CPHIMS MAIN EXAMINATION MANUAL 2026/2027
QUESTIONS AND SOLUTIONS RATED A+
✔✔What does implementation execution include? - ✔✔Definition of the team's roles
and responsibilities.
✔✔What is the implementation strategy where all functionality is implemented in one
location first? - ✔✔Big bang.
✔✔When should end-user training be completed in the implementation process? -
✔✔As early as possible.
✔✔What should planning for activation include? - ✔✔Completing a root cause analysis.
✔✔What should be measured and evaluated after the system is live? - ✔✔After the
system is live, system usability, duration of the implementation, quantity of printers, and
number of vendors responding to the request for proposal (RFP) should be measured
and evaluated.
✔✔What does the business continuity plan include? - ✔✔The business continuity plan
includes the release management plan, disaster recovery plan, risk management plan,
and configuration management plan.
✔✔What is the fundamental purpose of information system testing? - ✔✔The
fundamental purpose of information system testing is to manage risks of developing,
producing, operating, and sustaining systems.
✔✔What are testing methodologies? - ✔✔Testing methodologies are the formal or
informal set of conditions or variables under which a tester can identify issues and
determine if the application or software system is working correctly.
✔✔Which of the following is a manual test tool? - ✔✔A black-box test is a manual test
tool.
✔✔What is testing performed to validate successful system implementation called? -
✔✔Testing performed to validate successful system implementation is called
acceptance testing.
✔✔What is the goal of stress testing? - ✔✔The goal of stress testing is to ensure the
software does not crash under conditions of insufficient computational resources,
unusually high concurrency, or denial-of-service attacks.
, ✔✔What do system controls protect during testing? - ✔✔System controls are
implemented to protect the confidentiality, integrity, and availability of data during
testing.
✔✔What is version control? - ✔✔Version control is a formal process used to ensure that
changes to a product or system are introduced in a controlled and coordinated manner.
✔✔What should test reporting address? - ✔✔Test reporting should address the test
team members and their experience levels, the estimated cost of the test, the expected
outcomes of the test, and the mission of the test.
✔✔How should access privileges be set? - ✔✔Access privileges for each role should be
set to provide the minimum access necessary.
✔✔What are examples of physical safeguards? - ✔✔Locked doors, property control
tags on devices, and employee identification badges are examples of physical
safeguards.
✔✔What is the underlying principle for safeguarding a patient's health information? -
✔✔The underlying principle for safeguarding a patient's health information is to do no
harm to the patient.
✔✔What does HIPAA require a covered entity to maintain? - ✔✔HIPAA requires a
covered entity to maintain a program to ensure the privacy, security, and standards
compliance for PHI.
✔✔When is the inappropriate use of PHI presumed to be a breach? - ✔✔The
inappropriate use of PHI is presumed to be a breach unless it can be proven there is a
low probability the PHI was compromised.
✔✔What does GDPR apply to? - ✔✔GDPR applies to the personally identifiable
information of a European Union citizen.
✔✔What is the best approach to reduce risk to an acceptable level? - ✔✔The best
approach to reduce risk to an acceptable level is to mitigate by implementing
safeguards.
✔✔What can audits of a covered entity's security plan include? - ✔✔Audits of a covered
entity's security plan can include external penetration testing and internal vulnerability
testing.
✔✔What is a project manager responsible for? - ✔✔A project manager is responsible
for delivering project objectives within budget and on schedule.
QUESTIONS AND SOLUTIONS RATED A+
✔✔What does implementation execution include? - ✔✔Definition of the team's roles
and responsibilities.
✔✔What is the implementation strategy where all functionality is implemented in one
location first? - ✔✔Big bang.
✔✔When should end-user training be completed in the implementation process? -
✔✔As early as possible.
✔✔What should planning for activation include? - ✔✔Completing a root cause analysis.
✔✔What should be measured and evaluated after the system is live? - ✔✔After the
system is live, system usability, duration of the implementation, quantity of printers, and
number of vendors responding to the request for proposal (RFP) should be measured
and evaluated.
✔✔What does the business continuity plan include? - ✔✔The business continuity plan
includes the release management plan, disaster recovery plan, risk management plan,
and configuration management plan.
✔✔What is the fundamental purpose of information system testing? - ✔✔The
fundamental purpose of information system testing is to manage risks of developing,
producing, operating, and sustaining systems.
✔✔What are testing methodologies? - ✔✔Testing methodologies are the formal or
informal set of conditions or variables under which a tester can identify issues and
determine if the application or software system is working correctly.
✔✔Which of the following is a manual test tool? - ✔✔A black-box test is a manual test
tool.
✔✔What is testing performed to validate successful system implementation called? -
✔✔Testing performed to validate successful system implementation is called
acceptance testing.
✔✔What is the goal of stress testing? - ✔✔The goal of stress testing is to ensure the
software does not crash under conditions of insufficient computational resources,
unusually high concurrency, or denial-of-service attacks.
, ✔✔What do system controls protect during testing? - ✔✔System controls are
implemented to protect the confidentiality, integrity, and availability of data during
testing.
✔✔What is version control? - ✔✔Version control is a formal process used to ensure that
changes to a product or system are introduced in a controlled and coordinated manner.
✔✔What should test reporting address? - ✔✔Test reporting should address the test
team members and their experience levels, the estimated cost of the test, the expected
outcomes of the test, and the mission of the test.
✔✔How should access privileges be set? - ✔✔Access privileges for each role should be
set to provide the minimum access necessary.
✔✔What are examples of physical safeguards? - ✔✔Locked doors, property control
tags on devices, and employee identification badges are examples of physical
safeguards.
✔✔What is the underlying principle for safeguarding a patient's health information? -
✔✔The underlying principle for safeguarding a patient's health information is to do no
harm to the patient.
✔✔What does HIPAA require a covered entity to maintain? - ✔✔HIPAA requires a
covered entity to maintain a program to ensure the privacy, security, and standards
compliance for PHI.
✔✔When is the inappropriate use of PHI presumed to be a breach? - ✔✔The
inappropriate use of PHI is presumed to be a breach unless it can be proven there is a
low probability the PHI was compromised.
✔✔What does GDPR apply to? - ✔✔GDPR applies to the personally identifiable
information of a European Union citizen.
✔✔What is the best approach to reduce risk to an acceptable level? - ✔✔The best
approach to reduce risk to an acceptable level is to mitigate by implementing
safeguards.
✔✔What can audits of a covered entity's security plan include? - ✔✔Audits of a covered
entity's security plan can include external penetration testing and internal vulnerability
testing.
✔✔What is a project manager responsible for? - ✔✔A project manager is responsible
for delivering project objectives within budget and on schedule.