Answer Key
Chapter Quiz Answer and Rationale Key
Nursing Informatics: Systems, Data, AI, and Digital Practice
Edition: 2026
Validation date: September 15, 2026
This key is intentionally separated from the chapter manuscripts to preserve self-testing. For Select All That Apply (SATA) items, every option should be judged independently. Rationales explain the governing informatics principle rather than merely repeating the correct option.
Chapter 1 — Nursing Informatics as a Discipline
- A. Before adding a hard stop, informatics should establish the field’s purpose, duplication, workflow context, and downstream use. A low completion rate is a signal to investigate, not proof that mandatory entry is the correct intervention.
- C. Evaluating how an alert changes clinical workflow and role responsibility integrates nursing, information, and technology. The other choices are primarily infrastructure operations.
- A, B, C, D, F. Requirements analysis, workflow redesign, governance, system evaluation, and change planning are informatics capabilities. Keyboard shortcuts indicate application familiarity, not advanced informatics practice.
- B. A post-upgrade change in a metric may reflect workflow, configuration, scheduling, definition, or capture changes. Informatics should validate the measurement process before treating the dashboard trend as a clinical change.
- A. Clinical knowledge explains the care domain; informatics contributes methods for representing information, analyzing workflows, designing systems, and evaluating technology-mediated care.
- B, C, D, E, F. Informatics continues through sustainment, optimization, data-quality monitoring, and retirement. Go-live is a lifecycle transition, not the end of informatics work.
- A. Director-level practice shifts toward enterprise decision rights, priorities, standards, staffing, and capability-building rather than personally resolving every configuration issue.
- B. A discipline is defined by transferable concepts and methods that remain useful as particular software products change.
- A, C, D, E, F. A field may support regulatory, interface, reporting, CDS, historical, or legal-record functions. User dislike alone is not sufficient evidence for removal.
- A. Advanced development should be driven by desired scope and identified capability gaps rather than credential accumulation or dependence on one vendor platform.
Chapter 2 — Information, Knowledge, and Systems Thinking
- B. A number without units, definition, source, or context lacks the metadata needed for interpretation.
- A. The sites are using different meanings for the same apparent measure. That is a semantic-definition problem, not a network or storage problem.
- A, B, C, D, E. Provenance includes source, transformations, filters, transmitting system, and temporal context such as time zone. Aesthetic preference does not establish provenance.
- B. Improving one part of a system while shifting burden to another is local optimization. Systems thinking evaluates the effect on the whole work system.
- C. Sociotechnical outcomes arise from interactions among people, tasks, technology, organization, workflow, and environment rather than software in isolation.
- A, B, C, E, F. Blank data can represent several states, including missing assessment, inapplicability, uncertainty, refusal, or technical failure. It should not automatically be interpreted as normal.
- C. The stronger question examines conditions, workflow, timing, response, and alternatives before attributing the behavior to user motivation.
- B. False positives can reduce attention and trust, which increases dismissals and further weakens attention—a self-reinforcing cycle.
- B. Discovery should describe the unmet need and consequence without prematurely embedding a preferred solution such as a chatbot or vendor.
- A, C, D, E, F. Alert response can be affected by timing, workflow/documentation changes, staffing, informal pathways, and measurement logic. Restricting the boundary to source code would miss much of the sociotechnical system.
Chapter 3 — Evidence, Collaboration, Equity, and Professional Learning
- B. Published discrimination is only one evidence dimension. Local implementation requires evidence about data availability, workflow fit, subgroup performance, and the organization’s ability to act on the output.
- A. Complex change requires role-specific communication across the lifecycle, not a single broadcast after design decisions are already fixed.
- A, C, D, E. Productive conflict surfaces assumptions, tests what evidence could change positions, clarifies authority, and makes risk visible. Forced consensus and avoidance suppress useful disagreement.
- C. Outcomes among enrolled users may be favorable while access barriers limit population-level effectiveness and equity. Both findings can be true simultaneously.
- C. Accessibility is functional when users with disabilities can independently complete the required task, not merely when a statement or vendor assurance exists.
- B, C, D, E, F. Access, language, device compatibility, housing stability, and digital literacy can all systematically affect whether data are generated or captured.
- C. Message transmission alone does not prove clinically usable interoperability. Mapping, exceptions, display, reconciliation, and end-to-end workflow must also be validated.
- B. Deliberate capability development starts with the decisions and responsibilities the practitioner wants to handle, then targets the gaps that prevent that scope.
- A, C, D, E, F. Accuracy, subgroup performance, workflow feasibility, monitoring capacity, and equity are distinct evidence questions. Product branding is not evidence of fitness for use.
- D. LLMs can strengthen learning by retrieval practice, challenge, and scenario variation, but their factual claims and citations still require verification.
Chapter 4 — Ethics, Law, Privacy, Confidentiality, and Informatics Governance
- D. Privacy concerns appropriate collection, use, access, and disclosure; security concerns safeguards against unauthorized access, alteration, loss, or disruption.
- C. HIPAA suitability depends on the specific service, agreement, configuration, data handling, enabled features, and workflow. A vendor-wide marketing claim is insufficient.
- A, B, D, E, F. Minimum-necessary design considers role, job function, information needed, legitimate exceptions, and the risk of unsafe workarounds from over-restriction. Convenience alone does not justify broad access.
- B. Access controls determine what credentials are allowed to do; logs help establish what those credentials actually did and support accountability and investigation.
- C. The 2024 Part 2 Final Rule aligned several provisions more closely with HIPAA while retaining Part 2 protections; compliance with the updated rule was required February 16, 2026.
- A, B, C, D, E. Ethical secondary-use review considers necessity, proportionality, access, harmful inference, transparency, and governance. Mere availability of data does not make a use appropriate.
- C. Badge location and response-time data can become workforce surveillance even when collected through technically secure systems; proportionality and purpose therefore matter.
- A. Oversight is meaningful only when a qualified person has sufficient time, information, authority, and escalation pathways to evaluate consequential outputs.
- A, B, C, D, E, F. Governance should define stewardship, meaning, access, decision authority, quality expectations, and escalation rather than leaving these implicit.
- B. Informatics should implement an approved legal/privacy interpretation, not silently create legal policy through configuration.
Chapter 5 — Workflow Analysis, Requirements, and Solution Discovery
- B. A requested feature is a proposed solution. Informatics should first understand the underlying need and current workflow before deciding whether a button is the right intervention.
- C. Swimlanes show activities by actor or role and make handoffs between nursing, providers, pharmacy, laboratory, and other participants visible.
- A, B, D, E, F. Observation should capture waiting, interruption, exceptions, handoffs, and workarounds as well as technology interactions.
- A. Response time is a performance characteristic of the system and therefore a nonfunctional requirement; the other choices describe functions or workflow actions.
- B. Acceptance criteria make a requirement testable by defining observable conditions for determining whether it has been satisfied.
- A, C, D, E, F. Feasibility includes whether the solution can be built, operated, afforded, legally/regulatorily supported, and delivered in the needed time.
- B. A quick local build can create long-lived maintenance, testing, reporting, and upgrade burdens—classic operational and technical debt.
- C. Traceability connects the original need to requirements, design decisions, test evidence, implementation, and eventual outcomes.
- A. A workaround is an adaptation. It may be protective, efficient, or risky, so its function should be understood before it is eliminated or formalized.
- A, B, C, E, F. AI can help identify ambiguity, assumptions, untestable language, edge cases, and conflicting definitions. It should not invent facts about a workflow that was never observed.
Chapter 6 — Project Management, Change, and Improvement
- D. A project is a temporary structure for delivering change; product thinking continues to manage value, evolution, and lifecycle after the project ends.
- D. A possible future event is a risk. Once it has occurred and requires response, it becomes an issue.
