CPC Compliance and Regulatory Practice Test Questions Answers

CPC Compliance and Regulatory Practice Test Questions Answers with Explanation. Try our free American Academy of Professional Coders (AAPC) Certified Professional Coder (CPC) Compliance and Regulatory review questions and answers for better CPC certification prep.

Table of Contents

CPC Compliance and Regulatory Practice Test

Basic Questions

Q1. What does HIPAA stand for?

  • (A) Health Information Portability and Accountability Act
  • (B) Health Insurance Privacy and Accountability Act
  • (C) Health Insurance Portability and Accountability Act
  • (D) Health Information Privacy and Accountability Act
View Correct Answer
Answer Key: C

HIPAA stands for the Health Insurance Portability and Accountability Act, which sets standards for protecting health information.

Q2. What is the primary purpose of the Stark Law?

  • (A) To prevent healthcare fraud and abuse
  • (B) To regulate the confidentiality of patient records
  • (C) To prohibit physician self-referral
  • (D) To ensure proper medical billing practices
View Correct Answer
Answer Key: C

The Stark Law prohibits physicians from referring patients to receive “designated health services” payable by Medicare or Medicaid from entities with which the physician or an immediate family member has a financial relationship.

Q3. Which agency is responsible for enforcing the False Claims Act?

  • (A) Centers for Medicare & Medicaid Services (CMS)
  • (B) Department of Health and Human Services (HHS)
  • (C) Office of Inspector General (OIG)
  • (D) Department of Justice (DOJ)
View Correct Answer
Answer Key: D

The Department of Justice (DOJ) enforces the False Claims Act.

Q4. What is the purpose of the Office of Inspector General (OIG) Work Plan?

  • (A) To outline the OIG’s priorities for the coming year
  • (B) To provide guidelines for medical coding practices
  • (C) To ensure compliance with HIPAA regulations
  • (D) To regulate the use of electronic health records
View Correct Answer
Answer Key: A

The OIG Work Plan outlines the OIG’s priorities and planned areas of focus for the coming year to prevent and detect fraud, waste, and abuse in healthcare.

Q5. Under the False Claims Act, what can whistleblowers receive as a reward for reporting fraud?

  • (A) Nothing
  • (B) A fixed salary
  • (C) A percentage of the recovered funds
  • (D) A tax deduction
View Correct Answer
Answer Key: C

Whistleblowers can receive a percentage of the recovered funds as a reward for reporting fraud under the False Claims Act.

Q6. What is the main focus of the Health Information Technology for Economic and Clinical Health (HITECH) Act?

  • (A) To improve health information privacy and security
  • (B) To provide guidelines for medical billing practices
  • (C) To enhance the quality of healthcare
  • (D) To prevent physician self-referral
View Correct Answer
Answer Key: A

The HITECH Act focuses on improving health information privacy and security, particularly concerning electronic health records (EHRs).

Q7. Which of the following is a key component of a corporate compliance program?

  • (A) Regular audits and monitoring
  • (B) Limiting patient access to their medical records
  • (C) Increasing the number of billable services
  • (D) Reducing the number of staff in the compliance department
View Correct Answer
Answer Key: A

Regular audits and monitoring are key components of a corporate compliance program to ensure adherence to laws, regulations, and internal policies.

Scenario-Based Questions

Q8. A coder discovers that a physician consistently upcodes office visits. What should the coder do according to compliance guidelines?

  • (A) Ignore the issue to avoid conflict
  • (B) Report the issue to the compliance officer
  • (C) Correct the codes without informing anyone
  • (D) Discuss it with the physician only
View Correct Answer
Answer Key: B

According to compliance guidelines, the coder should report the issue to the compliance officer to address potential fraud or abuse.

Q9. During an audit, it is discovered that several patient records were accessed without proper authorization. What should be the first step in addressing this breach?

  • (A) Notify the affected patients immediately
  • (B) Determine the extent and source of the breach
  • (C) Dismiss the employees involved
  • (D) Report the breach to law enforcement
View Correct Answer
Answer Key: B

The first step should be to determine the extent and source of the breach to understand its impact and prevent further unauthorized access.

Q10. A healthcare facility receives a subpoena requesting patient records for a legal case. What must be done to comply with HIPAA?

  • (A) Immediately release the records without question
  • (B) Verify the subpoena and ensure minimum necessary information is provided
  • (C) Refuse to release the records
  • (D) Notify the patient before releasing the records
View Correct Answer
Answer Key: B

To comply with HIPAA, the facility must verify the subpoena and ensure that only the minimum necessary information is provided.

Q11. A billing department receives an overpayment from Medicare. What is the correct course of action?

  • (A) Keep the overpayment as a bonus
  • (B) Notify Medicare and return the overpayment promptly
  • (C) Adjust future claims to account for the overpayment
  • (D) Use the overpayment to cover other expenses
View Correct Answer
Answer Key: B

The correct course of action is to notify Medicare and promptly return the overpayment to avoid violating the False Claims Act.

Q12. A hospital is undergoing an external audit for potential Medicare fraud. What should the hospital’s compliance officer do?

  • (A) Destroy any incriminating records
  • (B) Cooperate fully with the auditors and provide requested documentation
  • (C) Refuse to provide any records without a court order
  • (D) Hire a legal team to obstruct the audit process
View Correct Answer
Answer Key: B

The compliance officer should cooperate fully with the auditors and provide the requested documentation to ensure transparency and compliance.

Q13. A healthcare provider’s electronic health record (EHR) system is hacked, and patient data is compromised. What is the immediate action required by HITECH Act regulations?

  • (A) Notify law enforcement immediately
  • (B) Conduct a thorough investigation and notify affected patients
  • (C) Shut down the EHR system permanently
  • (D) Ignore the breach to avoid public relations issues
View Correct Answer
Answer Key: B

According to HITECH Act regulations, the provider must conduct a thorough investigation and promptly notify affected patients.

Q14. A patient complains about a possible breach of their health information privacy. What is the appropriate response by the compliance officer?

  • (A) Ignore the complaint
  • (B) Investigate the complaint and take corrective action if necessary
  • (C) Blame the patient for the breach
  • (D) Dismiss the complaint as unimportant
View Correct Answer
Answer Key: B

The compliance officer should investigate the complaint and take corrective action, if necessary, to address potential privacy breaches.

Q15. An employee reports potential fraudulent billing practices within the organization. What protections are they afforded under the False Claims Act?

  • (A) They can be terminated for making false claims
  • (B) They are protected from retaliation and may receive a reward
  • (C) They must keep the information confidential
  • (D) They can be demoted to a lower position
View Correct Answer
Answer Key: B

Under the False Claims Act, whistleblowers are protected from retaliation and may be rewarded for reporting fraud.

See also: