Table of Contents
- Medicare Parts A, B, C, and D
- Medical Necessity, NCDs, and LCDs
- ABNs and the G Modifiers
- RBRVS and RVUs: How Physician Payment Works
- Fraud vs Abuse and the Big Three Laws
- HIPAA Essentials for Coders
- The OIG, Audits, and Compliance Programs
- Worked Example: One Denied Service, Four Outcomes
- How the CPC Exam Tests Compliance and Regulatory Topics
- Common Mistakes
- Final Exam Strategy for This Section
- Frequently Asked Questions
Ask CPC candidates what surprised them most on exam day and the same answer repeats: the compliance questions. Study plans built entirely around CPT and ICD-10 leave the regulatory material — Medicare structure, ABNs, medical necessity policy, payment methodology, fraud and abuse law, HIPAA — for a skim that never happens, and the exam bills those topics anyway, typically five to ten questions’ worth. The material is pure memorization with no code books to lean on, which cuts both ways: nothing to look up, but nothing you can’t lock down in advance. This guide consolidates every compliance concept the exam draws from into one place, complementing the exam-navigation frameworks in the CPC Exam Study Guide and CPC Exam Day Strategy.
Medicare Parts A, B, C, and D
Medicare is the federal health insurance program for people 65 and older, certain younger people with disabilities, and people with end-stage renal disease, and its four parts are a guaranteed exam item. Part A covers inpatient hospital care, skilled nursing facility stays, hospice, and home health — the institutional side. Part B covers physician services, outpatient care, durable medical equipment, and many preventive services — the professional side, and the part most relevant to CPC-level coding. Part C, Medicare Advantage, is the managed-care alternative: private plans contracted to deliver Parts A and B (and usually D) benefits. Part D is the prescription drug benefit, run through private plans. Medicaid, by contrast, is the joint federal-state program for low-income individuals, administered by states within federal rules — and the exam expects you to keep the two programs’ identities straight. Claims administration for traditional Medicare runs through Medicare Administrative Contractors (MACs), the regional contractors who process Part A and B claims and publish local policy.
Medical Necessity, NCDs, and LCDs
Medicare pays only for services that are reasonable and necessary — the medical necessity standard — and two document types define what qualifies. National Coverage Determinations (NCDs) are issued by CMS and bind the entire country: when an NCD addresses a service, every MAC follows it. Local Coverage Determinations (LCDs) are issued by individual MACs for their own jurisdictions, covering services no NCD addresses; they commonly specify the diagnoses that support a service, which is why real-world claims and exam questions alike hinge on linking the correct ICD-10-CM code to the procedure per ICD-10-CM Coding Guidelines. The hierarchy is the testable fact: national policy overrides local, and local policy fills national silence.
ABNs and the G Modifiers
The Advance Beneficiary Notice of Noncoverage (ABN) is the written notice a provider gives a fee-for-service Medicare beneficiary before furnishing a service Medicare is expected to deny as not reasonable and necessary. Delivered properly — before the service, with the reason and estimated cost — it shifts financial liability to the beneficiary, who chooses whether to receive and pay for the service. Delivered late or not at all, the provider absorbs the denial. Four HCPCS modifiers report the notice status, and the exam tests them as a set.
| Modifier | Meaning | Effect |
|---|---|---|
| GA | ABN on file for a service expected to be denied as not reasonable and necessary | Beneficiary liable if denied |
| GX | Voluntary notice issued for a statutorily excluded service | Informational; patient always liable for excluded services |
| GY | Service statutorily excluded from Medicare benefits | Automatic denial; patient liable, no ABN required |
| GZ | Service expected to be denied, no ABN obtained | Provider liable; claim denied and written off |
The conceptual split behind the grid: ABNs apply to services Medicare covers but may find unnecessary in a specific case (GA/GZ), while statutorily excluded services — never a Medicare benefit — need no ABN at all (GY, with GX for the courtesy notice). These modifiers extend the HCPCS modifier vocabulary from the HCPCS Level II Coding Guide.
RBRVS and RVUs: How Physician Payment Works
Medicare pays physicians under the Resource-Based Relative Value Scale (RBRVS), and its arithmetic is exam material. Every CPT code carries relative value units (RVUs) in three components: physician work (the skill, time, and intensity of the service), practice expense (staff, equipment, overhead), and malpractice expense (professional liability cost). Each component is adjusted by a geographic practice cost index (GPCI) for the locality, summed, and multiplied by the annual conversion factor — the dollar amount that turns RVUs into payment. Two downstream facts recur on the exam: the multiple-procedure payment reduction implemented through modifier 51, as covered in Modifier 59 vs X Modifiers, and the global-period concept that folds pre- and post-operative work into surgical payment per Global Surgical Package — both are RBRVS machinery, not just coding conventions.
Fraud vs Abuse and the Big Three Laws
The exam’s compliance vocabulary starts with the fraud/abuse distinction. Fraud is intentional deception designed to obtain unauthorized benefit — billing for services never rendered, deliberate upcoding, falsifying records. Abuse is practice inconsistent with accepted standards that results in unnecessary cost, without proven intent — patterns of unnecessary services, systematic coding errors. Intent is the dividing line, and it drives which enforcement tools apply.
Three statutes anchor the enforcement landscape. The False Claims Act imposes liability for knowingly submitting false claims to the government, carries per-claim penalties plus treble damages, and includes qui tam provisions allowing whistleblowers to sue on the government’s behalf and share in recoveries — the reason internal reporting channels matter. The Anti-Kickback Statute is a criminal law prohibiting knowing remuneration — anything of value — to induce or reward referrals of federal health care program business, with regulatory safe harbors protecting defined arrangements. The Stark Law (physician self-referral) is a civil statute prohibiting physicians from referring Medicare patients for designated health services to entities with which the physician or an immediate family member has a financial relationship, unless an exception applies — and it requires no intent at all, which is exactly the fact exams test against the Anti-Kickback Statute’s criminal-intent standard. Behind all three stands the OIG’s exclusion authority: individuals and entities on the List of Excluded Individuals/Entities may not participate in federal health care programs, and employing them creates liability for the employer.
HIPAA Essentials for Coders
The Health Insurance Portability and Accountability Act created the privacy and security framework every coder works inside. The Privacy Rule protects protected health information (PHI) — individually identifiable health information in any form — permitting use and disclosure without authorization for treatment, payment, and health care operations, and requiring the minimum necessary standard: use or disclose only the least PHI needed for the purpose. The Security Rule adds administrative, physical, and technical safeguards for electronic PHI (ePHI). The rules bind covered entities — providers, health plans, and health care clearinghouses — and their business associates, the vendors handling PHI on their behalf under written agreements. The HITECH Act strengthened enforcement and added breach notification: affected individuals must be notified of breaches of unsecured PHI, with regulators and media notified for large breaches. For coders, HIPAA also standardized the transaction code sets — the reason ICD-10-CM, CPT, and HCPCS are the mandated languages of claims, as explained in What Is ICD-10-CM.
The OIG, Audits, and Compliance Programs
The Office of Inspector General publishes an annual work plan announcing enforcement and audit priorities — historically a preview of what payers will scrutinize, from modifier usage patterns to place-of-service errors. Recovery Audit Contractors (RACs) review paid claims to identify over- and underpayments on a contingency-fee basis, while the CERT program measures the Medicare improper payment rate and Unified Program Integrity Contractors investigate suspected fraud. The provider-side defense is the compliance program, and the OIG’s seven elements are a straight memorization item: written policies and procedures; a designated compliance officer and committee; effective training and education; effective lines of communication (including anonymous reporting); internal auditing and monitoring; enforcement through well-publicized disciplinary standards; and prompt response to detected offenses with corrective action. Certified coders sit inside this machinery — the AAPC code of ethics obligates accurate coding regardless of pressure, the professional stakes described in Getting Certified: CPC and Beyond.
Worked Example: One Denied Service, Four Outcomes
A Medicare patient requests a screening service more frequently than the covered interval, and the physician agrees to furnish it. If the office issues a proper ABN and the patient signs, the claim goes out with modifier GA; when Medicare denies, the patient pays. If no ABN was obtained, the claim carries GZ, and the denial is the provider’s write-off. If the service were one Medicare never covers by statute, no ABN is needed: GY reports the exclusion, with GX available for the voluntary courtesy notice. Same service, four modifier postures, and liability lands somewhere different in each — the exam builds one question per posture and expects the grid to be automatic.
How the CPC Exam Tests Compliance and Regulatory Topics
Pattern 1 — Match the Medicare Part
A scenario names a setting or benefit — inpatient stay, physician office visit, drug coverage, Medicare Advantage — and asks which part pays. The A/B/C/D map answers it directly.
Pattern 2 — The ABN Liability Question
A service is denied as not medically necessary, and the question asks who pays. The answer follows the modifier grid: GA shifts liability to the patient, GZ leaves it with the provider, GY/GX mark statutory exclusions.
Pattern 3 — Fraud or Abuse, and Which Law
A vignette describes conduct — billing for unperformed services, paying for referrals, self-referral to an owned imaging center. Classify by intent (fraud versus abuse) and match the statute: False Claims Act for false billing, Anti-Kickback for remuneration, Stark for self-referral.
Pattern 4 — HIPAA Definitions
Questions test the vocabulary: what counts as PHI, who is a covered entity versus a business associate, what minimum necessary requires, and when treatment-payment-operations permits disclosure without authorization.
Common Mistakes
Swapping Medicare Parts A and B. Part A is institutional (inpatient, SNF, hospice, home health); Part B is professional and outpatient services with DME.
Treating an LCD as overriding an NCD. National coverage policy binds every contractor; local policy applies only where national policy is silent.
Using GA for statutorily excluded services. ABNs address covered services expected to fail medical necessity; excluded services take GY, with GX for voluntary notices.
Forgetting that GZ means provider liability. An expected denial without an ABN cannot be billed to the patient — the provider writes it off.
Defining fraud without intent. Fraud requires knowing deception; abuse is improper practice without established intent — and Stark liability requires no intent at all.
Confusing the Anti-Kickback Statute with the Stark Law. Anti-Kickback is criminal, covers any remuneration for referrals of federal program business, and applies broadly; Stark is civil, covers physician self-referral for designated health services, and is strict liability.
Overlooking the business associate. HIPAA obligations extend by written agreement to vendors handling PHI — billing companies and coding contractors included.
Skipping the seven compliance program elements. Policies, compliance officer, training, communication lines, auditing, discipline, and corrective response — the exam lists five and asks what’s missing.
Final Exam Strategy for This Section
Compliance material rewards a single dense review sheet: the four Medicare parts, the NCD/LCD hierarchy, the GA/GX/GY/GZ grid, the three RVU components and conversion factor, the fraud/abuse-and-statute map, HIPAA’s defined terms, and the OIG’s seven elements. There is no code book to consult, so these questions are pure preparation — build the sheet, add it to your CPC Exam Cheat Sheet rotation, and quiz the definitions through the error-log loop in the CPC Practice Exam Error Review Method. Candidates routinely leave these five to ten questions on the table; an evening of memorization picks them all up.
5 quick questions drawn from this guide. Click an answer to check it — explanations appear as you go.
1. An inpatient hospital admission is covered under Medicare:
2. A service with a properly executed ABN is denied as not medically necessary. Modifier GA means:
3. A physician receives a payment for each patient referred for federal-program services. This implicates:
4. An expected medical-necessity denial with no ABN issued (modifier GZ) means:
5. When national and local Medicare coverage policies address the same service:
Frequently Asked Questions
How many compliance questions are on the CPC exam?
The exam typically includes roughly five to ten questions on compliance and regulatory topics, covering Medicare structure, ABNs and liability modifiers, medical necessity policy, payment methodology, fraud and abuse laws, and HIPAA — all answerable from memory without a code book.
What is the difference between fraud and abuse?
Fraud is intentional deception to obtain unauthorized benefit, such as billing for services never rendered. Abuse is practice inconsistent with accepted standards that causes unnecessary cost without proven intent, such as patterns of medically unnecessary services. Intent is the dividing line.
When is an ABN required?
Before furnishing a normally covered service to a fee-for-service Medicare beneficiary when the provider expects denial as not reasonable and necessary. A properly delivered ABN, reported with modifier GA, shifts liability to the beneficiary; statutorily excluded services need no ABN.
What is an NCD vs an LCD?
A National Coverage Determination is CMS policy that binds all Medicare contractors nationwide. A Local Coverage Determination is issued by a regional Medicare Administrative Contractor for its own jurisdiction and applies only where no NCD addresses the service.
What are RVUs in medical coding?
Relative value units are the payment weights assigned to every CPT code under Medicare’s RBRVS system, with three components: physician work, practice expense, and malpractice expense. Adjusted geographically and multiplied by the conversion factor, they produce the Medicare payment amount.