- A, B, C, D, F. A meaningful milestone reflects readiness evidence, dependencies, prerequisites, validation, and accountable approval—not merely arrival of a date.
- C. Agile supports iterative delivery and learning but still depends on prioritized needs, clear acceptance criteria, and disciplined decision-making.
- D. If users understand the workflow but it doubles task time, the first hypothesis should be poor workflow/design fit rather than lack of knowledge.
- A. Missing required data is a balancing measure because it checks whether faster documentation creates a quality or safety cost.
- B, C, D, E, F. Staffing, equipment, leadership, competing initiatives, and organizational experience can all affect readiness for change.
- C. A decision log preserves the rationale, alternatives, assumptions, and consequences so future teams can understand why a choice was made.
- A. PDSA is designed for small-cycle learning: test a change, study what happened, and adapt the next iteration.
- A, B, C, D, E, F. Pre-mortems deliberately imagine failure across workflow, data, training, governance, vendor, staffing, and other plausible domains before the failure occurs.
Chapter 7 — Design, Usability, Human Factors, and Clinical Decision Support
- C. Forcing a nurse to remember information while navigating multiple screens creates avoidable working-memory and cognitive-load demands.
- A. Task-based testing with representative users directly evaluates whether the intended workflow can be completed safely and effectively.
- A, B, C, E, F. Completion, errors, time, assistance, and satisfaction are useful usability measures. Server age does not measure user interaction quality.
- B. A poorly chosen default can be accepted without active reassessment, allowing stale or incorrect data to propagate into clinical documentation.
- D. CDS combines patient-specific information with knowledge or logic at a decision point; a renal-dose warning at medication ordering is a clear example.
- A. Decision support must arrive while the responsible user can still act on the decision. Technically early or late information can be clinically useless.
- A, B, C, E, F. Overrides may reflect poor specificity, timing, duplication, missing context, or sound clinical judgment. A high override rate alone does not prove alert fatigue.
- D. Automation bias is over-reliance on automated recommendations at the expense of sufficient independent review.
- D. Contributing factors can help users interpret why a score is elevated and support appropriately calibrated trust, though they do not replace validation.
- B, C, D, E, F. Alert evaluation should include outcomes, responses, unintended care, burden, and subgroup effects; firing count alone cannot establish value or safety.
Chapter 8 — Testing, Training, Implementation, and Go-Live
- D. Integration testing evaluates whether separate systems exchange and process information correctly across their interface; unit testing examines a smaller component in isolation.
- D. UAT requires representative users, realistic scenarios, and predefined acceptance criteria so the organization can determine whether the solution is fit for intended use.
- A, B, C, D, E. Robust test data include boundary, missing, duplicate, uncommon, and role-dependent conditions rather than only the normal path.
- A. Regression testing checks whether a change or defect fix has unintentionally broken previously working functions elsewhere in the system.
- C. Matching counts can hide incorrect mappings, units, relationships, identities, truncation, or semantic changes. Migration validation must test meaning, not only quantity.
- A, B, D, E, F. Training should be driven by role, task frequency, baseline capability, consequence of error, and workflow context. Preferred learning style alone is not sufficient.
- C. Competency is demonstrated performance: the learner can carry out the required task correctly under realistic conditions.
- C. Backout criteria should be agreed before go-live so teams do not have to invent thresholds while already under pressure from a failing implementation.
- B. Stabilization restores reliable, safe operation after launch; optimization begins after stability and asks how design, workflow, or outcomes can be improved.
- B, C, D, E, F. AI-generated test cases can broaden edge-case thinking, but they must map to requirements and risk, be clinically plausible, protect sensitive data, and receive human validation.
Chapter 9 — Optimization, Support, Downtime, and Recovery
- B. Repeated tickets linked to the same triggering condition suggest a systemic provisioning or identity design problem, not a series of unrelated user failures.
