Practice questions › Clinical Informatics
The Swiss cheese model
A practice question in the style of the CPHIMS® exam, from the free questions of HealthITPrep. The question is in English, as in the exam.
An investigation finds that a wrong-dose error reached a patient only because an unclear order screen, a missed pharmacist check during a very busy shift, and a barcode scanner that was out of service all failed at the same time. Which safety model describes this?
Choose an answer, or open the explanation below.
Show the answer and the explanation
The correct answer: A. The Swiss cheese model
✅ Why this answer
The Swiss cheese model pictures the system’s layers of protection as slices of cheese, each with holes (weaknesses). Each layer alone stops most errors. Harm happens when the holes line up across all the layers at once, so the error passes all the way to the patient. This is exactly what happened: the screen, the pharmacist and the scanner.
❌ Why the other options are wrong
- (B) The Pareto principle: that about 80% of problems come from about 20% of causes; a tool for setting priorities.
- (C) Diffusion of innovations: describes how new ideas spread among groups of adopters.
- (D) Donabedian: a framework for classifying quality measures into structure, process and outcome.
💡 Key concept
The point of the model: incidents rarely have a single person or a single error as their cause. So:
- Independent layers of protection are added.
- Known holes are closed (clearer design, backup devices and lighter workload).
- Every layer is examined when analyzing the event, rather than searching only for “the guilty party”.
The model distinguishes active errors on the front line from latent conditions in the system that make them possible.
In the exam: “several layers of protection failed at the same time, so the error got through” = the Swiss cheese model.
🔗 Related facts and questions
- The action hierarchy after an analysis: strong actions: a physical change, a forcing function, or simplifying and standardizing. Intermediate actions: checklists, software improvements and more staff. Weak actions: a new policy, training, a warning label, or a double check.
Practice question: which action is stronger after a drug selection error: a pop-up reminder asking for attention, or a standardized order screen that shows the indication beside each drug? → The standardized screen, because it changes the design, while the reminder relies on attention. - The independent double check: two people calculate or verify the dose each separately, then compare the results. The second person looking at what the first did and agreeing is not an independent layer, because the second is influenced by what they saw.
- Defense in depth: the same idea in information security: a firewall, multi-factor authentication (MFA), encryption and monitoring. If one layer fails, another stops the attack.
- Where Pareto helps: the Pareto principle does not explain how a single event happened, but it helps set priorities after many events are collected: a Pareto chart ranks causes from most to least frequent, so the team starts with the few causes behind most events.
Practice question: a safety committee sorts 300 medication error reports from one year by cause: 150 come from look-alike drug names, 90 from dose calculation, and the other 60 are spread over eight smaller causes. Where does a Pareto chart tell the team to start, and what share of the reports does that cover? → The first two causes, which cover 80% of the reports (240 ÷ 300), although they are only two of the ten causes. - Latent conditions in technology: an unclear screen, a scanner with no backup when it fails, or an alert that is always overridden. They often exist long before the incident, and reviewing near misses reveals them before the holes line up.
- The report “To Err is Human”: a related question in the full bank.
- The closed medication loop and its layers: "The closed-loop medication process" (in the full bank).
- Analyzing failure modes before they happen: "Failure mode and effects analysis (FMEA)" (in the full bank).
Twenty questions like this one, free
A timed 30-question trial exam with this kind of explanation for every option and a score per domain. No payment details needed.
Start the trial examAll 20 free practice questions · CPHIMS guide
Practice questions written for study; they are not the questions of the real exam. An independent site, not affiliated with or endorsed by HIMSS. CPHIMS® is a registered trademark of HIMSS.