2026 CPCO Study Guide Certified
Professional Compliance Officer Practice
Questions Answer Explanations • Healthcare
Compliance • Fraud & Abuse • HIPAA
Regulations • Risk Management Review
Domains Covered (AAPC CPCO Content Outline): Compliance Program
Development & Governance (25%) • Fraud, Waste & Abuse (25%) • HIPAA &
Regulatory Compliance (20%) • Auditing, Monitoring & Risk Assessment (15%) •
Investigations, Enforcement & Corrective Action (15%)
Domain I: Compliance Program Development & Governance (Questions 1–
30)
1. How many fundamental elements does the OIG identify as necessary for an
effective healthcare compliance program?
A) Six
B) Seven
C) Five
D) Eight
Rationale: The OIG identifies seven fundamental elements of an effective
compliance program: (1) written policies and procedures, (2) compliance officer
and committee, (3) training and education, (4) effective lines of communication,
(5) internal monitoring and auditing, (6) enforcement through disciplinary
guidelines, and (7) responding to detected offenses with corrective action. These
elements were originally outlined in the Federal Sentencing Guidelines and
adopted by OIG in its Compliance Program Guidance documents.
2. Which element of an effective compliance program requires the designation of a
specific individual to oversee the day-to-day operations of the program?
A) Written policies and procedures
B) Compliance officer and compliance committee
,C) Internal monitoring and auditing
D) Effective lines of communication
Rationale: Element 2 of the OIG's seven elements calls for the designation of a
compliance officer and compliance committee. The compliance officer is
responsible for the day-to-day operations of the compliance program, while the
compliance committee provides oversight and strategic direction. The compliance
officer should have direct access to the organization's governing body and senior
leadership.
3. In the OIG's newly modernized Corporate Integrity Agreement (CIA) template,
the Compliance Officer must report directly to:
A) The legal department
B) The billing manager
C) The CEO or the Board of Directors
D) The marketing director
Rationale: In the Kinex CIA, OIG substantially elevated the role of the
Compliance Officer (CO) and prohibited certain conflicting job functions.
Specifically, the CO must report directly to either the CEO or the Board, have
direct and independent access to the Board, and possess "sufficient stature" to
interact as an equal with other senior leaders.
4. Under the new OIG CIA template, the Compliance Officer may NOT:
A) Report to the Board of Directors
B) Lead or report to the legal or financial functions
C) Have direct access to the Board
D) Interact with senior leaders as an equal
Rationale: The CO may not lead or report to the legal or financial functions,
provide legal or financial advice, or hold operational responsibility for healthcare
delivery, billing and coding, claims submission, medical review, administrative
appeals, or contracting. The revised structure reflects OIG's view that the CO
should function as an independent senior leader, not a part-time function layered
onto another role.
5. According to OIG's guidance, what does the use of the word "should" in
compliance program guidance indicate?
,A) It is a mandatory legal requirement
B) It is voluntary, nonbinding guidance
C) It is enforced by CMS
D) It carries criminal penalties
Rationale: OIG uses the word "should" in the Medicare Advantage ICPG and
General Compliance Program Guidance to present voluntary, nonbinding
guidance. The documents do not create any new obligations or standards for any
individual or entity. Compliance program guidance from OIG is advisory in nature.
6. In February 2026, the OIG released its second Industry Segment-Specific
Compliance Program Guidance (ICPG). Which industry does this guidance
specifically target?
A) Hospitals
B) Physician practices
C) Medicare Advantage
D) Nursing facilities
Rationale: In February 2026, the OIG released its Industry Segment-Specific
Compliance Program Guidance (ICPG) for Medicare Advantage (MA). This was
the first MA-focused update since 1999 and was issued on February 3, 2026. It
details several key risk areas relevant to the MA program.
7. The OIG's Medicare Advantage ICPG includes compliance recommendations
for all of the following key risk areas EXCEPT:
A) Risk adjustment data validation
B) Marketing to uninsured patients
C) Utilization management
D) Quality of care
Rationale: The Medicare Advantage ICPG addresses key risk areas including
access to care, marketing and enrollment, risk adjustment, quality of care,
oversight of third parties, and compliance programs within vertically integrated
organizations. Marketing to uninsured patients is not a specified risk area for
Medicare Advantage compliance guidance.
8. What is the primary purpose of a compliance committee in a healthcare
organization?
, A) To maximize revenue
B) To oversee the compliance program and provide multidisciplinary
leadership
C) To conduct clinical trials
D) To manage patient scheduling
Rationale: A compliance committee provides high-level, multidisciplinary
oversight of the compliance program. It should include representation from key
departments (legal, clinical, operations, finance) and is responsible for approving
compliance policies, reviewing audit results, and ensuring the compliance program
is effective.
9. How frequently should a compliance committee typically meet?
A) Annually
B) Every 5 years
C) At least quarterly
D) Only when a violation occurs
Rationale: A compliance committee should meet at least quarterly to oversee the
compliance program, review audit findings, address emerging risks, and ensure
that the program is functioning effectively. Regular meetings demonstrate active
oversight and commitment to compliance.
10. What is the purpose of a code of conduct in a compliance program?
A) To outline billing procedures
B) To articulate the organization's commitment to ethical behavior and
compliance
C) To replace written policies
D) To serve as a marketing tool
Rationale: The code of conduct establishes a formal statement of the
organization's commitment to ethical behavior and compliance with laws and
regulations. It sets expectations for all employees and serves as the foundation for
the compliance program.
