ASHRM CPHRM Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 3, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

ASHRM CPHRM Exam Details

Key details for this exam, checked against the published exam outline

119 Practice Questions (Our Bank)
120 minutes Exam Duration
USD 425 Exam Fee (United States)
Exam Code
CPHRM
Full Name
Certified Professional in Health Care Risk Management
Issuing Body
American Hospital Association Certification Center (AHA-CC)
Question Format (Our Bank)
Multiple Choice
Delivery
Online proctored or at a PSI Assessment Center
Eligibility
Baccalaureate degree or higher plus 5 years healthcare experience (3 in risk management), OR Associate degree plus 7 years healthcare experience (5 in risk management), OR High school diploma plus 9 years healthcare experience (7 in risk management). All
Validity
3 years, requires 45 continuing education credits for renewal
Practice Questions

Free CPHRM Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our CPHRM exam preparation team, who also write the explanation shown with each one. How we research and review these pages

An unstable patient in the emergency department needs transfer to another hospital. Which of the following statements is true regarding the refusal of an on-call physician to treat this patient?

Correct Answer: C
Explanation

Under Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, obligations under the Emergency Medical Treatment and Labor Act EMTALA govern on-call physician responsibilities. When a hospital maintains an on-call roster to provide specialty services for emergency department patients, physicians listed on call are required to respond and participate in the evaluation and stabilization of patients with emergency medical conditions.

An on-call physician may only be relieved of duty if legitimately unavailable due to circumstances beyond their control, such as actively caring for another patient or being otherwise unable to respond in accordance with hospital policy. Refusal to treat for convenience or non-clinical reasons may constitute an EMTALA violation and expose both the hospital and physician to regulatory penalties.

A blanket right to refuse care is inconsistent with EMTALA requirements. While financial discrimination is prohibited, refusal for other non-justifiable reasons may still violate federal law. Conversely, stating that a physician is never relieved of duty is inaccurate, as legitimate unavailability may excuse performance under specific circumstances.

Legal and regulatory objectives emphasize compliance with EMTALA, proper on-call coverage policies, and documentation of availability. Therefore, the correct statement is that relief occurs only when the physician is unavailable due to circumstances outside their control.

Which of the following should prompt a risk manager to give notice to a malpractice carrier?

Correct Answer: B
Explanation

Under Health Care Risk Management principles established by ASHRM and the American Hospital Association Certification Center, timely notice to a malpractice carrier is a critical obligation, particularly under claims-made policies. A demand letter from a patient constitutes a clear assertion of liability and a request for compensation, which typically meets the definition of a claim under most malpractice insurance policies. Failure to notify the carrier promptly may jeopardize coverage.

A written medical record request from an attorney may signal potential litigation, but it does not necessarily constitute a claim unless accompanied by an allegation of wrongdoing or a demand for damages. An internal incident report is a risk management tool used for quality and safety improvement and does not itself trigger insurance notification requirements. Similarly, disclosure to a patient regarding an adverse event aligns with transparency practices but does not automatically represent a formal claim.

Risk management objectives emphasize understanding policy language, particularly definitions of claim and reporting requirements. Because a demand letter explicitly alleges harm and seeks compensation, it most clearly triggers the duty to notify the malpractice carrier to preserve coverage and initiate appropriate claims handling procedures.

Which of the following are common techniques used to include patients and families in programs to educate patients about their safety?

lay persons on select committees

patient education opportunities

patient events referred for peer review

event reporting by patients and families

Correct Answer: B
Explanation

According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, patient and family engagement is a critical element of patient safety programs. Including lay persons on select committees, such as patient safety or quality committees, allows patients and families to contribute perspectives that enhance transparency and system improvement. Structured patient education opportunities empower individuals to understand their care, ask questions, and actively participate in safety practices, such as medication verification and infection prevention.

Event reporting by patients and families is another proactive strategy that promotes open communication and early identification of safety concerns. Encouraging patients to report perceived errors or near misses supports a culture of safety and partnership.

Referring patient events for peer review is an internal professional evaluation process focused on provider performance and quality improvement. While important for clinical oversight, it is not a technique designed to directly include patients and families in educational safety programs.

Clinical and patient safety objectives emphasize collaboration, transparency, and patient-centered care. Therefore, inclusion of lay persons on committees, patient education initiatives, and patient or family event reporting are appropriate techniques for involving patients in safety programs.

A root cause analysis of inpatient suicides would be most likely to discover problems with:

Correct Answer: A
Explanation

Inpatient suicide prevention is a high-stakes patient safety domain where RCAs frequently identify environmental hazards---particularly ligature risks, blind spots, and unit design that limits observation. Joint Commission--style reviews and published analyses note that the physical environment is commonly ''incriminated'' in inpatient suicides, emphasizing design/engineering controls alongside clinical monitoring. Risk management objectives prioritize layered defenses: ligature-resistant fixtures, environmental rounding, safe room standards, removal control for risky items, and observation policies matched to patient risk. Environmental mitigation is especially powerful because it reduces reliance on perfect human vigilance (which is not realistic). By treating suicide prevention as a systems problem---not an individual failure---organizations improve reliability and reduce recurrence. Environmental corrections also strengthen regulatory readiness and demonstrate that the facility addressed known hazards with sustainable controls.

An interrogatory requests insurance policy information. A risk manager should

Correct Answer: A
Explanation

According to Health Care Risk Management standards supported by ASHRM and the American Hospital Association Certification Center, insurance policy information is generally discoverable in litigation. Most jurisdictions require disclosure of applicable liability coverage, including policy limits, pursuant to civil procedure rules governing discovery. Therefore, when an interrogatory properly requests insurance policy information, the organization should provide the specifically requested information in coordination with defense counsel.

Providing more information than requested, such as automatically including excess limits if not asked, may exceed the scope of the interrogatory and should be guided by legal counsel. A certificate of insurance is not a substitute for responding to formal discovery requests, as it may not contain all required details regarding coverage, limits, and applicable policy periods.

Objecting to the interrogatory without valid legal grounds is generally inappropriate, as insurance coverage information is typically relevant to potential satisfaction of judgment.

Claims and litigation objectives emphasize cooperation with counsel, compliance with discovery rules, and accurate disclosure of coverage information. Therefore, the appropriate response is to provide the specifically requested insurance policy information in accordance with legal guidance.

Get Full Access

119 questions covering all exam domains, starting from $20

Study Guide

What the ASHRM CPHRM Exam Covers

Exam domains verified against: Official ASHRM CPHRM exam guide, last checked September 2026.

Domain 1: Clinical/Patient Safety

Candidates assess patient safety awareness, collaborate on proactive safety initiatives using methods like FMEA and RCA, and design educational programs. They promote safety culture through policy development, coach providers on disclosure methods, participate in incident debriefing and corrective action planning, and provide guidance on informed consent, substitute decision-makers, and abuse allegations. Manage incident reporting systems and review documentation to mitigate risk.

Sample questions from this domain above: Q1Q4Q5

Domain 2: Risk Financing

Candidates manage comprehensive insurance programs including captive management, self-insured coverages, and claims coordination. They oversee investigation of accidents and circumstances leading to financial loss, analyze loss experience and trends, develop enterprise risk financing strategies for exposures like general liability and professional liability, and ensure timely incident reporting according to insurance policy requirements.

Domain 3: Legal and Regulatory

Candidates promote compliance with federal and state laws and regulations through policy development and education, including HIPAA, EMTALA, CMS requirements, and NPDB. They manage patient confidentiality policies, reporting requirements for vulnerable populations and workplace violence, patient complaint resolution procedures, and accreditation readiness. They participate in responses to regulatory inquiries and develop organizational compliance plans.

Sample question from this domain above: Q3

Domain 4: Healthcare Operations

Candidates collaborate on workplace violence prevention, conduct risk assessments for new and existing services, establish reporting methods for harm and near-harm incidents, and supervise risk management staff. They develop departmental policies and procedures, coordinate risk activities, establish institutional goals, evaluate program effectiveness, provide education on patient rights, and collaborate on policies addressing high-risk topics like privacy, informed consent, and infection prevention.

Sample question from this domain above: Q2

Domain 5: Claims and Litigation

Candidates maintain data collection systems for potential compensatory events, open and closed claims, and loss runs. They notify carriers and claims administrators of potential claims, participate in claims management including counsel assignment, loss reserves, and discovery responses. They evaluate claims for organizational exposure, inform administration of high-exposure cases, manage legal case information under attorney-client privilege, and support insured defendants through litigation phases.

FAQ

CPHRM Exam FAQ

Common questions about the exam itself

What healthcare risk management experience do I need to qualify for CPHRM?
You must have a minimum of 3,000 hours of healthcare risk management experience within a defined timeframe depending on your education level. If you hold a bachelor's degree or higher, you need 5 years total healthcare experience with at least 3 years in risk management. With an associate degree, you need 7 years total with 5 in risk management. With only a high school diploma, you need 9 years total with 7 in risk management.
How long do I have to sit the CPHRM exam after applying?
You must schedule and complete the CPHRM exam within 90 days of receiving eligibility confirmation from the AHA. If you do not test within this window, your application and fees are forfeited and you must reapply and pay all fees again.
Can I reschedule or retake the CPHRM exam if I don't pass?
You can reschedule your exam at no charge if you do so at least two days before your scheduled test date, but any rescheduled exam must occur within 90 days of your original appointment. There is no limit on retakes, but each retake requires paying the full exam fee again and submitting a new application.
How long is the CPHRM certification valid and what does renewal require?
Your CPHRM credential is valid for 3 years. To renew, you must earn 45 continuing education credits related to healthcare risk management and submit your renewal application before your credential expires. If you do not renew within the grace period, you must retake and pass the full CPHRM exam to reinstate your credential.
What format is the CPHRM exam and how much time do I get to complete it?
The CPHRM exam is computer-based and consists of 110 multiple-choice questions, of which 100 are scored and 10 are unscored pretest questions. You have 2 hours to complete the entire exam. You can take it at a PSI Assessment Center or opt for a live remote-proctored exam with PSI.
What is the most challenging domain on the CPHRM exam and how should I prepare?
Legal and Regulatory is often identified as the most difficult domain because it requires knowledge of multiple federal regulations including HIPAA, EMTALA, CMS, and NPDB requirements. Focus your preparation on understanding how these regulations apply practically within healthcare settings and practice applying them to risk scenarios.
How much does the CPHRM exam cost and are there member discounts?
The exam fee is $425 for non-members. ASHRM members and other AHA Personal Membership Group members pay a reduced fee of $275. The fee covers both your application and exam administration through PSI.
How long should I plan to study for the CPHRM exam?
Most candidates who already work in healthcare risk management spend 2 to 4 months preparing for the CPHRM. The exact timeline depends on your existing knowledge of the five domains and how thoroughly you study. ASHRM offers exam prep courses and practice exams by domain to help you identify weak areas and focus your effort efficiently.
What happens on exam day when I take the CPHRM?
Arrive at your PSI test center 15-30 minutes early with your AHA Authorization to Test document which contains your unique ID number. After check-in, you must leave your mobile phone and personal belongings in your car or a secure locker outside the testing area. You will have 2 hours at your computer workstation to answer 110 questions.
What job role does the CPHRM certification prepare me for?
The CPHRM is designed for professionals working as healthcare risk managers, patient safety officers, or compliance specialists in hospitals and health systems. The certification validates your expertise across five critical domains including patient safety, risk financing, legal and regulatory compliance, healthcare operations management, and claims and litigation handling.