Yalla CPHQ

CPHQ Patient Safety: RCA, FMEA and Just Culture

Eighteen of the 125 scored CPHQ items come from patient safety. A working guide to the trigger that decides between RCA and FMEA, the action strength hierarchy, just culture, and an FMEA of mine that ranked the wrong failure mode.

DDr. Ahmed Habib, CPHQ, MD, MScSeptember 3, 202619 min read18 views

The short answer

Patient safety carries 18 of the 125 scored questions on the CPHQ exam, or 14.4 per cent of your result. CPHQ patient safety items turn on three decisions: whether an event needs retrospective analysis or a process needs prospective analysis, how strong a proposed corrective action is, and how the organisation should respond to the person involved. Get those three right and most of the domain follows.

What does the patient safety domain cover?

NAHQ's content outline assigns this domain 18 scored items. The paper is 140 questions, 15 of them unscored pretest items, sat in a maximum of three hours and reported as a scaled score from 200 to 800 with 600 passing. Patient safety is the fourth largest domain, and the one where clinical experience helps you most and misleads you most: you know what a serious event looks like on a ward, but the exam asks what a quality professional does about it. The full weighting of the seven domains is worth having in front of you when you plan revision.

It covers event identification and reporting, classification and severity rating, retrospective and prospective analysis, corrective action design, safety culture, high-reliability principles and disclosure. Stems almost always contain harm or its credible risk, the cue separating this domain from performance improvement.

Which CPHQ patient safety concepts does NAHQ test?

Incident reporting and event classification

Distinguish an adverse event from a near miss and an unsafe condition, and know that a reporting system's value lies in what is learned, not in the count of reports. A rising report rate alongside stable harm rates usually means reporting culture is improving, and items test that inversion. Severity classification drives what happens next: full analysis, aggregation, or trending.

Sentinel events and never events

A sentinel event is generally defined as a patient safety event reaching a patient that results in death, permanent harm or severe temporary harm, and which signals the need for immediate investigation and response. Never events are described as serious, largely preventable events of public concern, and several bodies publish lists of them. Learn the concept and the trigger rather than any one list: definitions differ between bodies, and items test the response required.

Root cause analysis and RCA2

RCA is retrospective. It runs after an event, with a multidisciplinary team including the people who do the work, and asks what happened, why, and what will prevent recurrence. Its structure is a timeline, contributing factors grouped by category, and causal statements linking cause to effect without naming an individual.

The refinement usually taught as RCA2 exists because too many analyses ended in weak actions. It adds triage of which events get analysed, involvement of the people at the sharp end, disciplined causal statements, actions ranked by strength, and measurement of whether the action worked. Where a stem describes an RCA whose only output was re-education and a policy update, the criticism intended is action strength.

Failure mode and effects analysis

FMEA is prospective. It examines a process before harm occurs, asking how each step could fail, what would follow, and how likely the failure is to be detected. Steps are scored for severity, occurrence and detectability, and the product prioritises where to act. The cue is a new, redesigned or high-risk process.

Action strength

The most productive thing to memorise here. Strong actions change the system so the error becomes difficult or impossible: forcing functions, physical changes, removing a hazardous product, simplification, automation with safeguards. Intermediate actions reduce reliance on memory: checklists, standardised protocols, redundancy, alerts. Weak actions depend on people behaving differently after being told: education, policies, warnings, human double checks. Where two options look sensible, the stronger is almost always right.

Just culture and high reliability

Just culture separates behaviour from outcome. Human error is consoled and the system examined; at-risk behaviour is coached, with attention to why the shortcut felt reasonable; reckless behaviour, a conscious disregard of substantial risk, attracts discipline. Outcome severity does not determine the response, and items test that by pairing a small lapse with a catastrophic result.

High-reliability organising is commonly taught as five principles: preoccupation with failure, reluctance to simplify, sensitivity to operations, commitment to resilience, and deference to expertise rather than seniority. Expect them as recognition items, and as scenarios where the right answer takes a small signal seriously.

Disclosure

Disclosure to the patient or family is prompt, factual, delivered by an appropriate clinician, and covers what is known, what is not, what will be done to find out, and an expression of regret. It is separate from the internal analysis and does not wait for it.

The FMEA that found the wrong failure mode

Some years ago I facilitated an FMEA on subcutaneous insulin administration on a medical floor. The trigger was reasonable: two dosing incidents in a quarter, a new insulin pen formulary, and a director who wanted the process examined before something worse happened. We mapped the process, scored the failure modes, and the highest score by a distance was "wrong dose drawn up or selected". So we built the intervention that score implied: an independent double check by a second nurse before every administration, a revised chart, and teaching on every shift. It took four months, pleased the committee, and the eight-week audit showed the check documented reliably. The next serious event had nothing to do with dose selection. A patient received a correct dose at the wrong time, after the meal trolley had been and before the glucose result returned, and became hypoglycaemic overnight. Timing coordination between glucose testing, meals and insulin had been on our FMEA. We scored it low on occurrence and high on detectability, and it ranked near the bottom. Why we scored it wrongly is the part worth repeating. The scoring room held the ward manager, two educators, a pharmacist and me. No bedside nurse was present for scoring, only for the mapping. We scored the process as written rather than as performed, so we could not know that trolley times moved with staffing, that glucose results were chased rather than delivered, and that nurses were making a timing judgement nobody had called a decision. We also scored from memory rather than from the incident reports, which held timing near misses nobody had read. We repeated the scoring with two staff nurses and a healthcare assistant present and a year of incident reports on the table. Timing coordination moved to the top, and the action was structural rather than instructional: the glucose result had to be visible before the dose was given, built into the round rather than taught. The first attempt cost four months, a double check abandoned within a year, and one patient harmed by a failure mode we had written down and dismissed.

From practice — to be written

RCA, RCA2, FMEA or aggregate review: which analysis does the stem want?

Most method-selection errors here come from reading the tool before the trigger, and the trigger is in the first line of the stem.

MethodTriggerLooksOutputWhere candidates go wrong
Root cause analysisA serious event has occurredBackwards from the eventCausal statements and actions with owners and measuresStopping at the individual instead of the system conditions
RCA2As above, where earlier analyses produced weak actionsBackwards, with triage and ranking addedRanked actions, strength assessed, effectiveness measuredAccepting education as an action and never measuring it
FMEAA high-risk, new or redesigned process, before harmForwards through each stepPrioritised failure modes and design changesScoring the process as written, without the people who perform it
Aggregate reviewMany low-harm events or near misses of one typeAcross cases for a shared patternSystem themes no single case would showRunning a full analysis on each minor event and exhausting the team

Three exam-style patient safety questions, worked through

These are written in the NAHQ style, not drawn from any exam.

Question 1: choosing the analysis

A hospital is introducing an intravenous chemotherapy preparation workflow in an area that has not handled these agents before. No incidents have occurred. The director of pharmacy asks the quality department to identify the risks before it goes live. Which method is most appropriate?

  1. Root cause analysis of chemotherapy incidents at other hospitals
  2. Failure mode and effects analysis of the proposed workflow
  3. An aggregate review of medication near misses from the past year
  4. A safety culture survey of the pharmacy staff

Answer: 2. The process is new, high risk, and no harm has occurred: the case for prospective analysis. Option 1 misuses a retrospective method on events at organisations whose processes are not the one being introduced. Option 3 examines a different process and misses failure modes unique to the new workflow. Option 4 measures perceptions rather than process risk.

Question 2: action strength

After a wrong-site block, an RCA team finds the site was marked but the mark was covered by drapes before the time-out, and that the time-out was performed while the surgeon was scrubbing and was not witnessed by the whole team. Which corrective action is strongest?

  1. Re-educate theatre staff on the time-out policy
  2. Add a reminder poster to each theatre
  3. Change the draping sequence so the mark stays visible at the time-out, and require the procedure to stop until every team member has responded
  4. Issue a revised policy requiring the surgeon to confirm the site verbally

Answer: 3. It changes the physical process so the mark cannot be hidden, and makes the time-out a forcing function that cannot proceed without the team. Options 1 and 2 are weak actions relying on memory, and a policy followed inattentively was already in place. Option 4 is another policy change and does not address the covered mark. Where one option redesigns the process and another tells people about it, choose the redesign.

Question 3: just culture

An experienced nurse administers a medication without scanning the barcode, as several colleagues routinely do because the scanner is slow and often fails. The patient suffers serious harm. What is the appropriate organisational response?

  1. Disciplinary action proportionate to the harm
  2. Coach the nurse, and investigate why bypassing the scan had become normal
  3. Console the nurse and take no further action, as the outcome was unintended
  4. Suspend the nurse pending the root cause analysis

Answer: 2. Skipping a step colleagues also skip, for a reason grounded in a malfunctioning system, is at-risk behaviour, and the response to at-risk behaviour is coaching plus removal of the incentive to drift. Option 1 lets the outcome determine the response, the specific error just culture exists to prevent. Option 3 treats at-risk behaviour as simple human error and leaves the scanner and the workaround in place. Option 4 is punitive by default and suppresses reporting from everyone watching. Read the behaviour, not the harm.

