top of page

CPHRM Exam Prep 7-Week Study Plan

This plan runs on a simple rhythm: one Part per week for six weeks, then a seventh week for full review and exam simulation. For each Part, read that Part's Study Guide first β€” it's your advance organizer, telling you what matters most and how the concepts connect before you open a single chapter. Treat the plan like a buffet, not a must-do list: do the work that closes your weak spots, and let the quiz bank tell you where those are.


The Made Easy Highlighting System


Before Week 1, set up the color system you'll use every single week. Highlighting isn't decoration β€” it's a learning strategy. When you tag information by type instead of by what feels "important," each color becomes a mental shortcut, and you build a color-coded study guide automatically as you read. Every weekly Part below tells you to "highlight as you read" using these six colors:


πŸŸ₯ Red: Adverse Events, Claims Triggers & High-Loss Exposures (The Things That Become Lawsuits) β€” Think: "This is the harm β€” or the early sign of a claim β€” I need to recognize." The adverse-event/sentinel-event/never-event definitions, wrong-patient and patient-identification events, maternal safety and OB risk, identifying potentially compensable events, and high-severity trends (social inflation, nuclear verdicts).


πŸŸͺ Purple: Laws, Regulations & Legal Doctrine (The Source of Liability) β€” Think: "What's the law, the doctrine, or the regulatory standard?" Tort law and the elements of negligence, vicarious liability and agency, EMTALA anti-dumping requirements, the HIPAA Privacy Rule, and The Joint Commission standards.


🟧 Orange: Risk Management Process & Operational Methods (The Step-by-Step Risk Work) β€” Think: "What procedure do I run to identify, analyze, or treat risk?" The core risk-management process (identify, analyze, treat, monitor), Root Cause Analysis and RCAΒ², Failure Mode and Effects Analysis, Hazard Vulnerability Analysis, and practitioner oversight (OPPE/FPPE).


🟩 Green: Risk Financing, Insurance & Cost of Risk (The Money Side of Risk) β€” Think: "How is the financial exposure structured, priced, or transferred?" Professional liability insurance (claims-made vs. occurrence), coverage extensions (tail and nose coverage), funding structures (self-insurance, captives), loss reserves and IBNR, and risk transfer 

through contracts and indemnification.


🟦 Blue: Claims, Litigation & Defense Strategy (When the Lawsuit Lands) β€” Think: "Who's doing what once a claim is filed?" Working with defense counsel, attorney-client privilege and work product, the discovery process (interrogatories, depositions, production), alternative dispute resolution (mediation, arbitration), and reporting obligations (NPDB, state boards, carriers).


🟨 Yellow: Disclosure, Documentation & Communication (The Conversations and Records That Make or Break the Case) β€” Think: "What gets said, written, or disclosed β€” and how does that change exposure?" CANDOR and communication-and-resolution programs, disclosure of adverse events to patients and families, documentation standards and legal risks, medical-record alterations and late entries, and informed consent (process and documentation).


Three rules: highlight as you go, not at the end; when in doubt pick the color that fits the type of information, not the topic; and review by color β€” read only the red highlights, then only the yellow, and so on. You've got the system. Now let it work for you.

Week 1: Part I, Healthcare Risk Management Foundations


Difficulty: Heavy


What it covers:

  • The definition of modern healthcare risk management and how the enterprise-wide discipline differs from the older insurance-only model

  • The ASHRM Enterprise Risk Management (ERM) framework and the eight ASHRM domains: Operational, Clinical/Patient Safety, Strategic, Financial, Human Capital, Legal/Regulatory, Technology, and Hazard

  • The four-step risk management process (identify, analyze, treat, monitor) and the four treatment options (avoid, reduce, transfer, retain)

  • Risk appetite versus risk tolerance and how each sits at the governance level

  • The risk manager's role, reporting structure, and the membership and function of the risk management committee

  • Foundational vocabulary the rest of the book depends on: inherent risk, residual risk, sentinel event, near miss, just culture


Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ Lock in the four-step risk management process before anything else in this Part. Identify the risk (incident reports, audits, claims data, regulatory findings, leading indicators), analyze it for likelihood and severity, treat it through one of four options (avoid, reduce, transfer, retain), and monitor outcomes to confirm the treatment is working. The CPHRM exam tests this loop repeatedly, often by giving you a fact pattern and asking which step the described activity belongs to.


☐ Memorize the eight ASHRM domains and be ready to classify any exposure into the correct one (or ones). Operational covers day-to-day delivery failures. Clinical/Patient Safety covers harm to patients. Strategic covers mission and vision risks. Financial covers payment, capital, and revenue cycle. Human Capital covers workforce. Legal/Regulatory covers laws, statutes, and compliance. Technology covers IT, EHR, cyber, and medical devices. Hazard covers natural disasters, fire, and environmental exposures. Real exposures usually cross multiple domains, and the exam often rewards the answer that names every domain in play.


