Page 1 of 60
CBCS CERTIFIED BILLING & CODING
SPECIALIST EXAM 2026 QUESTIONS LATEST
VERSION QUESTIONS AND ANSWERS
CBCS — CERTIFIED BILLING & CODING SPECIALIST EXAM — 250 Practice
Questions
This comprehensive CBCS practice exam is designed to assess your knowledge and readiness
for the National Healthcareer Association (NHA) Certified Billing & Coding Specialist
(CBCS) certification exam. Based on the official NHA test plan, the exam covers four
domains: Revenue Cycle and Regulatory Compliance (15%), Insurance Eligibility and Other
Payer Requirements (20%), Coding and Coding Guidelines (32%), and Billing and
Reimbursement (33%).
SECTION 1: REVENUE CYCLE AND REGULATORY COMPLIANCE (Questions 1-
38)
1. A medical billing specialist is reviewing the practice's compliance with HIPAA.
Which of the following is considered protected health information (PHI) under HIPAA?
A. Patient's name and date of birth.
B. Patient's medical diagnosis.
C. Patient's Social Security number.
D. All of the above.
Answer: D. Rationale: PHI includes any information that can be used to identify a patient
and relates to their health status, treatment, or payment. This includes names, dates of birth,
diagnoses, and Social Security numbers.
2. Under HIPAA, what is the maximum civil penalty for a violation of the Privacy Rule?
A. $1,000 per violation.
B. $10,000 per violation.
, Page 2 of 60
C. $50,000 per violation.
D. Up to $250,000 and/or imprisonment.
Answer: D. Rationale: HIPAA violations can result in significant civil and criminal
penalties, including fines up to $250,000 and imprisonment. The severity depends on the
nature and extent of the violation.
3. A billing specialist discovers that a coworker has been accessing patient records
without a valid reason. What is the MOST appropriate action?
A. Ignore the coworker's behavior.
B. Report the coworker to the supervisor or compliance officer.
C. Confront the coworker privately.
D. Access the same records to see what the coworker is looking at.
Answer: B. Rationale: Unauthorized access to patient records is a HIPAA violation and
should be reported immediately to the supervisor or compliance officer. The billing specialist
has a responsibility to protect patient privacy.
4. Which of the following is a requirement of the HIPAA Security Rule?
A. Posting the Notice of Privacy Practices.
B. Implementing administrative, physical, and technical safeguards.
C. Obtaining patient consent for treatment.
D. Providing patients with access to their records.
Answer: B. Rationale: The HIPAA Security Rule requires the implementation of
administrative, physical, and technical safeguards to protect electronic protected health
information (ePHI).
5. A patient requests a copy of their medical records. Under HIPAA, how long does the
practice have to respond to the request?
A. 15 days.
B. 30 days.
C. 60 days.
D. 90 days.
Answer: B. Rationale: Under HIPAA, healthcare providers have 30 days to respond to a
patient's request for access to their medical records. An extension of up to 30 additional days
may be granted if needed.
6. What is the purpose of a Notice of Privacy Practices (NPP)?
A. To inform patients about how their health information may be used and disclosed.
B. To provide patients with a list of their medical bills.
, Page 3 of 60
C. To give patients a copy of their medical records.
D. To collect payment from patients.
Answer: A. Rationale: The Notice of Privacy Practices informs patients about how their
health information may be used and disclosed, and their rights regarding their information. It
must be provided to patients at the first point of service.
7. Which of the following is considered a breach of patient confidentiality?
A. Discussing a patient's case with the physician in a private office.
B. Discussing a patient's case with a colleague in a public elevator.
C. Discussing a patient's case with the patient's family after obtaining consent.
D. Discussing a patient's case with a specialist for consultation purposes.
Answer: B. Rationale: Discussing patient information in public areas where it can be
overheard is a breach of confidentiality. Patient information should only be discussed in
private, secure settings.
8. Under HIPAA, which of the following is a patient's right regarding their medical
records?
A. The right to access their medical records.
B. The right to request amendments to their records.
C. The right to receive an accounting of disclosures.
D. All of the above.
Answer: D. Rationale: Under HIPAA, patients have the right to access, request amendments,
and receive an accounting of disclosures of their medical records.
9. What is the minimum necessary standard under HIPAA?
A. The requirement to use the minimum amount of PHI necessary to accomplish the intended
purpose.
B. The requirement to disclose all PHI to the patient.
C. The requirement to store PHI in a secure location.
D. The requirement to obtain patient consent for all disclosures.
Answer: A. Rationale: The minimum necessary standard requires that the use and disclosure
of PHI be limited to the minimum necessary to accomplish the intended purpose. This limits
exposure of protected health information.
10. A billing specialist is preparing to dispose of patient records. Which of the following
is the correct method for disposal?
A. Place the records in the regular trash.
B. Shred or securely destroy the records.
, Page 4 of 60
C. Recycle the records.
D. Donate the records to a medical library.
Answer: B. Rationale: Patient records must be securely destroyed (e.g., shredded) to prevent
unauthorized access to PHI. Proper disposal is required by HIPAA.
11. What is the purpose of the HITECH Act?
A. To establish standards for electronic health records.
B. To strengthen HIPAA privacy and security protections.
C. To provide incentives for meaningful use of EHRs.
D. All of the above.
Answer: D. Rationale: The HITECH Act (Health Information Technology for Economic and
Clinical Health Act) strengthened HIPAA, established EHR standards, and provided
incentives for meaningful use.
12. Which of the following is a requirement for a healthcare provider's compliance
program?
A. Conducting regular internal audits.
B. Implementing written policies and procedures.
C. Training employees on compliance.
D. All of the above.
Answer: D. Rationale: An effective compliance program includes written policies, employee
training, and regular internal audits to identify and correct issues.
13. The False Claims Act imposes liability on individuals who:
A. Knowingly submit false claims to the government.
B. Fail to report a HIPAA violation.
C. Refuse to provide patient records.
D. Bill for services not covered by insurance.
Answer: A. Rationale: The False Claims Act imposes liability on individuals who knowingly
submit false or fraudulent claims to the government for payment. This includes billing for
services not provided or medically unnecessary services.
14. What is the Anti-Kickback Statute?
A. A law that prohibits offering or receiving remuneration in exchange for referrals.
B. A law that requires providers to accept Medicare assignment.
C. A law that establishes standards for electronic health records.
D. A law that protects patient privacy.
CBCS CERTIFIED BILLING & CODING
SPECIALIST EXAM 2026 QUESTIONS LATEST
VERSION QUESTIONS AND ANSWERS
CBCS — CERTIFIED BILLING & CODING SPECIALIST EXAM — 250 Practice
Questions
This comprehensive CBCS practice exam is designed to assess your knowledge and readiness
for the National Healthcareer Association (NHA) Certified Billing & Coding Specialist
(CBCS) certification exam. Based on the official NHA test plan, the exam covers four
domains: Revenue Cycle and Regulatory Compliance (15%), Insurance Eligibility and Other
Payer Requirements (20%), Coding and Coding Guidelines (32%), and Billing and
Reimbursement (33%).
SECTION 1: REVENUE CYCLE AND REGULATORY COMPLIANCE (Questions 1-
38)
1. A medical billing specialist is reviewing the practice's compliance with HIPAA.
Which of the following is considered protected health information (PHI) under HIPAA?
A. Patient's name and date of birth.
B. Patient's medical diagnosis.
C. Patient's Social Security number.
D. All of the above.
Answer: D. Rationale: PHI includes any information that can be used to identify a patient
and relates to their health status, treatment, or payment. This includes names, dates of birth,
diagnoses, and Social Security numbers.
2. Under HIPAA, what is the maximum civil penalty for a violation of the Privacy Rule?
A. $1,000 per violation.
B. $10,000 per violation.
, Page 2 of 60
C. $50,000 per violation.
D. Up to $250,000 and/or imprisonment.
Answer: D. Rationale: HIPAA violations can result in significant civil and criminal
penalties, including fines up to $250,000 and imprisonment. The severity depends on the
nature and extent of the violation.
3. A billing specialist discovers that a coworker has been accessing patient records
without a valid reason. What is the MOST appropriate action?
A. Ignore the coworker's behavior.
B. Report the coworker to the supervisor or compliance officer.
C. Confront the coworker privately.
D. Access the same records to see what the coworker is looking at.
Answer: B. Rationale: Unauthorized access to patient records is a HIPAA violation and
should be reported immediately to the supervisor or compliance officer. The billing specialist
has a responsibility to protect patient privacy.
