Answer Key

Chapter Quiz Answer and Rationale Key

Nursing Informatics: Systems, Data, AI, and Digital Practice

Edition: 2026
Validation date: September 15, 2026

This key is intentionally separated from the chapter manuscripts to preserve self-testing. For Select All That Apply (SATA) items, every option should be judged independently. Rationales explain the governing informatics principle rather than merely repeating the correct option.

Chapter 1 — Nursing Informatics as a Discipline

  1. A. Before adding a hard stop, informatics should establish the field’s purpose, duplication, workflow context, and downstream use. A low completion rate is a signal to investigate, not proof that mandatory entry is the correct intervention.
  2. C. Evaluating how an alert changes clinical workflow and role responsibility integrates nursing, information, and technology. The other choices are primarily infrastructure operations.
  3. A, B, C, D, F. Requirements analysis, workflow redesign, governance, system evaluation, and change planning are informatics capabilities. Keyboard shortcuts indicate application familiarity, not advanced informatics practice.
  4. B. A post-upgrade change in a metric may reflect workflow, configuration, scheduling, definition, or capture changes. Informatics should validate the measurement process before treating the dashboard trend as a clinical change.
  5. A. Clinical knowledge explains the care domain; informatics contributes methods for representing information, analyzing workflows, designing systems, and evaluating technology-mediated care.
  6. B, C, D, E, F. Informatics continues through sustainment, optimization, data-quality monitoring, and retirement. Go-live is a lifecycle transition, not the end of informatics work.
  7. A. Director-level practice shifts toward enterprise decision rights, priorities, standards, staffing, and capability-building rather than personally resolving every configuration issue.
  8. B. A discipline is defined by transferable concepts and methods that remain useful as particular software products change.
  9. A, C, D, E, F. A field may support regulatory, interface, reporting, CDS, historical, or legal-record functions. User dislike alone is not sufficient evidence for removal.
  10. A. Advanced development should be driven by desired scope and identified capability gaps rather than credential accumulation or dependence on one vendor platform.

Chapter 2 — Information, Knowledge, and Systems Thinking

  1. B. A number without units, definition, source, or context lacks the metadata needed for interpretation.
  2. A. The sites are using different meanings for the same apparent measure. That is a semantic-definition problem, not a network or storage problem.
  3. A, B, C, D, E. Provenance includes source, transformations, filters, transmitting system, and temporal context such as time zone. Aesthetic preference does not establish provenance.
  4. B. Improving one part of a system while shifting burden to another is local optimization. Systems thinking evaluates the effect on the whole work system.
  5. C. Sociotechnical outcomes arise from interactions among people, tasks, technology, organization, workflow, and environment rather than software in isolation.
  6. A, B, C, E, F. Blank data can represent several states, including missing assessment, inapplicability, uncertainty, refusal, or technical failure. It should not automatically be interpreted as normal.
  7. C. The stronger question examines conditions, workflow, timing, response, and alternatives before attributing the behavior to user motivation.
  8. B. False positives can reduce attention and trust, which increases dismissals and further weakens attention—a self-reinforcing cycle.
  9. B. Discovery should describe the unmet need and consequence without prematurely embedding a preferred solution such as a chatbot or vendor.
  10. A, C, D, E, F. Alert response can be affected by timing, workflow/documentation changes, staffing, informal pathways, and measurement logic. Restricting the boundary to source code would miss much of the sociotechnical system.

Chapter 3 — Evidence, Collaboration, Equity, and Professional Learning

  1. B. Published discrimination is only one evidence dimension. Local implementation requires evidence about data availability, workflow fit, subgroup performance, and the organization’s ability to act on the output.
  2. A. Complex change requires role-specific communication across the lifecycle, not a single broadcast after design decisions are already fixed.
  3. A, C, D, E. Productive conflict surfaces assumptions, tests what evidence could change positions, clarifies authority, and makes risk visible. Forced consensus and avoidance suppress useful disagreement.
  4. C. Outcomes among enrolled users may be favorable while access barriers limit population-level effectiveness and equity. Both findings can be true simultaneously.
  5. C. Accessibility is functional when users with disabilities can independently complete the required task, not merely when a statement or vendor assurance exists.
  6. B, C, D, E, F. Access, language, device compatibility, housing stability, and digital literacy can all systematically affect whether data are generated or captured.
  7. C. Message transmission alone does not prove clinically usable interoperability. Mapping, exceptions, display, reconciliation, and end-to-end workflow must also be validated.
  8. B. Deliberate capability development starts with the decisions and responsibilities the practitioner wants to handle, then targets the gaps that prevent that scope.
  9. A, C, D, E, F. Accuracy, subgroup performance, workflow feasibility, monitoring capacity, and equity are distinct evidence questions. Product branding is not evidence of fitness for use.
  10. D. LLMs can strengthen learning by retrieval practice, challenge, and scenario variation, but their factual claims and citations still require verification.

Chapter 4 — Ethics, Law, Privacy, Confidentiality, and Informatics Governance

  1. D. Privacy concerns appropriate collection, use, access, and disclosure; security concerns safeguards against unauthorized access, alteration, loss, or disruption.
  2. C. HIPAA suitability depends on the specific service, agreement, configuration, data handling, enabled features, and workflow. A vendor-wide marketing claim is insufficient.
  3. A, B, D, E, F. Minimum-necessary design considers role, job function, information needed, legitimate exceptions, and the risk of unsafe workarounds from over-restriction. Convenience alone does not justify broad access.
  4. B. Access controls determine what credentials are allowed to do; logs help establish what those credentials actually did and support accountability and investigation.
  5. C. The 2024 Part 2 Final Rule aligned several provisions more closely with HIPAA while retaining Part 2 protections; compliance with the updated rule was required February 16, 2026.
  6. A, B, C, D, E. Ethical secondary-use review considers necessity, proportionality, access, harmful inference, transparency, and governance. Mere availability of data does not make a use appropriate.
  7. C. Badge location and response-time data can become workforce surveillance even when collected through technically secure systems; proportionality and purpose therefore matter.
  8. A. Oversight is meaningful only when a qualified person has sufficient time, information, authority, and escalation pathways to evaluate consequential outputs.
  9. A, B, C, D, E, F. Governance should define stewardship, meaning, access, decision authority, quality expectations, and escalation rather than leaving these implicit.
  10. B. Informatics should implement an approved legal/privacy interpretation, not silently create legal policy through configuration.

Chapter 5 — Workflow Analysis, Requirements, and Solution Discovery

  1. B. A requested feature is a proposed solution. Informatics should first understand the underlying need and current workflow before deciding whether a button is the right intervention.
  2. C. Swimlanes show activities by actor or role and make handoffs between nursing, providers, pharmacy, laboratory, and other participants visible.
  3. A, B, D, E, F. Observation should capture waiting, interruption, exceptions, handoffs, and workarounds as well as technology interactions.
  4. A. Response time is a performance characteristic of the system and therefore a nonfunctional requirement; the other choices describe functions or workflow actions.
  5. B. Acceptance criteria make a requirement testable by defining observable conditions for determining whether it has been satisfied.
  6. A, C, D, E, F. Feasibility includes whether the solution can be built, operated, afforded, legally/regulatorily supported, and delivered in the needed time.
  7. B. A quick local build can create long-lived maintenance, testing, reporting, and upgrade burdens—classic operational and technical debt.
  8. C. Traceability connects the original need to requirements, design decisions, test evidence, implementation, and eventual outcomes.
  9. A. A workaround is an adaptation. It may be protective, efficient, or risky, so its function should be understood before it is eliminated or formalized.
  10. A, B, C, E, F. AI can help identify ambiguity, assumptions, untestable language, edge cases, and conflicting definitions. It should not invent facts about a workflow that was never observed.

