CPHIMS Certification Exam — Questions and Answers
Question 1: During a go-live cutover, the project team discovers that a critical interface between the EHR and pharmacy system is failing. What is the FIRST action the implementation lead should take?
- Roll back to the legacy system immediately
- Escalate to the vendor's on-call support line
- Restart the interface engine server
- Activate the downtime procedures and notify clinical staff (Correct answer)
Correct answer: Activate the downtime procedures and notify clinical staff
Activating downtime procedures protects patient safety while the technical issue is investigated.
Question 2: LOINC codes are primarily used in clinical informatics to standardize the representation of:
- Procedure billing codes
- Drug names and dosages
- Laboratory tests, clinical observations, and clinical document names (Correct answer)
- Diagnoses and conditions
Correct answer: Laboratory tests, clinical observations, and clinical document names
LOINC (Logical Observation Identifiers Names and Codes) provides universal codes for labs, clinical measurements, and document types to enable consistent exchange.
Question 3: Under HIPAA, who bears ultimate accountability for ensuring a covered entity's compliance with security regulations?
- The CISO
- The organization's leadership/Board (Correct answer)
- The Privacy Officer
- The IT Department
Correct answer: The organization's leadership/Board
Ultimate accountability for HIPAA compliance rests with the organization's senior leadership and governing board, not individual staff roles.
Question 4: Which document formally defines the testing objectives, scope, approach, and schedule for a healthcare IT implementation?
- Test script
- Test plan (Correct answer)
- Test case
- Defect log
Correct answer: Test plan
A test plan is the comprehensive document that outlines the overall strategy, scope, resources, and schedule for the testing effort.
Question 5: Which implementation methodology is characterized by iterative development cycles, frequent stakeholder feedback, and adaptive planning?
- Critical path method
- Waterfall
- Agile/Scrum (Correct answer)
- PRINCE2
Correct answer: Agile/Scrum
Agile/Scrum uses short iterative sprints with continuous stakeholder collaboration and adaptive response to change.
Question 6: A hospital's population health management program relies MOST on which type of data integration?
- Real-time streaming of laboratory instrument results
- Aggregation of clinical, claims, social determinants, and patient-generated data across the care continuum (Correct answer)
- Integration of pharmacy and supply chain data only
- Integration of HR and payroll systems
Correct answer: Aggregation of clinical, claims, social determinants, and patient-generated data across the care continuum
Population health management requires aggregating diverse data—clinical, claims, social determinants, and patient-generated—to identify and manage health needs across a defined population.
Question 7: In healthcare IT governance, what does the principle of 'separation of duties' primarily protect against?
- Staff turnover
- Project scope creep
- Fraud, errors, and unauthorized system changes (Correct answer)
- Budget overruns
Correct answer: Fraud, errors, and unauthorized system changes
Separation of duties ensures no single individual controls all aspects of a critical process, reducing the risk of fraud, errors, and unauthorized modifications.
Question 8: Which cloud deployment model is MOST appropriate for a health system that requires strict data control but wants to share infrastructure costs across its affiliated hospitals?
- Public cloud
- Private cloud
- Hybrid cloud
- Community cloud (Correct answer)
Correct answer: Community cloud
A community cloud is shared among organizations with similar requirements (e.g., healthcare affiliates) and balances cost-sharing with data control.
Question 9: A project sponsor for an EHR implementation is BEST described as:
- The vendor's account representative
- The project manager who coordinates daily tasks
- The lead developer responsible for coding
- The executive who champions the project and provides resources (Correct answer)
Correct answer: The executive who champions the project and provides resources
The project sponsor is the senior executive who champions the initiative, secures funding, and removes organizational barriers.
Question 10: A nurse reports that a medication order placed in the EHR is not appearing in the pharmacy system 30 minutes after entry. Which system component should the support team investigate FIRST?
- The nurse's workstation network connectivity
- The pharmacy system's drug database
- The HL7 interface or integration engine transmitting orders (Correct answer)
- The EHR's clinical decision support rules
Correct answer: The HL7 interface or integration engine transmitting orders
A failure to transmit orders between systems most commonly points to an issue in the HL7 interface or integration engine.
Question 11: What is the primary goal of a healthcare organization's incident response plan (IRP) for a data breach?
- To immediately report all incidents to law enforcement
- To permanently delete all compromised data to prevent further exposure
- To identify which employees caused the breach and terminate them
- To contain the breach, eradicate the threat, recover systems, and fulfill notification obligations (Correct answer)
Correct answer: To contain the breach, eradicate the threat, recover systems, and fulfill notification obligations
An incident response plan guides an organization through contain-eradicate-recover phases while ensuring compliance with HIPAA breach notification and other regulatory obligations.
Question 12: A health system's strategic plan identifies patient engagement as a top priority. Which IT initiative BEST supports this goal?
- Network bandwidth expansion
- Patient portal with secure messaging and health record access (Correct answer)
- Legacy data archival project
- Internal staff scheduling system upgrade
Correct answer: Patient portal with secure messaging and health record access
A patient portal directly enables patient engagement by giving individuals access to their health information and communication tools.
Question 13: In IT governance, which committee is typically responsible for prioritizing and approving major health IT investments?
- Finance Audit Committee
- Medical Staff Committee
- IT Steering Committee (Correct answer)
- Quality Improvement Committee
Correct answer: IT Steering Committee
The IT Steering Committee brings together clinical, operational, and IT leaders to prioritize investments aligned with strategic objectives.
Question 14: A patient is discharged from a hospital after a cardiac event and receives follow-up care from a home health agency, followed by outpatient rehabilitation services. This coordinated approach to patient care across different healthcare settings is best described as which of the following?
- Fee-for-Service Model
- Continuum of Care (Correct answer)
- Integrated Delivery Network (IDN)
- Tertiary Care
Correct answer: Continuum of Care
The Continuum of Care refers to an integrated system of healthcare that guides and tracks a patient over time through a comprehensive array of services spanning all levels of intensity of care. This scenario, involving transition from an acute hospital stay to home health and then to outpatient services, is a classic example of the continuum of care model.
Question 15: A hospital is implementing a new Bar Code Medication Administration (BCMA) system to reduce medication errors. This is an example of leveraging health information technology to primarily improve which aspect of the healthcare environment?
- Physician credentialing
- Patient safety (Correct answer)
- Supply chain management
- Financial reimbursement
Correct answer: Patient safety
Health information technology, such as BCMA, electronic health records (EHRs), and computerized physician order entry (CPOE), plays a crucial role in improving patient safety by reducing the likelihood of human errors, such as medication errors and adverse drug events.
Question 16: A quality assurance analyst is assigned to test a new clinical decision support (CDS) alert module. The analyst is given the functional requirements but has no knowledge of the underlying code, database structure, or internal logic. They proceed to test by providing various inputs and verifying the outputs against the requirements. Which testing approach is being used?