4. Which of the following is a requirement of the HIPAA Security Rule?
A. Posting the Notice of Privacy Practices.
B. Implementing administrative, physical, and technical safeguards.
C. Obtaining patient consent for treatment.
D. Providing patients with access to their records.
Answer: B. Rationale: The HIPAA Security Rule requires the implementation of
administrative, physical, and technical safeguards to protect electronic protected health
information (ePHI).
5. A patient requests a copy of their medical records. Under HIPAA, how long does the
practice have to respond to the request?
A. 15 days.
B. 30 days.
C. 60 days.
D. 90 days.
Answer: B. Rationale: Under HIPAA, healthcare providers have 30 days to respond to a
patient's request for access to their medical records. An extension of up to 30 additional days
may be granted if needed.
6. What is the purpose of a Notice of Privacy Practices (NPP)?
A. To inform patients about how their health information may be used and disclosed.
B. To provide patients with a list of their medical bills.
, Page 3 of 60
C. To give patients a copy of their medical records.
D. To collect payment from patients.
Answer: A. Rationale: The Notice of Privacy Practices informs patients about how their
health information may be used and disclosed, and their rights regarding their information. It
must be provided to patients at the first point of service.
7. Which of the following is considered a breach of patient confidentiality?
A. Discussing a patient's case with the physician in a private office.
B. Discussing a patient's case with a colleague in a public elevator.
C. Discussing a patient's case with the patient's family after obtaining consent.
D. Discussing a patient's case with a specialist for consultation purposes.
Answer: B. Rationale: Discussing patient information in public areas where it can be
overheard is a breach of confidentiality. Patient information should only be discussed in
private, secure settings.
8. Under HIPAA, which of the following is a patient's right regarding their medical
records?
A. The right to access their medical records.
B. The right to request amendments to their records.
C. The right to receive an accounting of disclosures.
D. All of the above.
Answer: D. Rationale: Under HIPAA, patients have the right to access, request amendments,
and receive an accounting of disclosures of their medical records.
9. What is the minimum necessary standard under HIPAA?
A. The requirement to use the minimum amount of PHI necessary to accomplish the intended
purpose.
B. The requirement to disclose all PHI to the patient.
C. The requirement to store PHI in a secure location.
D. The requirement to obtain patient consent for all disclosures.
Answer: A. Rationale: The minimum necessary standard requires that the use and disclosure
of PHI be limited to the minimum necessary to accomplish the intended purpose. This limits
exposure of protected health information.
10. A billing specialist is preparing to dispose of patient records. Which of the following
is the correct method for disposal?
A. Place the records in the regular trash.
B. Shred or securely destroy the records.
, Page 4 of 60
C. Recycle the records.
D. Donate the records to a medical library.
Answer: B. Rationale: Patient records must be securely destroyed (e.g., shredded) to prevent
unauthorized access to PHI. Proper disposal is required by HIPAA.
11. What is the purpose of the HITECH Act?
A. To establish standards for electronic health records.
B. To strengthen HIPAA privacy and security protections.
C. To provide incentives for meaningful use of EHRs.
D. All of the above.
Answer: D. Rationale: The HITECH Act (Health Information Technology for Economic and
Clinical Health Act) strengthened HIPAA, established EHR standards, and provided
incentives for meaningful use.
12. Which of the following is a requirement for a healthcare provider's compliance
program?
A. Conducting regular internal audits.
B. Implementing written policies and procedures.
C. Training employees on compliance.
D. All of the above.
Answer: D. Rationale: An effective compliance program includes written policies, employee
training, and regular internal audits to identify and correct issues.
13. The False Claims Act imposes liability on individuals who:
A. Knowingly submit false claims to the government.
B. Fail to report a HIPAA violation.
C. Refuse to provide patient records.
D. Bill for services not covered by insurance.
Answer: A. Rationale: The False Claims Act imposes liability on individuals who knowingly
submit false or fraudulent claims to the government for payment. This includes billing for
services not provided or medically unnecessary services.
14. What is the Anti-Kickback Statute?
A. A law that prohibits offering or receiving remuneration in exchange for referrals.
B. A law that requires providers to accept Medicare assignment.
C. A law that establishes standards for electronic health records.
D. A law that protects patient privacy.