- C. Severity describes consequence if the problem occurs; priority determines when it should be addressed after considering severity, scope, urgency, dependencies, and other context.
- A, B, C, E, F. Environments can diverge in configuration, interfaces, roles, data, and software versions, making test results less representative of production.
- D. An uncontrolled production change exposes patients and users to unvalidated behavior and makes it harder to determine which change caused an outcome.
- D. The strongest request connects observed burden to a measurable desired effect while preserving required clinical information.
- B. Usage demonstrates adoption or exposure, not that the feature improves safety, quality, efficiency, or outcomes.
- A, B, C, D, E, F. Post-go-live evaluation spans technical performance, task completion, adoption, data quality, outcomes, and unintended effects.
- D. Downtime planning starts with the clinical capabilities and information that must continue, then maps technology and contingency procedures to those needs.
- B. Queued messages may replay out of order, duplicate, or arrive after local actions occurred, so recovery requires reconciliation rather than simply restarting interfaces.
- A, B, C, D, E, F. A meaningful drill tests materials, contact information, staff behavior, communication, authority, and post-restoration reconciliation.
Chapter 10 — Clinical Data, Terminologies, and Semantic Integrity
- B. The scale, timestamp, and assessment source provide the contextual metadata needed to interpret a pain value of 7.
- A. Standardized terminologies provide consistent representation of recurring clinical concepts so data can be communicated, compared, and reused without eliminating clinical judgment or narrative.
- A, B, D, E. Collection time, source device, unit, and correction status can materially change interpretation. Interface background color does not establish clinical provenance.
- D. Collapsing several local concepts into one broader standardized concept can remove distinctions that mattered clinically or operationally—semantic loss.
- C. LOINC is widely used to identify laboratory tests and other clinical observations. ICD-10-CM classifies diagnoses, RxNorm represents medications, and UCUM standardizes units.
- A. A field may be populated while still containing stale, copied, or clinically inaccurate information; completeness is not the same as validity.
- A, B, D, E. Mappings can be many-to-one or one-to-many, must be version controlled, can lose meaning, and require authoritative validation when AI assists. Exact equivalents do not always exist.
- A. ICD-10-CM is primarily a classification for diagnoses and reporting/administrative use; it is not a sufficiently expressive bedside clinical terminology for every concept nurses document.
- B. Data lineage traces the path from source through transformations, interfaces, stores, and downstream use so a value can be understood and audited.
- D. Documentation design should begin with the clinical meaning and downstream decisions the data need to support, then choose representation and controls.
Chapter 11 — Interoperability, HL7, FHIR, APIs, USCDI, and TEFCA
- D. The message reached the organization and was interpretable, but the allergy was placed outside the workflow where medication decision support could use it. The weakest layer is therefore organizational/workflow interoperability.
- D. HL7 Version 2 remains widely deployed for event-oriented healthcare messages including admissions, orders, and results; FHIR has not universally replaced it.
- A, B, D, E. A FHIR implementation guide can constrain profiles, terminology, exchange behavior, and use-case rules. Staffing budgets are outside the purpose of a FHIR implementation guide.
- B. A profile constrains a base FHIR resource for a defined context by specifying elements, cardinalities, terminology bindings, extensions, or other rules.
- A. USCDI defines an evolving core U.S. interoperability data baseline; it is not an exhaustive clinical data model or a private vendor specification.
- D. Federal rules often phase requirements by entity and date, so publication, effective date, compliance date, and technical implementation deadlines must be distinguished.
- A, B, C, D, E. Patient identity errors, conflicting lists, unknown codes, interface failures, and missing reconciliation workflows can all make technically successful exchange clinically unsafe or unusable.
- B. TEFCA is a nationwide framework for exchange among participating networks under common agreements and technical rules; it is not a single national EHR or database.
- C. A newer published FHIR release does not automatically invalidate an R4 implementation. Regulatory requirements, implementation guides, and deployed ecosystems can legitimately use earlier releases.
- C. Reconciliation by an accountable workflow converts received information into reviewed local clinical information by resolving conflicts, status, and authority.
Chapter 12 — Databases, SQL, Data Quality, and Data Governance
- C. Grain defines what one row represents. Here, the grain is one medication-administration event per row.
- B. A one-to-many relationship is expected when one patient has multiple encounters; a join therefore may legitimately create several encounter rows per patient.
- A, B, C, D, E. AI-generated SQL must be checked for joins, row grain, denominator logic, null handling, and known-case results because syntactically valid SQL can still produce wrong clinical measures.
- A. Data warehouses are designed for integrated longitudinal analytics and reporting, whereas transactional EHR systems are optimized for operational care processes such as order entry.
- D. Both numbers can be technically correct while representing different definitions of census. The discrepancy is semantic/operational definition rather than proof of database failure.
- C. Timeliness asks whether data are available soon enough for the decision or purpose they are intended to support.
- A, B, C, D, E. Metric definitions, stewardship, access, retention, and authoritative-source documentation are all legitimate governance responsibilities.
- C. Converting missing to zero changes the meaning from “no observed value” to an apparently observed numerical value and can produce unsafe analysis.
- C. Lineage documents the route from original source through transformations and storage to downstream use, supporting traceability and troubleshooting.
- D. A critical metric should have a governed definition, source fields, transformations, ownership, and change process rather than exist only as undocumented analyst knowledge.
Chapter 13 — Analytics, Visualization, Quality Measurement, RCA, and FMEA
- A. Raw counts are not comparable without a denominator, time interval, and consistent case definition that establish exposure and meaning.
- C. Descriptive analytics summarize what occurred; predictive analytics estimate what may occur, while prescriptive approaches address what action to take.
- A, B, C, D. Case mix, definitions, documentation completeness, and observation periods can distort comparisons. Appropriate risk adjustment is intended to improve—not undermine—comparability.
- D. High-risk units may receive more staff and also have more falls; the relationship between staffing and falls is therefore potentially confounded by underlying patient risk.
- A. A line chart is generally appropriate for displaying change and pattern over an ordered time series such as 24 months.
- D. FMEA prospectively identifies possible failure modes, causes, and effects before or during implementation; RCA is primarily retrospective after an event.
- A, B, C, D, E. A useful dashboard makes the signal, comparator, period, accountable actor, and path to investigation understandable rather than merely displaying numbers.
- D. A model that generates far more actionable cases than available staff can manage has an operational-capacity mismatch even if its predictive performance is strong.
- D. Data distributions, populations, workflows, and clinical practice change over time, so predeployment performance may not persist.
- D. An observational trend can support an association or temporal coincidence, but causal claims require consideration of competing explanations and stronger design/evidence.
Chapter 14 — EHR Architecture, Devices, Mobile Technology, and Clinical Infrastructure
- A. Failure of a shared identity service can make many otherwise healthy applications unusable. That illustrates dependency risk and a large blast radius.
- A. Latency is delay in response or transmission; availability is whether the service is accessible and usable at all.
- A, B, C, D, E. Battery, connectivity, infection-control processes, screen constraints, and notification load can all determine whether a mobile clinical workflow is safe and usable.
- B. Device integration can automate capture but does not remove identity and encounter-association risk; a valid measurement attached to the wrong patient is a serious safety event.
- B. Barcode medication administration helps verify relationships among the patient, ordered medication, product, timing, and administration workflow; it does not independently determine whether the medication is clinically appropriate.
- B. Long-lived, hard-to-patch devices require strong inventory, segmentation, access controls, monitoring, and compensating controls to limit exposure.
- A, B, C, D, E. Scope, location, onset, recent change, and reproducibility are foundational observations for isolating a technical problem before jumping to a cause.
- C. Failures clustered in a physical area strongly suggest testing wireless coverage, interference, roaming, or related environmental conditions early in troubleshooting.