11. Which of the following is a key responsibility of the compliance officer?
A) Managing the organization's investment portfolio
B) Overseeing the day-to-day operations of the compliance program
Professional Compliance Officer Practice
Questions Answer Explanations • Healthcare
Compliance • Fraud & Abuse • HIPAA
Regulations • Risk Management Review
Domains Covered (AAPC CPCO Content Outline): Compliance Program
Development & Governance (25%) • Fraud, Waste & Abuse (25%) • HIPAA &
Regulatory Compliance (20%) • Auditing, Monitoring & Risk Assessment (15%) •
Investigations, Enforcement & Corrective Action (15%)
Domain I: Compliance Program Development & Governance (Questions 1–
30)
1. How many fundamental elements does the OIG identify as necessary for an
effective healthcare compliance program?
A) Six
B) Seven
C) Five
D) Eight
Rationale: The OIG identifies seven fundamental elements of an effective
compliance program: (1) written policies and procedures, (2) compliance officer
and committee, (3) training and education, (4) effective lines of communication,
(5) internal monitoring and auditing, (6) enforcement through disciplinary
guidelines, and (7) responding to detected offenses with corrective action. These
elements were originally outlined in the Federal Sentencing Guidelines and
adopted by OIG in its Compliance Program Guidance documents.
2. Which element of an effective compliance program requires the designation of a
specific individual to oversee the day-to-day operations of the program?
A) Written policies and procedures
B) Compliance officer and compliance committee
,C) Internal monitoring and auditing
D) Effective lines of communication
Rationale: Element 2 of the OIG's seven elements calls for the designation of a
compliance officer and compliance committee. The compliance officer is
responsible for the day-to-day operations of the compliance program, while the
compliance committee provides oversight and strategic direction. The compliance
officer should have direct access to the organization's governing body and senior
leadership.
3. In the OIG's newly modernized Corporate Integrity Agreement (CIA) template,
the Compliance Officer must report directly to:
A) The legal department
B) The billing manager
C) The CEO or the Board of Directors
D) The marketing director
Rationale: In the Kinex CIA, OIG substantially elevated the role of the
Compliance Officer (CO) and prohibited certain conflicting job functions.
Specifically, the CO must report directly to either the CEO or the Board, have
direct and independent access to the Board, and possess "sufficient stature" to
interact as an equal with other senior leaders.
4. Under the new OIG CIA template, the Compliance Officer may NOT:
A) Report to the Board of Directors
B) Lead or report to the legal or financial functions
C) Have direct access to the Board
D) Interact with senior leaders as an equal
Rationale: The CO may not lead or report to the legal or financial functions,
provide legal or financial advice, or hold operational responsibility for healthcare
delivery, billing and coding, claims submission, medical review, administrative
appeals, or contracting. The revised structure reflects OIG's view that the CO
should function as an independent senior leader, not a part-time function layered
onto another role.
5. According to OIG's guidance, what does the use of the word "should" in
compliance program guidance indicate?
,A) It is a mandatory legal requirement
B) It is voluntary, nonbinding guidance
C) It is enforced by CMS
D) It carries criminal penalties
Rationale: OIG uses the word "should" in the Medicare Advantage ICPG and
General Compliance Program Guidance to present voluntary, nonbinding
guidance. The documents do not create any new obligations or standards for any
individual or entity. Compliance program guidance from OIG is advisory in nature.
6. In February 2026, the OIG released its second Industry Segment-Specific
Compliance Program Guidance (ICPG). Which industry does this guidance
specifically target?
A) Hospitals
B) Physician practices
C) Medicare Advantage
D) Nursing facilities
Rationale: In February 2026, the OIG released its Industry Segment-Specific
Compliance Program Guidance (ICPG) for Medicare Advantage (MA). This was
the first MA-focused update since 1999 and was issued on February 3, 2026. It
details several key risk areas relevant to the MA program.
7. The OIG's Medicare Advantage ICPG includes compliance recommendations
for all of the following key risk areas EXCEPT:
A) Risk adjustment data validation
B) Marketing to uninsured patients
C) Utilization management
D) Quality of care
Rationale: The Medicare Advantage ICPG addresses key risk areas including
access to care, marketing and enrollment, risk adjustment, quality of care,
oversight of third parties, and compliance programs within vertically integrated
organizations. Marketing to uninsured patients is not a specified risk area for
Medicare Advantage compliance guidance.
8. What is the primary purpose of a compliance committee in a healthcare
organization?
, A) To maximize revenue
B) To oversee the compliance program and provide multidisciplinary
leadership
C) To conduct clinical trials
D) To manage patient scheduling
Rationale: A compliance committee provides high-level, multidisciplinary
oversight of the compliance program. It should include representation from key
departments (legal, clinical, operations, finance) and is responsible for approving
compliance policies, reviewing audit results, and ensuring the compliance program
is effective.
9. How frequently should a compliance committee typically meet?
A) Annually
B) Every 5 years
C) At least quarterly
D) Only when a violation occurs
Rationale: A compliance committee should meet at least quarterly to oversee the
compliance program, review audit findings, address emerging risks, and ensure
that the program is functioning effectively. Regular meetings demonstrate active
oversight and commitment to compliance.
10. What is the purpose of a code of conduct in a compliance program?
A) To outline billing procedures
B) To articulate the organization's commitment to ethical behavior and
compliance
C) To replace written policies
D) To serve as a marketing tool
Rationale: The code of conduct establishes a formal statement of the
organization's commitment to ethical behavior and compliance with laws and
regulations. It sets expectations for all employees and serves as the foundation for
the compliance program.
11. Which of the following is a key responsibility of the compliance officer?
A) Managing the organization's investment portfolio
B) Overseeing the day-to-day operations of the compliance program