How this domain connects to the ones around it

Patient safety shares its cause-analysis tools with performance and process improvement, the largest domain at 27 scored items. Fishbone diagrams, five whys and process mapping appear in both, and the trigger separates them: harm or its risk points here, a performance gap points there. Corrective actions from an RCA are then delivered as improvement work, which is why the two domains keep handing scenarios back and forth.

It also touches quality review and accountability, 16 items, wherever an event raises a question about an individual practitioner rather than a process. A stem about whether a clinician should keep a privilege is not a patient safety item, even when it opens with an event.

A ten-point revision checklist for patient safety

  1. State the weighting from memory: 18 of 125 scored items, 14.4 per cent.
  2. Define adverse event, near miss and unsafe condition, with an example of each.
  3. Explain why a rising report rate can be a good sign.
  4. Write the trigger for RCA and for FMEA in one sentence each, without naming the tools.
  5. Reproduce the action hierarchy from strong to weak, with two examples at each level.
  6. Explain what RCA2 adds to a conventional RCA.
  7. Describe the three behaviours just culture separates, and the response to each.
  8. List the five high-reliability principles and say which one an ignored near miss fails.
  9. State what a disclosure conversation contains and when it happens.
  10. Take ten mixed safety items and record, for each error, whether you misread the trigger or the action strength.

What to do next

Practise the two habits that carry this domain: name the trigger before choosing a method, and rank every option by action strength before answering. The companion video lesson, which works an action hierarchy through a corrective action plan, is in the CPHQ study video library, and the free CPHQ practice test will show whether safety is costing you marks. The weighting comes from NAHQ's CPHQ credential page.

Frequently asked questions

How many patient safety questions are on the CPHQ exam?
Patient safety accounts for 18 of the 125 scored items, which is 14.4 per cent of your result and the fourth largest domain. The full paper contains 140 questions, 15 of them unscored pretest items, and you have a maximum of three hours to complete it.
What is the difference between RCA and FMEA?
RCA is retrospective and runs after an event has happened, working backwards to causal statements and corrective actions. FMEA is prospective and examines a high-risk, new or redesigned process before harm occurs, scoring each step for severity, occurrence and detectability. The trigger in the stem decides which one an exam item wants.
What is action strength in patient safety?
Action strength ranks corrective actions by how little they depend on people remembering. Strong actions change the system, such as forcing functions and physical redesign. Intermediate actions reduce reliance on memory, such as checklists and standardised protocols. Weak actions rely on education, policy and warnings. Where two options look sensible, choose the stronger.
How does just culture handle a serious error?
By separating behaviour from outcome. Human error is consoled and the system examined, at-risk behaviour is coached alongside removing the reason the shortcut felt reasonable, and reckless disregard of substantial risk attracts disciplinary action. The severity of the harm does not determine the response, and exam items test that point directly.
Does a rise in incident reports mean a hospital is less safe?
Not on its own. When harm rates stay stable while report numbers climb, the usual explanation is a reporting culture that is improving and staff who trust the process. Judge a reporting system by what is learned and acted upon, not by the number of reports it collects.
#patient-safety#nahq-blueprint#practice-questions#performance-improvement

More in Quality Practice

CPHQ Health Data Analytics: What the Exam Really Tests

The second-largest domain on the CPHQ exam, and the one strong clinicians most often lose marks on. Variation, chart choice, denominators and risk adjustment, with three original exam-style items fully explained.

health-data-analyticsnahq-blueprintpractice-questions
Dr. Ahmed Habib, CPHQ, MD, MSc10 min8

CPHQ Performance Improvement: PDSA, DMAIC and Lean Compared

The largest domain on the CPHQ exam carries 27 of the 125 scored items. A working guide to method selection, the mapping tools, sustainability, and three original exam-style questions worked through in full.

performance-improvementnahq-blueprintpractice-questions
Dr. Ahmed Habib, CPHQ, MD, MSc11 min6

The CPHQ Exam Content Outline: All 7 Domains Explained

Every scored question on the CPHQ exam, counted by domain, with the item-type split, the three-hour format, how scaled scoring works, and a 50-hour study allocation derived from the question counts with the arithmetic shown.

nahq-blueprintstudy-planperformance-improvement
Dr. Ahmed Habib, CPHQ, MD, MSc22 min17
Chat with Dr. AymanCourse Advisor