Study each CPCO topic as a decision rule rather than a definition. For every statute, program element, and HIPAA rule, write one line stating the question it asks, one fact that changes the outcome, and one action it requires. Then practice on composite scenarios where two or more rules overlap, because real compliance work — and the scenarios built to test it — rarely involves a single law in isolation. Administrative details such as registration belong to the issuer at aapc.com; this guide covers the subject matter only.
Why a Compliance Program Is Seven Functions, Not a Policy Binder
Federal compliance program guidance is commonly organized around seven elements, including oversight, standards, training, communication lines, auditing and monitoring, enforcement, and corrective action. Treat each element as a function the program must perform.
Rewrite each element as a function: designated personnel create accountability; written standards create expectations; training spreads them; a reporting line lets concerns surface; auditing verifies; discipline and corrective action close the loop. A thick binder with policies but no functioning reporting channel or follow-up process fails the functions even if it cites every element by name.
Apply this by labeling any fact pattern with the element it implicates. An employee who fears retaliation when reporting a concern implicates the communication and non-retaliation function. A recurring documentation error that repeats after training implicates auditing, discipline, and corrective action. Exercise: pick a mock practice, list its activities, and map each activity to the element that governs it; if any element receives no activity, that is your weakest study area.
Sorting One Arrangement Under AKS, Stark, and the False Claims Act
These laws overlap but differ in scope and requirements. AKS targets remuneration intended to induce federal program referrals; Stark restricts physician referrals for designated health services; the FCA penalizes knowingly false claims.
Compare them on three axes. First, intent: AKS requires intent to induce referrals; Stark is commonly described as operating without an intent requirement, which is why its exception criteria must be verified and documented. Second, covered conduct: AKS reaches any remuneration for federal program business; Stark applies specifically to physician referrals for designated health services to entities with which the physician has a financial relationship. Third, the FCA sits downstream: claims submitted in violation of the first two can create FCA liability. Run each axis separately for every arrangement.
Worked scenario: a medical group pays a referring physician a medical director salary well above fair market value. The plausible mistake is concluding the contract is compliant because it cites a Stark personal-services exception. The better decision is to run a separate AKS analysis, because above-market compensation can be remuneration to induce referrals even where a Stark exception is named — and to confirm the exception's criteria are actually met and documented. This matters because passing one statute does not clear the others, and claims paid under a tainted arrangement can carry FCA exposure. Use the table below to keep the analyses distinct.
Decision table: use the key question column as your first sorting step for any arrangement scenario.
| Law | What it restricts | Whose conduct | Key analysis question |
|---|---|---|---|
| Anti-Kickback Statute (AKS) | Remuneration to induce referrals of federal program business | Any party on either side of a referral | Was anything of value offered to induce federal program referrals? |
| Stark Law | Physician referrals for designated health services to entities with financial relationships | Physicians and DHS entities | Is there a financial relationship, and does an exception apply and get documented? |
| False Claims Act (FCA) | Knowingly submitting or causing false claims to the government | Anyone who presents or causes claims | Were claims knowingly false, including claims caused by a violating arrangement? |
| HIPAA Privacy Rule | Uses and disclosures of PHI in any form | Covered entities and business associates | Is there a permitted purpose or authorization for this use or disclosure? |
| HIPAA Security Rule | Safeguards for electronic PHI | Covered entities and business associates | Are administrative, physical, and technical safeguards protecting ePHI? |
Deciding Whether the Privacy Rule or the Security Rule Applies
The Privacy Rule governs when protected health information in any form may be used or disclosed. The Security Rule governs safeguards for electronic PHI. Identify the medium and the purpose before choosing the analysis.
Use a two-question test. Question one: what form is the information in? Any form implicates Privacy; electronic form additionally implicates Security. Question two: is there a permitted purpose? Treatment, payment, health care operations, patient authorization, or another specific permission under the Privacy Rule governs the use; the Security Rule then asks whether administrative, physical, and technical safeguards protected the electronic version. Minimum-necessary limits apply to routine uses and disclosures.
Contrast two incidents to fix the distinction. A billing clerk mails a paper statement to the wrong address: the Privacy Rule analysis asks whether the disclosure was permitted and whether it qualifies as a breach requiring response. A stolen laptop containing unencrypted patient records: the Security Rule analysis asks which safeguards failed, while the Privacy Rule still governs the exposure of the information. The same event can trigger both rules, so state the finding under each rather than merging them into one generic 'HIPAA problem.'
Testing Coding Questions Against Documentation and Medical Necessity
Coding compliance questions resolve to two separate tests: does the documentation support the code reported, and does the service meet the medical necessity standard for billing it? Both tests must pass, not just one.
Keep the tests independent in your analysis. A thoroughly documented service can still be non-billable if the service lacks medical necessity for the code billed, and a medically necessary service is non-billable at a level the record does not document. When you read a coding scenario, write down the answer to each test separately before deciding whether the claim is supportable.
Learn the named risk patterns so you can recognize them from facts: unbundling bundled services into separate claims, upcoding to a higher level than documentation supports, and billing services that do not meet payer coverage criteria. Each pattern maps to a corrective action type — coder education for documentation gaps, claim edits for unbundling, and coverage verification for necessity questions. Practice matching pattern to cause, because the fix differs even when the symptom, a denied or questionable claim, looks identical.
Choosing Between Auditing and Monitoring in the Compliance Plan
Monitoring is an ongoing check built into daily operations; auditing is a periodic, more independent evaluation, often retrospective and sample-based. A compliant program uses both, with findings feeding corrective action.
Distinguish them by independence, frequency, and scope. A billing supervisor reviewing daily claim edits is monitoring: continuous, operational, done by someone inside the process. An annual external audit of a random sample of high-risk charts is auditing: episodic, evaluative, and more independent of the people whose work is checked. When a scenario describes an activity, classify it by these three features rather than by its label, because organizations name activities inconsistently.
Connect the findings to a work plan. Risk-driven priorities — high-dollar services, high-volume codes, and historically error-prone areas — determine what gets audited and how often, and every finding should trace to a corrective response such as training, a policy revision, or a new monitoring step. Exercise: for a mock practice, list three monitoring activities and two audit activities, then state for each who performs it, how often, and which risk it addresses; a vague risk column usually signals an activity chosen without a reason.
Responding When an Audit Identifies an Overpayment
After an audit identifies overpayments, the compliance response is to determine scope, quantify the affected claims, stop the underlying cause, and follow the organization's process for reporting and returning the overpayment on the required timeline.
Federal law obligates organizations to report and return identified overpayments within defined timeframes, and the mechanics of that obligation are a core study point. Learn it as a sequence: identification triggers the duty, the duty covers report and return, and the clock and calculation method come from the governing rule. Match each scenario fact to a step so you can state what has been satisfied and what remains.
Worked scenario: an internal audit finds a coder has reported a higher evaluation-and-management level than documentation supports for the past six months. The plausible mistake is retraining the coder and correcting claims going forward only. The better decision is to assess the lookback scope, quantify the affected claims, document the analysis, route repayment through the organization's established process, and add a monitoring check on this code family. This matters because a forward-only fix leaves identified past overpayments unaddressed, which both fails the return obligation and leaves FCA exposure open on the original claims.
Building an Adaptable Study Sequence and Readiness Checks
Work the material in four passes: statutes and their distinctions, the program elements, HIPAA's two rules, then composite scenarios that combine all three. Finish each pass with a written self-check against the rubric below.
A workable sequence: first pass, build the statute table from memory and re-derive the key question for each law; second pass, map a mock practice's activities to the seven elements and find the gaps; third pass, sort ten records incidents into Privacy, Security, or both; fourth pass, write your own composite scenarios — an arrangement with a billing consequence, an audit with an overpayment finding — and solve them end to end. Adjust the pacing to your schedule; the order matters more than the calendar.
Readiness checks, as learning milestones rather than pass predictions: you can state in one sentence how AKS and Stark differ on intent and covered conduct; you can name the seven elements and give one example function for each; you can classify any records incident under Privacy, Security, or both with the next action for each; and you can outline the full overpayment response from identification to resolution. If any check fails, return to that pass's scenario work instead of rereading summaries. Then verify your understanding against the free practice questions on this site.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