Chapter 6 — Project Management, Change, and Improvement

  1. D. A project is a temporary structure for delivering change; product thinking continues to manage value, evolution, and lifecycle after the project ends.
  2. D. A possible future event is a risk. Once it has occurred and requires response, it becomes an issue.
  3. A, B, C, D, F. A meaningful milestone reflects readiness evidence, dependencies, prerequisites, validation, and accountable approval—not merely arrival of a date.
  4. C. Agile supports iterative delivery and learning but still depends on prioritized needs, clear acceptance criteria, and disciplined decision-making.
  5. D. If users understand the workflow but it doubles task time, the first hypothesis should be poor workflow/design fit rather than lack of knowledge.
  6. A. Missing required data is a balancing measure because it checks whether faster documentation creates a quality or safety cost.
  7. B, C, D, E, F. Staffing, equipment, leadership, competing initiatives, and organizational experience can all affect readiness for change.
  8. C. A decision log preserves the rationale, alternatives, assumptions, and consequences so future teams can understand why a choice was made.
  9. A. PDSA is designed for small-cycle learning: test a change, study what happened, and adapt the next iteration.
  10. A, B, C, D, E, F. Pre-mortems deliberately imagine failure across workflow, data, training, governance, vendor, staffing, and other plausible domains before the failure occurs.

Chapter 7 — Design, Usability, Human Factors, and Clinical Decision Support

  1. C. Forcing a nurse to remember information while navigating multiple screens creates avoidable working-memory and cognitive-load demands.
  2. A. Task-based testing with representative users directly evaluates whether the intended workflow can be completed safely and effectively.
  3. A, B, C, E, F. Completion, errors, time, assistance, and satisfaction are useful usability measures. Server age does not measure user interaction quality.
  4. B. A poorly chosen default can be accepted without active reassessment, allowing stale or incorrect data to propagate into clinical documentation.
  5. D. CDS combines patient-specific information with knowledge or logic at a decision point; a renal-dose warning at medication ordering is a clear example.
  6. A. Decision support must arrive while the responsible user can still act on the decision. Technically early or late information can be clinically useless.
  7. A, B, C, E, F. Overrides may reflect poor specificity, timing, duplication, missing context, or sound clinical judgment. A high override rate alone does not prove alert fatigue.
  8. D. Automation bias is over-reliance on automated recommendations at the expense of sufficient independent review.
  9. D. Contributing factors can help users interpret why a score is elevated and support appropriately calibrated trust, though they do not replace validation.
  10. B, C, D, E, F. Alert evaluation should include outcomes, responses, unintended care, burden, and subgroup effects; firing count alone cannot establish value or safety.

Chapter 8 — Testing, Training, Implementation, and Go-Live

  1. D. Integration testing evaluates whether separate systems exchange and process information correctly across their interface; unit testing examines a smaller component in isolation.
  2. D. UAT requires representative users, realistic scenarios, and predefined acceptance criteria so the organization can determine whether the solution is fit for intended use.
  3. A, B, C, D, E. Robust test data include boundary, missing, duplicate, uncommon, and role-dependent conditions rather than only the normal path.
  4. A. Regression testing checks whether a change or defect fix has unintentionally broken previously working functions elsewhere in the system.
  5. C. Matching counts can hide incorrect mappings, units, relationships, identities, truncation, or semantic changes. Migration validation must test meaning, not only quantity.
  6. A, B, D, E, F. Training should be driven by role, task frequency, baseline capability, consequence of error, and workflow context. Preferred learning style alone is not sufficient.
  7. C. Competency is demonstrated performance: the learner can carry out the required task correctly under realistic conditions.
  8. C. Backout criteria should be agreed before go-live so teams do not have to invent thresholds while already under pressure from a failing implementation.
  9. B. Stabilization restores reliable, safe operation after launch; optimization begins after stability and asks how design, workflow, or outcomes can be improved.
  10. B, C, D, E, F. AI-generated test cases can broaden edge-case thinking, but they must map to requirements and risk, be clinically plausible, protect sensitive data, and receive human validation.

Chapter 9 — Optimization, Support, Downtime, and Recovery

  1. B. Repeated tickets linked to the same triggering condition suggest a systemic provisioning or identity design problem, not a series of unrelated user failures.
  2. C. Severity describes consequence if the problem occurs; priority determines when it should be addressed after considering severity, scope, urgency, dependencies, and other context.
  3. A, B, C, E, F. Environments can diverge in configuration, interfaces, roles, data, and software versions, making test results less representative of production.
  4. D. An uncontrolled production change exposes patients and users to unvalidated behavior and makes it harder to determine which change caused an outcome.
  5. D. The strongest request connects observed burden to a measurable desired effect while preserving required clinical information.
  6. B. Usage demonstrates adoption or exposure, not that the feature improves safety, quality, efficiency, or outcomes.
  7. A, B, C, D, E, F. Post-go-live evaluation spans technical performance, task completion, adoption, data quality, outcomes, and unintended effects.
  8. D. Downtime planning starts with the clinical capabilities and information that must continue, then maps technology and contingency procedures to those needs.
  9. B. Queued messages may replay out of order, duplicate, or arrive after local actions occurred, so recovery requires reconciliation rather than simply restarting interfaces.
  10. A, B, C, D, E, F. A meaningful drill tests materials, contact information, staff behavior, communication, authority, and post-restoration reconciliation.

Chapter 10 — Clinical Data, Terminologies, and Semantic Integrity

  1. B. The scale, timestamp, and assessment source provide the contextual metadata needed to interpret a pain value of 7.
  2. A. Standardized terminologies provide consistent representation of recurring clinical concepts so data can be communicated, compared, and reused without eliminating clinical judgment or narrative.
  3. A, B, D, E. Collection time, source device, unit, and correction status can materially change interpretation. Interface background color does not establish clinical provenance.
  4. D. Collapsing several local concepts into one broader standardized concept can remove distinctions that mattered clinically or operationally—semantic loss.
  5. C. LOINC is widely used to identify laboratory tests and other clinical observations. ICD-10-CM classifies diagnoses, RxNorm represents medications, and UCUM standardizes units.
  6. A. A field may be populated while still containing stale, copied, or clinically inaccurate information; completeness is not the same as validity.
  7. A, B, D, E. Mappings can be many-to-one or one-to-many, must be version controlled, can lose meaning, and require authoritative validation when AI assists. Exact equivalents do not always exist.
  8. A. ICD-10-CM is primarily a classification for diagnoses and reporting/administrative use; it is not a sufficiently expressive bedside clinical terminology for every concept nurses document.
  9. B. Data lineage traces the path from source through transformations, interfaces, stores, and downstream use so a value can be understood and audited.
  10. D. Documentation design should begin with the clinical meaning and downstream decisions the data need to support, then choose representation and controls.

Chapter 11 — Interoperability, HL7, FHIR, APIs, USCDI, and TEFCA

  1. D. The message reached the organization and was interpretable, but the allergy was placed outside the workflow where medication decision support could use it. The weakest layer is therefore organizational/workflow interoperability.
  2. D. HL7 Version 2 remains widely deployed for event-oriented healthcare messages including admissions, orders, and results; FHIR has not universally replaced it.
  3. A, B, D, E. A FHIR implementation guide can constrain profiles, terminology, exchange behavior, and use-case rules. Staffing budgets are outside the purpose of a FHIR implementation guide.
  4. B. A profile constrains a base FHIR resource for a defined context by specifying elements, cardinalities, terminology bindings, extensions, or other rules.
  5. A. USCDI defines an evolving core U.S. interoperability data baseline; it is not an exhaustive clinical data model or a private vendor specification.
  6. D. Federal rules often phase requirements by entity and date, so publication, effective date, compliance date, and technical implementation deadlines must be distinguished.
  7. A, B, C, D, E. Patient identity errors, conflicting lists, unknown codes, interface failures, and missing reconciliation workflows can all make technically successful exchange clinically unsafe or unusable.
  8. B. TEFCA is a nationwide framework for exchange among participating networks under common agreements and technical rules; it is not a single national EHR or database.
  9. C. A newer published FHIR release does not automatically invalidate an R4 implementation. Regulatory requirements, implementation guides, and deployed ecosystems can legitimately use earlier releases.
  10. C. Reconciliation by an accountable workflow converts received information into reviewed local clinical information by resolving conflicts, status, and authority.

Chapter 12 — Databases, SQL, Data Quality, and Data Governance

  1. C. Grain defines what one row represents. Here, the grain is one medication-administration event per row.
  2. B. A one-to-many relationship is expected when one patient has multiple encounters; a join therefore may legitimately create several encounter rows per patient.
  3. A, B, C, D, E. AI-generated SQL must be checked for joins, row grain, denominator logic, null handling, and known-case results because syntactically valid SQL can still produce wrong clinical measures.
  4. A. Data warehouses are designed for integrated longitudinal analytics and reporting, whereas transactional EHR systems are optimized for operational care processes such as order entry.
  5. D. Both numbers can be technically correct while representing different definitions of census. The discrepancy is semantic/operational definition rather than proof of database failure.
  6. C. Timeliness asks whether data are available soon enough for the decision or purpose they are intended to support.
  7. A, B, C, D, E. Metric definitions, stewardship, access, retention, and authoritative-source documentation are all legitimate governance responsibilities.
  8. C. Converting missing to zero changes the meaning from “no observed value” to an apparently observed numerical value and can produce unsafe analysis.
  9. C. Lineage documents the route from original source through transformations and storage to downstream use, supporting traceability and troubleshooting.
  10. D. A critical metric should have a governed definition, source fields, transformations, ownership, and change process rather than exist only as undocumented analyst knowledge.

Chapter 13 — Analytics, Visualization, Quality Measurement, RCA, and FMEA

  1. A. Raw counts are not comparable without a denominator, time interval, and consistent case definition that establish exposure and meaning.
  2. C. Descriptive analytics summarize what occurred; predictive analytics estimate what may occur, while prescriptive approaches address what action to take.
  3. A, B, C, D. Case mix, definitions, documentation completeness, and observation periods can distort comparisons. Appropriate risk adjustment is intended to improve—not undermine—comparability.
  4. D. High-risk units may receive more staff and also have more falls; the relationship between staffing and falls is therefore potentially confounded by underlying patient risk.
  5. A. A line chart is generally appropriate for displaying change and pattern over an ordered time series such as 24 months.
  6. D. FMEA prospectively identifies possible failure modes, causes, and effects before or during implementation; RCA is primarily retrospective after an event.
  7. A, B, C, D, E. A useful dashboard makes the signal, comparator, period, accountable actor, and path to investigation understandable rather than merely displaying numbers.
  8. D. A model that generates far more actionable cases than available staff can manage has an operational-capacity mismatch even if its predictive performance is strong.
  9. D. Data distributions, populations, workflows, and clinical practice change over time, so predeployment performance may not persist.
  10. D. An observational trend can support an association or temporal coincidence, but causal claims require consideration of competing explanations and stronger design/evidence.

Chapter 14 — EHR Architecture, Devices, Mobile Technology, and Clinical Infrastructure

  1. A. Failure of a shared identity service can make many otherwise healthy applications unusable. That illustrates dependency risk and a large blast radius.
  2. A. Latency is delay in response or transmission; availability is whether the service is accessible and usable at all.
  3. A, B, C, D, E. Battery, connectivity, infection-control processes, screen constraints, and notification load can all determine whether a mobile clinical workflow is safe and usable.
  4. B. Device integration can automate capture but does not remove identity and encounter-association risk; a valid measurement attached to the wrong patient is a serious safety event.
  5. B. Barcode medication administration helps verify relationships among the patient, ordered medication, product, timing, and administration workflow; it does not independently determine whether the medication is clinically appropriate.
  6. B. Long-lived, hard-to-patch devices require strong inventory, segmentation, access controls, monitoring, and compensating controls to limit exposure.
  7. A, B, C, D, E. Scope, location, onset, recent change, and reproducibility are foundational observations for isolating a technical problem before jumping to a cause.
  8. C. Failures clustered in a physical area strongly suggest testing wireless coverage, interference, roaming, or related environmental conditions early in troubleshooting.
  9. B. RTLS data collected for safety or logistics can be repurposed for employee surveillance, making purpose limitation and governance important.
  10. D. Comparing an affected condition with a known-good user, device, location, or workflow isolates variables without introducing several new changes at once.

Chapter 15 — Patient-Generated Data, Telehealth, Remote Monitoring, and Population Informatics

  1. A. Expanding access without redesigning triage and routing can simply move burden into a single queue. Informatics must align access with accountable response workflows.
  2. A. Patient-generated data can extend observation beyond encounters, but device characteristics, collection conditions, adherence, and context affect interpretation.
  3. A, B, C, D, E. Remote monitoring requires ownership, prioritization, escalation, expected response, and contingency processes so incoming data lead to safe action rather than passive accumulation.
  4. A. Monitoring becomes clinically meaningful when there is an explicit response pathway for interpreting and acting on incoming data.
  5. C. The clinical encounter is blocked by the design of identity recovery, illustrating how authentication and account-management workflows can become digital-access barriers.
  6. C. Utilization reflects both need and access. People with high unmet need but poor access may appear deceptively low risk in utilization-based models.
  7. A, B, C, D, E. Connectivity, affordability, literacy, accessibility, language, and trust all influence whether digital services are genuinely reachable and usable.
  8. D. Collecting social-risk information creates duties around protection, appropriate use, follow-up, and avoidance of harmful or stigmatizing secondary uses.
  9. C. Telehealth workflows need defined escalation when remote assessment cannot safely answer the clinical question or a symptom requires urgent in-person examination.
  10. D. Overall registration can hide where inequity occurs. Stratifying drop-off at each step reveals whether barriers arise at enrollment, verification, device setup, visit completion, or follow-up.

Chapter 16 — Cybersecurity, Resilience, and Clinical Continuity

  1. D. Unauthorized alteration of a medication value compromises integrity even though the system remains available.
  2. B. Resilience is the ability to continue essential functions, absorb disruption, recover, and adapt rather than merely prevent every incident.
  3. A, B, D, E. Least privilege reduces accessible scope, sensitive-data exposure, administrative power, and ambiguity about role responsibility. It does not eliminate the need for authentication.
  4. B. A backup is only stored data. Recovery requires restoring systems, dependencies, configurations, interfaces, and data in usable order and validating that clinical operation is trustworthy.
  5. B. Prompt injection is an attempt to manipulate a model or agent through malicious instructions embedded in content the system processes.
  6. A. When immediate patching is not clinically or technically supported, organizations should apply compensating controls, monitoring, segmentation, and formal risk management while pursuing supported remediation.
  7. A, B, C, D, E, F. NIST CSF 2.0 contains six Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
  8. A. Dependency on an external service can interrupt care even when the healthcare organization itself was not directly compromised.
  9. B. Security and workflow goals should be reconciled through redesign and compensating approaches rather than simply removing the control or encouraging workarounds.
  10. A. Proposed rules should be labeled as proposals. They may inform planning, but they are not current mandatory requirements until finalized and applicable.

Chapter 17 — Artificial Intelligence, Machine Learning, NLP, and Generative AI

  1. C. Rules-based systems execute logic explicitly specified by humans; machine-learning models fit statistical patterns from data.
  2. C. Strong training performance with weak external performance is consistent with overfitting, local-pattern dependence, or otherwise poor generalization.
  3. B, C, D, E. Sensitivity, specificity, calibration, and subgroup performance each describe different aspects of model behavior. No single accuracy number is sufficient for every decision context.
  4. D. LLM output is generated probabilistically from learned patterns and context; fluent language therefore does not guarantee factual grounding.
  5. D. RAG supplies retrieved external information to the model to improve grounding and currency, but retrieval and generation still require verification.
  6. B. Tool use changes AI from a generator of recommendations into a system capable of affecting external systems, making permissions, logging, and control substantially more consequential.
  7. A, B, C, D, E. Bias can arise from sampling, labels, proxies, deployment context, and how humans interpret or act on outputs.
  8. A. Automation bias occurs when users defer excessively to automated recommendations despite contrary evidence or inadequate independent review.
  9. A. Two models may share training sources, assumptions, architectures, and failure patterns. Agreement between them is not independent authoritative evidence.
  10. C. Separating read, recommend, and act permissions applies progressively stronger controls as AI moves from information access to consequential execution.