☐ Distinguish risk appetite from risk tolerance and apply both to a board-level decision. Appetite is the broad governance statement of how much risk the organization will accept in pursuit of mission and strategy. Tolerance is the operational permissible variation around a specific objective. An organization can have near-zero appetite for preventable patient harm but moderate tolerance for revenue variability in a new ambulatory program. Both must be explicit so frontline decisions stay aligned with governance.


☐ Build a clean reference page comparing inherent risk versus residual risk, and explain how that distinction drives the prioritization of controls. Inherent risk is what exists before controls. Residual risk is what remains after controls. The gap between the two is the value of the risk treatment, and a residual that still exceeds tolerance is the signal that more treatment is needed.


☐ Know the definitions of sentinel event, adverse event, never event, and near miss cold before moving to Part II, because these terms reappear in every subsequent Part. The Joint Commission's sentinel event definition (death, permanent harm, or severe temporary harm reaching the patient) is the version the CPHRM tests.


☐ Complete the Practice Questions for Part I in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Healthcare Risk Management Foundations. Main branches: Definition & Modern Scope of Risk Management β†’ ASHRM ERM Framework β†’ The Eight ASHRM Domains (Operational, Clinical/Patient Safety, Strategic, Financial, Human Capital, Legal/Regulatory, Technology, Hazard) β†’ Four-Step Risk Management Process (Identify, Analyze, Treat, Monitor) β†’ Four Treatment Options (Avoid, Reduce, Transfer, Retain) β†’ Risk Appetite vs. Risk Tolerance β†’ Risk Manager Role & Reporting Structure β†’ Risk Management Committee β†’ Inherent vs. Residual Risk β†’ Just Culture & Event Definitions.


Comparison Charts:


☐ Chart 1, Traditional Risk Management vs. Enterprise Risk Management (ERM): scope (siloed claims and insurance vs. organization-wide), ownership level (department vs. governance), language used (insurance terms vs. business strategy terms), integration with mission and strategy, and how each handles risks that cross multiple domains.


☐ Chart 2, The Four Risk Treatment Options (Avoid, Reduce, Transfer, Retain): what each option does, when it is the right choice, the cost trade-off, the residual risk implication, and one healthcare example for each (avoiding a high-risk procedure line, reducing falls through a bundle, transferring through commercial liability insurance, retaining through a self-insured trust or captive).


☐ Chart 3, Risk Appetite vs. Risk Tolerance: definition, organizational level (governance vs. operational), granularity, how each is documented, how each is communicated to frontline staff, and a healthcare example showing both used together for the same exposure.


Cornell Notes:


☐ Page 1, Cue questions: What are the four steps of the risk management process, and what is the central question each step answers? What are the eight ASHRM domains, and into which domain would a ransomware attack on the EHR be classified primarily, and into which secondary domains would it spill?


☐ Page 2, Cue questions: What is the difference between risk appetite and risk tolerance, and at what governance level is each set? What is the difference between inherent risk and residual risk, and how do you use that distinction to evaluate whether a control is sufficient?


Week 2: Part II, Clinical and Patient Safety


Difficulty: Heavy, High Yield


What it covers:

  • Precise definitions for adverse event, sentinel event, never event, and near miss, plus The Joint Commission Sentinel Event Policy and reporting expectations

  • Incident reporting systems and the Just Culture framework that determines how to respond to human error, at-risk behavior, and reckless behavior

  • The three core analytical methods (RCA / RCAΒ², FMEA, and Common Cause Analysis) and when to use each

  • CANDOR and Communication-and-Resolution Programs as the structured framework for honest disclosure after harm

  • Informed consent, refusal of treatment, and Against Medical Advice (AMA) documentation

  • Documentation standards, late-entry conventions, and the prohibition on record alteration

  • High-yield clinical safety practice areas: medication administration, surgery, patient identification, falls, pressure injury, suicide risk, OB, ED, and diagnostic error

  • Health equity disparities recognized as a clinical and risk management exposure


Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ Master the harm-event hierarchy before anything else. An adverse event is any harm caused by medical management (preventable or not). A sentinel event is the subset of adverse events that reaches the patient and meets the harm threshold (death, permanent harm, or severe temporary harm requiring major intervention). A never event is a National Quality Forum Serious Reportable Event, clearly identifiable and largely preventable (wrong-site surgery, retained foreign object). CMS Hospital-Acquired Conditions overlap with never events but are defined by reimbursement policy. A near miss is an unsafe condition that did not reach the patient and is the highest-yield signal for proactive reduction. The CPHRM tests these distinctions by the question stem, so know which definition controls which scenario.


☐ Match the right analytical method to the right job. RCA / RCA² is retrospective, applied after a sentinel or high-harm event to find system causes and drive strong, system-level actions (commonly within a 45-business-day window per TJC). FMEA is prospective, applied to a high-risk process (new technology, new workflow, high-volume medication) before harm occurs. Common Cause Analysis is aggregate, reviewing many similar events together to surface shared system drivers. Choosing the wrong tool for the situation is a classic exam trap.


☐ Learn the Just Culture dispositions cold. Console human error (an honest slip a competent person can make). Coach at-risk behavior (drift from policy where the person did not perceive risk). Sanction reckless behavior (conscious disregard of a substantial and unjustifiable risk). The same act may be categorized differently depending on intent and system context, which is why review categorization happens together rather than at the manager's desk.


☐ Build a one-page CANDOR and Communication-and-Resolution Program reference. The elements: early honest conversation with patient and family, prompt investigation, support for the involved clinicians (the "second victims"), and an early offer of resolution when investigation finds the standard of care was not met. CRPs are associated with reduced litigation costs and faster, fairer outcomes for patients, and they do not violate any legal duty when implemented within state law.


☐ Informed consent is a process, not a form. Know the four required elements: decision-making capacity, voluntary participation, adequate disclosure (nature, indication, risks, benefits, alternatives, and the option of no treatment), and the patient's understanding. Be ready to identify what invalidates consent (incapacity, coercion, incomplete disclosure) and how AMA documentation differs from refusal of a specific intervention.


☐ Documentation standards are tested directly. Late entries must be clearly labeled with the date and time of the entry (not backdated). Never alter an existing record. Corrections use a single line through the error, the correction, the date and time, and the author's initials. The medical record is the single most important defense document in any negligence claim.


☐ Complete the Practice Questions for Part II in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Clinical and Patient Safety. Main branches: Harm-Event Definitions (Adverse, Sentinel, Never, Near Miss) β†’ TJC Sentinel Event Policy β†’ Incident Reporting & Just Culture β†’ Analytical Methods (RCA/RCAΒ², FMEA, Common Cause Analysis) β†’ CANDOR & CRP β†’ Informed Consent, Refusal, AMA β†’ Documentation Standards β†’ High-Yield Clinical Safety Domains (medication, surgery, patient ID, falls, pressure injury, suicide risk, OB, ED, diagnostic error) β†’ Health Equity as a Risk Exposure.


Comparison Charts:


☐ Chart 1, Adverse Event vs. Sentinel Event vs. Never Event vs. Near Miss: definition, reach to patient (yes/no), harm threshold, source body that defines the category (TJC vs. NQF vs. CMS), reporting expectation, and one classic exam example for each.


☐ Chart 2, RCA / RCA² vs. FMEA vs. Common Cause Analysis: timing (retrospective, prospective, aggregate), trigger event, output (action plan vs. risk priority number vs. shared driver list), required participants, and typical clinical use case.


☐ Chart 3, Just Culture Dispositions (Console, Coach, Sanction): behavior type (human error, at-risk behavior, reckless behavior), intent, perception of risk, organizational response, and one healthcare example for each.


☐ Chart 4, Informed Consent vs. Refusal of Treatment vs. AMA Discharge: the documentation required, the capacity assessment performed, the disclosure expected, the witnesses and counter-signatures involved, and the residual liability exposure for each.


Cornell Notes:


☐ Page 1, Cue questions: What are the four harm-event categories the CPHRM tests, and what distinguishes a sentinel event from a never event by source and threshold? What is the TJC expectation for RCA² completion after a sentinel event, and what makes an action plan "strong" rather than weak?


☐ Page 2, Cue questions: What are the three Just Culture behavior categories, and what is the appropriate organizational response to each? What are the elements of CANDOR, and how does it reduce claim frequency and severity without violating legal duty?


☐ Page 3, Cue questions: What are the four required elements of valid informed consent, and what conditions invalidate it? What is the correct way to make a late entry or correction in a medical record, and what does record alteration look like in a deposition?


Week 3: Part III, Risk Financing


Difficulty: Heavy


What it covers:

  • Risk financing as a discipline, and how it differs from risk control within the broader risk management function

  • Self-insurance, single-parent and group captive insurance, and commercial insurance, and when each is the right structure

  • Claims-made versus occurrence professional liability policies, plus tail coverage and nose coverage

  • The major commercial coverages (professional liability, general liability, property, D&O, cyber, workers' compensation) and the exposure each addresses

  • Layered programs: primary, excess, and reinsurance, plus per-claim limits and aggregate limit erosion

  • Actuarial loss projections, loss reserves, and IBNR (incurred but not reported) reserves

  • Broker relationships and the insurance procurement cycle, including submissions, renewals, and market dynamics

  • Contractual risk transfer: indemnification, hold harmless, additional insured, and waivers of subrogation

  • Total Cost of Risk (TCOR) as the financial metric that ties the discipline together


Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ Claims-made versus occurrence is the single most-tested distinction in healthcare insurance. An occurrence policy locks in coverage by the date of the incident: the policy in force when the incident happened pays, regardless of when the claim is made. A claims-made policy ties coverage to the date the claim is reported during the policy period (subject to the retroactive date). Know the transition events cold: leaving a claims-made policy without buying tail coverage leaves a gap; switching insurers may require nose coverage. For long-tail liability (OB and pediatrics especially), this choice has consequences decades later.


