QUESTIONS AND CORRECT ANSWERS WITH WELL
VERIFIED RATIONALES
SECTION 1: PROFESSIONALISM, ETHICS, AND COMPLIANCE (Questions 1–70)
1. Which federal law establishes national standards for the protection of protected
health information (PHI)?
A) EMTALA
B) HIPAA
C) Stark Law
D) ERISA
Correct Answer: B
Rationale: The Health Insurance Portability and Accountability Act (HIPAA) of 1996
established national standards for the privacy and security of protected health
information. EMTALA governs emergency medical treatment, the Stark Law
addresses physician self-referrals, and ERISA regulates employee benefit plans.
2. Under HIPAA's minimum necessary standard, a coder may access PHI:
A) For any purpose as long as they are an employee
B) Only to the extent needed to perform their job functions
C) Only with written patient authorization for each access
D) Freely, because coders are exempt from HIPAA
Correct Answer: B
Rationale: The minimum necessary standard requires covered entities to make
reasonable efforts to limit PHI access to the minimum needed to accomplish the
,intended purpose. Coders are not exempt; they may access PHI only as needed for
coding and billing functions.
3. A coder discovers that a physician is routinely documenting services that were not
performed. This is an example of:
A) Upcoding
B) Downcoding
C) Unbundling
D) Fraud
Correct Answer: D
Rationale: Documenting and billing for services not rendered constitutes healthcare
fraud, which is a violation of the False Claims Act. Upcoding involves billing for a
higher-level service than documented, downcoding is billing at a lower level, and
unbundling is billing separately for components of a bundled service.
4. Which of the following is NOT a component of the Fraud and Abuse Act?
A) Anti-Kickback Statute
B) False Claims Act
C) Stark Law
D) Fair Debt Collection Practices Act
Correct Answer: D
Rationale: The Fair Debt Collection Practices Act regulates debt collection practices
and is not part of the Fraud and Abuse Act. The Anti-Kickback Statute, False Claims
Act, and Stark Law are all federal fraud and abuse laws.
5. A coder is asked to change a diagnosis code to one that pays more, even though
the documentation does not support it. What should the coder do?
A) Change the code as requested
B) Refuse and report the request to a supervisor or compliance officer
,C) Change the code but document the request
D) Ignore the request and code from documentation
Correct Answer: B
Rationale: Coders must never assign codes not supported by documentation. They
should refuse and report the request through the organization's compliance
reporting mechanism. Changing the code would constitute fraud.
6. The Joint Commission's role in healthcare includes:
A) Setting Medicare reimbursement rates
B) Accrediting and certifying healthcare organizations
C) Investigating Medicare fraud
D) Regulating insurance premiums
Correct Answer: B
Rationale: The Joint Commission accredits and certifies healthcare organizations and
programs in the United States. It does not set reimbursement rates, investigate
fraud, or regulate insurance premiums.
7. Which of the following is an example of a conflict of interest for a medical
coder?
A) Coding from physician documentation
B) Owning stock in a company that provides coding software to their employer
C) Attending a coding conference
D) Using an encoder software
Correct Answer: B
Rationale: A conflict of interest arises when a coder's personal interests could
improperly influence their professional decisions. Owning stock in a vendor that
does business with their employer is a conflict of interest.
8. The HITECH Act primarily:
, A) Expanded HIPAA privacy and security protections and promoted electronic
health records
B) Established Medicare Part D
C) Regulated nursing home quality
D) Created the Affordable Care Act
Correct Answer: A
Rationale: The Health Information Technology for Economic and Clinical Health
(HITECH) Act of 2009 expanded HIPAA protections and provided incentives for the
adoption of electronic health records.
9. A coder notices that a colleague is accessing patient records of celebrities
without a business reason. This is:
A) Acceptable if the colleague is curious
B) A HIPAA violation that should be reported
C) Permitted for training purposes
D) Not a concern if the colleague does not share the information
Correct Answer: B
Rationale: Accessing PHI without a legitimate business need violates HIPAA's
minimum necessary standard and privacy rule, regardless of whether the
information is shared.
10. Which of the following is a responsibility of a medical coder under the
compliance plan?
A) Diagnosing patients
B) Auditing physician documentation for accuracy
C) Prescribing medications
D) Performing surgery
Correct Answer: B