CPE CPE Healthcare Technology & Innovation 2 — Questions and Answers
Question 1: When assessing the ROI of a health IT investment, which cost category is most frequently underestimated by physician executives?
- Software licensing fees
- Hardware procurement costs
- Implementation, training, and workflow redesign costs (Correct answer)
- Annual maintenance contracts
Correct answer: Implementation, training, and workflow redesign costs
Implementation, training, and workflow redesign costs are consistently the most underestimated because they involve significant organizational change beyond the technology purchase.
Question 2: A hospital's cybersecurity team reports a ransomware attack has encrypted EHR data. As the physician executive, what is the FIRST action?
- Pay the ransom to restore access quickly
- Activate the incident response plan and notify the CISO (Correct answer)
- Immediately notify all patients of the breach
- Shut down all hospital IT systems
Correct answer: Activate the incident response plan and notify the CISO
Activating the incident response plan and notifying the CISO is the immediate first step to coordinate a structured, legal, and clinically safe response.
Question 3: Which approach BEST describes a 'build vs. buy' analysis in healthcare technology decisions?
- Choosing whether to hire internal IT staff or outsource
- Evaluating total cost of ownership and strategic fit of custom development versus vendor solutions (Correct answer)
- Deciding between cloud and on-premise infrastructure
- Comparing two competing vendor products
Correct answer: Evaluating total cost of ownership and strategic fit of custom development versus vendor solutions
A build vs. buy analysis evaluates whether the organization should develop custom technology or purchase an existing vendor solution based on cost, timeline, and strategic alignment.
Question 4: What is the primary regulatory concern physician executives must address when using patient data to train internal AI models?
- ADA compliance requirements
- HIPAA minimum necessary standard and de-identification requirements (Correct answer)
- Joint Commission accreditation standards
- OSHA workplace safety rules
Correct answer: HIPAA minimum necessary standard and de-identification requirements
HIPAA requires that patient data used for purposes beyond direct care — such as AI model training — comply with minimum necessary standards and proper de-identification or authorization.
Question 5: A physician executive is designing a digital health equity initiative. Which data element is MOST critical to collect in the EHR to measure disparities?
- Insurance payer type
- Race, ethnicity, and preferred language (REaL data) (Correct answer)
- ZIP code of residence
- Primary care physician assignment
Correct answer: Race, ethnicity, and preferred language (REaL data)
Race, ethnicity, and language (REaL) data is the foundational dataset for identifying and measuring healthcare disparities across demographic groups.
Question 6: Which change management model is MOST applicable when leading a large-scale EHR implementation affecting hundreds of clinicians?
- Lewin's three-step model
- Kotter's 8-Step Change Model (Correct answer)
- The PDSA cycle
- Porter's Five Forces
Correct answer: Kotter's 8-Step Change Model
Kotter's 8-Step Change Model is widely used for large-scale organizational transformations because it provides a structured approach to creating urgency, building coalitions, and sustaining change.
When assessing the ROI of a health IT investment, which cost category is most frequently underestimated by physician executives?