HCR 363 Module 2 Assignment 2: Compliance Risk Assessment Survey Example

Reviewed by Emmett Rockwell, MBA Arizona State University Updated October 2026

This HCR 363 Module 2 sample is Assignment 2, the Risk Assessment Survey, in Risk Management, Auditing and Monitoring for Health Care Compliance, a required course on ASU's Health Care Compliance and Regulations track. Worth 65 points, the assignment in ASU HCR 363 asks students to write a Compliance Risk Assessment Survey for a system that runs hospitals, physician offices and a surgery center, to be answered by its Director of Billing, Jenny Gonzalez, the persona the course supplies. The composite analyst at Sonoran Ridge Health produces the survey itself: a short cover note, 30 questions grouped by risk area, two rating scales for likelihood and control strength, open questions that invite examples and a key showing how each answer will feed the risk workbook in later weeks.

CourseHCR 363 Risk Management, Auditing and Monitoring for Health Care Compliance
ModuleModule 2
Paper typeRisk assessment survey instrument
LengthAbout 869 words, 6 pages
FormatAPA 7 student paper
SchoolArizona State University
ProgramBS in Health Care Compliance and Regulations
UpdatedOctober 2026

Free sample paper for HCR 363 Module 2

1

Compliance Risk Assessment Survey: Revenue Cycle and Billing, Sonoran Ridge Health

Student Name

BS in Health Care Compliance and Regulations, Arizona State University

HCR 363: Risk Management, Auditing and Monitoring for Health Care Compliance

Instructor Name

Month Day, Year

What this page is doingThe title follows the form of an internal survey document, naming the area and the organization.
2

Compliance Risk Assessment Survey: Revenue Cycle and Billing, Sonoran Ridge Health

Cover Note to the Director of Billing

Ms. Gonzalez, the compliance department is updating Sonoran Ridge Health's annual compliance risk assessment, and billing is the first area we are reviewing. This survey asks about billing practices at our two hospitals, our physician clinics and the surgery center. Your answers will help us decide where to audit, where to train and where controls are already strong, following the risk assessment step in federal compliance guidance (Office of Inspector General [OIG], 2023). There are no wrong answers; a candid "I don't know" is useful too. The survey takes about 40 minutes, and we will follow up with a conversation to clarify anything that needs it. Responses are kept within the compliance department and shared with leadership only in summary.

Instructions

For each closed question, choose the answer that best fits the past 12 months. Where a question asks you to rate likelihood or controls, use the scales below. Please add an example in the comment box whenever you can; examples tell us more than ratings.

RatingLikelihood that the risk occursStrength of current controls
1Rare: not seen in the past 3 yearsStrong: documented, tested and monitored
2Possible: seen once or twiceAdequate: documented and usually followed
3Likely: seen several times a yearWeak: informal or inconsistently followed
4Frequent: seen monthly or moreNone: no control in place

Section A: Coding and Documentation

1. Who reviews coding accuracy for each setting (hospital inpatient, hospital outpatient, clinic, surgery center), and how often?

2. When was the last external coding audit in each setting, and what was the error rate?

3. Rate the likelihood that clinic evaluation and management (E/M) levels are not supported by documentation. Rate current controls.

4. How are modifiers such as 25 and 59 reviewed before claims are submitted?

5. Rate the likelihood that surgery center claims unbundle procedures that should be billed together. Rate current controls.

6. Are coders' credentials and continuing education tracked? By whom?

Section B: Overpayments and Credit Balances

7. How many credit balances older than 60 days are open today in each setting?

8. Describe the process from identifying a possible overpayment to refunding it. Who decides?

9. Rate the likelihood that an identified Medicare overpayment is not returned within 60 days. Rate current controls.

10. Have payer audits or recoupments occurred in the past year? Please list them.

Section C: Claims and Charge Integrity

11. When was the chargemaster last reviewed, and by whom?

12. How are new services added to the chargemaster and assigned codes?

13. What is the current denial rate by setting, and what are the top three denial reasons?

14. Rate the likelihood that claims are submitted for services ordered by a provider who is excluded or not enrolled. Rate current controls.

Section D: Physician Arrangements and Referrals

15. Does billing receive notice when a physician contract or lease expires?

16. Are any physicians paid in ways that vary with the volume of services they order? If so, describe.

17. Rate the likelihood that the hospitals bill for designated health services referred by a physician with an expired or unsigned agreement. Rate current controls.

18. Has billing ever been asked to waive copayments for a referring physician's patients or family?

Section E: Privacy and Security in Billing

19. Who in billing has access to the full medical record, and is access reviewed when staff change roles?

20. How are patient statements and remittances sent and stored?

21. Rate the likelihood of a billing-related privacy incident, such as a misdirected statement. Rate current controls.

22. Has billing staff completed phishing training in the past year?

Section F: Emergency Department and Patient Financial Practices

23. When are patients in the emergency departments asked about insurance or payment, relative to the medical screening examination?

