CPHIMS CPHIMS IT Governance and Management 5 — Questions and Answers
Question 1: What is the primary function of an IT policy in healthcare governance?
- To document software code standards
- To establish mandatory rules guiding behavior and decision-making related to IT resources (Correct answer)
- To outline vendor service terms
- To provide IT training materials
Correct answer: To establish mandatory rules guiding behavior and decision-making related to IT resources
IT policies set mandatory organizational rules that govern how IT resources, data, and systems are used, managed, and protected.
Question 2: Which CPHIMS domain concept involves tracking and managing all hardware and software assets throughout their lifecycle?
- Change management
- IT asset management (Correct answer)
- Incident management
- Problem management
Correct answer: IT asset management
IT asset management tracks and optimizes hardware and software assets from acquisition through disposal to ensure cost-effective and compliant use.
Question 3: A healthcare IT governance framework should include mechanisms for which of the following to be most effective?
- Technology trend monitoring only
- Decision rights, accountability structures, and performance metrics (Correct answer)
- Vendor relationship management only
- End-user training programs
Correct answer: Decision rights, accountability structures, and performance metrics
Effective IT governance requires clearly defined decision rights, accountability structures, and performance metrics to function as a system of organizational control.
Question 4: In a healthcare organization, which process ensures that IT systems meet defined performance standards before go-live?
- Needs assessment
- User acceptance testing (UAT) (Correct answer)
- Gap analysis
- Capacity planning
Correct answer: User acceptance testing (UAT)
User acceptance testing validates that a system meets end-user requirements and performance standards before it is deployed into the production environment.
Question 5: What does Total Cost of Ownership (TCO) analysis help IT governance leaders evaluate?
- Only the initial purchase price of technology
- All direct and indirect costs of a technology solution over its full lifecycle (Correct answer)
- Vendor reputation and market share
- Number of users who will use the system
Correct answer: All direct and indirect costs of a technology solution over its full lifecycle
TCO analysis captures all costs—acquisition, implementation, training, maintenance, and decommissioning—to support informed long-term investment decisions.
Question 6: Which governance control ensures only authorized individuals can access sensitive patient data in an EHR system?
- Network firewall configuration
- Role-based access control (RBAC) (Correct answer)
- Data backup procedures
- System performance monitoring
Correct answer: Role-based access control (RBAC)
Role-based access control restricts system access based on a user's organizational role, ensuring only authorized personnel can view or modify sensitive patient data.
Question 7: A healthcare CIO must report IT performance to the board. Which type of report is MOST appropriate for this audience?
- Detailed technical system logs
- Executive dashboard with KPIs aligned to strategic objectives (Correct answer)
- Full IT project management status reports
- Vendor invoice summaries
Correct answer: Executive dashboard with KPIs aligned to strategic objectives
Executive dashboards present high-level key performance indicators tied to strategic goals, giving board members actionable information without technical complexity.
What is the primary function of an IT policy in healthcare governance?