into it, and lets the claims go out. Can liability attach under the federal False Claims Act?

    • A.Yes, because 'knowing' includes deliberate ignorance and reckless disregard of the truth, and no specific intent to defraud is requiredAnswer
    • B.Yes, but only if the government proves a specific intent to defraud
    • C.No, because the Act reaches only claims the provider later admits were false
    • D.No, because the manager never actually knew the claims were false

    The False Claims Act defines 'knowing' and 'knowingly' to include actual knowledge, deliberate ignorance of the truth or falsity of the information, and reckless disregard of it, and the statute states that no proof of specific intent to defraud is required. Choosing not to investigate a known red flag is exactly the deliberate ignorance the definition captures.

    Source: False Claims Act, 31 U.S.C. 3729(b)(1) (definition of knowing and knowingly)Report a problem with this question

  9. 9. Which statement correctly describes the qui tam mechanism of the federal False Claims Act?

    • A.A private person may file suit on the government's behalf, may share in any recovery, and is protected against employer retaliation for the good-faith actionAnswer
    • B.A whistleblower shares in the recovery only when the government declines to intervene, and no protection from retaliation exists
    • C.Only the Department of Justice may start a case; private parties may do no more than complain to the payer
    • D.A whistleblower must first exhaust the payer's internal appeal process before any suit may be filed

    Under the qui tam provisions a private relator files the action under seal on the government's behalf; the government may intervene or decline, and the relator receives a statutory share of the recovery in either case, with a larger share when the government declines. A separate provision protects employees from discharge or discrimination for lawful acts taken to stop a false claim.

    Source: False Claims Act qui tam and whistleblower provisions, 31 U.S.C. 3730(b), (d), and (h)Report a problem with this question

  10. 10. A laboratory gives a physician free office space and free staff in return for the physician's referrals of Medicare patients. Which statement about the federal Anti-Kickback Statute is correct?

    • A.It applies only to the party who accepts the remuneration, not to the party who offers it
    • B.It applies only to cash paid directly to a physician
    • C.It is a civil statute that imposes liability regardless of intent
    • D.It is a criminal statute requiring knowing and willful conduct, it reaches anything of value offered to induce referrals payable by a federal health care program, and it applies to both the party offering and the party acceptingAnswer

    The Anti-Kickback Statute criminalizes knowingly and willfully soliciting, receiving, offering, or paying any remuneration to induce or reward referrals of items or services payable by a federal health care program; remuneration means anything of value, including free rent, free staff, or waived charges. Because both sides of the transaction are covered, the giver and the receiver are each exposed, and voluntary safe harbors describe arrangements that are protected when every condition is met.

    Source: Federal Anti-Kickback Statute, 42 U.S.C. 1320a-7b(b)Report a problem with this question

  11. 11. A physician group refers Medicare patients for imaging to an entity in which a physician's spouse holds a financial interest. The arrangement was set up in good faith, no one meant to influence referrals, and it fits no exception. Under the physician self-referral (Stark) law, what is the result?

    • A.There is no violation, because the financial interest belongs to a family member rather than to the referring physician
    • B.The referrals are prohibited, because Stark is a strict-liability civil prohibition on physician referrals for designated health services and an arrangement must fit squarely within an exceptionAnswer
    • C.There is no violation, because the physicians had no intent to influence referrals
    • D.The arrangement is protected so long as it satisfies an Anti-Kickback Statute safe harbor

    Stark bars a physician from referring Medicare patients for designated health services, such as imaging, to an entity with which the physician or an immediate family member has a financial relationship unless the arrangement meets an exception. It is civil and strict liability, so good intentions are irrelevant, immediate family members are expressly included, and an Anti-Kickback safe harbor does not cure a Stark problem because the two laws have separate requirements.

    Source: Physician self-referral (Stark) law, 42 U.S.C. 1395nnReport a problem with this question

  12. 12. Which description matches the kind of conduct the federal Civil Monetary Penalties Law reaches?

    • A.Presenting claims a person knows or should know are false, offering inducements likely to influence a beneficiary's choice of provider, or arranging with an excluded person to furnish items or services payable by a federal health care programAnswer
    • B.Only conduct that has already produced a criminal conviction
    • C.Only a physician's referral of designated health services
    • D.Only violations of the HIPAA Privacy Rule

    The Civil Monetary Penalties Law is an administrative enforcement tool that lets the government impose penalties, assessments, and exclusion for a defined list of conduct without a criminal conviction, and the 'knows or should know' standard means no proof of specific intent is needed. Beneficiary inducements and employing or contracting with an excluded individual are among the listed grounds.

    Source: Civil Monetary Penalties Law, 42 U.S.C. 1320a-7aReport a problem with this question

  13. 13. A coder reports each component procedure of a service separately even though a single comprehensive code describes the whole service, and the total payment rises as a result. This practice is known as:

    • A.Duplicate billing
    • B.Balance billing
    • C.Unbundling, also called fragmentationAnswer
    • D.Upcoding

    Unbundling is billing the parts of a service separately when a comprehensive code already includes them, and it is a named risk area in OIG compliance guidance because it inflates payment for work the comprehensive code covers. Upcoding is reporting a higher-paying level or code than the documentation supports, duplicate billing is submitting the same charge more than once, and balance billing is charging the patient a difference the payer contract or program rules disallow.

