CPC Exam Compliance and Regulatory Domain: Study Guide

The compliance and regulatory domain on the CPC exam covers fraud and abuse law at a conceptual level, including the Stark Law, the Anti-Kickback Statute, and the False Claims Act, along with related topics like NCCI edits and RVUs that connect coding accuracy to financial and legal consequences. It’s one of roughly 17 content domains on the exam, and it tests whether a candidate understands why coding correctly matters beyond getting the right answer on a multiple-choice question.

This domain sits apart from the pure code-lookup sections of the exam because it’s conceptual rather than reference-based. You can’t flip to a page in a code book to answer a Stark Law question the way you can look up a diagnosis code, so it rewards actual understanding over fast navigation.

(CPC Prep is not affiliated with or endorsed by AAPC or the OIG/HHS. This is a plain-English study overview for exam-prep purposes, not legal, compliance, or medical advice for any real situation, provider, or organization.)

What is the Stark Law, in plain English?

The Stark Law, formally the physician self-referral law, restricts a physician from referring Medicare or Medicaid patients for certain designated health services to an entity the physician (or an immediate family member) has a financial relationship with, unless an exception applies. The concern behind it is straightforward: a doctor who owns a stake in an imaging center shouldn’t be financially rewarded for ordering more scans there than medical necessity calls for. Stark Law is a strict-liability statute in the sense that it doesn’t require proof of intent to violate; the financial relationship and the referral pattern themselves are what matter, which makes it different in character from the intent-based statutes covered next.

What is the Anti-Kickback Statute, in plain English?

The Anti-Kickback Statute makes it a crime to knowingly and willfully offer, pay, solicit, or receive anything of value in exchange for referrals of services reimbursable by a federal healthcare program. Unlike Stark Law, this one is intent-based: prosecutors have to show the payment was made with the purpose of inducing referrals, not just that a financial relationship existed alongside a referral pattern. The classic conceptual example is a lab paying a physician a “consulting fee” that’s really compensation for sending patients its way, dressed up as something else on paper.

What is the False Claims Act, in plain English?

The False Claims Act, or FCA, is the primary federal statute used to pursue billing fraud, including upcoding, when a claim is knowingly submitted with false information to a federal healthcare program (OIG/HHS: Physician Relationships With Payers, accessed 2026-07-19). It attaches per-claim civil penalties plus treble damages in some cases, though the exact per-claim dollar figure is periodically inflation-adjusted by the Department of Justice and isn’t something this guide treats as a fixed number to memorize. The word doing the most work in the statute is “knowingly”: an honest coding mistake caught during normal review isn’t what the FCA is built to punish, a pattern of knowing misstatement is.

How do these three laws differ from each other?

LawWhat it restrictsIntent required?
Stark LawPhysician self-referral to entities with a financial relationship, for designated health servicesNo, strict liability
Anti-Kickback StatutePaying or receiving anything of value in exchange for federal-program referralsYes, knowing and willful
False Claims ActKnowingly submitting a false or fraudulent claim to a federal healthcare programYes, knowing

How does this connect to NCCI edits and RVUs?

NCCI edits and RVUs both get brief mention in this domain because they’re the mechanical side of the same coding-accuracy problem the fraud statutes exist to police. NCCI edits are CMS’s system for flagging code-pair combinations that shouldn’t normally be billed together on the same date of service, and using a modifier just to bypass an edit without documentation support crosses from coding into the same territory the FCA cares about. For the full mechanics, see NCCI edits explained rather than re-deriving it here. RVUs matter to this domain because they’re the direct financial consequence of the code selected, which is exactly why upcoding and downcoding has real teeth: the wrong code doesn’t just look wrong, it changes what gets paid. See what RVUs are and how CMS prices them for the full breakdown, and HIPAA and medical coding for the privacy half of this same compliance domain.

Why does consistent coding accuracy matter more than any single claim?

Because individual mistakes read as human error, but a sustained pattern of favorable-to-the-provider coding reads as a system, and that’s exactly what triggers OIG and payer audits. Coders are trained to code exactly what’s documented, no more and no less, and the compliance framework above exists precisely because the incentive to code favorably is real and the enforcement mechanism has to catch patterns that a single spot-check wouldn’t reveal. This is also why documentation queries matter so much in practice: when the note is ambiguous, resolving it with the provider is the compliant move, not defaulting to whichever code pays more.

Practice questions: compliance and regulatory domain

These are original scenarios written for this project. None reproduce real AAPC exam questions.

1. A physician refers a Medicare patient for an MRI at an imaging center the physician partially owns, with no applicable exception. Which law most directly governs this scenario? A) Anti-Kickback Statute B) Stark Law C) HIPAA minimum necessary standard D) NCCI PTP edits

Answer: B. This is a physician self-referral to a designated health service entity in which the physician has a financial relationship, the core scenario Stark Law addresses, and Stark Law applies regardless of provable intent.

2. A lab pays a physician a monthly “marketing fee” that is, in practice, compensation tied to the volume of patients the physician refers for lab testing reimbursed by Medicare. This arrangement most directly raises concerns under which law? A) False Claims Act B) Anti-Kickback Statute C) Stark Law only D) Minimum necessary standard

Answer: B. Paying something of value in exchange for federal-program referrals is the Anti-Kickback Statute’s core concern, and the intent behind the “marketing fee” label is exactly what an Anti-Kickback analysis would examine.

3. A coder notices that a provider’s claims consistently bill the highest-level E/M code regardless of documented complexity. What is the most compliant next step? A) Continue coding as submitted since the provider is responsible for documentation B) Downcode all future claims from that provider automatically C) Flag the pattern for compliance review and query unclear documentation going forward D) Ignore it unless a patient complains

Answer: C. The compliant response to a suspected pattern is to escalate for review and continue querying ambiguous documentation rather than either rubber-stamping the pattern or unilaterally downcoding, which would introduce its own inaccuracy.

4. Which statement correctly distinguishes the False Claims Act from the Anti-Kickback Statute? A) The FCA requires no intent; the Anti-Kickback Statute always requires knowing and willful conduct B) The FCA addresses false claims for payment; the Anti-Kickback Statute addresses payments made to induce referrals C) The FCA only applies to hospitals; the Anti-Kickback Statute only applies to physicians D) There is no meaningful difference between the two statutes

Answer: B. The FCA targets knowingly false claims submitted for payment; the Anti-Kickback Statute targets exchanging something of value for referrals. Both require knowing conduct, but they address different conduct.

5. A billing modifier is applied to a claim solely to bypass an NCCI PTP edit, with no supporting documentation for the modifier’s use. This practice is best described as: A) A legitimate coding technique for maximizing reimbursement B) A compliance violation, since modifiers require documentation support, not just a desire to get the claim paid C) Required whenever an NCCI edit blocks a claim D) Governed exclusively by the Anti-Kickback Statute

Answer: B. NCCI PTP-associated modifiers must be supported by documentation, not applied purely to bypass an edit; using one without support is a compliance violation, not a coding technique.

Test yourself further on this domain and the rest of the exam content with the free CPC practice exam, and see the full domain breakdown on what’s on the CPC exam. Keep the Stark/Anti-Kickback/FCA distinctions from the table above on the CPC Exam Prep Cheat Sheet as a quick reference while you work through the rest of the CPC exam content outline.

FAQ

Is the compliance and regulatory domain a large part of the CPC exam? It’s one of roughly 17 content domains covering the full exam, tested alongside code-specific sections like surgery and E/M rather than as a standalone separate exam.

Do I need to memorize exact FCA penalty dollar amounts for the exam? No. Exact per-claim penalty figures are periodically inflation-adjusted and aren’t stable numbers worth memorizing; understanding the mechanism (knowing false claims trigger FCA exposure) is what this domain actually tests.

What’s the simplest way to remember the difference between Stark Law and the Anti-Kickback Statute? Stark Law is about self-referral to entities with a financial relationship and doesn’t require proof of intent. The Anti-Kickback Statute is about exchanging value for referrals and does require proof of knowing, willful conduct.

Are NCCI edits and RVUs tested as part of this same domain? Yes, both connect to the compliance and regulatory domain since they tie coding accuracy directly to financial consequences, though each has its own dedicated mechanics worth studying separately.

Are the practice questions in this guide real AAPC exam questions? No. All five scenarios here are original, written for this project. Real AAPC exam questions aren’t reproduced anywhere in this content.

Bottom line: the compliance and regulatory domain tests whether you understand why coding accuracy carries legal weight, not just whether you can define Stark Law, the Anti-Kickback Statute, and the False Claims Act in isolation, and the fastest way to internalize the distinctions is to work scenario-based questions like the five above rather than memorizing definitions cold.

SponsoredMyShedPlans12,000 shed and outdoor-project plans with step-by-step blueprints and materials lists.See the plans →