Cheat sheet

CHC Certified in Healthcare Compliance Cheat Sheet

Standards, Policies, and Procedures

11%of exam

Compliance Program Administration

19%of exam

Screening and Evaluation

6%of exam

Communication, Education, and Training

14%of exam

Monitoring, Auditing, and Internal Reporting Systems

22%of exam

Discipline for Non-compliance

8%of exam

Discipline LeversDiscipline vs IncentivesConsistencyRegulatory reporting

Investigations and Remedial Measures

20%of exam

Quick Facts

Exam
CHC
Owner
CCB / HCCA
Items
120 total, 100 scored
Time
2 hours
Pass mark
Angoff cut score
Delivery
PSI center, remote, paper
Fee
$350 member / $450 non-member
Valid
2 years
Exam CEUs
20 total, 10 live
Renewal CEUs
40 total, 20 live
Domains
7 content areas
Blueprint
2025 CCB handbook

Seven Elements

Policies, Leaders, Training, Lines, Consequences, Risk, Response

Policies: codeLeaders: officer and boardTraining: general plus riskLines: hotlineConsequences: discipline plus incentivesRisk: assess, audit, monitorResponse: correct and disclose

AKS vs Stark Law

AKS

  • Intent required
  • Criminal statute
  • Safe harbors voluntary
  • Federal program business

Stark law

  • Strict liability
  • Civil statute
  • Exceptions mandatory
  • Medicare designated services

Intent versus strict liability

Law Picker

  1. Payment for referralsAnti-kickback statute(Intent needed)
  2. Physician refers designated servicesStark law(Strict liability)
  3. False or upcoded claimFalse Claims Act(Treble damages)
  4. OIG administrative penaltyCivil Monetary Penalties Law(Heard by ALJ)
  5. Kept identified overpayment60-day repayment rule
  6. Gift steering beneficiary choiceBeneficiary Inducements CMP
  7. Unauthorized PHI disclosureHIPAA breach rules
  8. Emergency patient turned awayEMTALA(Patient dumping)

Seven Elements

Element 1
Written policies and procedures
Element 2
Compliance leadership and oversight
Element 3
Training and education
Element 4
Communication and disclosure programs
Element 5
Consequences and incentives
Element 6
Risk assessment, auditing, monitoring
Element 7
Respond and correctOIG

Intent Test

AKS intent; Stark strict; FCA knowing

AKS: knowing and willfulStark: no intent neededFCA: reckless disregard counts

False Claims Act vs CMPL

False Claims Act

  • DOJ in court
  • Treble damages
  • Whistleblower suits allowed

CMPL

  • OIG administrative case
  • Penalties and assessments
  • Exclusion authority

Court case versus administrative

Code of Conduct

Code of conduct
Values and expected behavior
Policies
Specific operational compliance rules
Non-retaliation
Protects good-faith reporters
Accountability
Expected at all levels
Distribution
Reaches all workforce members

Fraud and Abuse Laws

AKS
Remuneration for referralsCriminal
Stark law
Physician self-referral banStrict
False Claims Act
False claims for paymentCivil
CMPL
OIG administrative penalties
Exclusion
Barred from federal programs
60-day rule
Report and return overpayments
HIPAA
Privacy and security rules
EMTALA
Emergency screening and stabilization
Beneficiary Inducements CMP
Remuneration influencing beneficiary choice

Policy Lifecycle

Draft
Address identified compliance risk
Review
Legal and subject experts
Approve
Authorized owner signs off
Communicate
Train affected workforce groups
Refresh
Annual policy review recommended

Officer vs Committee

Compliance officer

  • Day-to-day operations
  • Direct board access
  • Independent and objective

Compliance committee

  • Advises the officer
  • Cross-functional membership
  • Approves work plan

One owner versus group

Program Roles

Compliance officer
Day-to-day program operation
Compliance committee
Advises and supports officer
Governing body
Oversight and accountability
CEO and leadership
Resources and tone
Internal audit
Independent testing partner
Legal counsel
Privilege and legal advice
Risk partners
Quality, privacy, HR

Board Oversight

Reporting line
Direct access to board
Frequency
Regular compliance program reports
Independence
Officer free of conflicts
Resources
Board funds the program
Effectiveness review
Board directs the review

OIG Guidance Documents

GCPG
General compliance program guidance
ICPG
Industry-segment compliance guidance
Work Plan
OIG audit and enforcement priorities
Advisory opinion
Binds OIG and requestor
Special fraud alert
Flags suspect arrangements
CIA
Settlement obligations with IRO reviews
Effectiveness toolkit
Measuring compliance program effectiveness

LEIE vs SAM

LEIE

  • OIG healthcare exclusions
  • Blocks program payment
  • Updated monthly

SAM

  • Government-wide debarment
  • Blocks federal contracts
  • Procurement focused

Health programs versus contracts

Screening Picker

  1. Federal health program exclusionLEIE(Check monthly)
  2. Federal contract debarmentSAM.gov
  3. State Medicaid exclusionState exclusion list
  4. Clinical license statusState licensing board
  5. New vendor or acquisitionDue diligence review

Exclusion Lists

LEIE
OIG excluded individuals list
SAM
Federal procurement exclusion records
State Medicaid lists
State-level exclusion checks
Screening frequency
Monthly matches LEIE updates
Mandatory exclusion
Program crimes, patient abuse
Permissive exclusion
OIG discretion, license loss

Due Diligence

Job descriptions
Include compliance responsibilities
Performance reviews
Rate compliance behavior
Exit interviews
Ask compliance-related questions
Third parties
Vendors, consultants, acquisitions
Conflicts of interest
Identify, disclose, and manage

Anonymous vs Confidential

Anonymous

  • Identity not collected
  • No follow-up contact
  • Harder to investigate

Confidential

  • Identity known internally
  • Shared on need
  • Follow-up possible

Unknown versus protected identity

Training Types

General training
All workforce and board
Risk-specific training
Targeted high-risk groups
New hire
Onboarding compliance orientation
Refresher
Periodic repeat training
Attendance records
Track and document completion
Effectiveness check
Test understanding, not attendance

Reporting Channels

Hotline
Always-available reporting line
Open door
Supervisor or compliance officer
Web form
Written intake channel
Anonymity
Identity never collected
Confidentiality
Identity known, sharing limited
Non-retaliation
Monitor reporters after reports

Risk To Plan

Assess, Rank, Plan, Audit, Fix, Recheck

Assess risks annuallyRank by exposurePlan the auditsAudit with evidenceFix and retest

Monitor vs Audit

Monitoring

  • Ongoing and routine
  • Done by management
  • Early warning

Auditing

  • Periodic and formal
  • Independent reviewer
  • Evidence-based conclusion

Continuous versus independent

Audit Picker

  1. Known risk, ongoingMonitoring(Management performs)
  2. Need independent assuranceAuditing(Objective reviewer)
  3. Settlement requires reviewIndependent review organization
  4. Claim payment accuracyClaims audit(Add clinical review)
  5. Program health checkEffectiveness review(Board directs)

Risk Assessment

Risk inventory
List compliance risk areas
Scoring
Likelihood and impact
Sources
OIG Work Plan, hotline, audits
Prioritize
Rank highest exposure first
Work plan
Audits chosen from risks
Cadence
Assess at least annually

Audit Methods

Monitoring
Ongoing internal checks
Auditing
Formal independent review
Sampling
Method fits the circumstances
Medical necessity
Clinician reviews claim audits
External audits
Evaluate outside audit results
Trending
Track, trend, benchmark results
Corrective action tracking
Monitor management implementation
Feedback
Report results to management

Discipline vs Incentives

Discipline

  • Consequences for violations
  • Consistent across levels
  • Documented decisions

Incentives

  • Rewards compliant behavior
  • Built into evaluations
  • Reinforces culture

Punish versus promote

Discipline Levers

Consistency
Same rules across levels
Timeliness
Act without unnecessary delay
Proportionality
Match severity to conduct
Documentation
Record decision and rationale
Incentives
Reward compliant behavior
Regulatory reporting
Report when law requires

Investigation Flow

Stop, Preserve, Investigate, Correct, Repay, Report

Stop ongoing harmPreserve documentsInvestigate objectivelyCorrect root causeRepay overpaymentsReport when required

OIG SDP vs CMS SRDP

OIG SDP

  • AKS or false claims
  • Minimum 1.5x damages
  • Settlement floors apply

CMS SRDP

  • Stark-only arrangements
  • CMS may reduce amount
  • No OIG settlement

Kickbacks versus self-referral

Incident Picker

  1. Ongoing patient harmStop activity immediately
  2. Possible criminal conductNotify counsel first
  3. Kickback arrangement foundOIG SDP(AKS matters)
  4. Stark-only arrangementCMS SRDP(No AKS exposure)
  5. Simple billing overpaymentRefund the payer(60-day clock)
  6. PHI breach confirmedNotify individuals(Within 60 days)
  7. Government subpoena arrivesPreserve all records
  8. Reporter fears retaliationMonitor and protect

Investigation Steps

Intake
Log and acknowledge report
Triage
Assess severity and scope
Stop harm
Halt ongoing noncompliance
Preserve
Hold documents and data
Privilege
Coordinate with legal counsel
Interview
Fair, objective, discreet
Root cause
Find why it happened
Corrective action
Fix process, prevent recurrence

Disclosure Clock

60 days repay; 60 days breach notice

Overpayment: 60 daysBreach notice: 60 daysSDP submission suspends repayment

Disclosure Routes

OIG SDP
Self-disclose potential fraud
CMS SRDP
Stark-only self-referral matters
Payer refund
Return identified overpayments
OCR breach report
HIPAA breach notification
DOJ
Criminal conduct referrals
State Medicaid unit
Medicaid fraud referrals
60-day clock
Return after identifying overpayment

Common Traps

Intent vs strict liability

AKS needs intent Stark is strict

Safe harbor vs exception

Safe harbors voluntary Stark exceptions mandatory

Monitor vs audit

Monitoring is ongoing Auditing is independent

Anonymous vs confidential

Anonymous hides identity Confidential limits sharing

Exclusion vs debarment

LEIE blocks program payment SAM blocks federal contracts

OIG vs CMS disclosure

Kickbacks go to OIG Stark-only goes to CMS

Report vs repay

Reporting notifies government Repaying returns money

Attendance vs understanding

Tracking proves attendance Testing proves understanding

Last Minute

  1. 1.Exam has 120 items, 100 scored
  2. 2.Time limit is two hours
  3. 3.Passing score set by Angoff
  4. 4.Heaviest domain: Monitoring and Auditing
  5. 5.Lightest domain: Screening and Evaluation
  6. 6.AKS needs intent; Stark is strict
  7. 7.Repay identified overpayments within 60 days
  8. 8.Kickback disclosures go to OIG
  9. 9.Stark-only disclosures go to CMS
  10. 10.Screen LEIE and SAM monthly
  11. 11.Stop ongoing harm before investigating
  12. 12.Discipline must be consistent everywhere
  13. 13.Certification renews every two years
  14. 14.Renewal needs 40 CEUs, 20 live
Same family resources

Explore More CCB Healthcare Compliance Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.