HCC Risk Management & Mitigation 3 — Questions and Answers
Question 1: A hospital experiences a wrong-site surgery. Under Joint Commission standards, how is this event classified?
- Near miss
- Sentinel event (Correct answer)
- No-harm event
- Hazardous condition
Correct answer: Sentinel event
Wrong-site surgery is a sentinel event, a patient safety event resulting in death or severe harm that requires immediate investigation.
Question 2: A consultant advising on HIPAA compliance identifies that laptops containing patient data are not encrypted. Which type of risk does this primarily represent?
- Clinical risk
- Financial credit risk
- Data security and privacy risk (Correct answer)
- Environmental risk
Correct answer: Data security and privacy risk
Unencrypted devices with protected health information create a data breach risk under HIPAA's Security Rule.
Question 3: Which element is essential for a 'just culture' approach to risk management?
- Punishing all staff involved in errors to deter recurrence
- Distinguishing between human error, at-risk behavior, and reckless behavior (Correct answer)
- Eliminating all incident reporting requirements
- Assigning blame only to senior leadership
Correct answer: Distinguishing between human error, at-risk behavior, and reckless behavior
Just culture balances accountability by responding differently to inadvertent error, risky shortcuts, and conscious disregard for safety.
Question 4: A consultant calculates that a risk has a 10% annual probability and would cost $500,000 if it occurred. What is the annualized loss expectancy?
- $5,000
- $50,000 (Correct answer)
- $500,000
- $5,000,000
Correct answer: $50,000
Annualized loss expectancy equals probability times impact: 0.10 × $500,000 = $50,000.
Question 5: A hospital decides to discontinue its obstetrics service line entirely because of unsustainable liability exposure. Which risk strategy is this?
- Risk avoidance (Correct answer)
- Risk mitigation
- Risk transfer
- Risk acceptance
Correct answer: Risk avoidance
Eliminating the activity that creates the risk is risk avoidance.
Question 6: Which document should a consultant review first to understand how a client organization tracks and prioritizes its identified risks?
- The marketing plan
- The risk register (Correct answer)
- The employee handbook
- The chart of accounts
Correct answer: The risk register
A risk register is the central log of identified risks, their ratings, owners, and mitigation plans.
Question 7: After a data breach, a client immediately notifies affected patients and offers credit monitoring. This response is an example of what?
- Risk identification
- Risk appetite setting
- Harm mitigation and incident response (Correct answer)
- Risk avoidance
Correct answer: Harm mitigation and incident response
Actions taken after an event to limit damage and meet obligations are part of incident response and mitigation.
A hospital experiences a wrong-site surgery.
Under Joint Commission standards, how is this event classified?