Chapter 18 — Implementing, Evaluating, and Governing Clinical AI

  1. A. The stronger statement defines population, setting, timing, predicted outcome, user action, horizon, and exclusions rather than using a vague goal such as “improve nursing.”
  2. C. Local populations, prevalence, data capture, workflow, devices, and available response resources may differ from the vendor’s development and validation environment.
  3. A, B, C, D, E. Local validation should reflect intended patients, missingness, operational timing, subgroup behavior, and the organization’s capacity to respond to outputs.
  4. B. Equal statistical performance can still lead to unequal care when downstream resources or workflows differ. Equity evaluation must include the pathway after prediction.
  5. A. Rare errors combined with habitual acceptance can reduce vigilance and create automation bias even when average model accuracy is high.
  6. A. A base-model change can alter system behavior even if the user interface is unchanged, so change control should assess whether revalidation is required.
  7. A, B, C, D, E. Post-deployment monitoring should include technical, clinical, workflow, safety, and equity signals rather than only model uptime.
  8. B. Transparency documentation describes development and performance but cannot establish that the system is safe, effective, or appropriate in a specific local workflow.
  9. A. PHI use depends on the exact service and feature, applicable contract and BAA, configuration, organizational approval, and legal/data-governance requirements—not simply the vendor’s brand.
  10. C. In the NIST AI RMF, Measure addresses assessing, analyzing, and tracking identified AI risks and impacts.

Chapter 19 — Governance, Vendor Strategy, Integration, and Portfolio Management

  1. B. Governance establishes who can decide, what evidence is required, who is accountable, and how disagreements or high-risk decisions are escalated.
  2. C. Intake should first define the underlying problem, workflow, evidence, affected users, and intended outcome before locking the organization into an alert as the solution.
  3. A, B, C, D, E. Vendor evaluation should cover clinical fit, integration, security/privacy, data portability and exit, and operational support/recovery—not just features and price.
  4. A. An RFI is useful when an organization is exploring available approaches and market capability before finalizing detailed procurement requirements.
  5. C. A proof of concept is strongest when it answers a bounded question with explicit success criteria and a defined ending or decision gate.
  6. D. Broad direct database access can create excessive privilege, tight coupling, unclear change boundaries, and difficult revocation compared with a supported, scoped interface.
  7. A, B, C, D, E. Integration governance should document direction, authentication, monitoring, ownership, and how the connection can be disabled or terminated safely.
  8. D. Standardization can legitimately allow exceptions when a regulatory or clinical requirement is real, documented, risk-assessed, and governed.
  9. A. Technical debt is the future burden created by shortcuts, duplicated customization, deferred remediation, or complexity that constrains later change.
  10. B. Portfolio decisions encode organizational priorities, risk tolerance, opportunity cost, and values. AI may inform the analysis but should not assume accountable decision authority.

Chapter 20 — Informatics Leadership, Finance, Workforce, and Career Development

  1. D. A business case begins with the decision problem, affected population, alternatives, and intended outcomes so costs and benefits are evaluated against a real need rather than a predetermined vendor.
  2. B. Total cost of ownership includes implementation, integration, training, staffing, support, upgrades, infrastructure, change, and eventual retirement—not just acquisition price.
  3. A, B, C, D, E. Informatics value can appear as avoided cost, safety, compliance, capacity, resilience, and other organizational outcomes rather than only direct revenue.
  4. D. Time released from a task may create capacity, reduce burden, or enable higher-value work without becoming a direct payroll reduction; the value claim should reflect what actually changes.
  5. C. A hybrid/federated model can preserve enterprise standards while incorporating local expertise and context, provided decision rights and exception rules are explicit.
  6. A. When one leader personally holds critical problem-solving knowledge, the organization develops key-person risk and fails to grow scalable team capability.
  7. A, B, C, D, E. Executives need the decision, evidence, options, tradeoffs, risks, and next action more than exhaustive technical detail.
  8. C. Influence without formal authority depends on credibility, evidence, relationships, coalition-building, framing, and clear decision processes across organizational boundaries.
  9. D. Certification demonstrates knowledge against a defined standard; mastery also requires contextual judgment, repeated application, reflection, and experience with consequences.
  10. B. Leaders need to evaluate data provenance, model limitations, validation, workflow effects, governance, privacy, and automation risk—skills much broader than prompt construction.

