2026 CPCO Study Guide Certified
Professional Compliance Officer Practice
Questions Answer Explanations •
Healthcare Compliance • Fraud & Abuse •
HIPAA Regulations • Risk Management
Review
SECTION 1: Healthcare Compliance Foundations (Questions 1–30)
• 1. What is the primary purpose of a healthcare compliance program?
o A. Maximize hospital revenue
o B. Prevent, detect, and correct noncompliance with laws and
regulations
o C. Replace legal counsel
o D. Eliminate all audits
o Correct Answer: B
o Rationale: The core purpose of a compliance program is to
prevent, detect, and correct violations of law, regulations, and
internal policies. Revenue maximization is not a compliance objective,
and compliance programs complement—not replace—legal counsel
or audits.
• 2. Which federal agency oversees the Medicare program and issues many
compliance guidance documents?
o A. FBI
o B. CMS
, o C. DEA
o D. OSHA
o Correct Answer: B
o Rationale: The Centers for Medicare & Medicaid Services (CMS)
administers Medicare and Medicaid and issues compliance guidance.
The FBI investigates, the DEA handles controlled substances, and
OSHA handles workplace safety.
• 3. What are the seven elements of an effective compliance program?
o A. Hiring, firing, training, auditing, billing, coding, reporting
o B. Written standards, compliance officer, training, communication,
monitoring/auditing, discipline, corrective action
o C. Marketing, sales, finance, legal, HR, IT, operations
o D. Policies, procedures, forms, logs, reports, memos, files
o Correct Answer: B
o Rationale: The seven elements derive from the Federal
Sentencing Guidelines and OIG guidance: written standards, a
designated compliance officer, effective training, communication
lines, monitoring/auditing, discipline, and corrective action.
• 4. The OIG's Seven Elements were originally adapted from which source?
o A. HIPAA Privacy Rule
o B. Federal Sentencing Guidelines
o C. Stark Law
o D. Affordable Care Act
o Correct Answer: B
, o Rationale: The OIG modeled its compliance program elements on
the Federal Sentencing Guidelines, which establish criteria for
effective compliance programs to mitigate organizational liability.
• 5. A compliance officer's primary reporting relationship should be to:
o A. The billing manager
o B. The governing body/board of directors
o C. The marketing department
o D. The IT help desk
o Correct Answer: B
o Rationale: To maintain independence and authority, the
compliance officer should report directly to the governing body or a
high-level committee, not to operational managers whose work is
being monitored.
• 6. What does "tone at the top" refer to in compliance?
o A. The volume of training materials
o B. Leadership's demonstrated commitment to ethical and compliant
behavior
o C. The pitch of a compliance presentation
o D. Background music in offices
o Correct Answer: B
o Rationale: "Tone at the top" means leadership visibly and
consistently supports compliance, which strongly influences
organizational culture and employee behavior.
• 7. Which of the following is an example of an internal control?
o A. Employee break schedule
, o B. Segregation of duties
o C. Office holiday calendar
o D. Parking policy
o Correct Answer: B
o Rationale: Segregation of duties is a classic internal control that
prevents one person from having excessive control over a
transaction, reducing fraud risk.
• 8. A compliance program's effectiveness should be measured by:
o A. Number of policies written
o B. Number of employees hired
o C. Auditing, monitoring, and outcomes of corrective actions
o D. Revenue growth
o Correct Answer: C
o Rationale: Effectiveness is measured through ongoing auditing,
monitoring, and the resolution of identified issues—not by volume of
documents or revenue.
• 9. Which document typically formalizes a compliance program's scope and
authority?
o A. Employee handbook only
o B. Compliance charter or plan
o C. Payroll register
o D. Vendor contract
o Correct Answer: B
Professional Compliance Officer Practice
Questions Answer Explanations •
Healthcare Compliance • Fraud & Abuse •
HIPAA Regulations • Risk Management
Review
SECTION 1: Healthcare Compliance Foundations (Questions 1–30)
• 1. What is the primary purpose of a healthcare compliance program?
o A. Maximize hospital revenue
o B. Prevent, detect, and correct noncompliance with laws and
regulations
o C. Replace legal counsel
o D. Eliminate all audits
o Correct Answer: B
o Rationale: The core purpose of a compliance program is to
prevent, detect, and correct violations of law, regulations, and
internal policies. Revenue maximization is not a compliance objective,
and compliance programs complement—not replace—legal counsel
or audits.
• 2. Which federal agency oversees the Medicare program and issues many
compliance guidance documents?
o A. FBI
o B. CMS
, o C. DEA
o D. OSHA
o Correct Answer: B
o Rationale: The Centers for Medicare & Medicaid Services (CMS)
administers Medicare and Medicaid and issues compliance guidance.
The FBI investigates, the DEA handles controlled substances, and
OSHA handles workplace safety.
• 3. What are the seven elements of an effective compliance program?
o A. Hiring, firing, training, auditing, billing, coding, reporting
o B. Written standards, compliance officer, training, communication,
monitoring/auditing, discipline, corrective action
o C. Marketing, sales, finance, legal, HR, IT, operations
o D. Policies, procedures, forms, logs, reports, memos, files
o Correct Answer: B
o Rationale: The seven elements derive from the Federal
Sentencing Guidelines and OIG guidance: written standards, a
designated compliance officer, effective training, communication
lines, monitoring/auditing, discipline, and corrective action.
• 4. The OIG's Seven Elements were originally adapted from which source?
o A. HIPAA Privacy Rule
o B. Federal Sentencing Guidelines
o C. Stark Law
o D. Affordable Care Act
o Correct Answer: B
, o Rationale: The OIG modeled its compliance program elements on
the Federal Sentencing Guidelines, which establish criteria for
effective compliance programs to mitigate organizational liability.
• 5. A compliance officer's primary reporting relationship should be to:
o A. The billing manager
o B. The governing body/board of directors
o C. The marketing department
o D. The IT help desk
o Correct Answer: B
o Rationale: To maintain independence and authority, the
compliance officer should report directly to the governing body or a
high-level committee, not to operational managers whose work is
being monitored.
• 6. What does "tone at the top" refer to in compliance?
o A. The volume of training materials
o B. Leadership's demonstrated commitment to ethical and compliant
behavior
o C. The pitch of a compliance presentation
o D. Background music in offices
o Correct Answer: B
o Rationale: "Tone at the top" means leadership visibly and
consistently supports compliance, which strongly influences
organizational culture and employee behavior.
• 7. Which of the following is an example of an internal control?
o A. Employee break schedule
, o B. Segregation of duties
o C. Office holiday calendar
o D. Parking policy
o Correct Answer: B
o Rationale: Segregation of duties is a classic internal control that
prevents one person from having excessive control over a
transaction, reducing fraud risk.
• 8. A compliance program's effectiveness should be measured by:
o A. Number of policies written
o B. Number of employees hired
o C. Auditing, monitoring, and outcomes of corrective actions
o D. Revenue growth
o Correct Answer: C
o Rationale: Effectiveness is measured through ongoing auditing,
monitoring, and the resolution of identified issues—not by volume of
documents or revenue.
• 9. Which document typically formalizes a compliance program's scope and
authority?
o A. Employee handbook only
o B. Compliance charter or plan
o C. Payroll register
o D. Vendor contract
o Correct Answer: B