Skip to content
CPCSTUDY COURSEMy progress

Stage 10 · Compliance and reimbursement

HIPAA, fraud, abuse and professional judgment

Protect patient information and recognize when a coding or business practice needs compliance review.

2026 edition · 9 minute read · Bring your code books

Where you are

Accurate coding depends on more than knowing the right entry. A coder must protect the information used to make the decision, refuse unsupported reporting and recognize concerns that need review. This lesson gives you a practical way to identify those concerns without pretending that a short chart exercise can decide a legal case.

The core habit is simple: state what the record supports, state what remains uncertain and use the appropriate reporting channel. Do not hide an error, invent evidence or collect patient records for personal study.

Know what PHI includes

Protected health information, or PHI, includes individually identifiable health information held or transmitted by a covered entity or its business associate. It can concern health conditions, care or payment for care. It can exist on paper, in an electronic system or in a spoken conversation. Privacy does not stop at the edge of the electronic record. [hhs-privacy-summary, What Information is Protected]

A name is an obvious identifier, but it is not the only way to identify a person. Removing the name from a distinctive story does not automatically make the remaining information de-identified. HHS describes defined de-identification methods, not a general “delete the name” shortcut. [hhs-privacy-summary, What Information is Protected]

For this course, use only the supplied fictional charts or examples you invent without copying a real patient. Do not paste an employer's chart into a study field, search query, personal note system or public discussion. The course has no reason to receive a patient's information.

Understand the covered relationship

The Privacy Rule applies to health plans, clearinghouses and health care providers that conduct the specified electronic transactions. A billing service or other outside organization handling PHI for a covered entity may be a business associate. A contractor's access is governed by the applicable relationship and safeguards; working remotely does not remove those responsibilities. [hhs-privacy-summary, Who is Covered,Business Associates]

A business associate agreement is not permission to use information for any purpose. The agreement cannot authorize uses that would violate the rule. A coder still needs an authorized job purpose and the organization's approved handling process. [hhs-privacy-summary, Business Associates]

Apply minimum necessary to the purpose

The minimum necessary standard generally requires reasonable steps to limit PHI use, disclosure and requests to what the purpose needs. The organization's policies identify which roles need access, which information they need and under what conditions. That is more precise than saying every employee can read every chart. [hhs-minimum]

There are exceptions. Disclosures to, or requests by, a health care provider for treatment are among them. That exception does not give a coder permission to browse a neighbor's record or use a patient's history for personal curiosity. The purpose of the access still matters. [hhs-minimum]

Original fictional example: a coder needs documentation supporting a billed procedure. The approved workflow grants access to the relevant record. The coder does not also need to search unrelated records because the patient's surname is familiar. Technical access and authorized purpose are different facts.

Handle information through the approved process

Before sending a record, identify the recipient, purpose and approved channel. Follow the organization's rules for access, transmission and retention. If a request is unusual or broader than expected, seek the designated privacy review rather than improvising an exception.

If information reaches the wrong recipient, report the incident promptly through the organization's process. Preserve the relevant facts and follow instructions for containment. Do not conceal the event or assume that deleting your own copy proves the disclosure has been reversed. A privacy review needs accurate facts about what happened.

These are practical safeguards for the learner's work. They do not replace an employer's privacy training or a formal determination of whether a particular incident requires notification.

CMS describes fraud and abuse using facts, circumstances, intent and knowledge. An incorrect claim needs correction and review, but a beginner should not label every mistake criminal fraud. Equally, calling a repeated unsupported practice an “error” does not make it harmless. [fraud-cms-2026, pp5–7]

Upcoding means reporting a higher level or more expensive service than the actual work supports. Unbundling can involve reporting separately what belongs within a comprehensive service. Billing for services that did not occur is another concern. A supervisor's request or a software default does not supply missing clinical evidence. [fraud-cms-2026, pp5,14–15]

Original fictional example: a template proposes the highest visit level for every encounter. The coder should assess the documented service and applicable level requirements. Repeatedly accepting the template without checking does not become correct simply because the system allows it.

The civil False Claims Act includes reckless disregard

The civil False Claims Act addresses knowingly false or fraudulent claims submitted, or caused to be submitted, to the federal government. “Knowing” includes actual knowledge, deliberate ignorance and reckless disregard. Specific intent to defraud is not required for civil FCA liability. [fraud-cms-2026, p7; oig-laws, False Claims Act]

This distinction matters when someone says, “I never asked whether the claims were supported.” Deliberately avoiding the answer is not a dependable defense. The coder's practical response is to identify the unsupported facts and bring the concern to the appropriate compliance reviewer.

Do not memorize an old dollar penalty from a web page. Penalty rules and amounts can change, and the legal result depends on the violation. Learn the prohibited conduct and the need for qualified review.

Kickbacks concern things of value, not only cash

The Anti-Kickback Statute addresses knowing and willful offers, payments, requests or receipts of remuneration to induce or reward business involving services or items payable by federal health care programs. Remuneration can include things of value other than money, such as favorable rent or excessive compensation. [fraud-cms-2026, p8]

A referral arrangement therefore cannot be cleared merely by saying no envelope of cash changed hands. Safe harbors have specific requirements. A beginner should recognize the referral-and-value relationship and refer the arrangement for proper review, not announce that every business relationship is unlawful or that a single favorable fact makes it safe. [fraud-cms-2026, p8]

Stark has a different structure

The physician self-referral law, commonly called Stark, concerns physician referrals for specified designated health services payable by Medicare when the physician or an immediate family member has a financial relationship with the entity, unless an applicable exception is satisfied. It also restricts billing for improperly referred services. [fraud-cms-2026, pp8–9]

Stark is a strict-liability statute; a lack of intent to violate it does not settle the issue. Do not collapse it into the Anti-Kickback Statute's intent framework. Identify the referral, designated service, financial relationship and possible exception for the qualified reviewer. [fraud-cms-2026, p8]

Exclusions and civil penalties affect the workflow

OIG can exclude people or entities from federal health care programs under mandatory or permissive authorities. The effect is broader than whether the excluded person's name appears as the billing provider. Services provided, ordered or prescribed by an excluded person can raise payment concerns, with specific rules and exceptions. [fraud-cms-2026, pp10–12]

Reinstatement is not automatic when an exclusion period ends. OIG must authorize it. Follow the organization's screening process and refer a possible match for proper identification and review. A similar name alone is not enough to decide that the person is excluded. [fraud-cms-2026, p12]

The Civil Monetary Penalties Law provides another enforcement mechanism for specified violations, including certain false claims and excluded-person arrangements. It is distinct from deciding whether conduct meets the elements of a criminal offense. [fraud-cms-2026, p13]

Write a factual escalation

A useful report states the claim or workflow involved, the documented facts, the questionable action and the relevant rule. Separate what you observed from what you suspect. Use authorized channels and include only the information the review requires.

CMS identifies OIG, Medicare contractors and state Medicaid agencies among the appropriate reporting routes for different situations. Use the current official reporting instructions when an external report is appropriate. This course does not send reports or collect allegations. [fraud-cms-2026, pp23–24]

Book drill

Choose a completed procedure from a prior lesson and locate its full entry and family instructions in your licensed book. Imagine a draft claim also reports a component the applicable instruction includes. Write the factual coding concern and the source location you would give a reviewer. Keep the coding conclusion separate from any legal conclusion about intent.

Then locate the civil FCA knowledge standard in the CMS booklet. Explain why deliberately avoiding a repeated documentation problem differs from recognizing an isolated error and following the correction process. Use no real patient or employee information in your notes.

Checkpoint

Explain why treatment-related information sharing does not authorize personal chart browsing. Distinguish civil FCA knowledge, AKS remuneration and Stark's financial-referral relationship. Describe a factual response to a repeated unsupported coding instruction.

Protect the record and explain the concern

Use information for the authorized purpose through the approved process. Code what the record supports. Identify the facts and the specific uncertainty, preserve evidence appropriately and bring the concern to a qualified reviewer. Neither a software default nor a supervisor's preference changes the documented service.

Sources

  1. HHS OCR — Summary of the HIPAA Privacy Rule. 2026. Accessed 2026-09-12.
  2. HHS OCR — Minimum Necessary Requirement. 2026. Accessed 2026-09-12.
  3. CMS — Medicare Fraud and Abuse: Prevent, Detect, Report — April2026. 2026. Accessed 2026-09-12.
  4. HHS OIG — Fraud and Abuse Laws. 2026. Accessed 2026-09-12.