Chapter 21 — Digital Transformation, Learning Health Systems, and the Future of Nursing Informatics

  1. D. Converting paper content into digital form without changing the underlying process is digitization, not transformation.
  2. D. A learning health system closes the loop from care data to evidence or knowledge and then feeds that learning back into practice and future measurement.
  3. A, B, C, D, E. Agentic systems make permissions, logging, stop conditions, tool reliability, and human accountability more important because the system can take multi-step actions rather than only generate text.
  4. A. Ambient systems can reduce visibility into what was sensed, inferred, transformed, or acted upon, creating provenance, consent, and oversight risks.
  5. B. Novel technology should be evaluated against a defined problem, population, mechanism, comparator, evidence, and consequences rather than novelty or demonstration quality.
  6. B. Reversible pilots and modular choices allow an organization to learn while limiting sunk cost and harm if assumptions prove wrong.
  7. A, B, C, D, E. Scenario planning deliberately varies uncertain drivers such as regulation, workforce, AI capability, reimbursement, and cyber risk.
  8. A. A leading indicator is an earlier observable signal that may suggest movement toward a scenario before the ultimate outcomes are available.
  9. C. Systems thinking, evidence appraisal, workflow analysis, governance, and evaluation remain transferable even when individual AI products and interfaces change rapidly.
  10. D. In a highly automated environment, nursing informatics still integrates nursing practice, people, information, workflow, and technology so automation serves safe and effective care rather than replacing accountable clinical judgment.

Validation Notes

  • Total questions validated: 210
  • Questions per chapter: 10
  • SATA items: 51
  • Single-best-answer key balance: A = 40, B = 40, C = 40, D = 39
  • SATA scoring rule: all listed correct options should be selected; no unlisted option should be selected.
  • Option-order QA: choices were reordered after substantive validation to remove a strong A/B answer-position bias. The wording and set of options for every question were preserved. A programmatic semantic check confirmed that the correct option text before and after reordering is identical for all 210 items.
  • Current-law/current-standard questions: Chapters 4, 11, 16, and 18 were checked against authoritative 2026 sources during the September 15, 2026 editorial review.
  • Editorial finding: no item required removal for having two equally defensible best answers after review. Several items intentionally test the distinction between technical success and clinical/workflow success.

Source anchors for time-sensitive quiz content

  • American Nurses Credentialing Center. Informatics Nursing Board Certification Examination: Test Content Outline. Updated August 29, 2025. https://www.nursingworld.org/globalassets/informatics-tco_08292025-for-webposting.pdf
  • U.S. Department of Health and Human Services. Confidentiality of Substance Use Disorder (SUD) Patient Records: Final Rule. Compliance with the 2024 Final Rule was required February 16, 2026. https://www.hhs.gov/hipaa/part-2/
  • Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology. USCDI, information-blocking, HTI-1, and SAFER Guide resources. https://healthit.gov/
  • HL7 International. FHIR Release 5 and current FHIR development/ballot materials. https://hl7.org/fhir/
  • The Sequoia Project, TEFCA Recognized Coordinating Entity. Common Agreement Version 2.1. https://rce.sequoiaproject.org/common-agreement/
  • National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29
  • Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). https://doi.org/10.6028/NIST.AI.100-1
  • U.S. Food and Drug Administration. Clinical Decision Support Software. Final guidance, January 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/clinical-decision-support-software
  • U.S. Food and Drug Administration. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. Final guidance, February 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket