Credential type: certification examination · verified on the issuer's site September 20, 2026 issuer page
The Certified Professional Compliance Officer (CPCO) exam is administered by AAPC. It tests knowledge across five domains: healthcare compliance programs, the regulatory environment, coding and billing compliance, risk management, and HIPAA and privacy. The credential is aimed at professionals who build and run compliance programs in healthcare settings, and it carries a passing score of 70.
The CPCO suits compliance officers, practice managers, billing supervisors, auditors, and consultants who design or oversee healthcare compliance programs. Candidates typically have working knowledge of federal healthcare law, coding, and privacy rules before sitting for the exam.
Start with AAPC's official CPCO study guide and practice exams, then map each chapter to the five exam domains. Read the OIG General Compliance Program Guidance for the compliance program and regulatory environment sections. Build a checklist of the seven compliance program elements and rehearse applying them to short scenarios before test day.
Domain 1 covers the structure of a healthcare compliance program. It addresses written policies, codes of conduct, training, communication channels, enforcement standards, auditing, and corrective action initiatives that form an effective program.
Domain 2 covers the federal regulatory environment that frames healthcare compliance. It includes the anti-kickback statute, physician self-referral law, False Claims Act, civil monetary penalty authorities, exclusion authorities, and criminal healthcare fraud statutes.
Domain 3 covers coding and billing compliance. It focuses on identifying improper billing patterns, applying correct coding rules, and using audits and monitoring to detect and prevent coding and billing errors.
Domain 4 covers risk management within a compliance program. It addresses risk assessment, auditing and monitoring, and the response to detected offenses, including investigations, government reporting, and corrective action initiatives.
Domain 5 covers HIPAA and privacy. It addresses the HIPAA Privacy and Security Rules, breach response, patient rights, and the role of the compliance officer in protecting protected health information across the organization.
Arrive early with valid identification. The 180-minute, 90-question linear format allows about two minutes per question. Read each stem carefully, flag uncertain items, and review flagged questions before submitting.
The CPCO exam contains 90 multiple-choice questions delivered in a linear format. Candidates answer all items in one sitting and cannot return to earlier questions after advancing through the exam.
The passing score for the CPCO exam is 70. Candidates must achieve at least 70 to earn the Certified Professional Compliance Officer credential from AAPC.
The CPCO exam lasts 180 minutes, giving candidates three hours to answer all 90 multiple‑choice questions presented in a linear, one‑pass format, meaning you cannot return to earlier items once you move forward.
The CPCO exam costs $299 for AAPC members and $399 for non-members. Membership pricing is available through AAPC for candidates who hold or pursue other AAPC credentials.
The CPCO certification is valid for 2 years. Renewal is required, and certificants must meet AAPC's continuing education and renewal requirements to maintain the credential.
The CPCO exam covers five domains: Healthcare Compliance Programs, Regulatory Environment, Coding and Billing Compliance, Risk Management, and HIPAA and Privacy. Each domain tests a distinct area of compliance officer knowledge.
Verified 2026-09-02
This page was built from verified AAPC exam facts and the OIG General Compliance Program Guidance excerpt. Domain summaries were mapped directly to the five CPCO domains listed in the facts file.