- Grey-Box Testing
- Alpha Testing
- Black-Box Testing (Correct answer)
- White-Box Testing
Correct answer: Black-Box Testing
Black-box testing is a method of software testing that examines the functionality of an application without peering into its internal structures or workings. The tester is only concerned with the inputs and outputs of the software, which aligns with the described scenario.
Question 17: Which standard is MOST commonly used to represent clinical observations and measurements in healthcare data exchange?
- ICD-10-CM
- HL7 v2
- CPT
- LOINC (Correct answer)
Correct answer: LOINC
LOINC (Logical Observation Identifiers Names and Codes) is the universal standard for identifying clinical observations, laboratory tests, and measurements.
Question 18: A 'go/no-go' decision meeting held before a system go-live is used to?
- Determine whether the system is ready for production deployment (Correct answer)
- Finalize vendor contracts
- Assign post-go-live support roles
- Complete user acceptance sign-off
Correct answer: Determine whether the system is ready for production deployment
A go/no-go meeting formally evaluates readiness criteria and makes the decision to proceed with or delay the production launch.
Question 19: Which of the following best describes the concept of 'data integrity' in healthcare information security?
- Ensuring only authorized users can access data
- Ensuring data is encrypted during transmission
- Ensuring data is available when needed
- Ensuring data is accurate, complete, and has not been improperly altered (Correct answer)
Correct answer: Ensuring data is accurate, complete, and has not been improperly altered
Data integrity ensures that health information is accurate, complete, and protected from unauthorized modification, forming a key pillar of the CIA (Confidentiality, Integrity, Availability) triad.
Question 20: During EHR implementation testing, clinical staff report that the system workflow does not match actual clinical processes. This represents which type of issue?
- Data integrity error
- Security vulnerability
- Technical defect
- Workflow fit gap (Correct answer)
Correct answer: Workflow fit gap
A workflow fit gap occurs when the system's built-in processes do not align with the organization's actual clinical workflows, requiring configuration or process redesign.
Question 21: Which of the following is an example of an 'addressable' implementation specification under the HIPAA Security Rule?
- Automatic logoff (Correct answer)
- Integrity controls
- Access control
- Audit controls
Correct answer: Automatic logoff
Automatic logoff is an addressable implementation specification, meaning covered entities must assess whether it is a reasonable and appropriate safeguard given their environment and document their decision.
Question 22: Which standard is primarily used to define the structure for exchanging clinical documents such as discharge summaries in healthcare interoperability?
- X12 EDI
- HL7 CDA (Clinical Document Architecture) (Correct answer)
- DICOM
- IEEE 11073
Correct answer: HL7 CDA (Clinical Document Architecture)
HL7 CDA defines the structure and semantics of clinical documents for exchange, making it the primary standard for structured clinical document sharing.
Question 23: A Chief Information Officer (CIO) wants to present a holistic view of the IT department's performance to the executive board, moving beyond purely technical metrics like server uptime. They want to demonstrate how IT contributes to clinical quality, financial performance, and user satisfaction. Which framework would be most suitable for this purpose?
- The HIPAA Security Rule
- The System Development Life Cycle (SDLC)
- The ITIL Framework
- The Balanced Scorecard (Correct answer)
Correct answer: The Balanced Scorecard
The Balanced Scorecard is a strategic management framework used to provide a comprehensive view of organizational performance by measuring it across multiple perspectives, typically including Financial, Customer, Internal Business Processes, and Learning and Growth. This allows the CIO to translate IT activities into tangible contributions to the organization's broader strategic goals.
Question 24: A hospital's EHR is offline for a planned 6-hour upgrade. During this period, clinicians must revert to paper forms for orders, medication administration, and clinical notes. What is the MOST critical component that must be in place to ensure patient safety and operational continuity?
- A detailed and well-rehearsed downtime procedure (Correct answer)
- An overtime budget for data re-entry
- A post-downtime user satisfaction survey
- A communication plan for the local news media
Correct answer: A detailed and well-rehearsed downtime procedure
A comprehensive downtime procedure is essential for maintaining patient safety and continuity of care when an EHR is unavailable. This plan outlines specific manual workflows, documentation methods, and communication protocols. While other items like a re-entry budget and surveys are useful, the immediate safety and operational aspect hinges on a clear, practiced downtime procedure.
Question 25: Which regulatory body enforces HIPAA Privacy and Security Rules against covered entities?
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Centers for Medicare & Medicaid Services
- The Joint Commission
- Food and Drug Administration
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the federal agency responsible for enforcing HIPAA Privacy, Security, and Breach Notification Rules.
Question 26: Which type of analytics uses historical healthcare data to describe what has already happened?
- Descriptive analytics (Correct answer)
- Cognitive analytics
- Prescriptive analytics
- Predictive analytics
Correct answer: Descriptive analytics
Descriptive analytics summarizes past data—such as patient volumes, readmission rates, or revenue trends—to answer the question 'What happened?'
Question 27: Under the CMS Promoting Interoperability program, which capability was required for eligible hospitals to support patient access to their health information?
- Real-time pharmacy benefit checking
- Automated prior authorization submission
- Provider directory publication via FHIR
- Patient Electronic Access via certified EHR technology (Correct answer)
Correct answer: Patient Electronic Access via certified EHR technology
CMS Promoting Interoperability requires hospitals to provide patients electronic access to their health information through certified EHR technology.
Question 28: A hospital's IT governance committee is reviewing a proposal to adopt a SaaS EHR. Which risk is UNIQUE to SaaS compared to on-premises deployment?
- Need to maintain server hardware
- Requirement to manage OS patching
- Dependence on vendor for uptime, updates, and data access (Correct answer)
- Need to procure data center physical space
Correct answer: Dependence on vendor for uptime, updates, and data access
SaaS transfers infrastructure management to the vendor, creating dependency on the vendor's availability, update schedule, and data portability policies.
Question 29: As part of its HIPAA-mandated contingency plan, a healthcare clinic must regularly test its ability to recover data and resume operations after a simulated disaster. What is the PRIMARY purpose of this requirement?
- To train new IT staff on emergency procedures.
- To satisfy auditor requirements for a yearly review.
- To validate the effectiveness of the disaster recovery plan and identify gaps. (Correct answer)
- To determine the budget for new backup hardware.
Correct answer: To validate the effectiveness of the disaster recovery plan and identify gaps.
The primary purpose of regularly testing a disaster recovery plan is to ensure it is effective and will work as intended during an actual emergency. Testing validates procedures, recovery time objectives (RTOs), and the integrity of backed-up data, allowing the organization to identify and address any weaknesses or gaps before a real disaster strikes.
Question 30: In health informatics, which type of study design provides the HIGHEST level of evidence for evaluating the effectiveness of a health IT intervention?
