CPHIMS Ultimate CPHIMS 3 — Questions and Answers
Question 1: Which federal regulation requires hospitals to maintain electronic medication administration records and bar-code point-of-care verification to reduce medication errors?
- FDA Bar Code Label Rule (21 CFR Part 801) (Correct answer)
- HIPAA Security Rule
- CMS Conditions of Participation
- Joint Commission NPSG.03.04.01
Correct answer: FDA Bar Code Label Rule (21 CFR Part 801)
The FDA Bar Code Label Rule requires bar codes on medications, enabling point-of-care scanning to verify the 5 rights of medication administration.
Question 2: In an EHR implementation, which testing phase validates that integrated modules work correctly together as a complete system?
- Integration testing (Correct answer)
- Unit testing
- User acceptance testing
- Regression testing
Correct answer: Integration testing
Integration testing verifies that separately developed modules communicate and function correctly when combined into the full system.
Question 3: A CPHIMS candidate is reviewing database normalization. Which normal form eliminates partial dependencies, ensuring all non-key attributes depend on the ENTIRE primary key?
- Second Normal Form (2NF) (Correct answer)
- First Normal Form (1NF)
- Third Normal Form (3NF)
- Boyce-Codd Normal Form (BCNF)
Correct answer: Second Normal Form (2NF)
2NF eliminates partial dependencies by requiring every non-key attribute to be fully dependent on the entire composite primary key.
Question 4: An organization wants to ensure that critical clinical systems remain available during a cyberattack. Which strategy BEST addresses this need?
- Maintaining offline downtime procedures and read-only EHR access (Correct answer)
- Increasing firewall rules and blocking all external traffic
- Encrypting all data at rest and in transit
- Conducting annual penetration testing
Correct answer: Maintaining offline downtime procedures and read-only EHR access
Downtime procedures and read-only EHR access ensure clinical continuity even when primary systems are compromised or unavailable.
Question 5: Which healthcare data exchange framework uses RESTful APIs and JSON/XML to enable modern, internet-based interoperability between health systems?
- HL7 FHIR (Correct answer)
- HL7 v2
- DICOM
- X12 EDI
Correct answer: HL7 FHIR
HL7 FHIR (Fast Healthcare Interoperability Resources) uses RESTful APIs and resources in JSON/XML for modern web-based health data exchange.
Question 6: A healthcare CIO is reviewing the organization's IT portfolio for alignment with strategic goals. Which framework is MOST commonly used to align IT strategy with business objectives?
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- ITIL (IT Infrastructure Library)
- PMBOK (Project Management Body of Knowledge)
- TOGAF (The Open Group Architecture Framework)
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT provides a governance framework that aligns IT strategy with business goals and measures IT performance against organizational objectives.
Question 7: Under the ONC 21st Century Cures Act Final Rule, information blocking is prohibited. Which of the following IS a recognized exception that permits restricting access?
- Privacy exception when sharing would violate applicable law (Correct answer)
- Competitive advantage when a vendor withholds data from rivals
- Technical limitation when a vendor's API is partially built
- Cost savings when providing access would reduce revenue
Correct answer: Privacy exception when sharing would violate applicable law
The Privacy exception allows actors to withhold information when sharing would violate applicable privacy laws such as state mental health confidentiality statutes.
Which federal regulation requires hospitals to maintain electronic medication administration records and bar-code point-of-care verification to reduce medication errors?