Certified Professional in Healthcare Risk
Management (CPHRM) Practice Examination
100% Verified Answers LATEST UPDATE
1. The primary goal of an integrated Enterprise Risk Management (ERM) program
is to:
A) Eliminate all liability claims
B) Coordinate risk assessment across clinical, financial, operational, and strategic
domains to support organizational objectives
C) Focus exclusively on patient safety
D) Reduce insurance premiums to zero
**Answer: B**
Rationale: ERM provides a holistic framework to identify and manage risks across
the entire organization, not just clinical or financial areas in isolation.
2. A risk manager is developing a risk assessment tool. Which component of the
Donabedian model focuses on the physical environment, staffing, and
equipment?
A) Process
B) Outcome
C) Structure
D) Diagnosis
**Answer: C**
,Rationale: Structure includes the attributes of the care setting, such as facilities,
staffing ratios, and equipment. Process refers to care delivery, and outcomes are
the results.
3. An employee reports a needle stick injury. The risk manager's immediate
responsibility is to:
A) Terminate the employee
B) Ensure the employee receives immediate post-exposure evaluation and
treatment per the bloodborne pathogen exposure control plan
C) Report the incident to the local newspaper
D) Wait for OSHA to investigate
**Answer: B**
Rationale: The first priority is the safety and health of the exposed individual,
including rapid evaluation and prophylaxis, as required by OSHA's Bloodborne
Pathogens Standard.
4. Failure Mode and Effects Analysis (FMEA) is a tool used to:
A) Investigate a sentinel event after it occurs
B) Proactively identify potential failures in a process before they result in harm
C) Analyze financial losses
D) Determine the root cause of an adverse event
**Answer: B**
Rationale: FMEA is a prospective risk assessment method that examines a process
to identify where and how it might fail and to prioritize safety improvements.
Root cause analysis (D) is retrospective.
,5. The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule
permits disclosure of protected health information (PHI) without patient
authorization for:
A) Marketing
B) Treatment, payment, and healthcare operations (TPO)
C) Sale of PHI
D) Public relations purposes
**Answer: B**
Rationale: HIPAA allows covered entities to use and disclose PHI without
individual authorization for core functions of treatment, payment, and healthcare
operations.
6. A patient falls in a hospital and sustains a hip fracture. The risk manager
immediately places the facility's incident report in the:
A) Patient's medical record
B) Attorney's case file
C) Confidential peer review/quality file, as permitted by state law
D) Public website
**Answer: C**
Rationale: Incident reports prepared for quality improvement are generally
protected under state peer review and quality assurance privileges, not placed in
the medical record.
, 7. A risk manager is analyzing a claim involving a retained surgical sponge. The
legal doctrine most likely to apply is:
A) Respondeat superior
B) Res ipsa loquitur
C) Informed consent
D) Contributory negligence
**Answer: B**
Rationale: Res ipsa loquitur ("the thing speaks for itself") applies when the injury
would not normally occur without negligence, the instrument was under the
defendant's control, and the plaintiff did not contribute.
8. The "captain of the ship" doctrine traditionally holds surgeons liable for the
acts of operating room staff. In modern legal settings, this doctrine:
A) Is universally applied without exception
B) Has been largely eroded, with courts focusing on each provider's individual
negligence
C) Only applies to hospital administrators
D) Never existed
**Answer: B**
Rationale: While historically used, modern courts generally assess the actual
agency relationship and individual responsibility rather than automatically
imputing liability to the surgeon.
9. A patient is harmed due to a medication error. The risk manager facilitates a
root cause analysis (RCA). The primary goal of RCA is to:
Management (CPHRM) Practice Examination
100% Verified Answers LATEST UPDATE
1. The primary goal of an integrated Enterprise Risk Management (ERM) program
is to:
A) Eliminate all liability claims
B) Coordinate risk assessment across clinical, financial, operational, and strategic
domains to support organizational objectives
C) Focus exclusively on patient safety
D) Reduce insurance premiums to zero
**Answer: B**
Rationale: ERM provides a holistic framework to identify and manage risks across
the entire organization, not just clinical or financial areas in isolation.
2. A risk manager is developing a risk assessment tool. Which component of the
Donabedian model focuses on the physical environment, staffing, and
equipment?
A) Process
B) Outcome
C) Structure
D) Diagnosis
**Answer: C**
,Rationale: Structure includes the attributes of the care setting, such as facilities,
staffing ratios, and equipment. Process refers to care delivery, and outcomes are
the results.
3. An employee reports a needle stick injury. The risk manager's immediate
responsibility is to:
A) Terminate the employee
B) Ensure the employee receives immediate post-exposure evaluation and
treatment per the bloodborne pathogen exposure control plan
C) Report the incident to the local newspaper
D) Wait for OSHA to investigate
**Answer: B**
Rationale: The first priority is the safety and health of the exposed individual,
including rapid evaluation and prophylaxis, as required by OSHA's Bloodborne
Pathogens Standard.
4. Failure Mode and Effects Analysis (FMEA) is a tool used to:
A) Investigate a sentinel event after it occurs
B) Proactively identify potential failures in a process before they result in harm
C) Analyze financial losses
D) Determine the root cause of an adverse event
**Answer: B**
Rationale: FMEA is a prospective risk assessment method that examines a process
to identify where and how it might fail and to prioritize safety improvements.
Root cause analysis (D) is retrospective.
,5. The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule
permits disclosure of protected health information (PHI) without patient
authorization for:
A) Marketing
B) Treatment, payment, and healthcare operations (TPO)
C) Sale of PHI
D) Public relations purposes
**Answer: B**
Rationale: HIPAA allows covered entities to use and disclose PHI without
individual authorization for core functions of treatment, payment, and healthcare
operations.
6. A patient falls in a hospital and sustains a hip fracture. The risk manager
immediately places the facility's incident report in the:
A) Patient's medical record
B) Attorney's case file
C) Confidential peer review/quality file, as permitted by state law
D) Public website
**Answer: C**
Rationale: Incident reports prepared for quality improvement are generally
protected under state peer review and quality assurance privileges, not placed in
the medical record.
, 7. A risk manager is analyzing a claim involving a retained surgical sponge. The
legal doctrine most likely to apply is:
A) Respondeat superior
B) Res ipsa loquitur
C) Informed consent
D) Contributory negligence
**Answer: B**
Rationale: Res ipsa loquitur ("the thing speaks for itself") applies when the injury
would not normally occur without negligence, the instrument was under the
defendant's control, and the plaintiff did not contribute.
8. The "captain of the ship" doctrine traditionally holds surgeons liable for the
acts of operating room staff. In modern legal settings, this doctrine:
A) Is universally applied without exception
B) Has been largely eroded, with courts focusing on each provider's individual
negligence
C) Only applies to hospital administrators
D) Never existed
**Answer: B**
Rationale: While historically used, modern courts generally assess the actual
agency relationship and individual responsibility rather than automatically
imputing liability to the surgeon.
9. A patient is harmed due to a medication error. The risk manager facilitates a
root cause analysis (RCA). The primary goal of RCA is to: