Blueprint domain 4 · 25%
CPHIMS Domain 4: Management & Leadership
Management and Leadership is a quarter of the CPHIMS exam and, on the official outline, a single sub-area — 25 numbered task statements, A.1 to A.25, the longest list on the blueprint. It is also the domain you cannot revise by reading, because every statement describes something you either do at work or you do not.
- Share of the blueprint
- 25 %
- Official sub-areas
- 1 A.1–A.25
- Outline tasks
- 25
The other three domains hand you material: systems to name, standards to recognise, a lifecycle to walk. This one hands you judgement under constraint. HIMSS writes its items at three cognitive levels — recall, application and analysis — and this is the domain where the recall half has the least to work with. There is no glossary to learn. There is a list of 25 things a health-IT leader is expected to be able to do, and scenarios that ask whether you would do them.
Section 1: strategy, and the order things get done in
The first seven task statements are the planning half of the domain, and they read as a chain rather than a list. Assess the organisation, forecast what it will need, write the IT plan, measure whether the plan worked, then keep everyone honest about what the budget will and will not buy. Work through them in that order and the trade-off questions stop feeling arbitrary.
A.2 — read the organisation
Corporate culture, values and drivers, in the outline's own words. This is not soft framing: a system that fits how a department already works goes live, and the same system in a department that was not consulted stalls.
A.3 — forecast the need
Link resources to business needs. The verb is forecast — you are expected to see the storage, the interfaces and the staffing before a service line asks for them.
A.4 — write the IT strategic plan
It has to align and support organizational strategies and goals. An IT roadmap that is internally coherent but disconnected from what the health system promised its board is, on this exam, the wrong roadmap.
A.5 and A.6 — measure both halves
A.5 is performance: service level agreements, goal and performance indicators, systems effectiveness. A.6 is whether the people using the service think it works. They are two separate statements and the exam can ask either.
A.7 — manage the expectation
Promote stakeholder understanding of IT opportunities and constraints. The handbook's own parenthetical names budget and project prioritisation, which tells you where the scenario questions in this domain come from.
One structural point worth knowing before you revise: a failed attempt returns diagnostic information by content area. You find out that Domain 4 let you down. You do not find out which of the 25 statements did. That is an argument for auditing yourself against the list now rather than after a retake, and for reading the study guide as four separate revision problems rather than one.
Section 2: policy, ethics, and the room you have to run
Statements A.8 through A.14 cover the part of the job that produces documents and meetings. If you came up through engineering, this is the half of the domain to give the hours to. Policies and procedures for information and systems management (A.8). Compliance with legal and regulatory standards (A.9) and with the organisation's own ethical business principles (A.10). Comparative analytics — indicators and benchmarks (A.11). Business communications: presentations, reports, project plans (A.12). Facilitating group discussions, including consensus building and conflict resolution (A.13). And providing consultative technology services to the organisation (A.14) — advising a department that does not report to you.
Ethics is not a throwaway line
Two of the 25 statements are explicitly ethical — A.10 on the organisation's ethical business principles, A.18 on maintaining effective and ethical working relationships with clinicians, vendors and partners. HIMSS backs that up after you pass: of the 45 continuing-education hours required across each three-year renewal period, a minimum of two must relate to ethics or conflicts of interest. A vendor relationship question is not filler.
Benchmarks, and who you are talking to
A.11 asks for comparative analytics, A.19 asks you to present interpretations and recommendations of data analyses to decision makers. Pair them. A number you have not compared against anything is not an analysis, and an analysis a chief financial officer did not follow has not been presented. If your day job is already reporting, A.11 is free marks and A.19 is the one to rehearse.
Section 3: running the work — and where Domain 3 stops
Six statements carry the delivery half of this domain: change management (A.20), projects and portfolios of projects (A.23), educational strategy for the information and management systems function (A.15), keeping the organisation current on IT trends (A.16), defining roles, responsibilities and job descriptions for healthcare IT (A.21), and evaluating staff competency (A.22). Read together they describe a manager who is accountable for a portfolio and for the people running it, not for a single go-live.
It is also the seam where revision goes to the wrong domain. Domain 3 and Domain 4 use the same nouns — change, scope, budget, training, contracts — and split on the verb.
| The work | Domain 3 — Healthcare Information & Systems Management | Domain 4 — Management & Leadership |
|---|---|---|
| Change management | Selection C.2 — effective technical change management practices | A.20 — organisational change-management techniques supporting the implementation |
| Scope, schedule, budget | Selection C.4 — implement the solution while managing scope, schedule, budget and quality | A.23 — manage projects and portfolios of projects |
| Vendor paperwork | Analysis A.10 — analyse and interpret RFPs, RFIs, SLAs, SOWs and NDAs | A.24 — manage the agreement afterwards: cost, schedule, support, maintenance, performance |
| Training | Selection C.3 — the methods: classroom, computer-based, train-the-trainer, at-the-elbow superusers | A.15 and A.22 — the educational strategy for the function, and whether your staff are competent |
| Does it fit the strategy? | Analysis A.7 — evaluate whether a proposed solution aligns with the plans | A.4 — write the plan it is supposed to align with |
| Money on a project | Analysis A.8 — cost-benefit analysis of a proposed solution | A.25 — manage the budget and the financial risk |
The tell is reliable. Domain 3's verbs are apply, administer, ensure, validate — things you do to a system. Domain 4's are contribute, forecast, promote, facilitate, manage, present, define — things you do about people, money and plans. If a stem hands you a testing methodology or an interface, you are in Domain 3. If it hands you a department head who has stopped attending the steering meeting, you are here.
Section 4: money, contracts, and the numbers you defend
Health-IT money on this exam is not corporate finance. The outline never asks you to build a model. A.25 asks you to manage budget and financial risks; A.24 asks you to manage contractual agreements with vendors and partners, and it names the five things that agreement is judged on — contract cost, schedule, support, maintenance and performance. Those five words are effectively a checklist for any vendor scenario.
Work an underperforming-vendor stem against them before you look at the options. Is the complaint about cost, about a missed date, about support response, about maintenance that never happened, or about the system not doing what was demonstrated? Each one points at a different remedy, and the remedy usually sits in the contract or in the service level agreement from A.5 — not in restarting the selection, which is Domain 3's job and would be the expensive answer.
The two numbers you have to be able to defend
Financial risk (A.25) and comparative analytics (A.11) meet at the point where you tell a decision-maker what a system will actually cost to keep. Capital spend is the easy half. The half candidates underweight is the recurring one — support, maintenance, licensing, the staff time to run it — because that is what a three-year or five-year comparison exposes and what a benchmark against a peer organisation makes uncomfortable. A.19 then requires you to present that to people who do not work in IT, which is a different skill from producing it.
HIMSS is unusually direct about how to prepare for this material, and the instruction is worth taking literally.
All questions in the CPHIMS Examination are job-related/experience-based and test the application and analysis of information, not just the recollection of isolated facts.
The handbook's advice that follows is to review the outline and concentrate on the tasks you do not perform regularly. For Domain 4 that is the entire method — there is no body of facts here to memorise, only 25 things you either do at work or do not. Run this list. Anything you cannot answer out of your own working month is a gap, and gaps in this domain are where a quarter of the exam lives.
- Name two things your current IT plan is supposed to support in the organisation's strategy. (A.4)
- Say what one of your service level agreements measures, and what happens when it is missed. (A.5)
- Describe how one project got prioritised over another this year, and who made that call. (A.7)
- Point to the written policy that governs who gets access to a system you support. (A.8)
- Name one benchmark you have measured your organisation against. (A.11)
- Recall a meeting where two departments wanted incompatible things, and say how it was resolved. (A.13)
- State one risk on your current project and the mitigation actually in place. (A.17)
- Open a vendor contract and find the support and performance terms. (A.24)
- Write the job description for the healthcare IT role you would hire next. (A.21)
What to take away
- Domain 4 is 25% of the blueprint and one official sub-area: 25 task statements, A.1 to A.25. HIMSS publishes the percentage and nothing finer — there is no official item count for a domain.
- Nothing in the domain asks you to configure, build or test a system. Every statement is about plans, people, money or communication.
- When a scenario forces a trade-off, rank by patient impact and stated organisational strategy before cost, speed or vendor pressure.
- Domains 3 and 4 share nouns and split on verbs: analysing the RFP is Analysis A.10, living with the signed contract is A.24.
- Study it as an audit, not a reading list — the handbook says the items are job-related and tells you to focus on the tasks you do not perform regularly.
- A failed attempt reports by content area, so a weak Domain 4 arrives as one line. Narrow it down yourself before you book the retake.