- Case-control study
- Randomized Controlled Trial (RCT) (Correct answer)
- Cohort study
- Cross-sectional survey
Correct answer: Randomized Controlled Trial (RCT)
RCTs provide the strongest evidence by randomly assigning participants to intervention and control groups, minimizing bias.
Question 31: A CPHIMS professional is asked to justify an infrastructure upgrade. Which document best communicates business value to executive leadership?
- Technical specification document
- Risk register
- Business case with cost-benefit analysis (Correct answer)
- Project charter only
Correct answer: Business case with cost-benefit analysis
A business case with cost-benefit analysis presents financial justification, strategic alignment, and risk considerations in terms executives can evaluate.
Question 32: A Chief Information Officer (CIO) wants to demonstrate the value of IT investments beyond just financial metrics. They implement a performance management framework that tracks metrics across four key areas: Financial, Customer (Patient), Internal Processes, and Learning & Growth. This approach allows for a more holistic view of IT's contribution to the organization's strategic goals. Which framework is the CIO using?
- Balanced Scorecard (Correct answer)
- ITIL (Information Technology Infrastructure Library)
- Project Management Body of Knowledge (PMBOK)
- COBIT (Control Objectives for Information and Related Technologies)
Correct answer: Balanced Scorecard
The Balanced Scorecard is a strategic performance management framework that provides a comprehensive view of an organization by measuring performance across four key perspectives: Financial, Customer, Internal Processes, and Learning & Growth. This method is specifically designed to move beyond purely financial measures to align initiatives with overall strategy.
Question 33: During the SDLC analysis phase, which technique gathers information by observing users perform their actual job tasks?
- Benchmarking
- Workflow observation (Correct answer)
- Prototyping
- Joint application design (JAD)
Correct answer: Workflow observation
Workflow observation involves watching users perform tasks in their environment to capture real requirements that may not surface in interviews.
Question 34: A hospital is preparing for a major EHR implementation. The project team identifies respected clinicians and operational staff to receive advanced training. During the go-live, these individuals will provide at-the-elbow assistance to their colleagues, answer workflow questions, and act as a bridge between end-users and the IT project team. This role is best known as a:
- Project Manager
- Vendor Representative
- Clinical Analyst
- Super User (Correct answer)
Correct answer: Super User
A Super User is a specially trained end-user from a clinical or operational department who acts as a frontline resource for their peers during a system implementation. Their primary role is to provide immediate support, reinforce correct workflows, and champion the new system. A Project Manager oversees the entire project, a Clinical Analyst is typically an IT professional who helps design and configure the system, and a Vendor Representative is an employee of the software company.
Question 35: An IT steering committee is evaluating several proposed projects, including a CPOE upgrade, a new patient portal, and a data warehouse for analytics. Which of the following criteria is MOST important for prioritizing these projects within the IT portfolio?
- The estimated cost and budget requirements of each project in isolation.
- The technical complexity and difficulty of each project.
- Alignment with the organization's strategic objectives and potential business value. (Correct answer)
- The personal preference and influence of the Chief Information Officer (CIO).
Correct answer: Alignment with the organization's strategic objectives and potential business value.
Effective IT portfolio management prioritizes projects based on their alignment with the organization's strategic goals and their potential to deliver business value. While cost, complexity, and leadership input are factors, the primary driver for prioritization in a well-governed organization is ensuring that limited resources are allocated to initiatives that best support the overall mission.
Question 36: In healthcare IT project management, a RACI matrix defines:
- Roles as Responsible, Accountable, Consulted, and Informed (Correct answer)
- Resource Allocation, Cost, and Integration factors
- Risk, Assumption, Constraint, and Issue categories
- Requirements, Architecture, Coding, and Integration phases
Correct answer: Roles as Responsible, Accountable, Consulted, and Informed
A RACI matrix clarifies team member roles by designating who is Responsible, Accountable, Consulted, and Informed for each project task.
Question 37: A hospital seeking Magnet Recognition from the American Nurses Credentialing Center (ANCC) must demonstrate excellence in which domain?
- Financial sustainability and revenue cycle performance
- Physician recruitment and retention strategies
- Electronic health record implementation only
- Nursing practice, leadership, and patient outcomes (Correct answer)
Correct answer: Nursing practice, leadership, and patient outcomes
Magnet Recognition designates hospitals that demonstrate excellence in nursing practice, transformational leadership, structural empowerment, and superior patient outcomes.
Question 38: What issue is causing the most worry for healthcare management as more consumers and professionals access healthcare information online?
- Email communications
- Privacy (Correct answer)
- Web page development
- Usage
Correct answer: Privacy
As healthcare information becomes increasingly accessible online for both consumers and professionals, privacy concerns become paramount. Healthcare organizations must ensure the confidentiality and security of sensitive patient data, complying with regulations like HIPAA. The risk of data breaches, unauthorized access, and misuse of personal health information is a major worry, necessitating robust security measures and strict privacy policies.
Question 39: What is the primary purpose of the Medicare Severity Diagnosis Related Group (MS-DRG) system?
- To rank hospitals by patient satisfaction scores
- To determine outpatient visit reimbursement under the physician fee schedule
- To classify inpatient hospital cases into groups for standardized payment (Correct answer)
- To assess nursing home quality for five-star ratings
Correct answer: To classify inpatient hospital cases into groups for standardized payment
MS-DRGs classify inpatient cases into clinically coherent groups with similar resource utilization to establish fixed prospective payment amounts for Medicare.
Question 40: A lab system upgrade causes the medication reconciliation module to malfunction unexpectedly. What testing should have caught this?
- Unit testing
- User acceptance testing
- Regression testing (Correct answer)
- Volume testing
Correct answer: Regression testing
Regression testing after the lab system upgrade should have validated that the medication reconciliation module continued to function correctly.
Question 41: When conducting an IT risk assessment in a healthcare setting, which asset type typically requires the HIGHEST protection priority?
- Employee payroll systems
- Marketing databases
- Financial reporting systems
- Electronic Protected Health Information (ePHI) (Correct answer)
Correct answer: Electronic Protected Health Information (ePHI)
ePHI is subject to HIPAA regulations and represents the highest-priority asset due to patient privacy rights and significant regulatory penalties for breaches.
Question 42: Which ITIL (Information Technology Infrastructure Library) process is primarily concerned with restoring normal service operation as quickly as possible following an unplanned interruption and minimizing the adverse impact on business operations?
- Change Management
- Service Level Management
- Problem Management
- Incident Management (Correct answer)
Correct answer: Incident Management
The primary objective of the ITIL Incident Management process is to restore IT service to users as quickly as possible after an unplanned event to minimize business impact. Problem Management focuses on finding the root cause of incidents, Change Management controls the lifecycle of changes, and Service Level Management deals with negotiating and monitoring service level agreements.
Question 43: When managing vendor relationships strategically, which practice ensures long-term value alignment?
