CMCO logo
Focused certification exam prep
Start practice

CMCO Exam Domains 2026: Complete Guide to All 5 Content Areas

TL;DR
  • CMCO means Certified Medical Compliance Officer, issued through Practice Management Institute (PMI), and is aimed at non-hospital healthcare settings.
  • The exam has 85 regular questions plus four extra-credit questions, five hours allowed, and a passing score of at least 70%.
  • The five domains are PMI curriculum headings, not a separately weighted blueprint, so study all five rather than gaming percentages.
  • The exam is open book and hand-graded by the instructor, with results arriving in four to six weeks.

What the Five CMCO Domains Actually Are

The Certified Medical Compliance Officer credential, offered by Practice Management Institute, is built around a curriculum of five major content areas. If you have read other material about "CMCO," be careful: the same four letters are used by unrelated credentials in mission-critical operations. This article covers only the medical compliance credential for healthcare practices, and everything below applies to that program alone. If you are still orienting yourself, the explainers on what CMCO certification is and what CMCO stands for make a good starting point.

The five domains, using PMI's curriculum section headings, are:

  1. Compliance structure and enforcements
  2. Billing/coding/coverage and reimbursement
  3. Compliance, risks, actions, and issues
  4. Medicare exclusion and its impact on an organization
  5. Law enforcement investigation tools
Curriculum categories, not a weighted blueprint: PMI publishes these as section headings of the course content. They should be treated as categories to organize your preparation, not as an exam blueprint with official percentage weights. Any source claiming exact per-domain question counts for this credential is going beyond what PMI has published.

The program is designed for people working in non-hospital healthcare settings such as physician practices, clinics, and similar outpatient organizations, and PMI recommends medical-office experience. Core content threads running through all five domains include compliance-plan structure, billing and coverage, organizational risks, Medicare exclusions, investigations, HIPAA/HITECH, and the fraud-and-abuse laws. For the eligibility side, see CMCO requirements and how to qualify.

How the Exam Is Delivered and Graded

Understanding the delivery mechanics changes how you prepare, because this is not a typical multiple-choice, instant-score certification test.

FeatureCMCO (PMI)
Regular questions85
Extra-credit questions4 (89 total presented)
Time allowedFive hours
Passing scoreAt least 70%
Reference materialsOpen book: CMCO course manual and all notes permitted
GradingHand-graded by the instructor
Results timingFour to six weeks
ProctoringCoordinated by PMI through its Exam Coordinator and a testing facility
Online certification package$2,095, including instruction and the examination

Note the fee framing: the $2,095 figure is a package price covering instruction and the examination together, not a standalone exam fee. For a fuller look at what that includes and how renewal costs layer on, see the CMCO certification cost breakdown. Scheduling questions are covered in the guide to CMCO exam dates and scheduling, and the scoring threshold is unpacked in what you need to pass.

Because the instructor hand-grades the exam, answers that require explanation are judged by a person rather than a scanner. That favors candidates who can write clear, complete, well-organized responses grounded in the course manual's language.

Domain 1: Compliance Structure and Enforcements

The first domain establishes the architecture of a compliance program and the legal machinery that gives it teeth. Expect the exam to test whether you can describe how a practice should structure its program and who enforces the rules around it.

Compliance Structure and Enforcements

This domain covers how a medical practice builds a compliance plan and the enforcement landscape that makes one necessary.

  • The elements of a compliance-plan structure and how each element supports the others
  • The role and responsibilities of the compliance officer within a non-hospital practice
  • How written standards, training, auditing, and corrective action fit together
  • The major fraud-and-abuse laws and the agencies that enforce them
  • HIPAA and HITECH as enforcement frameworks, not just privacy concepts

A common mistake is memorizing a list of plan elements without understanding why they exist. Because the exam is open book and hand-graded, you gain more by understanding how a compliance officer would actually apply each element in a small practice, since a thoughtful explanation reads better than a copied phrase. Practices with limited staff face a distinct challenge: the compliance officer often wears several hats, and the curriculum's focus on non-hospital settings reflects that reality.

Domain 2: Billing, Coding, Coverage and Reimbursement

This is the domain where compliance meets the revenue cycle, and for many practice-based candidates it is the most familiar territory. The compliance angle, however, is different from simply knowing how to bill. You are expected to recognize where billing behavior creates legal exposure.

Billing, Coding, Coverage and Reimbursement

Understanding how claims are built, what payers cover, and where improper billing becomes a compliance problem.

  • How coding accuracy ties to documentation and medical necessity
  • Coverage rules and why a service can be medically appropriate yet not payable
  • Reimbursement mechanics and how errors create overpayments
  • Patterns that signal billing risk, such as upcoding or unbundled services
  • The link between billing practices and the fraud-and-abuse statutes from Domain 1

Candidates who come from front-office or revenue-cycle roles sometimes underestimate this domain because they know the mechanics. The test is whether you can reframe that knowledge through a compliance lens: not "how do I get this claim paid," but "does this claim practice create liability, and how would an audit find it." Practice thinking in terms of documentation trails, since auditors work backward from records.

Cross-domain connection: Billing errors are the most common way a well-meaning practice drifts into fraud-and-abuse territory. When you study Domain 2, keep Domain 1's enforcement laws and Domain 5's investigation tools in mind. The three form a chain from behavior to detection to consequence.

Domain 3: Compliance, Risks, Actions, and Issues

The third domain moves from structure to operations. It addresses the organizational risks a practice faces and how a compliance officer identifies, prioritizes, and responds to them. Here the curriculum emphasizes judgment: what do you do when something is wrong?

Compliance, Risks, Actions, and Issues

How to recognize organizational risk and take appropriate compliance action.

  • Identifying organizational risks across clinical, billing, and administrative functions
  • Auditing and monitoring as tools for surfacing issues before regulators do
  • Responding to reported concerns and documenting the response
  • Corrective action, including when repayment or disclosure is appropriate
  • HIPAA/HITECH breach and privacy issues as an ongoing risk category

Scenario-style questions are most likely here. Rather than asking what a term means, a question may describe a situation in a practice and ask what the compliance officer should do first, or what the risk is. Work through the course manual's examples, and for each one ask three things: what is the risk, who is affected, and what is the documented response. That habit translates directly to well-structured written answers.

Domain 4: Medicare Exclusion and Its Impact on an Organization

Exclusion is a narrow but high-stakes topic that many candidates treat as an afterthought. It deserves its own domain because the consequences for an organization are severe: employing or contracting with an excluded individual or entity can put payment for services at risk and create significant liability.

Medicare Exclusion and Its Impact

What exclusion means, who can be excluded, and how it affects the organizations connected to them.

  • The concept of exclusion from federal healthcare programs and why it is imposed
  • The difference between mandatory and permissive exclusion in the curriculum's framing
  • Screening practices a practice should use before hiring or contracting
  • The organizational impact of employing or billing through an excluded party
  • Ongoing monitoring, since exclusion status can change after hire

The practical takeaway for a small practice is that screening is not a one-time onboarding step. A compliance officer should be able to explain why routine, repeated screening of staff and vendors is part of a defensible program, and what the downstream financial and legal impact looks like if an excluded party slips through. Tie this domain back to Domain 3's monitoring concepts, since screening is a form of ongoing risk control.

Domain 5: Law Enforcement Investigation Tools

The final domain looks at the compliance world from the other side: the tools government agencies use when they investigate healthcare organizations. Knowing these tools helps a compliance officer prepare the organization, respond appropriately, and protect rights during an inquiry.

Law Enforcement Investigation Tools

How investigations begin, what authority investigators hold, and how a practice should respond.

  • Common mechanisms by which investigations are initiated or escalate
  • The investigative tools available to enforcement agencies, as described in the course manual
  • How a practice should respond to a subpoena, records request, or visit
  • The compliance officer's role in coordinating response and preserving records
  • How a strong existing compliance program influences an investigation's trajectory

This domain rewards procedural thinking. Know the sequence of what happens and who should be notified internally. Also note how Domain 1's compliance plan, Domain 2's documentation, and Domain 3's corrective actions all become evidence of good faith when an investigation arrives. For a quick refresher on the full set of facts, the CMCO cheat sheet condenses the must-know points.

Working an Open-Book, Hand-Graded Exam

An open-book format does not make the exam easy; it changes what difficulty looks like. With five hours for 85 regular questions plus four extra-credit items, time is generous, but only if you can find answers quickly and express them well. If you want a realistic view of the challenge, read how hard the CMCO exam is and the discussion of the CMCO pass rate (which, notably, depends on what has actually been published rather than on rumor).

Key Takeaway

Build your manual and notes for retrieval, not just reading. Tab each of the five domains, keep a one-page index of key terms and the section where each is explained, and annotate the manual with your own plain-language summaries. Since you may use all notes during the exam, your preparation should make any answer findable in under a minute.

Because the instructor grades by hand, completeness and clarity matter. Answer the question asked, cite the relevant concept in the manual's terms, and add one sentence of practical application where appropriate. Do not leave extra-credit questions blank; they exist to help you.

Sequencing the Domains in Your Prep

Rather than a generic schedule, order your study by dependency. Domain 1 gives you the legal vocabulary the other four rely on, so it comes first. Domain 2 comes second because billing is where most real-world compliance failures originate, and Domain 3 then teaches you how to respond to them. Domains 4 and 5 are narrower and benefit from the context built earlier. A fuller approach is laid out in the CMCO study guide.

Week 1

Domain 1 and index-building

  • Read compliance-plan structure and enforcement laws
  • Start your tabbed index of terms
Week 2

Domain 2

  • Work through billing, coding, coverage, and reimbursement
  • Note every point where billing behavior triggers a Domain 1 law
Week 3

Domains 3 and 4

  • Practice scenario responses for risk and corrective action
  • Study exclusion screening and organizational impact
Week 4

Domain 5 and full review

  • Cover investigation tools and response procedures
  • Run through sample questions at our practice test site and revisit weak sections

Adjust the pace to your experience. A candidate with years of billing background may compress Domain 2, while someone new to healthcare administration should extend it. If you want to test your recall before the real exam, the question sets at CMCO Exam Prep are designed around these same content areas.

Where the Credential Fits Professionally

Because the program targets non-hospital settings, the natural audience is people working in physician practices, specialty clinics, and other outpatient organizations, often practice managers, billing leads, and administrators who have taken on compliance duties. For context on how this plays out in the market, see the overview of CMCO-related jobs, the salary guide, and the ROI analysis. Those articles discuss earnings and value qualitatively; no single figure should be treated as a guaranteed outcome.

Keep in mind the maintenance side too. Annual renewal requires 12 CEUs earned during the preceding year and $90 for a single PMI credential, so factor ongoing education into your long-term plan. If you want broader background on the credential itself, the CMCO certification overview and CMCO training pages cover it from different angles.

Frequently Asked Questions

Are the five CMCO domains officially weighted?

No. The five domains reproduce PMI's published curriculum section headings and are best used as study categories. They should not be presented as a separately weighted exam blueprint, so prepare across all five rather than guessing at percentages.

How many questions are on the CMCO exam and what score passes?

PMI's exam description specifies 85 regular questions plus four extra-credit questions, for 89 total presented. You have five hours, and a passing score is at least 70%.

Can I use my materials during the exam?

Yes. The exam is open book, and the CMCO course manual and all of your notes may be used. This makes well-organized, indexed notes one of the most valuable things you can prepare.

How long until I get my results?

The examinations are hand-graded by the instructor, and results typically arrive in four to six weeks. Plan around that timeline if you need the credential for a specific deadline.

What does it cost to earn and keep the credential?

The online certification package is $2,095 and includes instruction and the examination; it is a package price, not a standalone exam fee. Annual renewal requires 12 CEUs from the preceding year and $90 for a single PMI credential.

Ready to pass your CMCO exam?

Put this into practice with free CMCO questions across every exam domain.