- B. RTLS data collected for safety or logistics can be repurposed for employee surveillance, making purpose limitation and governance important.
- D. Comparing an affected condition with a known-good user, device, location, or workflow isolates variables without introducing several new changes at once.
Chapter 15 — Patient-Generated Data, Telehealth, Remote Monitoring, and Population Informatics
- A. Expanding access without redesigning triage and routing can simply move burden into a single queue. Informatics must align access with accountable response workflows.
- A. Patient-generated data can extend observation beyond encounters, but device characteristics, collection conditions, adherence, and context affect interpretation.
- A, B, C, D, E. Remote monitoring requires ownership, prioritization, escalation, expected response, and contingency processes so incoming data lead to safe action rather than passive accumulation.
- A. Monitoring becomes clinically meaningful when there is an explicit response pathway for interpreting and acting on incoming data.
- C. The clinical encounter is blocked by the design of identity recovery, illustrating how authentication and account-management workflows can become digital-access barriers.
- C. Utilization reflects both need and access. People with high unmet need but poor access may appear deceptively low risk in utilization-based models.
- A, B, C, D, E. Connectivity, affordability, literacy, accessibility, language, and trust all influence whether digital services are genuinely reachable and usable.
- D. Collecting social-risk information creates duties around protection, appropriate use, follow-up, and avoidance of harmful or stigmatizing secondary uses.
- C. Telehealth workflows need defined escalation when remote assessment cannot safely answer the clinical question or a symptom requires urgent in-person examination.
- D. Overall registration can hide where inequity occurs. Stratifying drop-off at each step reveals whether barriers arise at enrollment, verification, device setup, visit completion, or follow-up.
Chapter 16 — Cybersecurity, Resilience, and Clinical Continuity
- D. Unauthorized alteration of a medication value compromises integrity even though the system remains available.
- B. Resilience is the ability to continue essential functions, absorb disruption, recover, and adapt rather than merely prevent every incident.
- A, B, D, E. Least privilege reduces accessible scope, sensitive-data exposure, administrative power, and ambiguity about role responsibility. It does not eliminate the need for authentication.
- B. A backup is only stored data. Recovery requires restoring systems, dependencies, configurations, interfaces, and data in usable order and validating that clinical operation is trustworthy.
- B. Prompt injection is an attempt to manipulate a model or agent through malicious instructions embedded in content the system processes.
- A. When immediate patching is not clinically or technically supported, organizations should apply compensating controls, monitoring, segmentation, and formal risk management while pursuing supported remediation.
- A, B, C, D, E, F. NIST CSF 2.0 contains six Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- A. Dependency on an external service can interrupt care even when the healthcare organization itself was not directly compromised.
- B. Security and workflow goals should be reconciled through redesign and compensating approaches rather than simply removing the control or encouraging workarounds.
- A. Proposed rules should be labeled as proposals. They may inform planning, but they are not current mandatory requirements until finalized and applicable.
Chapter 17 — Artificial Intelligence, Machine Learning, NLP, and Generative AI
- C. Rules-based systems execute logic explicitly specified by humans; machine-learning models fit statistical patterns from data.
- C. Strong training performance with weak external performance is consistent with overfitting, local-pattern dependence, or otherwise poor generalization.
- B, C, D, E. Sensitivity, specificity, calibration, and subgroup performance each describe different aspects of model behavior. No single accuracy number is sufficient for every decision context.
- D. LLM output is generated probabilistically from learned patterns and context; fluent language therefore does not guarantee factual grounding.
- D. RAG supplies retrieved external information to the model to improve grounding and currency, but retrieval and generation still require verification.
- B. Tool use changes AI from a generator of recommendations into a system capable of affecting external systems, making permissions, logging, and control substantially more consequential.
- A, B, C, D, E. Bias can arise from sampling, labels, proxies, deployment context, and how humans interpret or act on outputs.
- A. Automation bias occurs when users defer excessively to automated recommendations despite contrary evidence or inadequate independent review.
- A. Two models may share training sources, assumptions, architectures, and failure patterns. Agreement between them is not independent authoritative evidence.
- C. Separating read, recommend, and act permissions applies progressively stronger controls as AI moves from information access to consequential execution.
Chapter 18 — Implementing, Evaluating, and Governing Clinical AI
- A. The stronger statement defines population, setting, timing, predicted outcome, user action, horizon, and exclusions rather than using a vague goal such as “improve nursing.”
- C. Local populations, prevalence, data capture, workflow, devices, and available response resources may differ from the vendor’s development and validation environment.
- A, B, C, D, E. Local validation should reflect intended patients, missingness, operational timing, subgroup behavior, and the organization’s capacity to respond to outputs.
- B. Equal statistical performance can still lead to unequal care when downstream resources or workflows differ. Equity evaluation must include the pathway after prediction.
- A. Rare errors combined with habitual acceptance can reduce vigilance and create automation bias even when average model accuracy is high.
- A. A base-model change can alter system behavior even if the user interface is unchanged, so change control should assess whether revalidation is required.
- A, B, C, D, E. Post-deployment monitoring should include technical, clinical, workflow, safety, and equity signals rather than only model uptime.
- B. Transparency documentation describes development and performance but cannot establish that the system is safe, effective, or appropriate in a specific local workflow.
- A. PHI use depends on the exact service and feature, applicable contract and BAA, configuration, organizational approval, and legal/data-governance requirements—not simply the vendor’s brand.
- C. In the NIST AI RMF, Measure addresses assessing, analyzing, and tracking identified AI risks and impacts.
Chapter 19 — Governance, Vendor Strategy, Integration, and Portfolio Management
- B. Governance establishes who can decide, what evidence is required, who is accountable, and how disagreements or high-risk decisions are escalated.
- C. Intake should first define the underlying problem, workflow, evidence, affected users, and intended outcome before locking the organization into an alert as the solution.
- A, B, C, D, E. Vendor evaluation should cover clinical fit, integration, security/privacy, data portability and exit, and operational support/recovery—not just features and price.
- A. An RFI is useful when an organization is exploring available approaches and market capability before finalizing detailed procurement requirements.
- C. A proof of concept is strongest when it answers a bounded question with explicit success criteria and a defined ending or decision gate.
- D. Broad direct database access can create excessive privilege, tight coupling, unclear change boundaries, and difficult revocation compared with a supported, scoped interface.
- A, B, C, D, E. Integration governance should document direction, authentication, monitoring, ownership, and how the connection can be disabled or terminated safely.
- D. Standardization can legitimately allow exceptions when a regulatory or clinical requirement is real, documented, risk-assessed, and governed.
- A. Technical debt is the future burden created by shortcuts, duplicated customization, deferred remediation, or complexity that constrains later change.
- B. Portfolio decisions encode organizational priorities, risk tolerance, opportunity cost, and values. AI may inform the analysis but should not assume accountable decision authority.
Chapter 20 — Informatics Leadership, Finance, Workforce, and Career Development
- D. A business case begins with the decision problem, affected population, alternatives, and intended outcomes so costs and benefits are evaluated against a real need rather than a predetermined vendor.
- B. Total cost of ownership includes implementation, integration, training, staffing, support, upgrades, infrastructure, change, and eventual retirement—not just acquisition price.
- A, B, C, D, E. Informatics value can appear as avoided cost, safety, compliance, capacity, resilience, and other organizational outcomes rather than only direct revenue.
- D. Time released from a task may create capacity, reduce burden, or enable higher-value work without becoming a direct payroll reduction; the value claim should reflect what actually changes.
- C. A hybrid/federated model can preserve enterprise standards while incorporating local expertise and context, provided decision rights and exception rules are explicit.
- A. When one leader personally holds critical problem-solving knowledge, the organization develops key-person risk and fails to grow scalable team capability.
- A, B, C, D, E. Executives need the decision, evidence, options, tradeoffs, risks, and next action more than exhaustive technical detail.
- C. Influence without formal authority depends on credibility, evidence, relationships, coalition-building, framing, and clear decision processes across organizational boundaries.
- D. Certification demonstrates knowledge against a defined standard; mastery also requires contextual judgment, repeated application, reflection, and experience with consequences.
- B. Leaders need to evaluate data provenance, model limitations, validation, workflow effects, governance, privacy, and automation risk—skills much broader than prompt construction.
Chapter 21 — Digital Transformation, Learning Health Systems, and the Future of Nursing Informatics
- D. Converting paper content into digital form without changing the underlying process is digitization, not transformation.
- D. A learning health system closes the loop from care data to evidence or knowledge and then feeds that learning back into practice and future measurement.
- A, B, C, D, E. Agentic systems make permissions, logging, stop conditions, tool reliability, and human accountability more important because the system can take multi-step actions rather than only generate text.
- A. Ambient systems can reduce visibility into what was sensed, inferred, transformed, or acted upon, creating provenance, consent, and oversight risks.
- B. Novel technology should be evaluated against a defined problem, population, mechanism, comparator, evidence, and consequences rather than novelty or demonstration quality.
- B. Reversible pilots and modular choices allow an organization to learn while limiting sunk cost and harm if assumptions prove wrong.
- A, B, C, D, E. Scenario planning deliberately varies uncertain drivers such as regulation, workforce, AI capability, reimbursement, and cyber risk.
- A. A leading indicator is an earlier observable signal that may suggest movement toward a scenario before the ultimate outcomes are available.
- C. Systems thinking, evidence appraisal, workflow analysis, governance, and evaluation remain transferable even when individual AI products and interfaces change rapidly.
- D. In a highly automated environment, nursing informatics still integrates nursing practice, people, information, workflow, and technology so automation serves safe and effective care rather than replacing accountable clinical judgment.
Validation Notes
- Total questions validated: 210
- Questions per chapter: 10
- SATA items: 51
- Single-best-answer key balance: A = 40, B = 40, C = 40, D = 39
- SATA scoring rule: all listed correct options should be selected; no unlisted option should be selected.
- Option-order QA: choices were reordered after substantive validation to remove a strong A/B answer-position bias. The wording and set of options for every question were preserved. A programmatic semantic check confirmed that the correct option text before and after reordering is identical for all 210 items.
- Current-law/current-standard questions: Chapters 4, 11, 16, and 18 were checked against authoritative 2026 sources during the September 15, 2026 editorial review.
- Editorial finding: no item required removal for having two equally defensible best answers after review. Several items intentionally test the distinction between technical success and clinical/workflow success.
Source anchors for time-sensitive quiz content
- American Nurses Credentialing Center. Informatics Nursing Board Certification Examination: Test Content Outline. Updated August 29, 2025. https://www.nursingworld.org/globalassets/informatics-tco_08292025-for-webposting.pdf
- U.S. Department of Health and Human Services. Confidentiality of Substance Use Disorder (SUD) Patient Records: Final Rule. Compliance with the 2024 Final Rule was required February 16, 2026. https://www.hhs.gov/hipaa/part-2/
- Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology. USCDI, information-blocking, HTI-1, and SAFER Guide resources. https://healthit.gov/
- HL7 International. FHIR Release 5 and current FHIR development/ballot materials. https://hl7.org/fhir/
- The Sequoia Project, TEFCA Recognized Coordinating Entity. Common Agreement Version 2.1. https://rce.sequoiaproject.org/common-agreement/
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29
- Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). https://doi.org/10.6028/NIST.AI.100-1
- U.S. Food and Drug Administration. Clinical Decision Support Software. Final guidance, January 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/clinical-decision-support-software
- U.S. Food and Drug Administration. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. Final guidance, February 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket