Exam321 Logo

CPCO Study Guide: Fraud and Abuse Statutes Come First

By Editorial Team ·

Compliance Program Elements & Governance (30%): Build Around the Framework

  • Memorize OIG's seven elements of an effective compliance program in order, and practice mapping other exam content back to which element it relates to.
  • Understand the compliance officer's reporting relationship, including why direct access to senior leadership or the board matters for program independence and credibility.
  • Review exclusion screening requirements — knowing what the OIG LEIE and SAM exclusion lists are, and why routine screening matters, is a recurring, concrete topic.
  • Study "tone at the top" as a concept, since it connects governance-level leadership commitment to practical program effectiveness throughout the exam.

Auditing, Monitoring & Risk Assessment (25%): Know Your Definitions Precisely

  • Distinguish proactive/routine audits from reactive/for-cause audits, and know when each is typically used.
  • Understand extrapolation and why statistically valid sampling matters — this concept connects audit findings to potential overpayment liability at scale.
  • Learn the difference between auditing and monitoring explicitly — auditing is periodic and in-depth, monitoring is ongoing and routine — since the exam tests this distinction directly.
  • Review common audit findings (upcoding, downcoding, unbundling) and what each one means, since these terms are often confused with each other.

Fraud, Waste, Abuse & Regulatory Law (30%): The Highest-Stakes Domain

  • Build a comparison chart of the False Claims Act, Anti-Kickback Statute, and Stark Law — their intent standards, civil vs. criminal nature, and what conduct each actually prohibits.
  • Understand safe harbors and exceptions as "all-or-nothing" protections — partial compliance with a safe harbor's requirements generally doesn't provide protection.
  • Know the 60-day overpayment rule cold — it connects directly to False Claims Act liability through the "reverse false claim" concept and is a frequently tested, concrete rule.
  • Practice distinguishing fraud, waste, and abuse as three distinct concepts with different intent requirements, since exam scenarios often ask you to correctly categorize a described situation.

Reporting, Investigations & Enforcement (15%): Small but Practical

  • Understand the purpose and process of self-disclosure (OIG's Self-Disclosure Protocol and CMS's Stark self-referral disclosure protocol) and why voluntary disclosure typically results in better outcomes than waiting for discovery.
  • Review whistleblower protections and non-retaliation requirements, since these connect directly to the compliance program's internal reporting mechanisms.
  • Know the components of a corrective action plan and how it fits into the broader "respond promptly" element of an effective compliance program.

General Strategy: Treat Legal Precision as a Skill to Practice

Because so much of this exam rewards precise legal knowledge over general compliance intuition, practice questions that specifically test statute-to-scenario matching, not just definitions in isolation. This mirrors how the real exam is structured and builds the exact skill most likely to separate a pass from a near-miss.

Put These Tips Into Practice

Our CPCO exam page has free practice quizzes broken out by domain, plus a full mock exam, to help you target your remaining study time.

Official source: eligibility, fees, and the current content outline are set by AAPC. Confirm the details there before you register.