CHC Exam Prep 9 Week Study Plan
This plan runs on a simple rhythm: one Part per week for [X-1] weeks, then a final week for full review and exam simulation. For each Part, read that Part's Study Guide first β it's your advance organizer, telling you what matters most and how the concepts connect before you open a single chapter. Treat the plan like a buffet, not a must-do list: do the work that closes your weak spots, and let the quiz bank tell you where those are.
The Made Easy Highlighting System
Before Week 1, set up the color system you'll use every single week. Highlighting isn't decoration β it's a learning strategy. When you tag information by type instead of by what feels "important," each color becomes a mental shortcut, and you build a color-coded study guide automatically as you read. Every weekly Part below tells you to "highlight as you read" using these six colors:
π₯ Red: Laws, Statutes & Liability Triggers (Break This and Someone Goes to Court) β Think: "What's the specific law, and what makes a violation?" The False Claims Act (civil and criminal), the Anti-Kickback Statute elements, the Stark Law and physician self-referral, the Civil Monetary Penalties Law, and refund obligations under the 60-Day Rule.
πͺ Purple: Program Structure & Compliance Frameworks (The Skeleton of the Program) β Think: "What are the required parts, and how do they fit together?" The Seven Elements of an Effective Compliance Program, the Federal Sentencing Guidelines and compliance credit, compliance committees and board oversight, written policies/procedures/standards of conduct, and the DOJ Evaluation of Corporate Compliance Programs.
π§ Orange: Operational Methods & Tools (The Step-by-Step Compliance Work) β Think: "What procedure do I run to actually do compliance?" Risk-assessment methodologies, sanction screening (LEIE, SAM, state exclusion lists), sampling methods for compliance audits, conducting internal investigations, and audit reporting and corrective action plans.
π© Green: Regulatory Domains & Subject-Matter Rules (The Topical Rulebooks) β Think: "What are the specific rules for this domain of healthcare?" The HIPAA Privacy Rule core provisions, the HIPAA Security Rule and safeguards, E/M coding and the 2021/2023 guideline changes, 42 CFR Part 2 substance-use records, and research compliance (the Common Rule and IRB).
π¨ Yellow: People, Culture & Communication (The Human Infrastructure) β Think: "How do we train, communicate, and protect the people doing the work?" New-hire and annual compliance training, hotline design and vendor selection, non-retaliation policy and protections, whistleblower protections under federal law, and awareness campaigns and reinforcement.
π¦ Blue: Enforcement, Discipline & Government Response (When the Government Shows Up) β Think: "What happens when something goes wrong β internally or externally?" Sanction grids and progressive discipline, self-disclosure protocols (OIG, CMS, DOJ), corporate integrity agreements and settlement obligations, government investigation tools (subpoenas, search warrants, CIDs), and document preservation and legal hold.
Three rules: highlight as you go, not at the end; when in doubt pick the color that fits the type of information, not the topic; and review by color β read only the red highlights, then only the yellow, and so on. You've got the system. Now let it work for you.
Week 1 β Part I: Healthcare Compliance Foundations and Program Administration
Difficulty: Heavy
What it covers:
Origins of healthcare compliance and how the Federal Sentencing Guidelines created the modern framework of compliance credit
The role of OIG Compliance Program Guidance documents (sector-specific CPGs and the November 2023 General Compliance Program Guidance) in shaping compliance expectations
The Seven Elements of an Effective Compliance Program and the purpose and components of each
The distinction between compliance and ethics, including overlapping responsibilities and reporting structures
The Compliance Officer role, appropriate reporting lines, independence requirements, and the structure and duties of the compliance committee and board oversight
Application of the HCCA Code of Ethics, written policies, procedures, and standards of conduct in routine compliance practice
Healthcare compliance risk assessment methodology and translating findings into a prioritized, resourced compliance work plan
Evaluation of program maturity and effectiveness using metrics, documentation, records retention, and the DOJ Evaluation of Corporate Compliance Programs (ECCP)
Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Lock in the Seven Elements of an Effective Compliance Program before anything else in this Part. Written policies and procedures and standards of conduct; designation of a Compliance Officer and compliance committee; effective training and education; effective lines of communication including a confidential hotline; well-publicized disciplinary standards; internal monitoring and auditing; and prompt response to detected offenses with corrective action. Every CCB CHC question about program structure traces back to one of these seven. Be able to list them in order and give a one-sentence example of each.
β Understand the Federal Sentencing Guidelines (FSG) for organizations. The FSG is the legal engine behind the entire compliance industry. An organization convicted of a federal offense can receive a substantial reduction in its culpability score if it had an effective compliance and ethics program in place at the time of the offense. Know the culpability score mechanics at a high level (base score, aggravating factors, mitigating credit), the requirement that the program be effective in practice rather than just on paper, and the role of high-level personnel involvement as a disqualifier.
β OIG Compliance Program Guidance (CPG) documents are tested directly. Know that the OIG publishes sector-specific guidance (hospitals, nursing facilities, third-party billing companies, hospices, individual and small group physician practices, DME suppliers, pharmaceutical manufacturers, Medicare Advantage organizations, and others) and that the November 2023 General Compliance Program Guidance (GCPG) consolidates cross-cutting expectations. The CPGs are voluntary but functionally serve as the OIG's effectiveness benchmark.
β Distinguish the Compliance Officer from the General Counsel and the CEO. The Compliance Officer must have direct access to the governing body (board) and CEO, must not report solely up through legal or finance, and should not hold legal responsibility for the same organization the program oversees. The reporting line and independence question is a high-frequency CCB CHC item.
β Risk assessment methodology is testable. Know the basic flow: identify inherent risks across the operation, score by likelihood and impact, factor in existing controls to derive residual risk, prioritize, and translate the top risks into a documented work plan with owners, deliverables, and timelines. The risk assessment is the document that justifies what the compliance program does and does not do this year.
β Complete the Practice Questions for Part I in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Healthcare Compliance Foundations and Program Administration. Main branches: Origins of Healthcare Compliance and the FSG β OIG Compliance Program Guidance (sector-specific and GCPG) β The Seven Elements of an Effective Compliance Program β Compliance vs. Ethics β Compliance Officer Role, Reporting Lines, and Independence β Compliance Committee and Board Oversight β HCCA Code of Ethics β Written Policies, Procedures, and Standards of Conduct β Risk Assessment Methodology and Work Plan β DOJ Evaluation of Corporate Compliance Programs (ECCP) β Program Metrics, Documentation, and Records Retention.
