CPHIMS IT Governance and Management Questions and Answers — Questions and Answers
Question 1: A health system's board of directors has established a five-year strategic goal to become a national leader in patient-centric telehealth services. What is the MOST critical first step for the IT governance body to ensure alignment with this goal?
- Develop an IT strategic plan that explicitly maps technology initiatives and resource allocation to the telehealth goal. (Correct answer)
- Immediately purchase the highest-rated telehealth platform available on the market to gain a first-mover advantage.
- Hire additional help desk staff to prepare for the increased volume of user support tickets related to new services.
- Conduct a comprehensive security audit of all existing network infrastructure to identify vulnerabilities.
Correct answer: Develop an IT strategic plan that explicitly maps technology initiatives and resource allocation to the telehealth goal.
The primary role of IT governance is to ensure that IT strategy aligns with and supports the overall business strategy. Before any purchasing decisions or tactical hiring occurs, a strategic plan must be developed to outline how IT will enable the organization's goals, ensuring that investments are prioritized and resources are allocated effectively.
Question 2: Which ITIL (Information Technology Infrastructure Library) process is primarily concerned with restoring normal service operation as quickly as possible following an unplanned interruption and minimizing the adverse impact on business operations?
- Change Management
- Problem Management
- Incident Management (Correct answer)
- Service Level Management
Correct answer: Incident Management
The primary objective of the ITIL Incident Management process is to restore IT service to users as quickly as possible after an unplanned event to minimize business impact. Problem Management focuses on finding the root cause of incidents, Change Management controls the lifecycle of changes, and Service Level Management deals with negotiating and monitoring service level agreements.
Question 3: During a risk assessment, a hospital's IT department identifies that its primary on-premise data center is located in a region prone to seismic activity. The risk is deemed to have a high potential impact. The organization establishes a contract with a cloud provider for Disaster-Recovery-as-a-Service (DRaaS). This action is an example of which risk response strategy?
- Risk Acceptance
- Risk Avoidance
- Risk Transference
- Risk Mitigation (Correct answer)
Correct answer: Risk Mitigation
Risk mitigation involves taking active steps to reduce the likelihood or impact of a potential threat. Implementing a DRaaS solution doesn't eliminate the risk of an earthquake (avoidance) or simply accept the consequences. While it has elements of shifting operational burden, its primary purpose is to reduce the impact (downtime, data loss) of a data center failure, which is a core mitigation activity.
Question 4: An IT steering committee is evaluating several proposed projects, including a CPOE upgrade, a new patient portal, and a data warehouse for analytics. Which of the following criteria is MOST important for prioritizing these projects within the IT portfolio?
- The technical complexity and difficulty of each project.
- Alignment with the organization's strategic objectives and potential business value. (Correct answer)
- The estimated cost and budget requirements of each project in isolation.
- The personal preference and influence of the Chief Information Officer (CIO).
Correct answer: Alignment with the organization's strategic objectives and potential business value.
Effective IT portfolio management prioritizes projects based on their alignment with the organization's strategic goals and their potential to deliver business value. While cost, complexity, and leadership input are factors, the primary driver for prioritization in a well-governed organization is ensuring that limited resources are allocated to initiatives that best support the overall mission.
Question 5: A Chief Information Officer (CIO) wants to present a holistic view of the IT department's performance to the executive board, moving beyond purely technical metrics like server uptime. They want to demonstrate how IT contributes to clinical quality, financial performance, and user satisfaction. Which framework would be most suitable for this purpose?
- The System Development Life Cycle (SDLC)
- The ITIL Framework
- The HIPAA Security Rule
- The Balanced Scorecard (Correct answer)
Correct answer: The Balanced Scorecard
The Balanced Scorecard is a strategic management framework used to provide a comprehensive view of organizational performance by measuring it across multiple perspectives, typically including Financial, Customer, Internal Business Processes, and Learning and Growth. This allows the CIO to translate IT activities into tangible contributions to the organization's broader strategic goals.
Question 6: What is the primary function of an IT Steering Committee within a healthcare organization's governance structure?
- To perform detailed security penetration testing on the network.
- To provide daily, hands-on technical support to end-users across the organization.
- To write and debug the code for new software applications and system interfaces.
- To ensure IT strategy aligns with business strategy and to approve major IT investments and priorities. (Correct answer)
Correct answer: To ensure IT strategy aligns with business strategy and to approve major IT investments and priorities.
The IT Steering Committee is a high-level governance body composed of senior business and IT leaders. Its primary role is to provide strategic direction, prioritize major IT projects and investments, and ensure that the IT department's efforts are aligned with the overall strategic goals of the healthcare organization.
A health system's board of directors has established a five-year strategic goal to become a national leader in patient-centric telehealth services.
What is the MOST critical first step for the IT governance body to ensure alignment with this goal?