    Source: HHS OIG Compliance Program Guidance for Third-Party Medical Billing Companies (unbundling risk area); CMS National Correct Coding Initiative Policy ManualReport a problem with this question

  14. 14. A practice manager tells a coder to report a higher-level evaluation and management service than the note supports, saying the physician 'always does that much work anyway.' What should the coder do?

    • A.Follow the instruction, because the practice manager is responsible for billing policy
    • B.Report the supported level and edit the physician's note so that it matches the higher level
    • C.Report the higher level and attach a note to the claim describing the disagreement
    • D.Report only the level the documentation supports and raise the instruction through the compliance officer or the compliance program's reporting channelAnswer

    Codes must reflect the service the provider actually documented, so reporting a level the record does not support is upcoding regardless of who directed it, and an employer's instruction is not a defense. Coders may never alter or add to a provider's documentation; the correct outlet is the compliance program's open line of communication, which must protect good-faith reporters from retaliation.

    Source: HHS OIG Compliance Program Guidance for Third-Party Medical Billing Companies (upcoding risk area; open lines of communication and non-retaliation)Report a problem with this question

  15. 15. An auditor finds that a physician's progress notes for many different patients contain identical copied-forward text that does not reflect what happened at each visit. Why is that a compliance problem?

    • A.Cloned text does not show that the billed service was actually performed for that patient on that date, so the claims are unsupportedAnswer
    • B.It is a concern only in paper records, where copying is harder to detect
    • C.It matters only if the payer specifically requests the records
    • D.It is acceptable as long as the physician signs each note

    Payment depends on documentation that shows the specific service was furnished to that patient on that date, so identical copy-forward text fails to substantiate the claim and is a well-known audit red flag that can support findings of billing for services not rendered. A signature authenticates who wrote the note; it does not make generic or inaccurate content true.

    Source: Social Security Act 1833(e) (no payment without the information needed to determine amounts due); HHS OIG compliance guidance on documentation of servicesReport a problem with this question

  16. 16. A record lists sepsis in the assessment, while another entry in the same note states the patient was never septic. Which provider query is compliant?

    • A.One that tells the provider which diagnosis produces the higher payment
    • B.No query is needed; the coder should report the diagnosis listed in the assessment
    • C.One that presents the conflicting documentation and asks the provider to clarify, without suggesting an answer or referring to reimbursementAnswer
    • D.One that instructs the provider to document whichever diagnosis supports medical necessity

    When documentation is ambiguous, conflicting, or incomplete, the coder must resolve it with the provider rather than choose, and a compliant query is non-leading: it presents the clinical facts from the record, offers no preferred answer, and never mentions the payment consequences. A query that steers the provider toward a particular or better-paying diagnosis is itself a compliance risk.

    Source: AHIMA and ACDIS Guidelines for Achieving a Compliant Query Practice; HHS OIG compliance guidance on documentation-driven codingReport a problem with this question

  17. 17. Which of the following is one of the elements of an effective compliance program described in HHS OIG compliance program guidance?

    • A.A requirement that every employee hold a coding credential
    • B.Ongoing auditing and monitoring of risk areas, with prompt investigation and correction of the problems the audits revealAnswer
    • C.A guarantee that no claim the organization submits will ever be denied
    • D.Annual approval of the written program by the Department of Justice

    OIG guidance describes seven minimum elements: written standards and policies, a designated compliance officer and committee, effective training, open lines of communication such as a hotline with non-retaliation protection, enforcement through publicized disciplinary standards, auditing and monitoring, and prompt response to and correction of detected problems. Auditing may be prospective, reviewing claims before they go out, or retrospective, reviewing paid claims, and the elements are a floor rather than a ceiling; for most organizations the program itself is voluntary and no outside agency approves it.

    Source: HHS OIG Compliance Program Guidance for Third-Party Medical Billing Companies (seven elements of an effective compliance program); HHS OIG General Compliance Program GuidanceReport a problem with this question

  18. 18. An internal audit shows that a practice was paid on claims its documentation does not support. What does the practice's compliance obligation require?

    • A.Investigate and quantify the overpayment, then report and return it to the payer within the period federal law allows, using the OIG self-disclosure protocol where the conduct may involve fraudAnswer
    • B.Wait for the payer's next audit cycle so an outside reviewer can confirm the amount
    • C.Offset the overpayment quietly against other claims the practice believes were underpaid
    • D.Keep the funds unless and until the payer asks for them back, since payers audit their own claims

    Federal law requires an identified overpayment from Medicare or Medicaid to be reported and returned within the statutory window, and knowingly retaining it converts the money into a reverse false claim under the False Claims Act. Self-initiated audits, refunds, and, where appropriate, use of the OIG self-disclosure protocol are the corrective-action and repayment steps an effective compliance program is expected to take; silent offsets and waiting to be caught are not.

    Source: Overpayment reporting and return requirement, 42 U.S.C. 1320a-7k(d); False Claims Act reverse false claim provision, 31 U.S.C. 3729(a)(1)(G); HHS OIG Self-Disclosure ProtocolReport a problem with this question

  19. 19. A claim is coded correctly under CPT and ICD-10-CM guidelines, yet Medicare denies it as not reasonable and necessary. What does that outcome illustrate?

    • A.Medical necessity is established automatically whenever the code set guidelines are followed
    • B.The coder erred and should resubmit the claim with a diagnosis taken from the payer's covered list
    • C.The charge may simply be billed to the patient with no further steps, because the payer denied it
    • D.Coverage and medical necessity are determined separately from coding accuracy; the documented clinical reason must support the service, and the coder may not change the diagnosis to obtain paymentAnswer

    Medicare pays only for items and services that are reasonable and necessary for the diagnosis or treatment of illness or injury, which is a coverage judgment separate from whether the code selected accurately describes what was done. Selecting a diagnosis simply because it appears on a covered list is diagnosis fishing and misrepresents the record, and whether the patient can be billed depends on the applicable liability and notice rules, not on the denial alone.

    Source: Social Security Act 1862(a)(1)(A) (reasonable and necessary requirement)Report a problem with this question

  20. 20. No national policy addresses coverage of a particular service, but the practice's Medicare Administrative Contractor has published a policy on it. Which statement is correct?

    • A.Local policies are issued by CMS and national policies by the contractor
    • B.A local coverage determination is issued by the Medicare Administrative Contractor and applies only in its jurisdiction, while a national coverage determination is issued by CMS and binds nationwide; a local determination may not conflict with a national oneAnswer
    • C.A local coverage determination applies nationwide once it is published
    • D.A local coverage determination overrides a national coverage determination within that contractor's jurisdiction

    CMS issues national coverage determinations that bind every contractor, and Medicare Administrative Contractors issue local coverage determinations that apply only within their own jurisdictions, typically where no national policy exists. Because the local policy is subordinate, it may add detail but may not conflict with a national determination, so a coder must check for a national policy first and then the contractor's policy for that jurisdiction.

    Source: Social Security Act 1869(f) (national and local coverage determinations); CMS Medicare Program Integrity ManualReport a problem with this question

  21. 21. A practice has every Medicare fee-for-service patient sign an advance beneficiary notice of noncoverage at check-in, regardless of the service being furnished. Why is this improper?

    • A.An ABN must identify the specific service expected to be denied and the reason for the expected denial so the beneficiary can make an informed choice; routine blanket notices are not valid and do not transfer liabilityAnswer
    • B.An ABN may be signed only after the service has been furnished
    • C.An ABN is required before every Medicare service, so signing at check-in is both efficient and valid
    • D.An ABN is valid only for patients enrolled in a Medicare Advantage plan

    The advance beneficiary notice exists to give a fee-for-service beneficiary a genuine choice before a service the provider believes Medicare will deny as not reasonable and necessary, so it must name the service, state the expected reason for denial, give a cost estimate, and be delivered early enough to allow a decision. Routine blanket notices, and notices obtained in an emergency or under duress, are invalid; if no valid notice was given and Medicare denies the service as not reasonable and necessary, the provider absorbs the cost and may not bill the patient.

    Source: CMS Medicare Claims Processing Manual, Chapter 30 (Advance Beneficiary Notice of Noncoverage; prohibition on routine notices)Report a problem with this question

  22. 22. Two codes are subject to a National Correct Coding Initiative procedure-to-procedure edit whose correct coding modifier indicator is 0. What does that indicator mean?

    • A.The edit has been deleted and no longer applies
    • B.The edit caps the number of units that may be reported for a single code
    • C.The pair may not be reported together for that patient on that date of service, and no modifier will override the editAnswer
    • D.A modifier may be appended whenever the documentation supports distinct services

    In a procedure-to-procedure edit, the correct coding modifier indicator controls whether the column two code can ever be separately payable: 0 means no modifier may bypass the edit, 1 means an appropriate NCCI-associated modifier may be used when the clinical circumstances and documentation genuinely support separate services, and 9 means the edit no longer applies. Unit limits are a different edit type, the medically unlikely edits, which cap the units of a code for one patient on one date, and appending a bypass modifier just to get paid is an abusive practice that can rise to fraud.

    Source: CMS National Correct Coding Initiative Policy Manual (procedure-to-procedure edits and correct coding modifier indicators)Report a problem with this question

Practice questions based on the ICD-10-CM Official Guidelines for Coding and Reporting, the AMA CPT guidelines, the CMS HCPCS Level II system, and federal healthcare compliance law. CPC is a mark of the AAPC and CPT is a mark of the American Medical Association; this site is not affiliated with or endorsed by either. ICD-10-CM, CPT, and HCPCS Level II are revised every year, so these questions test coding rules and conventions rather than code values — always verify actual code selection against the current code books and your payer's published policy. Nothing here is medical, legal, or billing advice. About the CPC exam →