- Avoiding multi-year contracts
- Delegating all vendor management to procurement
- Selecting vendors solely on lowest bid
- Regular performance reviews tied to SLA metrics and strategic goals (Correct answer)
Correct answer: Regular performance reviews tied to SLA metrics and strategic goals
Regular SLA-based performance reviews ensure vendors deliver ongoing value aligned with organizational strategy, not just contractual minimums.
Question 44: A new CMIO and CIO have conflicting visions for the EHR optimization roadmap. What is the MOST effective resolution strategy?
- Escalate to the board immediately
- Delay all EHR work until agreement is reached
- Allow each leader to implement their preferred approach separately
- Co-develop a unified roadmap prioritized by patient care and operational outcomes (Correct answer)
Correct answer: Co-develop a unified roadmap prioritized by patient care and operational outcomes
Co-developing a unified roadmap grounded in shared organizational outcomes resolves leadership conflict while maintaining strategic coherence.
Question 45: The critical path in a project schedule is BEST defined as:
- The list of highest-risk activities in the project
- The longest duration path of dependent tasks that determines project end date (Correct answer)
- The sequence of tasks with the most budget allocated
- Tasks assigned to the most senior team members
Correct answer: The longest duration path of dependent tasks that determines project end date
The critical path is the longest sequence of dependent tasks; any delay on these tasks directly delays the overall project completion date.
Question 46: What term describes the SDLC approach where all phases are completed in strict sequence before moving to the next?
- Waterfall (Correct answer)
- Agile
- Spiral
- Iterative
Correct answer: Waterfall
The Waterfall model follows a linear, sequential approach where each phase must be completed before the next begins.
Question 47: In healthcare, 'utilization management' primarily involves:
- Auditing financial statements for regulatory compliance
- Managing the physical space and equipment in clinical departments
- Tracking employee attendance and shift scheduling
- Reviewing the necessity, appropriateness, and efficiency of healthcare services (Correct answer)
Correct answer: Reviewing the necessity, appropriateness, and efficiency of healthcare services
Utilization management evaluates the medical necessity and appropriateness of healthcare services at various stages—before, during, and after care delivery—to ensure efficient resource use.
Question 48: Which of the following is a primary goal of applying usability principles, such as those developed by Jakob Nielsen, to the design of a new electronic health record (EHR) system?
- To guarantee the system can be accessed from any mobile device.
- To decrease the financial cost of system development and implementation.
- To reduce the cognitive load on clinicians and minimize the risk of errors. (Correct answer)
- To ensure the system meets all regulatory requirements for data security.
Correct answer: To reduce the cognitive load on clinicians and minimize the risk of errors.
A core objective of usability is to create systems that are effective, efficient, and satisfying for users. In healthcare, this translates to designing EHRs that are intuitive, reduce the mental effort (cognitive load) required to perform tasks, and prevent errors, thereby enhancing patient safety and clinician satisfaction.
Question 49: In the US healthcare system, what is the primary role of a Federally Qualified Health Center (FQHC)?
- To provide specialty care to insured patients only
- To coordinate Medicare Advantage plans
- To offer comprehensive primary care to underserved populations regardless of ability to pay (Correct answer)
- To manage electronic health records for rural hospitals
Correct answer: To offer comprehensive primary care to underserved populations regardless of ability to pay
FQHCs are community-based healthcare providers that receive federal funding to provide primary care services in underserved areas on a sliding-fee scale.
Question 50: A healthcare organization is selecting between a big-bang and a phased implementation approach. Which scenario BEST supports choosing a big-bang strategy?
- The system involves multiple hospitals with varying workflows
- The vendor requires an 18-month implementation timeline
- End users have minimal technical experience
- All departments share a single standardized workflow and the system is replacing a critically failing legacy system (Correct answer)
Correct answer: All departments share a single standardized workflow and the system is replacing a critically failing legacy system
A big-bang approach is best when workflows are uniform and the urgency of replacing a failing system outweighs phased risk management.
Question 51: A healthcare IT governance framework should include mechanisms for which of the following to be most effective?
- End-user training programs
- Vendor relationship management only
- Decision rights, accountability structures, and performance metrics (Correct answer)
- Technology trend monitoring only
Correct answer: Decision rights, accountability structures, and performance metrics
Effective IT governance requires clearly defined decision rights, accountability structures, and performance metrics to function as a system of organizational control.
Question 52: A CMIO is implementing a sepsis early warning algorithm in the EHR. Which ethical concern is MOST critical when deploying predictive algorithms in clinical care?
- Algorithmic bias leading to disparate outcomes across patient populations (Correct answer)
- Vendor contract terms for the algorithm's intellectual property
- Hardware costs for running machine learning models
- Increased alert fatigue from all notification systems
Correct answer: Algorithmic bias leading to disparate outcomes across patient populations
Algorithmic bias can cause predictive models to perform differently across racial, socioeconomic, or demographic groups, leading to health disparities.
Question 53: Which type of system interface standard is commonly used in healthcare to exchange patient data between systems during implementation?
- ODBC
- REST
- SOAP
- HL7 (Correct answer)
Correct answer: HL7
HL7 (Health Level 7) is the primary healthcare interoperability standard for exchanging clinical and administrative data between systems.
Question 54: Which IT management approach emphasizes continuous service improvement through defined processes, roles, and metrics?
- ITIL (Information Technology Infrastructure Library) (Correct answer)
- Waterfall development
- Agile Scrum
- Six Sigma manufacturing
Correct answer: ITIL (Information Technology Infrastructure Library)
ITIL is a framework specifically designed for IT service management that emphasizes process-driven continuous service improvement.
Question 55: The Leapfrog Group is best known for which activity in the US healthcare environment?
- Administering the CPHIMS examination
- Accrediting healthcare information professionals
- Setting federal EHR certification standards
- Publicly reporting hospital safety and quality scores (Correct answer)
Correct answer: Publicly reporting hospital safety and quality scores
The Leapfrog Group is an employer-driven coalition that publicly reports hospital performance data to improve transparency, safety, and quality.
Question 56: A hospital CIO is developing a 3-year IT strategic plan. Which framework best aligns IT goals with organizational mission?
- PESTLE analysis only
- Balanced Scorecard (Correct answer)
- Gap analysis only
- SWOT analysis only
Correct answer: Balanced Scorecard
The Balanced Scorecard aligns IT objectives with financial, customer, internal process, and learning perspectives tied to organizational mission.
Question 57: In healthcare data analytics, 'data governance' PRIMARILY refers to:
- Archiving old records to reduce storage costs
- Policies and processes ensuring data quality, security, and appropriate use across the organization (Correct answer)
- Limiting data access to only IT administrators
- Encrypting all patient data at rest
Correct answer: Policies and processes ensuring data quality, security, and appropriate use across the organization
Data governance establishes the policies, standards, roles, and responsibilities that ensure healthcare data is accurate, consistent, secure, and used appropriately.
Question 58: Which of the following is a characteristic of a Preferred Provider Organization (PPO) that distinguishes it from an HMO?
- Members can see out-of-network providers at higher cost without a referral (Correct answer)
- Coverage is only available for preventive services
- Premiums are always lower than HMO premiums
- Members must select a primary care physician gatekeeper
Correct answer: Members can see out-of-network providers at higher cost without a referral
PPOs allow members to visit out-of-network providers without a referral, though at a higher cost-sharing level than in-network care, providing greater flexibility than HMOs.
Question 59: Which practice helps prevent unauthorized changes to production code by requiring a second reviewer to approve code before deployment?
- Regression testing
- Code review/peer review (Correct answer)
- Waterfall gating
- Pair programming
Correct answer: Code review/peer review
Code peer review requires a second developer to review and approve changes before they are merged or deployed to production.
Question 60: To further pinpoint potential system abuse, a healthcare institution has integrated application audit recording and reporting. Which of the following authorization tactics should yield the MOST valuable audit data while reducing false-positive outcomes?
- Implement role-based authorization (Correct answer)
- Grant specific user-level privileges for services as required.
- Implement group-based authorization
- Grant specific user-level privileges to each service.
Correct answer: Implement role-based authorization
Role-based authorization (RBA) assigns permissions based on a user's job function or role within the organization, rather than individual user-level privileges. This approach ensures that users only have access to the information and functions necessary for their specific duties, thereby reducing the likelihood of unauthorized access or actions. When auditing, RBA makes it easier to identify deviations from expected behavior for a given role, providing more meaningful data and minimizing false positives compared to managing individual user-level privileges.
Question 61: The 'five rights' of clinical decision support (5 Rights of CDS) include delivering the right information to the right person EXCEPT which of the following?
- At the right time in workflow
- At the right cost to the hospital (Correct answer)
- Through the right channel
- In the right intervention format
Correct answer: At the right cost to the hospital
The 5 Rights of CDS focus on information, person, format, channel, and workflow timing—cost is not one of the five rights.
Question 62: Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
- Medical record numbers
- De-identified patient data released per Safe Harbor method (Correct answer)
- Patient name combined with diagnosis
- Dates of service tied to a patient
Correct answer: De-identified patient data released per Safe Harbor method
Data de-identified using the Safe Harbor method (removing all 18 identifiers) is no longer considered PHI under HIPAA.
Question 63: What is the main benefit of employing radiology information systems and medical imaging systems?
- The ability to track patient exams
- The ability to view images (Correct answer)
- The ability to input patient symptoms
- The ability to make a diagnosis
Correct answer: The ability to view images
The primary benefit of Radiology Information Systems (RIS) and medical imaging systems is their ability to capture, store, and display high-quality medical images (e.g., X-rays, MRIs, CT scans). This direct visualization is crucial for diagnosis, treatment planning, and monitoring patient conditions. While other benefits exist, the core function and main advantage revolve around the efficient management and viewing of these critical diagnostic images.
Question 64: Which concept describes the ability of a healthcare IT system to increase capacity by adding more servers rather than upgrading existing ones?
- Vertical scaling
- Elastic provisioning
- Horizontal scaling (Correct answer)
- Load balancing
Correct answer: Horizontal scaling
Horizontal scaling (scale-out) adds more servers to distribute load, whereas vertical scaling upgrades the existing server's resources.
Question 65: The concept of 'minimum necessary' data access in healthcare information systems is MOST directly linked to:
- CMS Conditions of Participation
- TEFCA exchange framework
- HIPAA Privacy Rule (Correct answer)
- Meaningful Use Stage 2
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule establishes that covered entities may only access, use, or disclose the minimum amount of PHI necessary to accomplish the intended purpose.
Question 66: A hospital implements a sepsis alert that triggers when lactate > 2 mmol/L AND systolic BP < 90 mmHg. This type of CDS logic is called:
- Single-parameter threshold alert
- Drug-drug interaction alert
- Passive reference recommendation
- Multi-condition composite rule (Correct answer)
Correct answer: Multi-condition composite rule
Multi-condition composite rules combine multiple clinical parameters using Boolean logic to improve alert specificity and reduce false-positive rates.
Question 67: A hospital contracts with a third-party cloud storage provider to archive its electronic health records (EHR). The provider guarantees the data will be encrypted at rest. Under HIPAA, what is the most critical document the hospital must have in place with this vendor before transferring any Protected Health Information (PHI)?
- Business Associate Agreement (BAA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Service Level Agreement (SLA)
- Data Use Agreement (DUA)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and a business associate. It establishes the vendor's responsibility to protect PHI in accordance with HIPAA guidelines. While an SLA, NDA, or DUA may also be used, the BAA is the specific, legally mandated contract for this relationship.
Question 68: Which of the following does a clinical informatics worker in an acute care setting normally NOT need to have knowledge of or experience with?
- population health
- clinical medicine
- computer science
- quantitative statistics (Correct answer)
Correct answer: quantitative statistics
Clinical informatics workers in acute care settings primarily focus on the application of information technology to improve patient care, requiring knowledge of clinical medicine, computer science, and population health to understand data trends and system implementation. While data analysis is involved, deep expertise in advanced quantitative statistics is typically not a core requirement for their day-to-day operational roles, which often lean more towards system design, implementation, and user support.
Question 69: A healthcare IT professional implements two-factor authentication (2FA) for EHR access. Which security principle does this PRIMARILY support?
- Non-repudiation
- Data availability
- Authentication assurance (Correct answer)
- Data integrity
Correct answer: Authentication assurance
Two-factor authentication strengthens authentication assurance by requiring users to prove identity through two independent factors, reducing the risk of unauthorized access from stolen credentials.
Question 70: Which entity is responsible for publishing and maintaining Current Procedural Terminology (CPT) codes?
- National Committee for Quality Assurance
- Centers for Medicare & Medicaid Services
- American Health Information Management Association
- American Medical Association (Correct answer)
Correct answer: American Medical Association
CPT codes are owned and maintained by the American Medical Association (AMA) and are used to describe medical, surgical, and diagnostic services for billing purposes.
Question 71: When building a healthcare analytics report, stratifying patient outcomes by age, gender, and race PRIMARILY supports:
- Vendor performance evaluation
- Staff scheduling optimization
- Billing accuracy and claim submission rates
- Health equity analysis to identify and address disparate outcomes (Correct answer)
Correct answer: Health equity analysis to identify and address disparate outcomes
Stratifying outcomes by demographic factors allows organizations to identify disparities in care and take targeted action to promote health equity.
Question 72: In healthcare IT, a project management office (PMO) is PRIMARILY responsible for:
- Negotiating vendor contracts for all departments
- Providing direct patient care support tools
- Managing the hospital's operational IT help desk
- Standardizing project governance, methodologies, and oversight across the organization (Correct answer)
Correct answer: Standardizing project governance, methodologies, and oversight across the organization
A PMO establishes standardized processes, governance frameworks, and oversight to ensure consistent project delivery across the healthcare organization.
Question 73: What is the primary function of a Health Information Service Provider (HISP) in the Direct Secure Messaging ecosystem?
- To provide the security and transport infrastructure for sending and receiving Direct messages (Correct answer)
- To manage patient consent for data sharing across organizations
- To store all exchanged clinical documents in a regional repository
- To validate clinical content for accuracy before transmission
Correct answer: To provide the security and transport infrastructure for sending and receiving Direct messages
A HISP provides the technical infrastructure, including security certificates and message routing, that enables healthcare entities to send and receive Direct Secure Messages.
Question 74: Which CPHIMS domain concept involves tracking and managing all hardware and software assets throughout their lifecycle?
- Incident management
- Change management
- IT asset management (Correct answer)
- Problem management
Correct answer: IT asset management
IT asset management tracks and optimizes hardware and software assets from acquisition through disposal to ensure cost-effective and compliant use.
Question 75: Six months after a new telehealth platform went live, the health IT team is actively monitoring system performance, applying security patches, resolving user-reported help desk tickets, and planning for a minor version upgrade. These ongoing activities are characteristic of which SDLC phase?
- Design
- Implementation
- Maintenance and Evaluation (Correct answer)
- Planning
Correct answer: Maintenance and Evaluation
The Maintenance and Evaluation phase begins after the system is deployed. It involves the ongoing support, monitoring, and enhancement of the system throughout its operational life to ensure it continues to function correctly, securely, and effectively.
Question 76: In portfolio management, what does 'value realization' refer to in a health IT context?
- Confirming that implemented systems deliver the projected benefits (Correct answer)
- Tracking project completion dates
- Measuring IT staff productivity
- Calculating software license costs
Correct answer: Confirming that implemented systems deliver the projected benefits
Value realization confirms that post-implementation outcomes match the projected benefits outlined in the original business case.
Question 77: A clinical informaticist is asked to evaluate why nurses skip structured data fields and free-text their assessments. The MOST appropriate first step is:
- Remove the free-text option
- Retrain all nurses on documentation standards
- Mandate structured field use through system settings
- Observe nurses in their workflow to understand the root cause (Correct answer)
Correct answer: Observe nurses in their workflow to understand the root cause
Observing clinicians in real workflows (contextual inquiry) reveals true barriers to structured documentation that surveys or audits may miss.
Question 78: During the final stage of testing for a new telehealth platform, a group of nurses and physicians is asked to use the system in a simulated environment that mirrors their actual clinic workflow. They follow test scripts to schedule appointments, conduct video visits, and document encounters to ensure the system meets their operational needs. This type of testing is called:
- Unit Testing
- User Acceptance Testing (UAT) (Correct answer)
- Integration Testing
- Regression Testing
Correct answer: User Acceptance Testing (UAT)
User Acceptance Testing (UAT) is the final phase of testing where end-users validate that the system meets business requirements and is suitable for the production environment. It focuses on real-world scenarios and workflows from the user's perspective. Unit testing checks individual components, integration testing verifies that modules work together, and regression testing ensures new changes haven't broken existing functionality.
Question 79: Which data exchange framework, developed by CommonWell Health Alliance and Carequality, focuses on establishing trust between different HIE networks to enable broad nationwide data sharing?
- The eHealth Exchange
- The Commonwell-Carequality Bridge (Correct answer)
- The Strategic Health IT Advanced Research Projects (SHARP)
- The Patient Unified Lookup System for Emergencies (PULSE)
Correct answer: The Commonwell-Carequality Bridge
The CommonWell-Carequality Bridge connects the two largest national interoperability networks, enabling their combined participants to exchange health information regardless of which network they belong to.
Question 80: Which visualization type is BEST suited for showing a trend in hospital-acquired infection rates over 12 months?
- Heat map
- Pie chart
- Line chart (Correct answer)
- Scatter plot
Correct answer: Line chart
A line chart is the most effective visualization for displaying trends in a continuous metric over time.
Question 81: Which activity is MOST critical during the cutover planning phase to ensure business continuity if the new system fails immediately after go-live?
- Vendor contract renegotiation
- Final user training completion
- Downtime and rollback procedure documentation and testing (Correct answer)
- Post-implementation benefit realization analysis
Correct answer: Downtime and rollback procedure documentation and testing
Documented and tested downtime and rollback procedures ensure the organization can revert safely if critical failures occur at go-live.
Question 82: Under value-based purchasing (VBP), Medicare withholds a percentage of DRG payments and redistributes them based on what?
- Hospital size and teaching status
- Number of patients served
- Performance scores on quality and patient experience measures (Correct answer)
- Percentage of uncompensated care provided
Correct answer: Performance scores on quality and patient experience measures
CMS withholds a portion of base DRG payments and returns them—potentially with bonuses—based on hospitals' Total Performance Scores across multiple quality domains.
Question 83: Which access control model assigns permissions based on a user's role within an organization rather than individual identity?
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) grants permissions based on organizational roles, making it the most widely used model in healthcare IT systems.
Question 84: Which testing activity ensures that data migrated from a legacy system to a new EHR is complete, accurate, and properly formatted?
- Data migration validation testing (Correct answer)
- Security penetration testing
- User acceptance testing
- Performance testing
Correct answer: Data migration validation testing
Data migration validation testing specifically verifies that migrated data retains its integrity, completeness, and correct formatting in the new system.
Question 85: A nurse reviews a patient's vital signs in the EHR. The discrete values for heart rate (85 bpm), blood pressure (120/80 mmHg), and temperature (98.6°F) represent which level of the DIKW pyramid?
- Data (Correct answer)
- Information
- Knowledge
- Wisdom
Correct answer: Data
In the DIKW (Data, Information, Knowledge, Wisdom) pyramid, raw, discrete facts without context or interpretation are considered 'Data'. The individual vital sign measurements are raw data points. They only become 'Information' when they are organized and given context (e.g., trended over time, compared to normal ranges).
Question 86: What is the PRIMARY purpose of establishing a formal help desk ticketing system during and after a healthcare IT go-live?
- To systematically capture, prioritize, track, and resolve reported issues (Correct answer)
- To document vendor contract violations
- To bill end users for support services rendered
- To replace the need for superusers on the floors
Correct answer: To systematically capture, prioritize, track, and resolve reported issues
A ticketing system provides structured issue tracking that ensures problems are categorized, assigned, and resolved in a measurable and accountable manner.
Question 87: In healthcare IT, which approach BEST ensures business continuity when a critical application vendor discontinues support?
- Purchase extended support directly from the vendor
- Switch immediately to a manual paper-based process
- Continue using the unsupported software with enhanced monitoring
- Initiate a planned migration to a supported alternative system (Correct answer)
Correct answer: Initiate a planned migration to a supported alternative system
A planned migration to a supported system addresses the root risk (lack of security patches and vendor support) while maintaining operational continuity.
Question 88: In the US healthcare system, a 'never event' as defined by the National Quality Forum refers to:
- A medical procedure that has never been approved by the FDA
- A diagnosis code that cannot be assigned to an inpatient stay
- An insurance claim that is automatically denied on first submission
- A serious, largely preventable patient safety event that should never occur in a healthcare setting (Correct answer)
Correct answer: A serious, largely preventable patient safety event that should never occur in a healthcare setting
NQF defines 'never events' as serious reportable events that are unambiguous, serious, usually preventable, and of concern to the public and healthcare providers.
Question 89: Which SDLC phase produces the system architecture diagram and database schema?
- Analysis
- Planning
- Design (Correct answer)
- Testing
Correct answer: Design
The design phase translates requirements into technical blueprints including system architecture, database schemas, and interface designs.
Question 90: A healthcare organization experiences a ransomware attack that encrypts patient records. Under HIPAA Breach Notification Rule, when must affected individuals be notified?
- Within 24 hours of discovery
- Within 60 days of discovery (Correct answer)
- Within 90 days of discovery
- Within 30 days of discovery
Correct answer: Within 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach.
Question 91: A healthcare organization wants to evaluate whether its new patient portal meets usability standards. Which testing method is most appropriate?
- Regression testing
- Load testing
- Penetration testing
- Usability testing with representative end users (Correct answer)
Correct answer: Usability testing with representative end users
Usability testing with representative end users directly measures whether the system meets usability standards and user experience expectations.
Question 92: Under the HIPAA Privacy Rule, a patient's right to request an amendment to their health record applies when:
- The patient wants to delete all records older than 5 years
- The record contains information the patient believes is inaccurate or incomplete (Correct answer)
- The covered entity made the record available to a third party
- The patient disagrees with a clinical diagnosis
Correct answer: The record contains information the patient believes is inaccurate or incomplete
Patients have the right to request amendments to their PHI if they believe information in their record is incorrect or incomplete, though the covered entity may deny the request.
Question 93: What is the primary objective of the 'Testing' phase within the System Development Life Cycle (SDLC)?
- To verify that the system meets the documented requirements and to identify and resolve defects before go-live. (Correct answer)
- To develop the system's architecture and database schema.
- To deploy the system into the live production environment for end-user access.
- To provide initial training to super-users and clinical champions.
Correct answer: To verify that the system meets the documented requirements and to identify and resolve defects before go-live.
The Testing phase is a critical quality assurance step dedicated to verifying that the system functions as specified in the requirements documentation. It involves various types of testing (unit, integration, user acceptance) to find and fix bugs and ensure the system is stable and fit for purpose before deployment.
Question 94: Which approach to IT portfolio management BEST balances innovation with operational stability in healthcare?
- Investing only in maintenance of existing systems
- Maintaining a mix of run-the-business, grow-the-business, and transform-the-business investments (Correct answer)
- Prioritizing lowest-cost projects regardless of strategic value
- Focusing exclusively on transformational projects
Correct answer: Maintaining a mix of run-the-business, grow-the-business, and transform-the-business investments
A three-horizon portfolio approach balances keeping current systems operational while funding growth and transformational initiatives.
Question 95: The CPHIMS exam expects HIT professionals to understand that the 'V-model' of SDLC pairs each development phase with a corresponding?
- Design document
- Testing phase (Correct answer)
- User story
- Budget review
Correct answer: Testing phase
The V-model pairs each development phase (requirements, design, coding) with a corresponding testing phase to validate that phase's outputs.
Question 96: A hospital that participates in a Pioneer Accountable Care Organization (ACO) model primarily aims to:
- Increase patient volume through aggressive marketing
- Negotiate higher commercial insurance rates
- Reduce nurse-to-patient ratios to cut operational costs
- Improve care coordination and share in savings achieved below a spending benchmark (Correct answer)
Correct answer: Improve care coordination and share in savings achieved below a spending benchmark
ACOs coordinate care for an assigned Medicare population and share in any savings when total spending falls below a set benchmark while meeting quality thresholds.
Question 97: Which data governance role is primarily responsible for defining policies for data quality, access, and use within a specific business domain?
- Database administrator
- Data custodian
- Chief Information Officer
- Data steward (Correct answer)
Correct answer: Data steward
Data stewards own data quality and usage policies within their business domain and ensure compliance with governance standards.
Question 98: Which of the following best describes a Health Information Exchange (HIE)?
- A billing system that transmits claims electronically to payers
- A government database that stores all patient records nationally
- A private network used only within a single hospital system
- The electronic mobilization of health-related information according to nationally recognized standards (Correct answer)
Correct answer: The electronic mobilization of health-related information according to nationally recognized standards
An HIE enables the electronic sharing of health-related information across organizations according to nationally recognized standards to improve care coordination.
Question 99: A health system's IT department has numerous project requests, including a data warehouse upgrade, a new telehealth platform, a patient portal enhancement, and a cybersecurity overhaul. Due to limited financial and human resources, leaders must select, prioritize, and manage this collection of projects as a single entity to maximize their contribution to the organization's strategic goals. This process is known as:
- Program Management
- System Development Life Cycle (SDLC)
- IT Service Management (ITSM)
- Project Portfolio Management (PPM) (Correct answer)
Correct answer: Project Portfolio Management (PPM)
Project Portfolio Management (PPM) is the centralized management of the processes, methods, and technologies used by project managers and project management offices (PMOs) to analyze and collectively manage current or proposed projects based on numerous key characteristics. The key is managing a collection of projects to align with strategic business objectives and optimize resource allocation, which is exactly what the scenario describes.
Question 100: An implementation team is conducting parallel testing by running legacy and new systems simultaneously. What is the PRIMARY goal of this approach?
- To demonstrate vendor contract compliance
- To allow users to choose which system to use during the transition
- To compare outputs of both systems and confirm the new system produces accurate results before cutover (Correct answer)
- To reduce the cost of the new system implementation
Correct answer: To compare outputs of both systems and confirm the new system produces accurate results before cutover
Parallel testing compares real-world outputs from both systems to validate accuracy and build confidence before decommissioning the legacy system.
Question 101: When a hospital EHR project is experiencing scope creep, the project manager should FIRST:
- Approve all requested changes immediately to satisfy stakeholders
- Halt the project until original scope is restored
- Evaluate change requests through the formal change control process (Correct answer)
- Reassign team members to accommodate additional work
Correct answer: Evaluate change requests through the formal change control process
All scope changes must be evaluated through the formal change control process to assess impact on schedule, cost, and quality.
Question 102: In clinical informatics governance, the PRIMARY purpose of a clinical informatics committee is to:
- Manage vendor contract negotiations
- Align health information technology decisions with clinical priorities and safety (Correct answer)
- Conduct HIPAA compliance audits
- Approve IT infrastructure purchases
Correct answer: Align health information technology decisions with clinical priorities and safety
Clinical informatics committees bridge clinical and IT leadership to ensure technology decisions are driven by clinical needs, safety goals, and evidence.
Question 103: When building an IT strategic roadmap, what is the purpose of defining 'quick wins'?
- To reduce the overall project budget
- To identify underperforming staff
- To build stakeholder momentum and demonstrate early value (Correct answer)
- To eliminate long-term planning requirements
Correct answer: To build stakeholder momentum and demonstrate early value
Quick wins deliver visible early benefits that build credibility, maintain stakeholder support, and demonstrate progress toward strategic goals.
Question 104: A hospital is implementing a new EHR system and wants to test all interfaces between subsystems. Which type of testing is most appropriate?
- Stress testing
- Integration testing (Correct answer)
- Regression testing
- Unit testing
Correct answer: Integration testing
Integration testing validates that different subsystems and interfaces work correctly together as a combined system.
Question 105: In Agile SDLC, what is a 'sprint'?
- A performance benchmark test
- An emergency patch release
- A time-boxed iteration delivering working software (Correct answer)
- A type of regression test
Correct answer: A time-boxed iteration delivering working software
A sprint is a fixed-duration iteration (typically 1–4 weeks) in Agile during which a defined set of features is developed and delivered.
Question 106: During a large-scale EHR implementation, the project team decides to release functional modules in short, two-week cycles. Each cycle includes planning, design, building, and testing, and concludes with a stakeholder demonstration. This iterative and flexible approach to system development is best described as which methodology?
- Waterfall
- V-Model
- Agile (Correct answer)
- Spiral
Correct answer: Agile
The Agile methodology is characterized by its iterative and incremental approach. Projects are broken down into short cycles called sprints, which allows for flexibility, continuous feedback from stakeholders, and the ability to adapt to changing requirements throughout the development process.
Question 107: A health information management professional is tasked with ensuring that the organization's new electronic health record (EHR) system can exchange data with the local pharmacy's system. Which type of organization is primarily responsible for developing the standards that make this interoperability possible?
- Standards Development Organization (SDO) (Correct answer)
- Accreditation Body
- Healthcare Insurance Company
- Governmental Regulatory Agency
Correct answer: Standards Development Organization (SDO)
Standards Development Organizations (SDOs), such as HL7 and ISO, are responsible for creating, maintaining, and publishing standards that enable interoperability between different health information systems. These standards provide the common language and framework for data exchange.
Question 108: During EHR go-live, the system experiences significantly slower response times than during testing. Which type of testing was likely inadequate?
- Usability testing
- Regression testing
- Performance testing (Correct answer)
- Unit testing
Correct answer: Performance testing
Performance testing, including load and stress testing, should have identified response time degradation under realistic production volumes.
Question 109: What is the primary purpose of regression testing in a healthcare IT system?
- Validate system performance under peak load
- Test new features before deployment
- Ensure existing functionality still works after changes (Correct answer)
- Confirm user interface design meets requirements
Correct answer: Ensure existing functionality still works after changes
Regression testing ensures that previously working functions have not been broken by new code changes or system updates.
Question 110: Earned Value Management (EVM) uses which metrics to measure project performance?
- Planned Value, Earned Value, and Actual Cost (Correct answer)
- Budget, Schedule, and Quality baselines
- Scope, Time, and Cost variances only
- Return on Investment, Net Present Value, and Payback Period
Correct answer: Planned Value, Earned Value, and Actual Cost
EVM integrates Planned Value (PV), Earned Value (EV), and Actual Cost (AC) to objectively measure schedule and cost performance.
Question 111: What is an IT program management office's main responsibility?
- Create a comprehensive list of all IT projects being worked on at the company, and take responsibility for their completion.
- Provide executive leadership with a risk-managed enterprise project portfolio to keep them updated on the status of organizational initiatives. (Correct answer)
- Assemble an exhaustive list of all IT projects being worked on within an organization, and take responsibility for their execution.
- Manage resources, oversee project monitoring, and oversee direct administration of all IT projects for an organization.
Correct answer: Provide executive leadership with a risk-managed enterprise project portfolio to keep them updated on the status of organizational initiatives.
An IT Program Management Office (PMO) is responsible for overseeing multiple related projects and programs, ensuring they align with strategic organizational goals. Its primary role is to provide a holistic view of the IT project landscape to executive leadership, including progress, risks, and resource allocation. This strategic oversight helps executives make informed decisions and ensures that IT initiatives support the broader business objectives.
Question 112: A hospital is in the final stages of implementing a new electronic health record (EHR) system. Before the system goes live, a group of nurses, physicians, and registration staff are brought in to perform tasks in a mock environment that mirrors their actual workflows. What is this critical phase of testing called?
- Regression Testing
- User Acceptance Testing (UAT) (Correct answer)
- Integration Testing
- Unit Testing
Correct answer: User Acceptance Testing (UAT)
User Acceptance Testing (UAT) is the final phase of testing where end-users validate that the system meets their business requirements and can support their workflows before it is deployed to the production environment.
Question 113: What is the role of a Chief Privacy Officer (CPO) in a healthcare organization?
- Approving all vendor contracts involving data sharing
- Managing network security and firewall configurations
- Conducting penetration testing of clinical systems
- Overseeing compliance with privacy laws and policies governing patient information (Correct answer)
Correct answer: Overseeing compliance with privacy laws and policies governing patient information
The CPO is responsible for developing, implementing, and maintaining the organization's privacy program, ensuring compliance with applicable privacy laws and regulations.
Question 114: A healthcare IT project is considered in 'scope creep' when:
- Unauthorized features or work are added without going through change control (Correct answer)
- The budget is reduced mid-project by the sponsor
- The project finishes ahead of schedule
- Vendors deliver components earlier than planned
Correct answer: Unauthorized features or work are added without going through change control
Scope creep occurs when unapproved additions to the project scope accumulate without formal change control evaluation, threatening schedule and budget.
Question 115: The 'triple aim' framework developed by the Institute for Healthcare Improvement (IHI) includes improving population health, enhancing patient experience, AND:
- Increasing hospital market share
- Reducing per capita cost of care (Correct answer)
- Expanding the number of licensed providers
- Standardizing electronic health record platforms
Correct answer: Reducing per capita cost of care
IHI's Triple Aim framework focuses simultaneously on improving population health, enhancing patient experience of care, and reducing the per capita cost of healthcare.
CPHIMS Certification Exam
The CPHIMS (Certified Professional in Healthcare Information and Management Systems) exam validates competency in healthcare IT management, covering technology environments, systems lifecycle, and administration leadership.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds