
The short answer
Patient safety carries 18 of the 125 scored questions on the CPHQ exam, or 14.4 per cent of your result. CPHQ patient safety items turn on three decisions: whether an event needs retrospective analysis or a process needs prospective analysis, how strong a proposed corrective action is, and how the organisation should respond to the person involved. Get those three right and most of the domain follows.
What does the patient safety domain cover?
NAHQ's content outline assigns this domain 18 scored items. The paper is 140 questions, 15 of them unscored pretest items, sat in a maximum of three hours and reported as a scaled score from 200 to 800 with 600 passing. Patient safety is the fourth largest domain, and the one where clinical experience helps you most and misleads you most: you know what a serious event looks like on a ward, but the exam asks what a quality professional does about it. The full weighting of the seven domains is worth having in front of you when you plan revision.
It covers event identification and reporting, classification and severity rating, retrospective and prospective analysis, corrective action design, safety culture, high-reliability principles and disclosure. Stems almost always contain harm or its credible risk, the cue separating this domain from performance improvement.
Which CPHQ patient safety concepts does NAHQ test?
Incident reporting and event classification
Distinguish an adverse event from a near miss and an unsafe condition, and know that a reporting system's value lies in what is learned, not in the count of reports. A rising report rate alongside stable harm rates usually means reporting culture is improving, and items test that inversion. Severity classification drives what happens next: full analysis, aggregation, or trending.
Sentinel events and never events
A sentinel event is generally defined as a patient safety event reaching a patient that results in death, permanent harm or severe temporary harm, and which signals the need for immediate investigation and response. Never events are described as serious, largely preventable events of public concern, and several bodies publish lists of them. Learn the concept and the trigger rather than any one list: definitions differ between bodies, and items test the response required.
—
Root cause analysis and RCA2
RCA is retrospective. It runs after an event, with a multidisciplinary team including the people who do the work, and asks what happened, why, and what will prevent recurrence. Its structure is a timeline, contributing factors grouped by category, and causal statements linking cause to effect without naming an individual.
The refinement usually taught as RCA2 exists because too many analyses ended in weak actions. It adds triage of which events get analysed, involvement of the people at the sharp end, disciplined causal statements, actions ranked by strength, and measurement of whether the action worked. Where a stem describes an RCA whose only output was re-education and a policy update, the criticism intended is action strength.
—
Failure mode and effects analysis
FMEA is prospective. It examines a process before harm occurs, asking how each step could fail, what would follow, and how likely the failure is to be detected. Steps are scored for severity, occurrence and detectability, and the product prioritises where to act. The cue is a new, redesigned or high-risk process.
Action strength
The most productive thing to memorise here. Strong actions change the system so the error becomes difficult or impossible: forcing functions, physical changes, removing a hazardous product, simplification, automation with safeguards. Intermediate actions reduce reliance on memory: checklists, standardised protocols, redundancy, alerts. Weak actions depend on people behaving differently after being told: education, policies, warnings, human double checks. Where two options look sensible, the stronger is almost always right.
Just culture and high reliability
Just culture separates behaviour from outcome. Human error is consoled and the system examined; at-risk behaviour is coached, with attention to why the shortcut felt reasonable; reckless behaviour, a conscious disregard of substantial risk, attracts discipline. Outcome severity does not determine the response, and items test that by pairing a small lapse with a catastrophic result.
High-reliability organising is commonly taught as five principles: preoccupation with failure, reluctance to simplify, sensitivity to operations, commitment to resilience, and deference to expertise rather than seniority. Expect them as recognition items, and as scenarios where the right answer takes a small signal seriously.
Disclosure
Disclosure to the patient or family is prompt, factual, delivered by an appropriate clinician, and covers what is known, what is not, what will be done to find out, and an expression of regret. It is separate from the internal analysis and does not wait for it.
The FMEA that found the wrong failure mode
Some years ago I facilitated an FMEA on subcutaneous insulin administration on a medical floor. The trigger was reasonable: two dosing incidents in a quarter, a new insulin pen formulary, and a director who wanted the process examined before something worse happened. We mapped the process, scored the failure modes, and the highest score by a distance was "wrong dose drawn up or selected". So we built the intervention that score implied: an independent double check by a second nurse before every administration, a revised chart, and teaching on every shift. It took four months, pleased the committee, and the eight-week audit showed the check documented reliably. The next serious event had nothing to do with dose selection. A patient received a correct dose at the wrong time, after the meal trolley had been and before the glucose result returned, and became hypoglycaemic overnight. Timing coordination between glucose testing, meals and insulin had been on our FMEA. We scored it low on occurrence and high on detectability, and it ranked near the bottom. Why we scored it wrongly is the part worth repeating. The scoring room held the ward manager, two educators, a pharmacist and me. No bedside nurse was present for scoring, only for the mapping. We scored the process as written rather than as performed, so we could not know that trolley times moved with staffing, that glucose results were chased rather than delivered, and that nurses were making a timing judgement nobody had called a decision. We also scored from memory rather than from the incident reports, which held timing near misses nobody had read. We repeated the scoring with two staff nurses and a healthcare assistant present and a year of incident reports on the table. Timing coordination moved to the top, and the action was structural rather than instructional: the glucose result had to be visible before the dose was given, built into the round rather than taught. The first attempt cost four months, a double check abandoned within a year, and one patient harmed by a failure mode we had written down and dismissed.
—
RCA, RCA2, FMEA or aggregate review: which analysis does the stem want?
Most method-selection errors here come from reading the tool before the trigger, and the trigger is in the first line of the stem.
| Method | Trigger | Looks | Output | Where candidates go wrong |
|---|---|---|---|---|
| Root cause analysis | A serious event has occurred | Backwards from the event | Causal statements and actions with owners and measures | Stopping at the individual instead of the system conditions |
| RCA2 | As above, where earlier analyses produced weak actions | Backwards, with triage and ranking added | Ranked actions, strength assessed, effectiveness measured | Accepting education as an action and never measuring it |
| FMEA | A high-risk, new or redesigned process, before harm | Forwards through each step | Prioritised failure modes and design changes | Scoring the process as written, without the people who perform it |
| Aggregate review | Many low-harm events or near misses of one type | Across cases for a shared pattern | System themes no single case would show | Running a full analysis on each minor event and exhausting the team |
Three exam-style patient safety questions, worked through
These are written in the NAHQ style, not drawn from any exam.
Question 1: choosing the analysis
A hospital is introducing an intravenous chemotherapy preparation workflow in an area that has not handled these agents before. No incidents have occurred. The director of pharmacy asks the quality department to identify the risks before it goes live. Which method is most appropriate?
- Root cause analysis of chemotherapy incidents at other hospitals
- Failure mode and effects analysis of the proposed workflow
- An aggregate review of medication near misses from the past year
- A safety culture survey of the pharmacy staff
Answer: 2. The process is new, high risk, and no harm has occurred: the case for prospective analysis. Option 1 misuses a retrospective method on events at organisations whose processes are not the one being introduced. Option 3 examines a different process and misses failure modes unique to the new workflow. Option 4 measures perceptions rather than process risk.
Question 2: action strength
After a wrong-site block, an RCA team finds the site was marked but the mark was covered by drapes before the time-out, and that the time-out was performed while the surgeon was scrubbing and was not witnessed by the whole team. Which corrective action is strongest?
- Re-educate theatre staff on the time-out policy
- Add a reminder poster to each theatre
- Change the draping sequence so the mark stays visible at the time-out, and require the procedure to stop until every team member has responded
- Issue a revised policy requiring the surgeon to confirm the site verbally
Answer: 3. It changes the physical process so the mark cannot be hidden, and makes the time-out a forcing function that cannot proceed without the team. Options 1 and 2 are weak actions relying on memory, and a policy followed inattentively was already in place. Option 4 is another policy change and does not address the covered mark. Where one option redesigns the process and another tells people about it, choose the redesign.
Question 3: just culture
An experienced nurse administers a medication without scanning the barcode, as several colleagues routinely do because the scanner is slow and often fails. The patient suffers serious harm. What is the appropriate organisational response?
- Disciplinary action proportionate to the harm
- Coach the nurse, and investigate why bypassing the scan had become normal
- Console the nurse and take no further action, as the outcome was unintended
- Suspend the nurse pending the root cause analysis
Answer: 2. Skipping a step colleagues also skip, for a reason grounded in a malfunctioning system, is at-risk behaviour, and the response to at-risk behaviour is coaching plus removal of the incentive to drift. Option 1 lets the outcome determine the response, the specific error just culture exists to prevent. Option 3 treats at-risk behaviour as simple human error and leaves the scanner and the workaround in place. Option 4 is punitive by default and suppresses reporting from everyone watching. Read the behaviour, not the harm.
How this domain connects to the ones around it
Patient safety shares its cause-analysis tools with performance and process improvement, the largest domain at 27 scored items. Fishbone diagrams, five whys and process mapping appear in both, and the trigger separates them: harm or its risk points here, a performance gap points there. Corrective actions from an RCA are then delivered as improvement work, which is why the two domains keep handing scenarios back and forth.
It also touches quality review and accountability, 16 items, wherever an event raises a question about an individual practitioner rather than a process. A stem about whether a clinician should keep a privilege is not a patient safety item, even when it opens with an event.
A ten-point revision checklist for patient safety
- State the weighting from memory: 18 of 125 scored items, 14.4 per cent.
- Define adverse event, near miss and unsafe condition, with an example of each.
- Explain why a rising report rate can be a good sign.
- Write the trigger for RCA and for FMEA in one sentence each, without naming the tools.
- Reproduce the action hierarchy from strong to weak, with two examples at each level.
- Explain what RCA2 adds to a conventional RCA.
- Describe the three behaviours just culture separates, and the response to each.
- List the five high-reliability principles and say which one an ignored near miss fails.
- State what a disclosure conversation contains and when it happens.
- Take ten mixed safety items and record, for each error, whether you misread the trigger or the action strength.
What to do next
Practise the two habits that carry this domain: name the trigger before choosing a method, and rank every option by action strength before answering. The companion video lesson, which works an action hierarchy through a corrective action plan, is in the CPHQ study video library, and the free CPHQ practice test will show whether safety is costing you marks. The weighting comes from NAHQ's CPHQ credential page.



