Aug-2026 ASHRM CPHRM Actual Questions and 100% Cover Real Exam Questions
CPHRM Free Exam Questions and Answers PDF Updated on Aug-2026
NEW QUESTION # 54
If there is no OSHA standard for a given potential health hazard, OSHA may:
- A. Ignore it if it is expensive
- B. Have no authority at all
- C. Govern it under the General Duty Clause
- D. Transfer it to the FDA
Answer: C
Explanation:
OSHA can cite employers under theGeneral Duty Clausewhen a recognized serious hazard exists and no specific standard applies. Risk management objectives require proactive hazard identification and controls even when regulations are not prescriptive: risk assessments, engineering controls where feasible, administrative controls (policies, training), and PPE as a final layer. In healthcare, this is relevant for emerging hazards (novel chemical exposures, workplace violence risks, certain ergonomic hazards) where specific standards may be limited. Maintaining documentation of hazard recognition and mitigation is essential for defensibility during inspections and for staff safety outcomes.
NEW QUESTION # 55
What are risk treatment strategies?
- A. Staff vacation scheduling
- B. Litigation, denial, delay
- C. Risk avoidance, risk retention, risk transfer (and risk reduction/mitigation)
- D. Public relations, branding, advertising
Answer: C
Explanation:
Core risk treatment strategies includeavoidance(stop the activity),reduction/mitigation(controls that reduce likelihood/severity),retention(accept risk within appetite and fund losses via reserves/self-insurance), and transfer(contracts/insurance shifting financial consequences). In healthcare, the highest priority is often mitigation for patient safety risks (standardization, technology, training), with financing mechanisms ensuring the organization can absorb residual loss without destabilizing operations. ERM aligns these strategies to enterprise objectives so leadership invests in the best mix of prevention and financing.
NEW QUESTION # 56
Which of the following should be included in a risk management plan?
* purpose of the program
* budget for the department
* process of risk management activities
* structure of the program
- A. 2, 3, and 4 only
- B. 1, 2, and 4 only
- C. 1, 3, and 4 only
- D. 1, 2, and 3 only
Answer: C
Explanation:
According to Health Care Risk Management standards defined by ASHRM and the American Hospital Association Certification Center, a formal risk management plan is a governance document that outlines the framework, scope, and operational processes of the program. It is intended to define how risk management activities support organizational objectives and regulatory compliance.
The plan should clearly state the purpose of the program, establishing its mission, goals, and alignment with patient safety and enterprise risk management strategies. It must also describe the structure of the program, including reporting relationships, committee oversight, leadership roles, and accountability mechanisms.
Additionally, the process of risk management activities should be detailed, including event reporting, investigation procedures, claims management, education initiatives, and performance evaluation methods.
While financial planning is important for departmental operations, the budget for the department is typically addressed in administrative or financial planning documents rather than the risk management plan itself. The plan focuses on governance, structure, and operational processes rather than line-item budgeting.
Therefore, inclusion of the program's purpose, structural framework, and operational processes appropriately defines a comprehensive risk management plan.
NEW QUESTION # 57
Which of the following should a risk manager consider when evaluating the effectiveness of a claims management program?
* indemnity-to-expense ratios
* total number of cases reported
* percentage of cases resolved within reserves
* percentage of cases identified prior to claim
- A. 2, 3, and 4 only
- B. 1, 2, and 4 only
- C. 1, 3, and 4 only
- D. 1, 2, and 3 only
Answer: C
Explanation:
According to Health Care Risk Management principles outlined by ASHRM and the American Hospital Association Certification Center, evaluation of a claims management program focuses on efficiency, financial accuracy, and proactive identification of risk exposures.
Indemnity-to-expense ratios are important performance indicators that measure the proportion of funds spent on compensation versus defense costs. A balanced ratio reflects efficient claim handling and appropriate litigation management. The percentage of cases resolved within reserves evaluates the accuracy of initial reserve setting and ongoing claims assessment, demonstrating financial forecasting effectiveness.
Additionally, the percentage of cases identified prior to formal claim filing reflects proactive risk identification and early intervention practices, which may reduce litigation costs and improve resolution outcomes.
In contrast, the total number of cases reported alone does not measure program effectiveness, as volume may be influenced by patient population, service lines, or reporting culture rather than management quality.
Claims and litigation objectives emphasize accurate reserving, early case identification, and cost-effective resolution strategies. Therefore, indemnity-to-expense ratios, resolution within reserves, and early case identification are appropriate metrics for evaluating the effectiveness of a claims management program.
NEW QUESTION # 58
What is a best-practice early objective in a disclosure-and-resolution conversation after an adverse event?
- A. Provide no information to avoid lawsuits
- B. Provide timely explanation of what is known, express empathy/apology, and commit to prevention steps
- C. Delay communication until legal discovery is complete
- D. Blame an individual staff member immediately
Answer: B
Explanation:
Modern communication-and-resolution programs emphasize early, honest communication with patients
/families after harm, including a timely explanation of what is known, an authentic expression of empathy and apology, and a commitment to investigate and prevent recurrence. This approach supports core risk management objectives: preserve trust, reduce emotional harm, strengthen transparency, and improve learning. Evidence-based disclosure models link timely communication and apology with improved patient experience and, in some programs, fewer claims and lower litigation costs-especially when paired with strong investigation and corrective action. Importantly, organizations should coordinate disclosure through trained coaches and follow local policy and state apology protections. The purpose is not to "admit fault prematurely," but to communicate responsibly, support patients, and demonstrate accountability and improvement.
NEW QUESTION # 59
Generally, an incident is defined as:
- A. Only billing disputes
- B. Only events that cause death
- C. Only patient complaints
- D. Any happening not consistent with routine care/operations (including near-misses)
Answer: D
Explanation:
Broad incident definitions (including near-misses and unsafe conditions) support proactive risk management.
If reporting is limited only to severe harm, the organization loses learning opportunities from early warning signals. Risk management objectives favor capturing deviations from expected process-falls without injury, specimen labeling near-misses, medication dispensing discrepancies-because these events reveal system vulnerabilities that can later cause major harm. Strong incident management includes classification, timely review, escalation thresholds, root cause analysis for significant events, and feedback to frontline staff. This approach aligns with systems-based safety: identify hazards, implement controls, and monitor effectiveness.
NEW QUESTION # 60
Which of the following wouldnotbe considered an emergency condition for EMTALA purposes (as a general example set)?
- A. Active labor with complications
- B. Myocardial infarction
- C. Ruptured appendix
- D. Stable chronic kidney failure without acute destabilization
Answer: D
Explanation:
EMTALA applies when an individual comes to the ED and requires a medical screening exam to determine whether anemergency medical condition (EMC)exists. Conditions like myocardial infarction, ruptured appendix, and unstable labor can constitute EMCs because absence of immediate medical attention could reasonably be expected to place health in serious jeopardy. By contrast,stable chronic kidney failurewithout acute destabilization may not meet the EMC threshold-though the screening exam must be performed before that determination is made. Risk management objectives emphasize: never "triage out" without an appropriate screening exam, document findings and decision-making, and apply consistent policies to avoid discriminatory practice. EMTALA failures often stem from process breakdowns (delays, refusal, inadequate screening, improper transfer), so standardized ED workflows and training are critical.
NEW QUESTION # 61
All of the following are valid reasons for performing risk management review of policies and procedures EXCEPT
- A. identifying potential risk exposures.
- B. monitoring compliance with standards.
- C. ensuring consistency between practice and policy.
- D. maintaining staff competency.
Answer: D
Explanation:
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, periodic review of policies and procedures is essential to ensure alignment with current laws, regulatory standards, accreditation requirements, and best practices. Reviewing policies helps ensure consistency between written procedures and actual clinical practice, thereby reducing liability exposure.
Policy review also supports identification of potential risk exposures by detecting outdated language, conflicting guidance, or gaps in processes that could lead to adverse events. Additionally, monitoring compliance with standards-such as federal regulations, state statutes, and accreditation requirements-is a central purpose of policy review, ensuring that organizational practices meet required benchmarks.
Maintaining staff competency, however, is primarily addressed through education, training programs, credentialing, and performance evaluation processes. While policies provide guidance for staff conduct, competency assessment is not the primary objective of policy review itself.
Health Care Operations objectives emphasize governance oversight, regulatory compliance, and risk mitigation through clear, current policies. Therefore, maintaining staff competency is not a direct reason for performing risk management review of policies and procedures, making it the correct exception.
NEW QUESTION # 62
A hospital uses the same labels for all prescriptions, but they don't fit on small containers, so employees must cut/paste labels in a special way. This is an example of:
- A. Extra processing (Lean waste)
- B. Risk financing
- C. Clinical decision support
- D. Value-added work
Answer: A
Explanation:
In Lean terms,extra processingis work that does not add value from the patient's perspective and often introduces defect risk. Cutting and reformatting labels is a classic extra-processing waste: it consumes time, creates variability, and increases the likelihood of mislabeling-one of the most serious medication safety hazards. Risk management objectives prioritize eliminating rework and standardizing the labeling process through right-sized labels, standardized print templates by container type, barcode integration, and human factors design (font size, tall-man lettering where appropriate). Removing extra processing improves efficiency and reduces cognitive load and workaround culture-both strongly associated with error.
Operationally, this is a system design failure: staff are compensating for poor equipment/process fit. Fixing the system reduces the chance of a high-severity adverse event and strengthens defensibility by demonstrating proactive hazard elimination.
NEW QUESTION # 63
The following is a table of expense and indemnity figures for an organization's last 6 years.
What is the ratio of total incurred expense to total incurred indemnity for Year 4?
- A. 3.23
- B. 0.18
- C. 0.15
- D. 0.20
Answer: D
Explanation:
According to Health Care Risk Management principles supported by ASHRM and the American Hospital Association Certification Center, total incurred amounts include both paid amounts and reserves. Incurred expense equals expense paid plus expense reserves. Incurred indemnity equals indemnity paid plus indemnity reserves.
For Year 4:
Total incurred expense = $25,000 reserves + $15,000 paid = $40,000.
Total incurred indemnity = $150,000 reserves + $75,000 paid = $225,000.
The ratio of total incurred expense to total incurred indemnity is calculated as:
$40,000 รท $225,000 = 0.1778, which rounds to approximately 0.18.
However, among the answer options provided, the closest value is 0.20 only if rounded broadly. Since precise calculation yields approximately 0.18, the mathematically correct ratio is approximately 0.18.
In risk financing analysis, expense-to-indemnity ratios help evaluate claims handling efficiency and cost allocation. Monitoring this ratio assists in forecasting defense costs, evaluating litigation management strategies, and supporting actuarial review. Accurate calculation of incurred values is essential for financial planning and reserve adequacy assessment.
NEW QUESTION # 64
A hospital's Ethics Committee is seeking advice on a case involving the elective sterilization of an adolescent patient who is developmentally disabled. One of the parents is refusing consent. The risk manager should evaluate which of the following?
* who has consent authority
* competency level of the patient
* diagnosis of the patient
* state statutes and laws
- A. 2, 3, and 4 only
- B. 1, 3, and 4 only
- C. 1, 2, and 4 only
- D. 1, 2, and 3 only
Answer: C
Explanation:
Under Health Care Risk Management principles outlined by ASHRM and the American Hospital Association Certification Center, cases involving sterilization of minors, particularly those who are developmentally disabled, raise significant legal and regulatory concerns. The risk manager's primary responsibility is to ensure compliance with applicable consent laws and protect patient rights while minimizing organizational liability.
First, determining who has legal consent authority is essential. When parents disagree, state law typically governs whether both parents must consent, whether one parent's consent is sufficient, or whether court involvement is required. Second, evaluating the competency level of the patient is critical because decision- making capacity influences whether the patient can participate in consent or assent processes. Capacity assessments may require clinical and legal evaluation.
Third, state statutes and laws are highly relevant, as many jurisdictions impose strict legal requirements or court approval for sterilization of minors or individuals with developmental disabilities. These laws are designed to protect vulnerable populations.
The patient's diagnosis alone is not the determining legal factor; rather, decision-making capacity and statutory requirements are central. Therefore, the risk manager must evaluate consent authority, competency, and applicable state laws to ensure regulatory compliance and ethical integrity.
NEW QUESTION # 65
A hospital risk manager has been called to the Neonatal Intensive Care Unit to discuss a 25-week premature infant whose parents are refusing a planned blood transfusion due to their religious beliefs. After gathering information on the infant's condition and hearing the parents and the healthcare professionals disagree on the best interests of the infant, the risk manager should
- A. advise the care team to proceed with the blood transfusion.
- B. contact legal counsel to arrange for an emergency court hearing to obtain a court order from the state to intervene.
- C. arrange for an ethics committee consultation to meet the parents and discuss the issue.
- D. prohibit the blood transfusion, respecting the parents' rights as substitute decision-makers for the infant.
Answer: B
Explanation:
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, while parents generally serve as surrogate decision-makers for minors, their authority is not absolute. When refusal of treatment places a child at significant risk of serious harm or death, healthcare providers have an ethical and legal obligation to act in the best interests of the child.
In cases involving life-sustaining treatment for a premature infant, refusal of a medically necessary blood transfusion may constitute potential medical neglect if it threatens the infant's survival. When disagreement persists after appropriate communication and ethics consultation, and the infant's life is at risk, the appropriate step is to seek judicial intervention. Contacting legal counsel to obtain an emergency court order allows the state to exercise its parens patriae authority to protect the child's welfare.
An ethics consultation may help clarify values and promote dialogue but does not override urgent medical necessity. Simply prohibiting or proceeding without legal authority exposes the organization to liability.
Legal and regulatory objectives emphasize protecting vulnerable patients while respecting due process.
Therefore, seeking an emergency court order through legal counsel is the appropriate action.
NEW QUESTION # 66
Which of the following should be the primary consideration when designing a new risk management program for a facility?
- A. history of the facility
- B. type of insurance the facility carries
- C. mission and vision of the facility
- D. size of the facility
Answer: C
Explanation:
According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, the primary consideration in designing a risk management program is alignment with the organization's mission and vision. A risk management program must support the strategic goals, values, and patient care objectives of the facility. This ensures that risk identification, mitigation strategies, and reporting structures are integrated into the broader organizational framework.
While facility size, insurance structure, and historical claims experience are important operational factors, they are secondary to strategic alignment. The mission and vision guide priorities such as patient safety, quality improvement, regulatory compliance, and financial stewardship. Risk management activities should be structured to advance these priorities, reinforce leadership commitment, and support governance oversight.
An effective program reflects organizational culture, scope of services, and community role. It establishes reporting mechanisms to leadership, integrates enterprise risk management principles, and promotes collaboration across departments.
Health Care Operations objectives emphasize governance integration, strategic alignment, and organizational accountability. Therefore, the mission and vision of the facility should be the primary consideration when designing a new risk management program.
NEW QUESTION # 67
Which type of information was associated with the former HIPDB (now within NPDB) but not the original NPDB focus?
- A. School disciplinary actions
- B. Restaurant health inspections
- C. Public voter registration files
- D. Fraud/abuse-related actions and exclusions involving providers/suppliers (HIPDB purpose)
Answer: D
Explanation:
The HIPDB was established to help combathealthcare fraud and abuse, while the NPDB historically focused on practitioner competence and professional conduct (including items like malpractice payments and certain adverse actions). HRSA explains that HIPDB is no longer separate and that its information is now collected and disclosed through the NPDB following the 2013 merger. For risk managers, the objective is to ensure credentialing, contracting, and compliance teams understand the expanded scope and proper use:
querying supports safer hiring/privileging decisions and reduces negligent credentialing risk, while reporting supports system integrity. Organizations must also ensure due process and correct categorization of reportable events to avoid wrongful reporting exposure.
NEW QUESTION # 68
In general, how many steps should an FMEA proceed in each direction (upstream/downstream) when mapping a process for failure analysis?
- A. Only the current step; context is irrelevant
- B. Two steps in each direction (a common practical rule-of-thumb)
- C. Steps are not mapped in FMEA
- D. Ten steps minimum regardless of complexity
Answer: B
Explanation:
A practical FMEA requires enough process context to capture upstream causes and downstream consequences without becoming unmanageably large. A common operational rule-of-thumb is to examine roughlytwo steps upstream and two steps downstreamfrom a target step to uncover handoffs, dependencies, and failure propagation. Risk management objectives focus on identifying failure modes that originate earlier (e.g., incorrect patient ID at registration leading to lab/specimen mismatch) and harms that emerge later (e.g., delayed result communication causing deterioration). The exact boundary depends on complexity and risk; high-hazard workflows (blood products, surgery, chemo) may require deeper mapping. The goal is usable granularity: map, identify failure modes, score (S-O-D), prioritize, implement controls, and reassess residual risk.
NEW QUESTION # 69
What is the voluntary relinquishment by the insurer or self-insurer of the right to recover from a third party?
- A. Coinsurance
- B. Experience rating
- C. Underwriting
- D. Waiver of subrogation
Answer: D
Explanation:
Subrogation is the insurer's right to seek recovery from a responsible third party after paying a loss. Awaiver of subrogationclause means the insurer (or self-insured entity) gives up that recovery right, usually to support business relationships and reduce litigation between contracting parties. Risk financing objectives include understanding when waivers are acceptable (balanced against increased retained loss), ensuring the waiver aligns with insurance policy endorsements, and preventing unintended coverage gaps. Poorly managed waivers can shift costs back onto the organization and complicate recovery efforts. Contracts should be reviewed to ensure the waiver is mutual when appropriate and consistent with the organization's risk appetite and insurance program.
NEW QUESTION # 70
The enterprise risk management process extends beyond clinical risk management by
- A. maintaining risks in silos as the best risk management approach.
- B. ensuring its strategic priority at the senior leadership and governance levels.
- C. comparing the organization's internal and external environment for efficacy.
- D. analyzing the organization's medication administration program.
Answer: B
NEW QUESTION # 71
What factors are included in a calculation of Risk Priority Number (RPN) in FMEA?
- A. Legal privilege, media attention, reputation
- B. Insurance premiums, deductibles, coinsurance
- C. Severity, occurrence (probability), detection
- D. Cost, staff satisfaction, marketing risk
Answer: C
Explanation:
In Failure Modes and Effects Analysis (FMEA), the Risk Priority Number (RPN) is commonly calculated as the product of three ratings:Severity (S)of impact,Occurrence (O)likelihood/probability, andDetection (D) ability to detect the failure before it causes harm (lower detectability increases risk). This structured scoring helps teams prioritize which failure modes deserve immediate mitigation. Risk management objectives include proactively identifying high-risk process steps (medication administration, specimen labeling, surgery scheduling), designing controls (standard work, forcing functions, redundancy), and tracking residual risk after changes. While cost and feasibility may influence selection of mitigations, they are not the core RPN elements. Using S-O-D improves transparency in prioritization, supports interdisciplinary alignment, and provides a defensible rationale for resource allocation toward patient safety improvements.
NEW QUESTION # 72
Which of the following are proactive elements of a workplace violence prevention program?
- A. notification to Drug Enforcement Agency of drug theft and crisis intervention
- B. de-escalation, law enforcement notification, restraining order, and victim support
- C. pre-employment background screening, training, rounding, and active shooter drills
- D. medical record documentation of events and emergency command center activation
Answer: C
Explanation:
According to Health Care Risk Management standards outlined by ASHRM and the American Hospital Association Certification Center, proactive workplace violence prevention focuses on measures implemented before an incident occurs. These strategies aim to identify risks, strengthen preparedness, and reduce the likelihood or severity of violent events.
Pre-employment background screening helps identify applicants with histories that may pose safety concerns, consistent with legal hiring standards. Ongoing staff training enhances awareness of warning signs, communication skills, and reporting procedures. Leadership rounding increases visibility, supports early identification of environmental or behavioral risks, and reinforces safety culture. Active shooter drills and emergency preparedness exercises ensure that staff understand response protocols and can act effectively under stress.
Options B, C, and D primarily describe reactive or post-incident measures. Law enforcement notification, restraining orders, crisis intervention, DEA notification, documentation, and emergency command activation occur after an event has taken place or when an immediate threat is present.
Health Care Operations objectives emphasize prevention, preparedness, environmental assessment, and workforce education as foundational elements of a workplace violence program. Therefore, pre-employment screening, training, rounding, and drills represent proactive components of an effective prevention strategy.
NEW QUESTION # 73
According to The Joint Commission, which of the following should be done to patient-owned electrical devices entering the facility?
- A. conduct an electrical safety inspection
- B. inventory with patient belongings
- C. tag by biomedical engineering
- D. sequester the electrical device
Answer: A
NEW QUESTION # 74
......
ASHRM CPHRM Real 2026 Braindumps Mock Exam Dumps: https://certblaster.prep4away.com/ASHRM-certification/braindumps.CPHRM.ete.file.html