Comparison Charts:
β Chart 1 β Compliance Officer vs. General Counsel vs. CEO: Primary duty, reporting line to the board, independence requirements, scope of authority, and example of a decision that belongs to each role alone.
β Chart 2 β FSG vs. OIG CPG vs. DOJ ECCP: Issuing authority, legal status (binding vs. voluntary vs. enforcement framework), what each is used for, when each comes into play, and how each shapes program design or evaluation.
β Chart 3 β Risk Assessment vs. Work Plan vs. Audit Plan: Purpose, inputs, outputs, owner, frequency, and how each one feeds the next in the annual compliance cycle.
Cornell Notes:
β Page 1 β Cue questions: What are the Seven Elements of an Effective Compliance Program, and what is the foundational document or activity that proves each element to a regulator? What is the difference between compliance and ethics, and where do their responsibilities overlap inside a healthcare organization?
β Page 2 β Cue questions: How does the Federal Sentencing Guidelines culpability score work, and what makes a compliance program effective enough to qualify for mitigation credit? What independence and reporting-line characteristics must a Compliance Officer have, and why does the DOJ ECCP treat that structure as a test of program credibility?
Week 2 β Part II: Fraud, Waste, and Abuse Laws
Difficulty: Heavy, High Yield
What it covers:
The False Claims Act (civil and criminal), including the elements required to establish a violation
FCA whistleblower (qui tam) procedure, relator awards, and anti-retaliation protections under 31 U.S.C. Β§ 3730(h)
The Anti-Kickback Statute, its elements, and how AKS safe harbors protect otherwise lawful arrangements
The Stark Law and how it differs from AKS in scope, intent standard, penalties, and exceptions
Stark Law exceptions for ownership, compensation, and other physician financial relationships
The Civil Monetary Penalties Law and the major categories of conduct it reaches
Mandatory and permissive OIG exclusion authorities and how the LEIE is used to screen workforce and vendors
EMTALA requirements (screening, stabilization, transfer) and the beneficiary inducement and patient-choice rules in common operational scenarios
Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter. β Highlight as you read. Follow the Made Easy Highlighting System
β The False Claims Act is the most-tested single statute on the CCB CHC. Memorize the elements. A person who knowingly presents, or causes to be presented, a false or fraudulent claim for payment to the government is liable, where "knowingly" includes actual knowledge, deliberate ignorance, or reckless disregard (no specific intent to defraud required). Materiality is required, meaning the falsehood must have a natural tendency to influence the government's payment decision. Damages are treble the government's loss plus per-claim civil penalties indexed annually for inflation. Know the qui tam procedure: relator files under seal, government investigates and intervenes or declines, and relator share runs roughly 15 to 25 percent if the government intervenes and 25 to 30 percent if it does not. Anti-retaliation under 31 U.S.C. Β§ 3730(h) protects the relator's job.
β Anti-Kickback Statute (AKS) versus Stark Law is the most common compare-and-contrast item on the exam. AKS is a criminal, intent-based statute that prohibits knowingly and willfully offering, paying, soliciting, or receiving any remuneration to induce or reward referrals for items or services paid by a federal healthcare program. It applies to anyone, not just physicians. AKS has statutory exceptions and regulatory safe harbors that protect arrangements meeting every element. Stark is a civil, strict-liability statute that prohibits a physician from making a referral for designated health services (DHS) to an entity with which the physician (or immediate family member) has a financial relationship, unless an exception applies. Stark requires no intent. Confusing scope, intent standard, and remedies between AKS and Stark is the most common wrong answer on the exam.
β Civil Monetary Penalties Law (CMPL) is the OIG's flexible enforcement tool. It reaches false claims, kickback violations, employing excluded persons, EMTALA violations, beneficiary inducement, and many other categories. Know the basic per-violation penalty structure and that the OIG can impose CMPs administratively without DOJ involvement.
β OIG exclusions: mandatory exclusion applies to convictions for program-related crimes, patient abuse or neglect, felony healthcare fraud, and felony controlled-substance offenses. Permissive exclusion is discretionary and reaches misdemeanors, license loss, default on health education loans, and other categories. Excluded persons cannot be paid directly or indirectly by any federal healthcare program for any item or service. The List of Excluded Individuals and Entities (LEIE) is the OIG's official database; SAM.gov adds debarments from many other federal agencies. Screen at hire and at least monthly thereafter.
β EMTALA's three duties on Medicare-participating hospitals with emergency departments: provide an appropriate medical screening examination to any individual who presents requesting examination or treatment; stabilize any individual found to have an emergency medical condition (or an unstabilized woman in active labor) within the hospital's capability; and conduct an appropriate transfer if the receiving hospital has accepted and the benefits of transfer outweigh the risks. Be able to identify which step of EMTALA fails in a clinical scenario.
β Beneficiary inducement under CMPL prohibits offering or giving anything of value to a Medicare or Medicaid beneficiary that the giver knows or should know is likely to influence the beneficiary's selection of a particular provider, practitioner, or supplier. Know the major exceptions (nominal-value items, financial-need-based remuneration, copayment waivers based on financial need or after good-faith collection effort, retailer rewards, and so on).
β Complete the Practice Questions for Part II in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Fraud, Waste, and Abuse Laws. Main branches: False Claims Act (civil and criminal, elements, knowingly, materiality, damages) β Qui Tam and Anti-Retaliation β Anti-Kickback Statute (elements, safe harbors) β Stark Law (designated health services, exceptions, strict liability) β Civil Monetary Penalties Law β OIG Exclusion Authorities (mandatory vs. permissive, LEIE, SAM) β EMTALA (screening, stabilization, transfer) β Beneficiary Inducement and Patient-Choice Rules β Refund Obligations and the 60-Day Rule.
Comparison Charts:
β Chart 1 β Anti-Kickback Statute vs. Stark Law: Civil or criminal, intent standard, who the statute reaches (anyone vs. physicians only), what triggers it (any referral for federal-program items or services vs. referral for designated health services), use of safe harbors vs. exceptions, and remedies including penalties and exclusion.
β Chart 2 β FCA Civil vs. FCA Criminal: Burden of proof, intent standard, penalties, who can bring the action (government and qui tam relators vs. DOJ only), and the role of materiality.
β Chart 3 β Mandatory vs. Permissive OIG Exclusion: Triggering conduct, length of exclusion, appeal rights, and consequences for an organization that employs or contracts with an excluded person.
β Chart 4 β EMTALA Screening vs. Stabilization vs. Transfer: What each duty requires, when the duty attaches, what counts as compliance, and the classic scenario in which each step fails.
Cornell Notes:
β Page 1 β Cue questions: What are the elements of a False Claims Act violation, what does "knowingly" mean under the FCA, and what does "materiality" add to the proof requirement? What is the qui tam procedure from filing through unsealing, and what relator-share percentages apply when the government intervenes versus declines?
β Page 2 β Cue questions: How do the Anti-Kickback Statute and the Stark Law differ in scope, intent, who they reach, and how they are excused (safe harbors vs. exceptions)? What is the 60-Day Rule for refund obligations, and how does it interact with the False Claims Act?
β Page 3 β Cue questions: What conduct triggers mandatory OIG exclusion versus permissive exclusion, and what is an organization's obligation when an employee, contractor, or vendor appears on the LEIE? What are the three EMTALA duties, what exception allows a transfer of an unstabilized patient, and what is the role of the beneficiary inducement rule alongside EMTALA's anti-dumping requirements?
Week 3 β Part III: Coding, Billing, and Reimbursement Compliance
Difficulty: Heavy, High Yield
What it covers:
Medicare Parts A, B, C, and D and the basic eligibility, services, and financing of each
The distinction between Medicaid State Plan coverage and Medicaid Managed Care, including the role of waivers
The purpose and scope of CPT, ICD-10-CM, ICD-10-PCS, and HCPCS Level II code sets
Documentation requirements that support billed services, including authentication, medical necessity, and code-claim linkage
The 2021 and 2023 E/M guideline changes and how MDM and total time drive office, hospital, ED, and other E/M code selection
Correct use of common modifiers and recognition of misuse patterns that drive audit and FCA risk
The Medicare medical necessity standard, including the role of LCDs, NCDs, and Advance Beneficiary Notices
Upcoding, unbundling, and duplicate billing risks; the 60-Day refund obligation; the audit functions of RAC, MAC, UPIC, and related contractors; and the rules governing provider-based billing and 340B participation
Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Lock in the Medicare structure before working on coding details. Part A is Hospital Insurance (inpatient, SNF, hospice, some home health), financed primarily through payroll taxes, with deductibles and coinsurance keyed to benefit periods. Part B is Medical Insurance (outpatient, physician, DME, preventive), financed through premiums and general revenue, with an annual deductible and 20 percent coinsurance after deductible. Part C (Medicare Advantage) is the managed-care alternative, with private plans paid on a capitated basis to deliver A and B benefits and usually D. Part D is outpatient prescription drug coverage delivered by PDPs and MA-PDs. Most CCB CHC questions on Medicare test which Part covers which service or which financing mechanism applies.
β Code sets and what they describe: CPT (AMA) for physician and outpatient procedures and services; ICD-10-CM for diagnoses across all settings; ICD-10-PCS for inpatient hospital procedures only; HCPCS Level II for products, supplies, and services not in CPT (drugs, DME, ambulance, orthotics). Know which code set drives which payment system: CPT/HCPCS drives Part B physician fee schedule and OPPS for outpatient hospital; ICD-10-CM plus ICD-10-PCS drives MS-DRG assignment under inpatient prospective payment.
β The 2021 and 2023 E/M guideline changes are exam-critical. Office and outpatient E/M (2021) and most other E/M categories (2023) eliminated history and exam as code-selection elements. Code selection is now driven by medical decision making (MDM) or total time on the date of the encounter. MDM has three elements: number and complexity of problems addressed, amount and complexity of data reviewed, and risk of complications or morbidity. Total time includes both face-to-face and non-face-to-face time on the date of service by the reporting physician or other qualified health professional. Know which categories the 2023 changes added (hospital inpatient and observation, consultations, ED, nursing facility, home or residence services, prolonged services).
β Medical necessity is a documentation-and-coverage question. Build a clean reference for the Medicare medical necessity standard, the role of National Coverage Determinations (NCDs) and Local Coverage Determinations (LCDs) from MACs, and the Advance Beneficiary Notice (ABN) workflow that shifts financial responsibility to the beneficiary when a Part B service is expected to be denied as not reasonable and necessary.
β Know the high-risk billing patterns the audit contractors look for: upcoding (selecting a higher-paying code than documentation supports), unbundling (billing component codes separately when a single bundled code applies, often a National Correct Coding Initiative (NCCI) edit violation), duplicate billing, billing for services not rendered, and provider-based billing errors when a department is improperly claimed as provider-based. The 60-Day Rule (Section 6402 of the Affordable Care Act) requires reporting and returning an identified overpayment within 60 days of identification; failure converts the retained overpayment into a False Claims Act liability.
β Audit-contractor landscape: MAC (Medicare Administrative Contractor) processes claims and conducts prepayment and postpayment review; RAC (Recovery Audit Contractor) conducts postpayment review of paid claims, paid on contingency; UPIC (Unified Program Integrity Contractor) investigates fraud across Medicare and Medicaid; ZPIC has been largely superseded by the UPICs. Know each contractor's scope and how a provider responds to a records request, demand letter, and appeal at each level.
β Complete the Practice Questions for Part III in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Coding, Billing, and Reimbursement Compliance. Main branches: Medicare Parts A, B, C, D β Medicaid State Plan vs. Managed Care β Code Sets (CPT, ICD-10-CM, ICD-10-PCS, HCPCS Level II) β Documentation Requirements (authentication, medical necessity, code-claim linkage) β 2021 and 2023 E/M Guideline Changes (MDM, total time) β Modifier Use and Misuse β Medical Necessity (NCD, LCD, ABN) β High-Risk Billing Patterns (upcoding, unbundling, duplicate billing) β 60-Day Refund Rule β Audit Contractors (MAC, RAC, UPIC) β Provider-Based Billing β 340B Drug Pricing Program.
Comparison Charts:
β Chart 1 β Medicare Part A vs. B vs. C vs. D: Services covered, eligibility, financing source, beneficiary cost-sharing structure, and one compliance risk unique to each Part.
β Chart 2 β CPT vs. ICD-10-CM vs. ICD-10-PCS vs. HCPCS Level II: Code-set owner, what it describes, where it is used (setting and payer), and which payment system it drives.
β Chart 3 β RAC vs. MAC vs. UPIC: Scope of authority, prepayment vs. postpayment review, payment model (fee vs. contingency), kinds of claims targeted, and the provider's response and appeal process for each.
β Chart 4 β Upcoding vs. Unbundling vs. Duplicate Billing: Definition, classic example, controlling rule or edit (NCCI for unbundling), audit trigger, and remediation step including the 60-Day refund obligation.
Cornell Notes:
β Page 1 β Cue questions: What services and financing distinguish Medicare Parts A, B, C, and D, and which Part covers a specific service in a clinical scenario? What is the difference between Medicaid State Plan coverage and Medicaid Managed Care, and what role do Section 1115 and 1915 waivers play?
β Page 2 β Cue questions: What are the three elements of Medical Decision Making under the 2021 and 2023 E/M guidelines, and how is total time selected as an alternative? What documentation must support each billed service to satisfy authentication, medical necessity, and code-claim linkage?
β Page 3 β Cue questions: What does the 60-Day Rule require once an overpayment is identified, and how does failure to report and return it create False Claims Act liability? What are the scopes of the MAC, RAC, and UPIC, and how does a provider respond to a records request and adverse determination at each appeal level?
Week 4 β Part IV: Privacy, Security, and Other Regulatory Compliance
Difficulty: Heavy, High Yield
What it covers:
Core provisions of the HIPAA Privacy Rule, including permitted uses and disclosures, the minimum necessary standard, and the Notice of Privacy Practices
The HIPAA Security Rule's administrative, physical, and technical safeguards for electronic Protected Health Information (ePHI)
HITECH Act changes to HIPAA, including direct liability for business associates and the Breach Notification Rule
Patient rights under HIPAA: access, amendment, accounting of disclosures, restrictions, and confidential communications
The interaction of HIPAA with state privacy laws and proper application of HIPAA preemption analysis
Special protections of 42 CFR Part 2 for substance use disorder records, including consent and redisclosure rules and the 2024 Final Rule
Information blocking under the 21st Century Cures Act and the eight exceptions that distinguish it from HIPAA privacy obligations
Baseline research compliance requirements (Common Rule, IRB review, informed consent, clinical research billing) and workforce-facing compliance touchpoints under OSHA Bloodborne Pathogens, ADA, and FMLA
Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β The HIPAA Privacy Rule and Security Rule serve different functions and are tested for that distinction. Privacy (45 C.F.R. Parts 160 and 164, Subparts A and E) governs who may use and disclose PHI and under what circumstances; it covers PHI in any form (electronic, paper, oral). Security (Subparts A and C) governs how electronic PHI must be protected through administrative, physical, and technical safeguards. Know the difference between required and addressable implementation specifications under the Security Rule. Addressable is not optional; the covered entity must implement it or document why an equivalent measure is reasonable and appropriate.
β Permitted uses and disclosures without authorization fall into well-defined buckets: treatment, payment, and healthcare operations (TPO); disclosures to the individual; uses required by law; public health activities; law enforcement under specific conditions; and others. The minimum necessary standard applies to most uses and disclosures but not to TPO between providers for treatment of the individual. Know what a Notice of Privacy Practices must contain and when it must be provided.
β The Breach Notification Rule is high-yield. A breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. There is a four-factor risk assessment that can demonstrate low probability of compromise. Encryption to NIST standards renders PHI not "unsecured" and removes the disclosure from the definition of a breach in most circumstances. Notice timelines: to affected individuals without unreasonable delay and no later than 60 days from discovery; to HHS within 60 days if 500 or more individuals, otherwise annually; to media if 500 or more in a state or jurisdiction.
β Patient rights under HIPAA: right of access to PHI in a designated record set (timely, in the form requested when readily producible, at a reasonable cost-based fee); right to amend; right to an accounting of disclosures (with TPO exceptions); right to request restrictions (covered entity must agree to restrict disclosure to a health plan for a service paid in full out of pocket); and right to confidential communications. The HITECH-era access rights and OCR's enforcement initiative on access have produced a wave of OCR resolutions; expect questions on access timelines and fee limits.
β 42 CFR Part 2 is the most heavily protected health-information regime in U.S. law and operates alongside HIPAA, not instead of it. Part 2 covers records from federally assisted SUD treatment programs. Historically it required patient consent for nearly every disclosure including TPO; the 2024 Final Rule aligns Part 2 more closely with HIPAA by permitting a single patient consent for TPO that remains in effect until revoked, while preserving heightened protections for use in legal proceedings. Know the redisclosure notice requirement and the prohibition on use in criminal proceedings without a court order.
β Information blocking under the 21st Century Cures Act prohibits actors (healthcare providers, health IT developers of certified health IT, health information exchanges, and health information networks) from interfering with the access, exchange, or use of electronic health information. There are eight exceptions, grouped as: not fulfilling requests (preventing harm, privacy, security, infeasibility, health IT performance) and procedures for fulfilling requests (content and manner, fees, licensing). HIPAA permits disclosure does not equal information blocking compliance; the two regimes overlap but are not identical.
β Complete the Practice Questions for Part IV in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Privacy, Security, and Other Regulatory Compliance. Main branches: HIPAA Privacy Rule (TPO, minimum necessary, NPP, patient rights) β HIPAA Security Rule (administrative, physical, technical safeguards; required vs. addressable) β HITECH and Business Associate Direct Liability β Breach Notification Rule (definition, four-factor analysis, timelines, encryption safe harbor) β HIPAA Preemption of State Law β 42 CFR Part 2 (SUD records, consent, redisclosure, 2024 Final Rule) β Information Blocking and the Eight Exceptions β Research Compliance (Common Rule, IRB, informed consent, clinical research billing) β Workforce-Facing Compliance (OSHA Bloodborne Pathogens, ADA, FMLA).
Comparison Charts:
β Chart 1 β HIPAA Privacy Rule vs. HIPAA Security Rule: What each protects, what forms of PHI it covers, the kinds of safeguards required, who it reaches (covered entities and business associates), and one classic violation example for each.
β Chart 2 β Required vs. Addressable Security Rule Implementation Specifications: What each label means, the documentation burden when an addressable specification is not implemented as written, and three examples of each.
β Chart 3 β HIPAA vs. 42 CFR Part 2: Scope and population covered, baseline consent rule, redisclosure obligations, use in legal proceedings, and how the 2024 Part 2 Final Rule changed the consent landscape.
β Chart 4 β HIPAA Breach Notification Timelines and Audiences: Who must be notified (individuals, HHS, media), when the obligation triggers, the difference between fewer-than-500 and 500-or-more incidents, and the encryption safe harbor.
Cornell Notes:
β Page 1 β Cue questions: What is the difference in function and scope between the HIPAA Privacy Rule and the HIPAA Security Rule, and what are the three categories of Security Rule safeguards? What are the four factors of the breach risk assessment, and how does encryption to NIST standards remove an incident from the breach definition?
β Page 2 β Cue questions: What patient rights does the HIPAA Privacy Rule grant, and what are the access timelines and fee limits enforced by OCR? When does a covered entity have to agree to a requested restriction on disclosure, and what triggers a confidential communications obligation?
β Page 3 β Cue questions: How does 42 CFR Part 2 differ from HIPAA for substance use disorder records, and what did the 2024 Final Rule change about TPO consent and redisclosure? What are the eight information-blocking exceptions, and why is "permitted under HIPAA" not the same as "not information blocking"?
Week 5 β Part V: Screening, Evaluation, and Internal Reporting Systems
Difficulty: Moderate
What it covers:
Sanction screening using the LEIE, SAM, and applicable state exclusion lists at hire and on an ongoing monthly basis
Definition of the screening population and the frequency required for a compliant exclusion screening program
Credentialing, privileging, and vendor due diligence touchpoints where compliance screening intersects medical staff and supply chain functions
Background check, fitness-for-duty, and ongoing workforce monitoring practices consistent with FCRA, ADA, EEOC, and state law constraints
Design of a confidential, well-publicized internal reporting hotline that supports anonymous reporting and aligns with OIG and FSG expectations
Non-retaliation protections and federal whistleblower statutes that protect reporters across healthcare contexts (FCA, SOX, Dodd-Frank)
An intake, triage, and case-routing process that handles allegations consistently, confidentially, and within defined service levels
Documentation and tracking of reports through a centralized case management system, with appropriate communication with reporters from intake through closure
Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Sanction screening obligations are practical and tested. The OIG expects screening against the LEIE at hire and at least monthly thereafter. The screening population includes all individuals and entities that furnish items or services payable by a federal healthcare program: employees, contractors, agents, vendors, locum tenens, and medical staff. SAM exclusions capture procurement and non-procurement debarments from many federal agencies and are commonly screened in parallel. State Medicaid exclusion lists must also be checked where the entity bills Medicaid, and many states require independent screening regardless of LEIE results.
β Background-check and pre-employment screening compliance is shaped by federal employment law, not just OIG guidance. FCRA governs use of consumer reports for employment, including the pre-adverse and adverse action notice sequence. Title VII and EEOC guidance constrain disqualifying use of arrest and conviction records (individualized assessment, business necessity). ADA restricts when medical examinations and disability-related inquiries may occur (post-offer, pre-employment; job-related and consistent with business necessity for incumbents). Several states have ban-the-box and salary-history restrictions. Compliance is the intersection of these regimes, not LEIE alone.
β Hotline design is testable. A compliant hotline must be well publicized, confidential, support anonymous reporting where state law permits, accept reports from multiple intake channels (phone, web, in person, email), operate 24/7, and route to a defined intake owner with documented service levels. The OIG, FSG, and DOJ ECCP all treat hotline activity (volume, anonymity rate, retaliation reports, time to closure) as a measure of program credibility. Anonymity protects the reporter; confidentiality is the organization's obligation regardless of whether the reporter chose anonymity.
β Non-retaliation is both a policy and a federal-law obligation. The FCA's anti-retaliation provision (31 U.S.C. Β§ 3730(h)) protects employees, contractors, and agents who engage in protected activity in furtherance of a qui tam action or other efforts to stop FCA violations. Sarbanes-Oxley and Dodd-Frank protect reporters of securities-law violations in publicly traded companies and certain affiliates. Many state false claims acts add their own protections. The compliance officer must be able to recognize a protected-activity claim and route it through the proper channels.
β Intake, triage, and case routing is the operational backbone of Part V. Know the standard flow: intake captures a complete record (allegation, parties, dates, attachments), triage assigns severity and category (FWA, HIPAA, EMTALA, HR, quality), routing assigns an investigator and tracks deadlines, communication with the reporter is maintained where possible, and the case is documented from intake through closure. Centralized case management software is the standard, and the OIG and DOJ both inspect case-management metrics during investigations.
β Complete the Practice Questions for Part V in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Screening, Evaluation, and Internal Reporting Systems. Main branches: Sanction Screening (LEIE, SAM, state exclusion lists, screening population, frequency) β Credentialing, Privileging, and Vendor Due Diligence β Background Check and Pre-Employment Screening (FCRA, ADA, EEOC, state law) β Ongoing Workforce Monitoring β Hotline Design (confidential, anonymous, multi-channel, well publicized) β Intake, Triage, and Case Routing β Non-Retaliation Policy β Federal Whistleblower Protections (FCA, SOX, Dodd-Frank) β Case Management Documentation.
Comparison Charts:
β Chart 1 β LEIE vs. SAM vs. State Exclusion Lists: Owning agency, scope of conduct covered, screening frequency, who must be screened, and consequences of employing an excluded individual against each list.
β Chart 2 β Anonymous Reporting vs. Confidential Reporting: Definition, what the organization can and cannot promise the reporter, how each is documented, and the operational trade-offs (investigation difficulty, retaliation protection, reporter trust).
β Chart 3 β FCA Β§ 3730(h) vs. Sarbanes-Oxley vs. Dodd-Frank Anti-Retaliation: Covered employers, protected activity, who can sue, remedies, and statute of limitations for each.
Cornell Notes:
β Page 1 β Cue questions: Who must be screened against the LEIE, how often, and what is the difference between LEIE, SAM, and a state exclusion list? What federal employment laws constrain pre-employment background checks, and how do FCRA, ADA, and EEOC requirements stack with state law?
β Page 2 β Cue questions: What are the design elements of an OIG- and FSG-compliant compliance hotline, and what is the difference between anonymity and confidentiality from the organization's perspective? What does the FCA's Β§ 3730(h) anti-retaliation provision protect, and how is a protected-activity allegation routed and documented inside a compliance program?
Week 6 β Part VI: Training, Communication, Auditing, and Monitoring
Difficulty: Moderate to Heavy
What it covers:
The distinction between general and role-based compliance training, and a training calendar that includes new-hire, annual, and specialized modules
Documentation of training completion in a way that supports audit, regulatory, and corrective-action review
Ongoing compliance communication, awareness campaigns, and reinforcement activities, with training effectiveness measured using multilevel evaluation
The operational distinction between auditing and monitoring and assignment of each to the appropriate owner
A risk-based compliance audit work plan with defined scope, methodology, owners, and timelines
Appropriate sampling methods (random, stratified, judgmental, probe) and the conditions under which statistical extrapolation is permissible
Execution of coding and billing audits, HIPAA privacy and security audits, and research compliance audits, including when an Independent Review Organization (IRO) is appropriate or required
Reporting of audit findings and corrective action plans, tracking through closure, and trend analysis that feeds the next risk assessment
Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Training is layered, not flat. General compliance training is required of every workforce member and covers the code of conduct, the hotline, non-retaliation, HIPAA, fraud and abuse, and the standards of conduct. Role-based training is tailored to specific compliance risks of a function: coders and billers, researchers, pharmacy, sales and marketing, IT, executive leadership. Specialized or high-risk role training is deep, function-specific training for functions with elevated FCA, AKS, Stark, privacy, or quality risk. The new-hire requirement is before substantive job duties begin wherever feasible, and annual refresh is the floor for most workforce members.
β Auditing versus monitoring is one of the most-tested distinctions in this Part. Auditing is a formal, independent, point-in-time review against an objective standard, performed by someone outside the function being reviewed, producing a written report and recommendations. Monitoring is ongoing operational oversight performed by the function itself or by compliance to detect issues in real time, often without a formal written report at each cycle. The OIG and DOJ both expect a healthcare compliance program to do both, with audit work prioritized by the annual risk assessment.
β Sampling methods are testable in their own right. Random sampling supports statistical extrapolation if the sample size and design meet statistical requirements. Stratified sampling divides the population into homogeneous subgroups and samples within each, improving precision when subgroup variation is high. Judgmental sampling targets known or suspected risk areas and does not support extrapolation. Probe samples are small, exploratory pulls used to size up a population before a full audit. Know when extrapolation is permissible (statistically valid random or stratified random sample, sustained error rate, OIG and CMS sustained-extrapolation rules).
β The audit work plan is the document that turns risk assessment into action. It identifies the audits the program will conduct this year, defines scope, methodology, sample size, owner, timeline, and reporting structure. Coding and billing audits remain the largest category in most provider settings; HIPAA privacy and security audits, research compliance audits, vendor and contract audits, and sanction screening audits round out a typical hospital or system plan.
β Independent Review Organizations come into play in two main contexts: (1) operating under a Corporate Integrity Agreement (CIA) where the IRO is required by the agreement to conduct claims reviews and arrangements reviews on a defined schedule, and (2) voluntarily, when the organization wants an independent third-party validation in a high-risk area. The IRO must meet OIG independence and objectivity standards.
β Reporting and follow-through closes the loop. Every audit produces findings, a corrective action plan with owners and deadlines, validation testing to confirm the corrective action worked, and trend analysis that feeds back into the next risk assessment. An audit with no documented corrective action and no follow-up testing is the single most common deficiency cited by the OIG.
β Complete the Practice Questions for Part VI in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Training, Communication, Auditing, and Monitoring. Main branches: Training Types (general, role-based, specialized/high-risk) β Training Calendar and Documentation β Effectiveness Measurement (multilevel evaluation) β Compliance Communication and Awareness β Auditing vs. Monitoring β Risk-Based Audit Work Plan β Sampling Methods (random, stratified, judgmental, probe) β Statistical Extrapolation Rules β Audit Categories (coding and billing, HIPAA, research, vendor, sanction screening) β Independent Review Organizations and CIAs β Audit Reporting, Corrective Action, and Trend Analysis.
Comparison Charts:
β Chart 1 β General vs. Role-Based vs. Specialized/High-Risk Training: Audience, content focus, frequency, documentation expectations, and example clinical or operational role for each tier.
β Chart 2 β Auditing vs. Monitoring: Who performs the activity, formality and independence required, output (report vs. operational record), cadence, and how each one is documented for an external regulator.
β Chart 3 β Random vs. Stratified vs. Judgmental vs. Probe Sampling: Sampling design, when used, whether it supports extrapolation, statistical precision, and a representative healthcare audit application for each.
Cornell Notes:
β Page 1 β Cue questions: What is the difference between general compliance training, role-based training, and specialized/high-risk role training, and what triggers a workforce member into each tier? How is training effectiveness measured beyond completion rates, and what is the documentation standard the OIG expects?
β Page 2 β Cue questions: What is the operational difference between auditing and monitoring, who owns each, and how does the audit work plan flow from the annual risk assessment? Which sampling method supports statistical extrapolation, and when must an organization engage an Independent Review Organization?
Week 7 β Part VII: Enforcement, Discipline, and Investigations
Difficulty: Heavy
What it covers:
Consistent discipline for non-compliance and design of a sanction grid that supports progressive discipline across the workforce
Planning and scoping a compliance investigation, including team composition, privilege strategy, and document preservation
Conducting an internal investigation using structured fact-gathering, witness and subject interviews, and defensible documentation
Issuing litigation holds and coordinating with legal counsel to protect attorney-client privilege and work product
Evaluation and execution of self-disclosure under the OIG Self-Disclosure Protocol (SDP), the CMS Self-Referral Disclosure Protocol (SRDP), and DOJ disclosure pathways
Operating under a Corporate Integrity Agreement (CIA), including IRO engagement, claims and arrangements reviews, and required reporting
Responding to government investigations (subpoenas, civil investigative demands, search warrants, inspector visits) with the right immediate steps
Implementing remedial measures, documenting lessons learned, and feeding outcomes into the next risk assessment and training cycle
Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Consistent discipline is a DOJ ECCP fundamental. The DOJ asks whether discipline is applied uniformly regardless of rank, tenure, or referral volume. A sanction grid maps categories of violations (HIPAA, billing, code of conduct, harassment, kickback exposure) to ranges of disciplinary outcomes (counseling, written warning, training, suspension, termination, exclusion-screening implications). The grid supports consistency and reduces the appearance of selective enforcement. Progressive discipline escalates with repetition or severity, with carve-outs for serious offenses warranting immediate termination.
β Investigations have a defined sequence and the CCB CHC tests it. Plan and scope: define the allegation, identify the legal theories implicated (FCA, AKS, Stark, HIPAA, EMTALA), assemble the team (compliance, legal, HR, IT, sometimes outside counsel), and decide privilege strategy. Preserve: issue a litigation hold to custodians, suspending normal document retention and deletion. Gather facts: collect documents and ESI before interviews so interviewers can challenge inconsistencies. Interview witnesses before subjects; provide Upjohn warnings when the interview is conducted by counsel to make clear the attorney represents the company, not the individual. Document: factual memos kept under privilege when prepared at the direction of counsel for the purpose of legal advice.
β Privilege is the most frequently mishandled topic in this Part. Attorney-client privilege protects communications between counsel and client made for the purpose of seeking or providing legal advice. Work product protects materials prepared in anticipation of litigation. Compliance reports prepared in the ordinary course of business are not privileged simply because they are sensitive. Routing investigations through counsel with a clear privilege purpose preserves the protection; circulating the same memo to operational leaders for business decisions can waive it.
β Self-disclosure protocols are exam-critical because each has a different forum, scope, and credit structure. The OIG Self-Disclosure Protocol (SDP) handles conduct that potentially violates federal fraud and abuse statutes (FCA, AKS, CMPL, exclusion violations) and produces resolution including reduced multiplier on damages and ordinary exclusion release in lieu of permissive exclusion. The CMS Self-Referral Disclosure Protocol (SRDP) is for actual or potential Stark Law violations only and is the only path for Stark-only self-disclosure; CMS retains broad settlement discretion. DOJ disclosure is appropriate when there is a likely FCA case, particularly when the conduct is broader than what the OIG SDP reaches; the recent DOJ Voluntary Self-Disclosure Policy offers structured benefits for timely, voluntary disclosure. Pick the right forum the first time; cross-protocol mistakes cost both credit and time.
β Corporate Integrity Agreements are the post-settlement compliance regime imposed by the OIG. A CIA typically runs five years, requires an Independent Review Organization, defined claims and arrangements reviews on a schedule, designated compliance officer and committee, training and reporting obligations to the OIG, and disclosure-of-events triggers. Breach of a CIA can lead to stipulated penalties or exclusion. The CIA is not optional once accepted.
β Government investigation response has a first-30-minutes playbook and the CCB CHC tests it. On receipt of a subpoena or civil investigative demand (CID), immediately notify counsel, identify the custodians and timeframe, issue a litigation hold, and begin a privileged review of responsive materials. On a search warrant or unannounced inspector visit, contact counsel immediately; verify identity and the scope of the warrant; do not obstruct, but do not consent to expansion of scope; treat the warrant inventory as the official record; instruct employees on their right not to speak without counsel present.
β Complete the Practice Questions for Part VII in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Enforcement, Discipline, and Investigations. Main branches: Sanction Grid and Progressive Discipline β Investigation Planning and Scoping β Litigation Holds and Document Preservation β Privilege Strategy (Attorney-Client, Work Product, Upjohn) β Witness and Subject Interviews β Self-Disclosure Pathways (OIG SDP, CMS SRDP, DOJ) β Corporate Integrity Agreements and IROs β Government Investigation Response (Subpoenas, CIDs, Search Warrants, Inspector Visits) β Remediation and Feedback to Risk Assessment and Training.
Comparison Charts:
β Chart 1 β Counseling vs. Written Warning vs. Suspension vs. Termination: Triggering conduct severity, documentation requirements, escalation criteria, exclusion-screening implications, and an example healthcare scenario for each.
β Chart 2 β OIG SDP vs. CMS SRDP vs. DOJ Voluntary Self-Disclosure: Scope of conduct each one handles, forum and decision-maker, typical resolution and credit structure, the role of damages multipliers and exclusion release, and the right-forum decision in a Stark-only versus FCA scenario.
β Chart 3 β Subpoena vs. Civil Investigative Demand vs. Search Warrant: Issuing authority, scope and target, response timeline, the organization's first three steps, and the limits of cooperation.
β Chart 4 β Attorney-Client Privilege vs. Work Product Doctrine: What each protects, when each attaches, who can waive, classic waiver pitfalls in a compliance investigation, and the role of Upjohn warnings in preserving privilege over employee interviews.
Cornell Notes:
β Page 1 β Cue questions: What is a sanction grid, and how does progressive discipline interact with the DOJ ECCP's consistency-of-discipline test? What is the proper sequence of an internal investigation from planning through closure, and at what point in that sequence does the litigation hold issue?
β Page 2 β Cue questions: Which self-disclosure protocol applies to a Stark-only violation, an FCA violation, and a kickback violation, and what credit or resolution structure does each offer? When is engaging outside counsel important to preserving privilege, and what is the function of an Upjohn warning in an employee interview?
β Page 3 β Cue questions: What are the operating components of a Corporate Integrity Agreement, and what role does the Independent Review Organization play across its term? What are the immediate response steps when a search warrant is executed at a facility, and how does the response differ for a civil investigative demand?
Week 8 β Part VIII: Emerging and Cross-Cutting Compliance Topics
Difficulty: Moderate
What it covers:
Telehealth compliance rules, including originating site, distant site, modality, state licensure, prescribing, and billing requirements
AI and algorithmic decision-making risks across coverage, clinical decision support, billing, and workforce decisions
Cybersecurity and ransomware response, including the OCR Recognized Security Practices and the HIPAA breach analysis
Conflict-of-interest disclosure programs and the Physician Payments Sunshine Act / Open Payments rules
Vendor and Group Purchasing Organization due diligence consistent with AKS safe harbors and 340B requirements
Compliance due diligence and integration in mergers, acquisitions, and divestitures, including successor liability under the FCA
Federal and state enforcement trends, including state Medicaid Fraud Control Units, state AG offices, and state-specific regulators
International and cross-border compliance considerations, including the FCPA, EU GDPR, and cross-border data transfer rules that affect U.S. healthcare organizations
Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages
Study Tasks
β Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.
β Highlight as you read. Follow the Made Easy Highlighting System
β Telehealth compliance breaks into five clean buckets and the CCB CHC will test you on the bucket, not just the service. Originating site (where the patient is, with post-PHE rules permitting the home for many services), distant site (where the clinician is), modality (audio-video versus audio-only and where each is permitted), state licensure (where the patient is at the time of service generally controls), and prescribing (the Ryan Haight Act and the DEA's evolving in-person evaluation rules for controlled substances). Billing requires correct place-of-service codes and modifiers and accurate documentation of modality and patient location.
β Conflict-of-interest and the Sunshine Act. The Physician Payments Sunshine Act / Open Payments requires applicable manufacturers and GPOs to report payments and transfers of value to covered recipients (physicians and teaching hospitals, with the 2021 expansion adding APRNs, PAs, CNSs, CRNAs, and CNMs to the covered-recipient definition). The reporting obligation is on the manufacturer, but providers should monitor their Open Payments record and resolve disputes. Know the categories of reportable payments (research, consulting, food and beverage, travel, education, gifts) and the small-payment thresholds that are adjusted annually.
β Cybersecurity has become a HIPAA Security Rule and breach-notification question. Recognized Security Practices (RSPs), formalized by Congress in the HITECH amendments in 2021, give HHS discretion to consider an entity's documented adoption of recognized practices (such as the NIST Cybersecurity Framework or HHS 405(d) Health Industry Cybersecurity Practices) as a mitigating factor in audits and penalty determinations. A ransomware incident on systems containing ePHI is presumed to be a HIPAA breach unless the four-factor analysis demonstrates low probability of compromise; encryption alone may not be sufficient if the threat actor obtained credentialed access.
β Vendor and Group Purchasing Organization (GPO) due diligence connects back to AKS and 340B. Vendor arrangements should be screened against the AKS safe harbors (personal services and management contracts, space and equipment rentals, GPO safe harbor with the administrative-fee disclosure rule), checked against the LEIE and SAM, and documented with written agreements that match the operational reality. 340B compliance requires accurate covered-entity status, eligible patient definition, GPO-prohibition rules for disproportionate share hospitals, duplicate-discount prohibition with Medicaid, and increasingly contentious contract-pharmacy arrangements.
β M&A compliance due diligence is its own discipline. Pre-close diligence covers billing-and-coding accuracy, AKS and Stark exposure in physician arrangements, HIPAA and 42 CFR Part 2 obligations, open investigations and CIAs, sanction-screening history, exclusion exposure, open self-disclosures, and historical settlement and CIA terms that may transfer to the acquirer. Successor liability is real under the FCA. Integration planning must align two compliance programs, codes of conduct, and risk assessments without leaving exposure gaps in the post-close period.
β Cross-border issues are the lowest-frequency but rising-trend section of this Part. The FCPA reaches U.S. healthcare manufacturers' interactions with foreign government officials, with state-owned hospital systems creating particular exposure. EU GDPR applies to processing of personal data of EU data subjects regardless of where the controller or processor is located, with significant penalty exposure. Cross-border health-data transfers from the EU to the U.S. operate under the EU-U.S. Data Privacy Framework (adequacy decision in effect since July 2023), with Standard Contractual Clauses as the secondary mechanism.
β Complete the Practice Questions for Part VIII in your quiz bank. Review every rationale, correct and incorrect.
How to Use Your Templates
β Mind Map: Central node = Emerging and Cross-Cutting Compliance Topics. Main branches: Telehealth (originating site, distant site, modality, state licensure, prescribing, billing) β AI and Algorithmic Decision-Making β Cybersecurity and Ransomware Response (OCR Recognized Security Practices, HIPAA breach analysis) β Conflict of Interest and the Sunshine Act / Open Payments β Vendor and GPO Due Diligence (AKS safe harbors, 340B) β M&A Compliance Due Diligence and Integration β Federal vs. State Enforcement Trends (MFCUs, state AGs) β International and Cross-Border Compliance (FCPA, EU GDPR, EU-U.S. Data Privacy Framework).
Comparison Charts:
β Chart 1 β Pre-PHE vs. Post-PHE Telehealth Rules: Originating-site geography, eligible practitioners, audio-only permissibility, controlled substance prescribing rules, and billing and modifier expectations.
β Chart 2 β Open Payments Reportable Categories: Research vs. consulting vs. food and beverage vs. travel vs. education vs. gifts, who reports, who is a covered recipient (including the 2021 expansion), and the small-payment threshold.
β Chart 3 β FCPA vs. EU GDPR: Jurisdictional reach, kind of conduct or data covered, enforcement authority, penalty exposure, and a representative U.S. healthcare organization scenario where each applies.
Cornell Notes:
β Page 1 β Cue questions: What are the five compliance buckets of a telehealth visit (originating site, distant site, modality, licensure, prescribing), and which state's licensure law generally controls? How does the post-PHE rule for the home as an originating site change billing and documentation?
β Page 2 β Cue questions: What does the OCR Recognized Security Practices provision do for an organization facing a HIPAA enforcement action, and how is a ransomware incident analyzed under the HIPAA Breach Notification Rule? Who is a covered recipient under Open Payments after the 2021 expansion, and what are the operational steps a provider should take to verify and dispute reported payments?
Week 9 β Full Review & Exam Simulation
Your final week is not about learning new material. It is about consolidating everything you have built and proving it under exam conditions.
Review Tasks
β Re-draw one Mind Map from memory for each Part you feel least confident about. Check it against your original.
β Work through your Cornell Notes cue columns for every Part. Cover the right-hand notes and answer from memory.
β Re-do any quiz bank questions you got wrong across all Parts. Focus on the rationales.
β Review the Common Mistakes, Rapid Review, and Self-Assessment Checklist sections for your two or three weakest Parts.
Exam Simulation
β Take the full-length CHC practice exam using the QR code in the back matter of this book. Complete it in one sitting, timed, as close to real exam conditions as possible.
β Review your emailed score report. Identify which Parts you missed most and spend your remaining time on those Parts' Rapid Review and clinical scenarios only.
You've worked the whole plan. Now prove it.
β
Take your free full-length practice test under real conditions and see exactly where you stand. βββββββ
Bonus Study Resources

Already included with your book. Make sure you're using all of it:
β
-
Quiz Bank: drill your recall with exam-style questions (access link on your landing page).
-
Study Guide: the full content breakdown, built into this book.
-
1 Full-Length Simulation Exam: your first timed, exam-day practice run.
-
Anki Flashcard Deck: digital flashcards for every key term, ready to import into Anki for spaced-repetition study.
-
Free Resource Hub: every book includes free access to your landing page, with the Practice Lab and study games, your study plan, and the links to launch your Quiz Bank and simulation exam.β
Close every gap. Get the Complete Bundle.β
ββCheat Sheets, Workbook, and 3 more Full-Length Simulation Exams, together in one bundle.βββββ
β
Cheat Sheets
The entire exam condensed into high-yield sheets for fast review in the final days.

