RHIA Exam Tips: Compliance
Compliance is one of the most heavily tested domains on the RHIA certification exam. This content area covers the legal, regulatory, and ethical frameworks that govern health information management. Because compliance touches every aspect of healthcare operations, expect to see these concepts woven into questions across multiple domains. A thorough understanding of compliance is essential for passing the exam.
High-Yield Topics You Must Know
The following compliance topics have the highest likelihood of appearing on the RHIA exam. Prioritize these in your study plan:
- HIPAA Privacy Rule - Know the core provisions including the minimum necessary standard, patient rights (access, amendment, accounting of disclosures), permitted uses and disclosures, and the role of the Notice of Privacy Practices. Understand the difference between required and permitted disclosures.
- HIPAA Security Rule - Be able to categorize safeguards as administrative, physical, or technical. Know the difference between required and addressable implementation specifications. Understand risk analysis as the foundation of the security program.
- HITECH Act - Know how HITECH expanded HIPAA enforcement, extended breach notification requirements, and increased penalties. Understand the meaningful use (now Promoting Interoperability) connection.
- Fraud and abuse laws - Distinguish between the False Claims Act, Anti-Kickback Statute, and Stark Law. Know what each prohibits and the key differences in their scope and penalties.
- Release of information (ROI) processes - Understand valid authorization requirements, exceptions to authorization, and the specific rules for sensitive information categories like substance abuse treatment records (42 CFR Part 2), psychotherapy notes, and HIV/AIDS information.
Breach Notification Requirements
Breach notification is a high-priority exam topic. Make sure you know the following notification timeline and thresholds:
- Individual notification - Required without unreasonable delay and no later than 60 days after discovery of the breach.
- HHS notification - For breaches affecting 500 or more individuals, notify HHS simultaneously with individual notification. For breaches affecting fewer than 500 individuals, maintain a log and report annually.
- Media notification - Required for breaches affecting 500 or more residents of a state or jurisdiction. Must be provided to prominent media outlets serving that area.
- Business associate obligations - Business associates must notify the covered entity of a breach no later than 60 days after discovery (or sooner if specified in the business associate agreement).
Remember that a breach is presumed unless the covered entity can demonstrate through a risk assessment that there is a low probability the information was compromised. The four-factor risk assessment evaluates: the nature and extent of PHI involved, the unauthorized person who used or received the PHI, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
Common Traps and Pitfalls
Compliance questions on the RHIA exam are designed to test nuanced understanding. Avoid these common mistakes:
- Confusing "required" with "permitted" disclosures. HIPAA requires disclosure in only two situations: to the individual upon request and to HHS during a compliance investigation. All other disclosures are permitted but not required. This distinction appears frequently on the exam.
- Forgetting the minimum necessary standard exceptions. The minimum necessary standard does not apply to disclosures to the individual, disclosures pursuant to an authorization, disclosures to HHS for enforcement, disclosures required by law, and treatment purposes. Many exam questions test whether you know these exceptions.
- Mixing up Stark Law and the Anti-Kickback Statute. Stark Law is a strict liability statute (no intent required) that applies only to physician self-referrals for designated health services. The Anti-Kickback Statute requires intent (knowing and willful) and applies broadly to anyone who offers or receives remuneration for referrals. The exam expects you to distinguish between these two laws.
- Applying state law incorrectly. When state and federal privacy laws conflict, the more stringent law prevails (the preemption analysis). If state law provides greater privacy protections than HIPAA, state law applies. Do not assume federal law always takes precedence.
Test-Taking Strategies for Compliance Questions
Use these approaches to navigate compliance questions effectively:
- Identify the specific law or regulation being tested. Before evaluating answer choices, determine which regulation the question is targeting. A question about a physician referring patients to a lab they own is testing Stark Law. A question about a vendor paying a hospital for referrals is testing the Anti-Kickback Statute.
- Default to patient rights. When in doubt on privacy-related questions, the answer that best protects patient rights and autonomy is usually correct. HIPAA was designed to give patients control over their health information.
- Follow the authorization checklist. For questions about whether a valid authorization exists, mentally verify: Does it contain the required core elements (description of information, persons authorized to disclose and receive, purpose, expiration, signature, date)? Is it for a use that requires authorization rather than being covered by another provision?
- Think "risk analysis first." Many compliance questions about security measures have "conduct a risk analysis" as an answer choice. If the scenario describes an organization that has not yet assessed its risks, the risk analysis is almost always the correct first step.
Special Categories of Protected Information
The RHIA exam tests your knowledge of information categories that receive additional legal protections beyond standard HIPAA requirements:
- Substance abuse treatment records (42 CFR Part 2) - These records have stricter consent requirements than HIPAA and cannot be redisclosed without specific patient consent. A general HIPAA authorization is not sufficient.
- Psychotherapy notes - Maintained separately from the medical record. Require specific patient authorization for most uses and disclosures, even for treatment, payment, or healthcare operations.
- Genetic information - Protected under GINA (Genetic Information Nondiscrimination Act) in addition to HIPAA. Know the employment and insurance discrimination protections.
Final Review Checklist
Ensure you are prepared by reviewing these compliance essentials before exam day:
- HIPAA Privacy and Security Rule provisions and their specific requirements
- Breach notification procedures, timelines, and thresholds
- Valid authorization elements and exceptions to authorization requirements
- Fraud and abuse laws and their distinct applications
- State preemption analysis and when state law overrides federal law
- Special protections for sensitive health information categories
- Compliance program structure, including the seven elements of an effective compliance program