CPHRM Exam Questions & Answers
Certified Professional in Health Care Risk Management • ASHRM
100% money-back guarantee
Sample CPHRM Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
The risk manager is called by an administrator and told that a member of the pharmacy staff was arrested last night for illegal distribution of controlled substances. Which of the following recommendations should the risk manager make to administration?
Verify the pre-employment background check.
Inventory controlled drug stock.
Interview other pharmacy staff.
Notify the National Practitioner Data Bank.
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, when a pharmacy staff member is arrested for illegal distribution of controlled substances, the organization must focus on immediate operational and patient safety concerns. Verifying the pre-employment background check ensures compliance with hiring policies and identifies whether due diligence was properly conducted.
An immediate inventory of controlled drug stock is essential to detect diversion, identify discrepancies, and comply with DEA requirements for controlled substance accountability. Prompt reconciliation of medication records protects patient safety and mitigates regulatory exposure.
Interviewing other pharmacy staff supports investigation of potential diversion patterns, internal control weaknesses, and workflow vulnerabilities. This step aligns with system-based risk management and prevention of further loss.
Notification to the National Practitioner Data Bank is not automatically required based solely on an arrest. NPDB reporting typically involves certain professional review actions, licensure restrictions, or clinical privilege actions, not merely criminal charges unless formal disciplinary action occurs.
Health Care Operations objectives emphasize safeguarding controlled substances, regulatory compliance, and internal investigation. Therefore, verifying background checks, inventorying stock, and interviewing staff are appropriate recommendations.
A patient has been declared brain dead as a result of injuries sustained during a criminal act. His driver's license states that he is an organ donor. The attending physician is planning to remove the life-support equipment. A risk manager should recommend
According to Health Care Risk Management standards established by ASHRM and the American Hospital Association Certification Center, deaths resulting from criminal acts fall under medico-legal jurisdiction and are typically subject to coroner or medical examiner review. Even when a patient is a documented organ donor, as indicated on a driver's license under the Uniform Anatomical Gift Act framework, the circumstances of death may require legal investigation.
When a death is associated with trauma from a criminal act, it is generally considered a reportable death. The medical examiner or coroner has statutory authority to determine whether an autopsy is required and to ensure preservation of forensic evidence. Organ procurement activities must not interfere with legal investigation obligations. Therefore, prior to organ retrieval or withdrawal of life support, the appropriate legal authorities must be notified.
While honoring the patient's documented donation wishes is important, compliance with state statutes governing reportable deaths and forensic investigations takes precedence. The family's wishes do not override a valid donor designation, but coordination must occur within the legal framework.
Thus, the most appropriate action for the risk manager is to ensure that authorities are notified to determine autopsy requirements before proceeding.
Which of the following best describes the appropriate scope of a risk manager's involvement in community disaster preparedness?
According to Health Care Risk Management standards endorsed by ASHRM and the American Hospital Association Certification Center, a risk manager's role in community disaster preparedness extends beyond narrow liability analysis. The appropriate scope involves integration of emergency management into the organization's broader enterprise risk management framework.
Enterprise risk management ERM is a structured, organization-wide approach to identifying, assessing, and managing risks that may affect strategic objectives, operations, financial stability, and reputation. Disaster preparedness is a critical operational risk that must be aligned with governance, compliance, continuity planning, and asset protection strategies. By incorporating emergency management into ERM, the risk manager ensures coordination across clinical services, facilities, supply chain, communications, and leadership structures.
Option A focuses only on post-event liability. Option C limits involvement to quantification without strategic integration. Option D addresses reimbursement processes rather than preparedness strategy.
Health Care Operations objectives emphasize collaboration with emergency management teams, regulatory compliance with preparedness standards, and resilience planning to protect patients, staff, and assets. Therefore, integrating emergency management into a comprehensive enterprise risk management plan best defines the risk manager's appropriate scope of involvement.
A 22-year-old man has been treated at a hospital for a psychiatric condition. His mother requests that a copy of the patient's medical record be released to her. The risk manager's advice to the medical records department should be to
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, a 22-year-old patient is a legal adult and retains full rights to privacy and control over disclosure of protected health information under HIPAA and applicable state confidentiality laws. Psychiatric records are subject to heightened confidentiality protections in many jurisdictions.
Absent a court order or legal guardianship determination, a parent does not have automatic access to an adult child's medical records. Therefore, before releasing any information, the organization must verify that the patient has executed a valid, specific authorization for release of information that complies with HIPAA requirements. The authorization must clearly identify the recipient, the information to be disclosed, and be properly signed and dated.
Consulting legal counsel or a treating psychiatrist does not substitute for proper authorization. Similarly, requesting guardianship documentation would only be appropriate if the mother asserts legal guardianship status; however, in the absence of such documentation, release cannot occur.
Legal and regulatory objectives emphasize strict adherence to privacy laws, protection of psychiatric records, and proper authorization procedures. Therefore, verification of a signed release of information from the patient is required before disclosure.
The Joint Commission requires that after a healthcare organization becomes aware of a sentinel event, it must complete a root cause analysis and action plan within how many days?
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, The Joint Commission's sentinel event policy requires organizations to complete a thorough root cause analysis and develop an action plan within 45 days of becoming aware of the sentinel event.
The root cause analysis must identify underlying system failures and contributing factors rather than focusing solely on individual performance. The resulting action plan must outline specific corrective measures, assign responsibility, establish implementation timelines, and include mechanisms to monitor effectiveness. The emphasis is on sustainable system improvement to reduce the likelihood of recurrence.
Failure to complete the analysis and action plan within the required timeframe may result in additional review, accreditation consequences, or other follow-up actions by The Joint Commission. Timely completion demonstrates organizational accountability, leadership oversight, and commitment to patient safety.
Clinical and patient safety objectives emphasize structured investigation processes, documentation of corrective actions, and alignment with accreditation standards. Therefore, the required timeframe for completion of the root cause analysis and action plan following awareness of a sentinel event is 45 days.
Get access to all 119 verified questions with detailed answers.
Unlock All CPHRM Questions