CPHRM COMPREHENSIVE QUESTIONS AND
ANSWERS SET A+
✔✔Outline the requirements for a valid HIPAA notice (Notice of Privacy Practices or
NPP) - ✔✔Valid HIPAA Notice/NPP
As per HIPAA regulations 45 CFR 164.520 the NPP must be written in plain language
and include:
➣ Permissible types of Uses and Disclosures of PHI (Protected Health Info) when no
authorization from patient is required.
➣ Describe Patient's Rights (e.g., right to access, request amendments to, and receive
an accounting of disclosures of their PHI)
➣ Describe Entity's duties (required statements on how the entity is legally required to
maintain the privacy of PHI and abide by the notice privacy practices).
➣ When authorization is required (description of uses and disclosures that require
specific authorization and the individual's right to revoke an authorization)
➣ Revision of Notice (statement that the entity retains the rights to revise the notice)
➣ Effective date of the notice (when first in effect)
Full details:
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-
164.520
✔✔Discuss the four main requirements for a healthcare facility to comply with HIPAA
Security rules - ✔✔HIPAA Security Rule - 45 CFR Part 164 Subpart C
Requirements in this section ca be summarized in four main objectives:
1. Facility must the Confidentiality, Integrity, and Availability of electronic PHI. any ePHI
the facility creates, received, maintains or transmits (includes administrative, physical,
and technical safeguards)
2. Protect against any anticipated threats (e.g., cyber attacks) or hazards to the security
of ePHI (e.g., clear policies & procedures on Security Risk Analysis or IT Risk
Management Plan)
, 3. Protect against any reasonable anticipates uses/disclosures of ePHI that are not
permitted or required
4. Ensure compliance with these requirements by its workforce
✔✔Discuss the main difference between the HIPAA Privacy and Security rules - ✔✔The
Privacy rule covers and outlines requirements to protect all types of PHI (written, oral,
and electronic)
The Security rule covers and outlines requirements to protect ePHI (electronic) only.
✔✔In healthcare billing, Recovery Audit Contractors (RAC) play a role in Medicare
reimbursement - ✔✔Recovery Audit Contractors (RAC) are private companies
contracted by the Centers for Medicare & Medicaid Services (CMS) to identify and
correct improper payments in Medicare. Any improper payments or identified
overpayments made to the facility during the audit and medical record review, must be
refunded back to Medicare within 45 days.
If facility disagree with the findings, they can appeal accordingly.
Risk management professionals can assist the facility in compliance with RAC medical
record request as appropriate. The best practice is to proactively conduct internal
coding and billing audits. Consult with the revenue cycle leader to learn about how the
entity process and responds to these requests, which are routine audits triggered by
payment patters CMS identifies from national and regional databases.
✔✔Define Medicare Conditions of Participation (CoP) and give examples - ✔✔Medicare
Conditions of Participations (CoP) are rules that providers must follow in order to
participate and bill Medicare accordingly. CMS is the oversight federal agency.
Some CoP examples:
➣ Infection Prevention - facility must have in place an Infection Prevention Program and
internal policies & procedures.
➣ Patient rights - facility must advise patients on their rights to confidentiality, decision-
making, and safe care, and a process and policies to address Patient Grievances
➣ Discharge planning - facility must have policies & procedures in place to provide a
safe discharge plan and assess patients for discharge needs.
➣ Quality improvement - facility must have an effective data-driven performance
improvement quality and patient safety programs.
CoP for hospitals - 42 CFR Part 482
CoP for CAH - 42 CFR 485 subpart F
CoP for LTC - 42 CFR Part 483
CoP fro Home Health - 42 CFR Part 484
✔✔Discuss the purpose of the regulatory requirements arising from the National Organ
Transplant Act - ✔✔The National Organ Transplant Act of 1984 was established to set
standards to address national organ donation shortages and improve the distribution of
organs for transplant.
ANSWERS SET A+
✔✔Outline the requirements for a valid HIPAA notice (Notice of Privacy Practices or
NPP) - ✔✔Valid HIPAA Notice/NPP
As per HIPAA regulations 45 CFR 164.520 the NPP must be written in plain language
and include:
➣ Permissible types of Uses and Disclosures of PHI (Protected Health Info) when no
authorization from patient is required.
➣ Describe Patient's Rights (e.g., right to access, request amendments to, and receive
an accounting of disclosures of their PHI)
➣ Describe Entity's duties (required statements on how the entity is legally required to
maintain the privacy of PHI and abide by the notice privacy practices).
➣ When authorization is required (description of uses and disclosures that require
specific authorization and the individual's right to revoke an authorization)
➣ Revision of Notice (statement that the entity retains the rights to revise the notice)
➣ Effective date of the notice (when first in effect)
Full details:
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-
164.520
✔✔Discuss the four main requirements for a healthcare facility to comply with HIPAA
Security rules - ✔✔HIPAA Security Rule - 45 CFR Part 164 Subpart C
Requirements in this section ca be summarized in four main objectives:
1. Facility must the Confidentiality, Integrity, and Availability of electronic PHI. any ePHI
the facility creates, received, maintains or transmits (includes administrative, physical,
and technical safeguards)
2. Protect against any anticipated threats (e.g., cyber attacks) or hazards to the security
of ePHI (e.g., clear policies & procedures on Security Risk Analysis or IT Risk
Management Plan)
, 3. Protect against any reasonable anticipates uses/disclosures of ePHI that are not
permitted or required
4. Ensure compliance with these requirements by its workforce
✔✔Discuss the main difference between the HIPAA Privacy and Security rules - ✔✔The
Privacy rule covers and outlines requirements to protect all types of PHI (written, oral,
and electronic)
The Security rule covers and outlines requirements to protect ePHI (electronic) only.
✔✔In healthcare billing, Recovery Audit Contractors (RAC) play a role in Medicare
reimbursement - ✔✔Recovery Audit Contractors (RAC) are private companies
contracted by the Centers for Medicare & Medicaid Services (CMS) to identify and
correct improper payments in Medicare. Any improper payments or identified
overpayments made to the facility during the audit and medical record review, must be
refunded back to Medicare within 45 days.
If facility disagree with the findings, they can appeal accordingly.
Risk management professionals can assist the facility in compliance with RAC medical
record request as appropriate. The best practice is to proactively conduct internal
coding and billing audits. Consult with the revenue cycle leader to learn about how the
entity process and responds to these requests, which are routine audits triggered by
payment patters CMS identifies from national and regional databases.
✔✔Define Medicare Conditions of Participation (CoP) and give examples - ✔✔Medicare
Conditions of Participations (CoP) are rules that providers must follow in order to
participate and bill Medicare accordingly. CMS is the oversight federal agency.
Some CoP examples:
➣ Infection Prevention - facility must have in place an Infection Prevention Program and
internal policies & procedures.
➣ Patient rights - facility must advise patients on their rights to confidentiality, decision-
making, and safe care, and a process and policies to address Patient Grievances
➣ Discharge planning - facility must have policies & procedures in place to provide a
safe discharge plan and assess patients for discharge needs.
➣ Quality improvement - facility must have an effective data-driven performance
improvement quality and patient safety programs.
CoP for hospitals - 42 CFR Part 482
CoP for CAH - 42 CFR 485 subpart F
CoP for LTC - 42 CFR Part 483
CoP fro Home Health - 42 CFR Part 484
✔✔Discuss the purpose of the regulatory requirements arising from the National Organ
Transplant Act - ✔✔The National Organ Transplant Act of 1984 was established to set
standards to address national organ donation shortages and improve the distribution of
organs for transplant.