☐ Self-insurance, captive insurance, and commercial insurance occupy different points on the retention-versus-transfer spectrum, and the CPHRM expects you to match each to the right exposure. Self-insurance is funded retention, typically through an actuarially supported trust. A single-parent captive is a licensed insurance company owned by one health system to insure its own risks. A group captive is owned by several unrelated organizations that share similar risks and pool premium. Captives offer insurance-company tax and regulatory treatment, formal underwriting discipline, and direct access to reinsurance markets. Commercial insurance is full transfer to a third-party carrier.


☐ Memorize the commercial insurance stack. Professional liability covers medical errors and harm to patients. General liability covers slips, falls, and non-professional bodily injury and property damage. Property covers buildings, contents, and business interruption. D&O covers governance decisions made by board members and executives. Cyber liability covers data breach response, regulatory fines, business interruption, and third-party claims. Workers' compensation covers employee on-the-job injuries and is statutory in every state. Each policy has its own triggers, exclusions, and underwriting rhythm.


☐ Learn the layered program structure. A primary policy responds first up to its limit. One or more excess layers sit above and respond after the primary is exhausted. Reinsurance protects the insurer or captive at the back end. Aggregate limits (total payout across all claims in a policy period) matter as much as per-claim limits, and erosion of the aggregate can leave the organization exposed mid-year. A high-frequency, lower-severity year and a low-frequency catastrophic-loss year stress the program at different layers.


☐ IBNR is the reserve that captures the latent severity of long-tail claims. Actuaries project ultimate losses from historical experience and recent triangle development; the reserve includes both case reserves (open known claims) and IBNR (claims incurred but not yet reported). Underfunding IBNR understates Total Cost of Risk and produces unpleasant balance-sheet surprises later. TCOR (retained losses + insurance premiums + administrative costs + risk control costs) is the single number that ties the discipline together and the metric the CPHRM expects you to define.


☐ Contractual risk transfer is the non-insurance side of risk financing. Know the four key levers: indemnification (one party agrees to make the other whole for defined losses), hold harmless (one party agrees not to hold the other liable), additional insured status (the other party's policy provides direct coverage), and waiver of subrogation (the insurer gives up its right to pursue the other party after paying a loss). These show up in every vendor and physician contract and are tested in fact-pattern questions.


☐ Complete the Practice Questions for Part III in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Risk Financing. Main branches: Risk Financing vs. Risk Control β†’ Retention Vehicles (Self-Insurance, Single-Parent Captive, Group Captive) β†’ Commercial Insurance Stack (Professional Liability, General Liability, Property, D&O, Cyber, Workers' Comp) β†’ Claims-Made vs. Occurrence (Tail and Nose Coverage) β†’ Layered Programs (Primary, Excess, Reinsurance) β†’ Aggregate vs. Per-Claim Limits β†’ Actuarial Analysis, Loss Reserves, IBNR β†’ Broker Relationship & Procurement Cycle β†’ Contractual Risk Transfer (Indemnification, Hold Harmless, Additional Insured, Waiver of Subrogation) β†’ Total Cost of Risk (TCOR).


Comparison Charts:


☐ Chart 1, Claims-Made vs. Occurrence Policies: coverage trigger (incident date vs. report date), role of the retroactive date, what tail coverage does, what nose coverage does, premium pattern over time, and the long-tail liability exposure each leaves open.


☐ Chart 2, Self-Insurance vs. Single-Parent Captive vs. Group Captive vs. Commercial Insurance: ownership structure, regulatory and tax treatment, underwriting discipline, access to reinsurance, typical use case in a health system, and the residual catastrophic exposure for each.


☐ Chart 3, Primary vs. Excess vs. Reinsurance Layers: order of response, who pays first, typical attachment point, premium relationship, and what happens when the aggregate of one layer erodes mid-year.


☐ Chart 4, Indemnification vs. Hold Harmless vs. Additional Insured vs. Waiver of Subrogation: legal mechanism, party benefited, what it shifts, where it shows up in a typical hospital contract, and one healthcare example of each.


Cornell Notes:


☐ Page 1, Cue questions: What is the difference between a claims-made policy and an occurrence policy, and what does the retroactive date do? When does a departing physician need tail coverage, and when does an incoming physician need nose coverage?


☐ Page 2, Cue questions: What are the components of the Total Cost of Risk, and how does a fully funded IBNR reserve change the TCOR picture? What is the difference between a per-claim limit and an aggregate limit, and what is the practical consequence of aggregate erosion?


☐ Page 3, Cue questions: What are the four contractual risk transfer levers (indemnification, hold harmless, additional insured, waiver of subrogation), and what does each one shift between the parties? When is a single-parent captive the right structure, and when does a group captive make more sense?


Week 4: Part IV, Legal and Regulatory Environment


Difficulty: Heavy, High Yield


What it covers:

  • Tort, negligence, and the four elements of a malpractice claim (duty, breach, causation, damages), plus how the standard of care is established at trial

  • Vicarious liability (respondeat superior), apparent agency, and direct corporate liability of the hospital

  • EMTALA obligations: medical screening exam, stabilization, and appropriate transfer

  • HIPAA Privacy, Security, and Breach Notification Rules together with state privacy laws, 42 CFR Part 2, and the 21st Century Cures Act information-blocking rule

  • Fraud and abuse statutes: Stark Law, the Anti-Kickback Statute, and the False Claims Act, including their intent requirements and remedies

  • Patient Safety Organization (PSO) protections and peer review confidentiality and privilege

  • The accreditation and licensure environment: The Joint Commission, CMS Conditions of Participation, state licensure, mandatory reporting laws

  • ADA requirements, jurisdictional differences in informed consent doctrine, and hospital exposure for the acts of independent contractors

  • Preemption: when federal law supplants state law and when state law (especially more protective privacy law) controls


Print: 1 Mind Map, 4 Comparison Charts, 3 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ The four elements of negligence are tested constantly. Duty (a provider-patient relationship establishing a duty of care), breach (departure from the standard of care), causation (factual and proximate, meaning the breach actually caused the harm), and damages (compensable harm). The standard of care is the level of skill and care a reasonably competent practitioner in the same specialty would exercise under similar circumstances, established at trial through expert testimony. If any element is missing, the claim fails, which is why documentation and clinical bundles matter so much to the defense.


☐ Distinguish the three theories of hospital liability and be ready to identify which one applies to a fact pattern. Vicarious liability (respondeat superior) holds the hospital responsible for the negligent acts of its employees within the scope of employment. Apparent agency extends similar exposure to independent contractors (most often ED physicians, hospitalists, anesthesiologists, and radiologists) when the patient reasonably believed they were dealing with the hospital. Corporate liability is the hospital's own direct duty to select competent practitioners, maintain safe equipment, supervise care, and respond to known risks. CPHRM reasoning often turns on which theory fits the facts.


☐ EMTALA imposes two core duties on Medicare-participating hospitals with emergency departments: provide a medical screening examination within the hospital's capability to anyone who comes to the ED requesting examination, and stabilize any patient with an emergency medical condition before transfer or discharge. The classic violations are inappropriate transfers ("dumping") and failure to screen. Penalties include civil monetary penalties, exclusion from Medicare, and private civil action. Insurance status and ability to pay are irrelevant to the duty.


☐ Map the federal privacy floor and the more protective state ceiling. HIPAA Privacy governs use and disclosure of PHI; Security governs administrative, physical, and technical safeguards for ePHI; Breach Notification sets the timing and content of breach notice. HIPAA preempts contrary state law but does not preempt state laws that are more protective. 42 CFR Part 2 imposes substantially stricter rules on substance use disorder treatment records from federally assisted programs. The Cures Act information-blocking rule prohibits practices that interfere with EHI access, exchange, or use except where a defined exception applies.


☐ Stark, AKS, and FCA are three distinct enforcement tools. Stark Law is a strict-liability prohibition on physician self-referral for designated health services where a financial relationship exists, unless an exception applies. Anti-Kickback is a criminal intent statute prohibiting remuneration to induce referrals for federally reimbursed services. False Claims Act creates civil and criminal liability for knowingly submitting false or fraudulent claims (and supports qui tam whistleblower actions). The intent standard is the key distinguisher among the three.


☐ Patient Safety Organization (PSO) protections and state peer review privilege protect the candid analysis that quality improvement depends on. PSO Patient Safety Work Product (PSWP) is privileged and confidential under federal law when properly developed and reported through a listed PSO. State peer review privilege protects the deliberations of a medical staff committee from discovery in civil litigation, with state-by-state variation in scope. Know what is protected, what is not, and what conduct waives the privilege.


☐ Complete the Practice Questions for Part IV in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Legal and Regulatory Environment. Main branches: Tort & Negligence (Duty, Breach, Causation, Damages, Standard of Care) β†’ Hospital Liability Theories (Vicarious, Apparent Agency, Corporate) β†’ EMTALA β†’ HIPAA Privacy/Security/Breach + 42 CFR Part 2 + Cures Act β†’ Fraud & Abuse (Stark, AKS, FCA) β†’ PSO Protections & Peer Review Privilege β†’ Accreditation & Licensure (TJC, CMS CoPs, State) β†’ Mandatory Reporting β†’ ADA β†’ Preemption Doctrine.


Comparison Charts:


☐ Chart 1, Vicarious Liability vs. Apparent Agency vs. Corporate Liability: legal basis, who is liable, who is the wrongdoer, the typical clinical scenario (employed nurse, contracted ED physician, hospital's own failure to credential), and the strongest defense available against each.


☐ Chart 2, HIPAA vs. 42 CFR Part 2 vs. State Privacy Law: scope of records covered, consent requirements, breach notification rules, preemption posture (federal floor, more protective state ceiling, special SUD overlay), and the practical impact on disclosure to family, payers, and law enforcement.


☐ Chart 3, Stark Law vs. Anti-Kickback Statute vs. False Claims Act: intent standard (strict liability vs. knowing and willful vs. knowing), conduct prohibited, type of remedy (civil monetary penalty, exclusion, criminal penalty, qui tam recovery), and one classic healthcare example of each violation.


☐ Chart 4, Stark Law vs. Anti-Kickback Statute Safe Harbors and Exceptions: how each safe harbor or exception is structured, what it allows, the specific documentation required, and one common arrangement (physician compensation, medical director agreement, space lease) that depends on each.


Cornell Notes:


☐ Page 1, Cue questions: What are the four elements of negligence, and how is the standard of care established at trial? Which of the four elements is the hardest to prove in a typical hospital fact pattern, and why does documentation matter so much to that element?


☐ Page 2, Cue questions: Under what circumstances does EMTALA's medical screening duty apply, and what counts as stabilization before transfer? What are the most common EMTALA violations the OIG has cited, and what is the typical penalty structure?


☐ Page 3, Cue questions: What is the intent standard for Stark Law, the Anti-Kickback Statute, and the False Claims Act, and which of the three is strict-liability? What is the difference between PSO Patient Safety Work Product and state peer review privilege, and what conduct waives each?


Week 5: Part V, Healthcare Operations


Difficulty: Moderate to Heavy


What it covers:

  • Credentialing, privileging, OPPE, and FPPE, plus medical staff bylaws and fair hearing procedures

  • National Practitioner Data Bank (NPDB) reporting and querying obligations

  • Workplace violence prevention, active shooter response, hazard vulnerability analysis, and business continuity

  • Environment of Care, Life Safety, infection prevention, and medical device safety from a risk perspective

  • Contract review for vendor, physician, and service agreements, plus due diligence for mergers, acquisitions, and affiliations

  • Risks in telemedicine, cross-state practice, and the use of AI and algorithmic tools in clinical care

  • The patient grievance and complaint process and how patient experience data functions as a leading risk signal

  • Cybersecurity, ransomware, and data breach response across clinical, operational, and regulatory dimensions


Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ The credentialing and privileging cycle is the hospital's single most direct corporate-liability exposure. Credentialing verifies who the practitioner is (education, training, licensure, certifications, work history, malpractice history, references) through primary source verification. Privileging decides what they may do based on demonstrated competence. OPPE monitors performance continuously against defined indicators (typically reviewed every 6 to 12 months under TJC). FPPE applies focused review when there is a new practitioner, a new privilege, or a performance concern. HCQIA federal peer review immunity attaches only when the adverse action follows a reasonable investigation, reasonable belief in furtherance of quality care, adequate notice and hearing, and reasonable belief in the warranted action.


☐ Memorize NPDB reporting and querying obligations. The NPDB is the federal repository of practitioner adverse action and payment information. Reportable actions include adverse clinical privileges actions lasting more than 30 days, professional society membership actions, state licensure actions, and medical malpractice payments. Querying is mandatory at initial appointment and reappointment (every two years) and is good practice at additional times defined in policy. Failure to report or query exposes the organization to loss of HCQIA immunity and federal sanctions.


☐ Build an emergency preparedness map that connects the Hazard Vulnerability Analysis to the Emergency Operations Plan. The CMS Emergency Preparedness Rule requires risk assessment, communication plan, policies and procedures, and training and testing for most provider types, and integrates with TJC standards and community planning. Workplace violence is a separate and substantial exposure (healthcare workers experience workplace violence at rates several times the general workforce); effective programs combine threat assessment, environmental design, training, reporting, and post-incident support.


☐ Contracts are where operational risk lives. Every vendor, physician, and service agreement allocates risk through indemnification, insurance requirements, scope, term, termination, intellectual property, data and compliance provisions. Mergers, acquisitions, and affiliations magnify this work because risk management participates in due diligence across clinical quality, claims and reserves, compliance history, contract obligations, EHR and data integration, real estate, and accreditation. A failed merger transfers multi-decade liabilities and pre-existing claims to the new entity by operation of law.


☐ Telemedicine, cross-state practice, and AI in clinical care are the emerging exposures the CPHRM increasingly tests. Cross-state practice raises licensure and informed consent jurisdiction questions; the Interstate Medical Licensure Compact streamlines but does not eliminate them. Algorithmic tools that drive diagnosis, triage, imaging interpretation, or workflow may meet the FDA Software as a Medical Device (SaMD) definition and may be subject to ONC algorithm transparency requirements for certified EHR products.


☐ Cyber and ransomware response is no longer purely an IT problem. Successful response requires pre-event tabletop exercises, an incident response plan that defines clinical downtime procedures, contractual obligations to notify and cooperate with carriers, regulatory breach notification timelines (HIPAA and state), and operational continuity planning so patient care continues during the event.


☐ Complete the Practice Questions for Part V in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Healthcare Operations. Main branches: Credentialing & Privileging Cycle (PSV, OPPE, FPPE, Bylaws, Fair Hearing, HCQIA Immunity) β†’ NPDB Reporting & Querying β†’ Workplace Violence Prevention β†’ Hazard Vulnerability Analysis & Emergency Preparedness (CMS Rule, EOP) β†’ Environment of Care, Life Safety, Infection Prevention, Medical Device Safety β†’ Contract Review (Vendor, Physician, Service) β†’ M&A and Affiliation Due Diligence β†’ Telemedicine & Cross-State Practice β†’ AI & Algorithmic Tools (SaMD, ONC Algorithm Transparency) β†’ Patient Grievance Process β†’ Cybersecurity, Ransomware, Breach Response.


Comparison Charts:


☐ Chart 1, Credentialing vs. Privileging vs. OPPE vs. FPPE: what each step does, when it is performed, who is involved, the documentation produced, and how each is used in a fair hearing or NPDB-reportable adverse action.


☐ Chart 2, Hazard Vulnerability Analysis vs. Emergency Operations Plan vs. Business Continuity Plan: purpose, scope, output, applicable regulatory requirement (CMS Emergency Preparedness Rule, TJC), and how each interacts with the other two during a real event.


☐ Chart 3, Telemedicine vs. In-Person Care from a Risk Perspective: licensure and jurisdiction, informed consent, standard of care, documentation, technology and connectivity failure exposure, and the new risk surfaces created by remote prescribing and remote patient monitoring.


Cornell Notes:


☐ Page 1, Cue questions: What are the four phases of the credentialing and privileging cycle (credentialing, privileging, OPPE, FPPE), and what is the difference between OPPE and FPPE in trigger and scope? What NPDB queries are mandatory, what actions are reportable, and what is the federal consequence of failing to query or report?


☐ Page 2, Cue questions: What are the four required elements of the CMS Emergency Preparedness Rule, and how does the Hazard Vulnerability Analysis drive the Emergency Operations Plan? What are the principal risk exposures in telemedicine and AI-driven clinical tools, and what regulatory frameworks (state licensure compacts, FDA SaMD, ONC algorithm transparency) shape each?


Week 6: Part VI, Claims and Litigation Management


Difficulty: Moderate to Heavy


What it covers:

  • Identifying potentially compensable events (PCEs) early, before formal claims emerge

  • Early intervention within the first 24 to 72 hours, including disclosure conversations, fact preservation, and provider support

  • Communication-and-Resolution Programs (CRPs), including the Michigan Model, and apology laws (currently in 39 states)

  • Working with defense counsel, including selection, coordination, and the limits of attorney-client privilege and work product doctrine

  • The discovery process: interrogatories, depositions, requests for production, and the realities of e-discovery

  • Mediation, arbitration, and alternative dispute resolution as paths to faster, more controlled resolution

  • Reporting obligations after settlement or verdict: NPDB, state licensing boards, and insurance carriers

  • The role of bill suspension or write-off for adverse-outcome care, and the risk created by balance billing for harm-related care


Print: 1 Mind Map, 3 Comparison Charts, 2 Cornell Notes pages


Study Tasks


☐ Read the Study Guide first. Complete the High-Yield Objectives, Key Terms and Definitions, and Concept Overview sections before opening the chapter.


☐ Highlight as you read. Follow the Made Easy Highlighting System


☐ Potentially Compensable Event identification is the front edge of claims management. A PCE is an adverse outcome with potential for a future claim, surfaced through incident reports, provider notification, patient complaints, death certificates, autopsy findings, demand letters, or disclosure conversations. Common triggers include unexpected deaths, returns to the OR, transfer to ICU after a procedure, birth injuries, medication errors with harm, wrong-site procedures, retained foreign objects, delayed diagnoses, HAIs with serious outcome, and patient complaints suggesting harm. Early identification preserves investigation opportunity, evidence integrity, witness recall, and mitigation options before formal claims erupt.


☐ The first 24 to 72 hours after an event drive the trajectory of the entire matter. Early intervention allows for disclosure conversations, fact preservation, provider support, and family communication before adversarial positioning hardens. CRPs (the Michigan Model is the canonical example) demonstrate that transparent communication, honest investigation, and early compensation when warranted reduce both claim frequency and severity. Disclosure to patients and families should be within 24 hours when feasible, must be factual, empathetic, and non-speculative, and should be followed up as investigation findings are completed.


☐ Apology laws (currently in roughly 39 states) protect expressions of sympathy from being admitted as evidence of liability. Admissions of fault generally remain admissible. Know the distinction the statute draws in your jurisdiction. Early offers under CRP frameworks are not admissions of liability in most jurisdictions but require state legal review before implementation. The exam tests whether you know the protection covers the apology, not the admission of fault.


☐ Build a one-page reference on the privileges that protect investigation and defense work product. Attorney-client privilege protects confidential communications between the organization and its counsel for the purpose of legal advice. Work product doctrine protects materials prepared in anticipation of litigation. PCE files structured under these doctrines, when channeled through counsel, preserve protection from discovery. Routine quality and incident review is not automatically privileged; the structure matters.


☐ The discovery process is the single largest cost driver in a claim. Interrogatories (written questions to the parties), depositions (sworn out-of-court testimony), and requests for production (documents, ESI, devices) are the three principal tools. E-discovery brings the EHR audit trail, secure messaging, and back-end metadata into scope. The therapist of poor documentation here is litigation: every late entry, every alteration, every missing signature surfaces in deposition.


☐ Know the reporting obligations that follow a settlement or verdict. Medical malpractice payments made on behalf of a practitioner are reportable to the NPDB, and most states require parallel reporting to the state licensing board. Carriers (and captives) require notice under policy terms, often within tight windows; late notice can jeopardize coverage. The bill suspension or write-off question for adverse-outcome care matters too: balance billing for harm-related care is a frequent driver of claim filings that could otherwise have been resolved.


☐ Complete the Practice Questions for Part VI in your quiz bank. Review every rationale, correct and incorrect.


How to Use Your Templates


☐ Mind Map: Central node = Claims and Litigation Management. Main branches: Identifying Potentially Compensable Events (PCEs) β†’ Early Intervention (24 to 72 hours) β†’ CRPs & Michigan Model β†’ Disclosure & Apology Laws β†’ Defense Counsel Relationship β†’ Attorney-Client Privilege & Work Product β†’ Discovery Process (Interrogatories, Depositions, Production, E-Discovery) β†’ Mediation, Arbitration, ADR β†’ Reporting Obligations (NPDB, State Boards, Carriers) β†’ Bill Suspension & Adverse-Outcome Care Billing.


Comparison Charts:


☐ Chart 1, Disclosure vs. Apology vs. Admission of Fault: what each communication contains, the legal protection (apology laws, CRP framework, none), the impact on liability exposure, the documentation required, and the timing relative to investigation findings.


☐ Chart 2, Attorney-Client Privilege vs. Work Product Doctrine vs. PSO Patient Safety Work Product: what each protects, the scope, what waives the protection, how each is structured operationally to preserve protection, and the discoverability of materials that fall outside each.


☐ Chart 3, Mediation vs. Arbitration vs. Trial: decision-maker, finality of outcome, formality, cost, timeline, confidentiality, and the typical clinical and litigation profile that favors each path.


Cornell Notes:


☐ Page 1, Cue questions: What is a Potentially Compensable Event, and what are the top triggers a mature program scans for? What is the appropriate disclosure timeline, content, and tone in the first 24 hours after a harm event, and what does an apology law protect versus not protect?


☐ Page 2, Cue questions: What is the difference between attorney-client privilege and the work product doctrine, and what operational structure preserves each? What are the three reporting obligations that follow a settlement or verdict (NPDB, state board, carrier), and what is the risk of late or missed reporting?


Week 7: Final Review & Exam Simulation


Your final week is not about learning new material, it is about consolidating everything you have built and proving it under exam conditions.


Review Tasks


☐ Re-draw one Mind Map from memory for each Part you feel least confident about. Check it against your original.


☐ Work through your Cornell Notes cue columns for every Part. Cover the right-hand notes and answer from memory.


☐ Re-do any quiz bank questions you got wrong across all Parts. Focus on the rationales.


☐ Review the Common Mistakes, Rapid Review, and Self-Assessment Checklist sections for your two or three weakest Parts.


Exam Simulation


☐ Take the full-length CPHRM practice exam using the QR code in the back matter of this book. Complete it in one sitting, timed, as close to real exam conditions as 

possible.


☐ Review your emailed score report. Identify which Parts you missed most, and spend remaining time on those Parts' Rapid Review and application scenarios only.

You've worked the whole plan. Now prove it.

​

Take your free full-length practice test under real conditions and see exactly where you stand. ​​​​​​​

Bonus Study Resources

AdobeStock_458104473_edited.png

 

Already included with your book. Make sure you're using all of it:

​

  • Quiz Bank: drill your recall with exam-style questions (access link on your landing page).

  • Study Guide: the full content breakdown, built into this book.

  • 1 Full-Length Simulation Exam: your first timed, exam-day practice run.

  • Anki Flashcard Deck: digital flashcards for every key term, ready to import into Anki for spaced-repetition study.

  • Free Resource Hub: every book includes free access to your landing page, with the Practice Lab and study games, your study plan, and the links to launch your Quiz Bank and simulation exam.​

Close every gap. Get the Complete Bundle.​

​​Cheat Sheets, Workbook, and 3 more Full-Length Simulation Exams, together in one bundle.​​​​​

​

Cheat Sheets

The entire exam condensed into high-yield sheets for fast review in the final days.

Duplicate page 4.png

18,000+ Scenario-Based Questions  |  70+ Courses and Growing

bottom of page