24. Rate the likelihood that registration or financial questions delay screening. Rate current controls.

25. How are good faith estimates provided to self-pay patients scheduling surgery center procedures?

Section G: Training, Reporting and Culture

26. How often do billing staff receive compliance training specific to their jobs?

27. Do staff know how to report a concern to compliance? How would you know?

28. Has a billing employee raised a compliance concern in the past year? What happened?

29. What keeps you up at night about billing compliance?

30. If you could fix one process in billing tomorrow, what would it be?

What this page is doingEnding with two open questions invites the risks the survey's structure might miss, which is often where the most useful answers come from.
3

How Responses Will Be Used

Ratings for likelihood and control strength will be carried into the Risk Identification and Analysis tab, and open answers will be coded into new risks where they reveal something the survey did not ask.

SectionLaw or area from Assignment 1Workbook use
A, CFalse Claims Act and coding rulesRisk identification for coding and charge integrity
B60-day overpayment rule (42 C.F.R. § 401.305)Risk identification and likelihood rating for refunds
DStark Law and Anti-Kickback StatuteRisk identification for physician arrangements
EHIPAA Security RuleRisk identification for billing data
FEMTALA (42 U.S.C. § 1395dd) and price transparencyRisk identification for registration practices
GCompliance program elementsControl strength across all areas

References

Emergency Medical Treatment and Labor Act, 42 U.S.C. § 1395dd (2024).

Office of Inspector General. (2023). General compliance program guidance. U.S. Department of Health and Human Services. https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf

Reporting and returning of overpayments, 42 C.F.R. § 401.305 (2024).

HCR 363 Module 2 instructions, in plain terms

Assignment 2 in HCR 363 is a survey, not an essay. The syllabus asks you to create a Compliance Risk Assessment Survey for the course's three-setting organization (hospitals, clinics and a surgery center), addressed to its Director of Billing, Jenny Gonzalez. The survey is the foundation of the risk assessment you build for the rest of the term: in Assignment 3 you put it to a chatbot playing Ms. Gonzalez and record the answers, and in Assignments 4 and 5 those answers go into the Risk Identification and Analysis and Evaluate and Rank tabs of a mock workbook. That sequence should shape your design. Questions need to produce answers you can rate and rank, so include scales for likelihood and control strength, and they need to cover the laws you identified in Assignment 1. Both are due in Week 2.

How this HCR 363 Module 2 example is built

The sample is laid out as a working survey document. A cover note addressed to the Director of Billing explains the purpose, time required and confidentiality. Instructions define two four-point scales, one for likelihood and one for control strength, in a table so every rating means the same thing. Thirty questions follow in seven sections, from coding and overpayments to physician arrangements, privacy, emergency department registration and culture, mixing factual questions, ratings and requests for examples. Two open questions close the survey. A final table shows which law from the pre-work paper each section tests and where its answers go in the workbook, which ties the instrument to the assignments that follow it.

Where the marks sit in the HCR 363 Module 2 rubric

Sixty-five points ride on the survey. Readers credit an instrument that covers the main billing risk areas for all three settings, ties its sections to the laws and regulations in Assignment 1, asks questions a Director of Billing could actually answer, uses rating scales that are defined and consistent, mixes closed and open questions and is organized so the answers can feed risk identification and ranking. Points go when questions are leading or vague, when the survey covers only one setting, when scales are missing or undefined, when the instrument is too long for a busy director or when it asks about things outside billing's knowledge. Readers also look for a professional cover note, since the survey is meant to be sent to a real person in the scenario.

HCR 363 Module 2 help: mistakes that cost marks

Write your list of risk areas from Assignment 1 first, then draft questions under each. Ask about facts the director knows, such as error rates, denial reasons and refund processes. Set the meaning of each rating once, then hold every question to it. Keep questions neutral; "How are modifiers reviewed?" works better than "Do you ensure modifiers are always correct?" Add a comment box or request for examples. Close with open questions. Show how the answers will be used. Unsure whether a question belongs in a billing survey? Send the draft and the desk will compare it with the scenario.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official Arizona State University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More HCR 363 and BS in Health Care Compliance and Regulations sample papers

HCR 363 Module 2 questions, answered

Where can I find a free HCR 363 Module 2 sample paper?

The full Assignment 2 sample is on this page: a 30-question compliance risk assessment survey for a health system's Director of Billing.

Who answers the HCR 363 risk assessment survey?

Jenny Gonzalez, the Director of Billing in the course scenario, played by a chatbot in Assignment 3.

What should a compliance risk assessment survey include?

A cover note, defined rating scales, questions grouped by risk area, requests for examples and open questions.

How do the survey answers get used in HCR 363?

They feed the Risk Identification and Analysis and Evaluate and Rank tabs of the mock workbook in Assignments 4 and 5.

How should likelihood be rated in a risk survey?

On a defined scale, such as rare, possible, likely and frequent, used the same way for every question.