The exam's data domain (26 items) tests whether you can choose the right measure, collect it soundly, display it honestly, and protect it legally. It runs 4A (data needs) through 4L (health information exchange), with HIPAA woven through the middle.
4A–4D. From needs to measures
Determine organizational data needs and goals. Start from the decision: what will this data change? The quality professional translates goals into data requirements — which populations, which timeframes, which level of aggregation — before a single chart is pulled.
Ensure data privacy, security, and confidentiality (see the HIPAA section below).
Identify measures/types. The outline expects you to select measures across its own categories — structure, process, outcome, and experience — and to develop each measure with explicit definitions, goals, thresholds, numerators, and denominators before collecting a single data point[1]. The AHRQ Quality Indicators show what real measure sets look like: they "use inpatient administrative data available from individual hospitals"[2] and span "four measure areas: inpatient, prevention, patient safety, and pediatric care"[2]. Two examples the exam uses: Patient Safety Indicators "identify adverse events occurring during hospitalization"[2] — an outcome-flavored use of billing data — and Prevention Quality Indicators identify "ambulatory care sensitive conditions," "conditions that can be effectively treated in an outpatient setting"[2], so the hospitalization itself becomes the signal of a prevention failure. The PSI 90 bundles selected indicators into one composite — "PSI 90 composite (Patient Safety for Selected Indicators, NQF-endorsed #531)"[2] — the kind of single summary number boards ask for.
4E–4F. Sampling and collection
Use sampling methodology. You cannot review every chart, so you sample — and the outline names sampling methodology as part of every data collection plan[1]. The HCAHPS program shows sampling in practice: "HCAHPS is administered to a random sample of adult (18 years and older) inpatients between 48 hours and 42 days after discharge"[3] — a defined population, a random draw, a defined window. The exam tests whether your sampling plan matches the question you are asking: the sample must represent the population the decision is about.
Oversee data collection. Collection fails in predictable ways: unclear definitions, untrained abstractors, no pilot of the form. The quality professional pins down the measure's definitions, goals, thresholds, numerators, and denominators up front[1], trains the collectors, pilots the tool, and audits early data.
4G–4H. Analysis tools
Use data analysis tools. The workhorses:
- Run charts. A run chart "shows a line connecting many data points collected from a process running over time"[4] and simple rules let you "identify four types of nonrandom patterns in the data displayed on a run chart"[5]. The center line is the median, and a run "consists of one or more consecutive data points on the same side of the median"[5]. The interpretation rules are exact: "A trend is five or more consecutive points all increasing or decreasing"[5]; "Too many or too few runs is a nonrandom number of runs"[5]; and a shift is six or more consecutive points above or below the median. Four points drifting up is not a trend; five is. The exam counts — and it counts carefully: IHI's reference sheet raises the thresholds for long charts, "Use 6 points if you have 20 or more total data points" for a trend[5] and 8 for a shift, and says "Don't count points on the median"[5]. To count runs, "Count the number of times the sequence of data points crosses the median and add "1.""[5]
- Control charts (SPC). The control chart answers the question the run chart cannot: is this variation normal for the process, or a signal? "Common cause variation, which is intrinsic to the process and will always be present"[6], while "Special cause variation, which stems from external sources and indicates that the process is out of statistical control"[6]. The decision rule: "Control charts attempt to distinguish between two types of process variation"[6]. React to common-cause variation as if it were special — tampering — and you make the process worse. The classic exam scenario: one bad month after a year of stability is a special cause; investigate, don't redesign.
- Benchmarking and comparison. Comparative data needs context: "Benchmarking: A technique in which an organization measures its performance against that of best-in-class organizations"[7]. The exam trap: comparing against your own past performance is trending, not benchmarking — benchmarking studies the best to learn what they do differently.
- Scorecards and dashboards. The outline expects you to "Design scorecards and dashboards for different audiences"[1] — the audience decides the content: executives get trends against targets on a decision rhythm, frontline teams get their own run charts. A dashboard nobody looks at is wallpaper.
Rates, sensitivity, and specificity — worked step by step. Two calculations recur on the exam, and both punish a wrong denominator.
Rates. A count means nothing until it has a denominator. Fall rates, for example, are reported per 1,000 patient days: "Fall rates reported in the literature were approximately 2.3 to 7 falls per 1000 patient days"[8]. A unit with 9 falls in 3,600 patient days has a rate of 9 ÷ 3,600 × 1,000 = 2.5 falls per 1,000 patient days. Comparing raw counts between a 20-bed and a 40-bed unit compares their sizes, not their safety.
Screening tests and triggers. Put the results in a 2 × 2 table against a gold standard: true positives (TP), false positives (FP), false negatives (FN), true negatives (TN). Then:
- Sensitivity = TP ÷ (TP + FN) — "Probability of being test positive when disease present"[9].
- Specificity = TN ÷ (TN + FP) — "Probability of being test negative when disease absent"[9].
- Positive predictive value (PPV) = TP ÷ (TP + FP) — "the percentage of patients with a positive test who actually have the disease"[9].
- Negative predictive value (NPV) = TN ÷ (TN + FN) — "the percentage of patients with a negative test who do not have the disease"[9].
Worked example: a sepsis screening tool is checked against chart review for 200 patients. Fifty truly had sepsis and the tool flagged 40 of them (TP 40, FN 10). Of the 150 without sepsis, the tool cleared 135 and flagged 15 (TN 135, FP 15). Sensitivity = 40 ÷ 50 = 80%. Specificity = 135 ÷ 150 = 90%. PPV = 40 ÷ 55 = 72.7%. NPV = 135 ÷ 145 = 93.1%. The trap is the denominator: sensitivity and specificity divide by the true condition (the columns), predictive values divide by the test result (the rows). Predictive values also move with how common the condition is — "the PPV will increase with increasing prevalence; and NPV decreases with increase in prevalence"[9] — so a tool that performed well in an ICU can produce mostly false alarms on a general ward. A highly sensitive test is the one to trust when it is negative: "A highly sensitive test if negative, rules out the disease"[9].
4I–4K. Display, interpretation, variation
Interpret charts and graphs. Read before reacting: check the axes, the center line, the annotation of interventions. A run chart with a marked intervention date tells a PDSA story; one without annotations is just wiggles.
Manage and integrate data (dashboards). Dashboards serve decisions: the right KPIs, refreshed on the decision's rhythm, with thresholds that trigger action. A dashboard nobody looks at is wallpaper.
Evaluate variation. This is the chapter's capstone concept and it loops back to SPC: common-cause variation is the system's voice — only a system change moves it; special-cause variation is an intruder — find and remove it. The quality professional's first question about any change in the data is always: which kind of variation is this?
4H and data protection. Exchange and minimum necessary
Health information exchange (HIE). Sharing data across organizations multiplies its value — and its risk. The quality professional supports exchange for care coordination and population health while enforcing the protections below.
HIPAA Privacy Rule. The minimum necessary standard: a covered entity "must make reasonable efforts to use, disclose, and request only the minimum amount of protected health information needed to accomplish the intended purpose"[10]. Quality analysts get the data elements the project needs — not the whole record. (Confidentiality duties continue in Chapter 6: minimum necessary for PHI and the federal privilege for patient safety work product.)
Key numbers
- AHRQ Quality Indicators: four measure areas — inpatient, prevention, patient safety, pediatric care — built from hospitals' inpatient administrative data[2].
- Run chart trend: 5+ consecutive points in one direction[5]; runs counted about the median[5].
- Common cause: intrinsic to the process, always present; special cause: from external sources, process out of statistical control[6].
- Long run charts (20+ points): trend needs 6, shift needs 8[5].
- Sensitivity = TP ÷ (TP + FN); specificity = TN ÷ (TN + FP); PPV = TP ÷ (TP + FP); NPV = TN ÷ (TN + FN)[9].
- Rates need denominators: falls are reported per 1,000 patient days[8].
- HCAHPS: random sample of adult inpatients, 48 hours to 42 days after discharge[3].
- This domain is 26 items on the exam[1].
Key takeaways
- Pin down every measure before collecting: definitions, goals, thresholds, numerators, denominators.
- Sample to represent the population the decision is about — the outline names sampling methodology as part of every collection plan.
- Five points make a trend; control charts separate common-cause (system) from special-cause (intruder) variation.
- Benchmark against the best in class — your own trend line is not a benchmark.
- Minimum necessary for PHI; confidentiality duties continue in Chapter 6.
Chapter 4 quiz
1. A team plots weekly nurse staffing hours against the unit's fall counts to see whether the two move together. Which display shows the relationship between two variables?
- A. A scatter plot of the two variables against each other
- B. A check sheet tallying fall types
- C. A histogram of the fall counts alone
- D. A run chart of staffing hours over the full study period
2. Complaint data show that 4 of 20 complaint categories account for 82 percent of all complaints. Which principle tells the team to focus improvement on those 4 categories?
- A. The control chart rule for common cause variation
- B. The rule that every category deserves equal effort
- C. The Pareto principle
- D. The requirement to survey more complainants first
3. The hospital's overall readmission rate looks flat year over year, but splitting the data by discharge disposition reveals one disposition driving the entire rate. What technique exposed this?
- A. Increasing the sample size behind the overall rate
- B. Stratification of the data by category
- C. Aggregating all dispositions into a single rate
- D. Removing the outlier group and recalculating
4. During 50 observed medication passes, observers must tally each defect by type — wrong time, wrong dose, missed scan. Which simple tool fits this recording job?
- A. A check sheet recording defect types
- B. A fishbone diagram of defect causes
- C. A control chart of defect rates
- D. A checklist of the five medication rights
5. The team wants to see the shape of the distribution of door-to-balloon times — where cases cluster and how far the tail extends. Which graphic displays the distribution?
- A. A histogram of the recorded times
- B. A run chart of monthly median times
- C. A scatter plot of times against patient outcomes
- D. A check sheet of time categories
6. Before redesigning triage, the team diagrams every step of the current process exactly as it happens today, including the rework loops. Which tool did they build?
- A. A Pareto chart of delay reasons
- B. A flowchart of the process steps
- C. A fishbone diagram of triage delay causes
- D. A control chart of triage times
7. A control chart shows two of three consecutive points on the same side of the center line, each more than two standard deviations from it. What does this pattern signal?
- A. A correctly centered process with no assignable cause
- B. The process is out of control and needs investigation
- C. Normal common cause variation within the process
- D. An error in calculating the control limits
8. A hospital wants to scan its billing data for hospitalizations that may have involved an adverse event, to select cases for deeper clinical review. Which AHRQ tool fits?
- A. The NHSN antimicrobial use module
- B. HCAHPS survey results on the patient experience
- C. Patient Safety Indicators, built to flag potential adverse events
- D. Prevention Quality Indicators for outpatient-sensitive conditions
9. The infection preventionist submits the hospital's infection data to the CDC's national surveillance system so the hospital can benchmark against others. Which system is this?
- A. The Leapfrog Hospital Safety Grade
- B. The AHRQ Patient Safety Indicators
- C. The National Healthcare Safety Network (NHSN)
- D. The hospital's internal incident reporting system
10. A population-health team wants measures of hospital admissions for conditions that timely outpatient care could have prevented. Which AHRQ indicator set identifies these admissions?
- A. Prevention Quality Indicators (PQIs)
- B. Inpatient Quality Indicators for procedure volumes
- C. Patient Safety Indicators for inpatient adverse events
- D. HCAHPS composites for the care experience
11. A run chart of monthly falls shows points alternating above and below the median with no long sequences on either side. How does the analyst count "runs"?
- A. Points that fall outside the control limits
- B. Consecutive points on the same side of the median
- C. Months in which the reported fall count was zero
- D. Data points collected on the same weekday
12. A run chart of patient satisfaction shows seven consecutive months of declining scores. What does this pattern indicate?
- A. A harmless sawtooth pattern
- B. Random variation around the median
- C. A trend by the run chart rules
- D. An eight-point shift on one side
13. A run chart has 40 data points but only 4 runs — nearly all points sit on one side of the median before crossing once. What does this indicate?
- A. Excellent process stability
- B. A nonrandom pattern: too few runs
- C. A sample too small to interpret
- D. A correctly calibrated median
14. A clinic's no-show rate holds steady for a year, then spikes for one month when the reminder system goes down, then returns to baseline. How should the spike be classified?
- A. Normal common cause variation, inherent in the everyday scheduling process
- B. A trend requiring process redesign
- C. A balancing measure signal
- D. Special cause variation, sporadic and from outside the system
15. The quality analyst puts the no-show data on a control chart to decide whether the spike warrants a system redesign. What is the chart's purpose?
- A. Assign blame for the reminder system outage
- B. Calculate the average no-show rate for the year
- C. Replace the run chart permanently
- D. Separate common-cause from special-cause variation
16. For the eleven stable months, the no-show rate wiggles within the chart's upper and lower bounds. How should that wiggle be classified?
- A. Special cause variation requiring investigation
- B. Common cause variation
- C. Evidence that staff fabricated the data
- D. A signal to recalculate the median
17. A clinic wants to reduce patient wait times and visits a renowned outpatient center to study its scheduling and flow practices. Which technique is the clinic using?
- A. Stratification of waits by provider
- B. Benchmarking against best-in-class organizations
- C. Trending the clinic's own wait times over time
- D. A root cause analysis of long waits
18. A new quality director asks what the AHRQ Quality Indicators cover as a set. Which four measure areas do they comprise?
- A. Inpatient, outpatient, emergency, and long-term care
- B. Structure, process, outcome, and patient experience
- C. Mortality, readmissions, cost, and satisfaction
- D. Inpatient, prevention, patient safety, and pediatric care
19. The board wants one summary number for patient-safety performance across several indicators, built from data the hospital already collects. Which composite fits?
- A. The CMS overall hospital star rating
- B. The HCAHPS top-box summary score
- C. The PSI 90 patient-safety composite
- D. The hospital's raw incident-report count
20. HCAHPS surveys are sent to which patients, and when?
- A. Randomly sampled adult inpatients, 48 hours–42 days post-discharge
- B. All emergency department patients, at the time of triage
- C. Every discharged patient, within 24 hours of discharge
- D. A convenience sample of outpatients, one year after the visit
21. A hospital wants to screen for potential safety problems using data it already collects for billing, without new chart abstraction. What makes the AHRQ QIs suitable for this?
- A. The QIs are calculated only from patient surveys
- B. The QIs require prospective data collection by clinicians
- C. The QIs use hospitals' inpatient administrative data
- D. The QIs replace the need for any clinical review
22. A sepsis screening tool is checked against chart review for 250 patients. Forty truly had sepsis, and the tool flagged 36 of them. Of the 210 patients without sepsis, the tool flagged 24. What is the tool's sensitivity?
- A. 60 percent
- B. 90 percent
- C. 88.6 percent
- D. 97.9 percent
23. Using the same 250 patients — 36 true positives, 24 false positives, 4 false negatives, and 186 true negatives — what share of the patients the tool flags actually have sepsis?
- A. 90 percent
- B. 88.6 percent
- C. 40 percent
- D. 60 percent
24. A medical unit reports 9 patient falls in a quarter during which it recorded 3,600 patient days. What is the unit's fall rate per 1,000 patient days?
- A. 2.5 falls
- B. 0.25 falls
- C. 25 falls
- D. 400 falls
25. A run chart of monthly readmission rates has 24 data points. The last five points each rise above the one before. Using IHI's run chart rules reference sheet, how should the analyst read this?
Sources cited in this excerpt
- Certified Professional in Healthcare Quality (CPHQ) Detailed Content Outline (2024). National Association for Healthcare Quality (NAHQ).
- AHRQ Quality Indicators (QIs). https://www.ahrq.gov/talkingquality/measures/setting/hospitals/measurement-sets.html
- HCAHPS Fact Sheet (CAHPS Hospital Survey), December 2024. Centers for Medicare & Medicaid Services. https://hcahpsonline.org/globalassets/hcahps/facts/hcahps_fact_sheet_december_2024.pdf
- 7 Basic Quality Tools: Quality Management Tools | ASQ. https://asq.org/quality-resources/seven-basic-quality-tools
- Run Chart Rules Reference Sheet. https://www.saskhealthauthority.ca/system/files/2023-06/GUIDE-QS-RunChartRulesReferenceSheet.pdf
- Control Chart - Statistical Process Control Charts | ASQ. https://asq.org/quality-resources/control-chart
- Six Sigma Tools: DMAIC, Lean & Other Techniques | ASQ. https://asq.org/quality-resources/sixsigma/tools
- Patient Falls Prevention — PSNet (AHRQ). https://psnet.ahrq.gov/web-mm/tale-two-falls
- Understanding and using sensitivity, specificity and predictive values (Parikh et al.). Indian Journal of Ophthalmology (via PubMed Central). https://pmc.ncbi.nlm.nih.gov/articles/PMC2636062/
- HIPAA Minimum Necessary Standard — HHS/OCR. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html