Skip to main content
v2026.11,610 entries · CC-BY 4.0

CPPS Certification: The Four Domains, Their Item Counts, and the 91-Task Second Axis

What the CBPPS content outline and candidate handbook actually publish for the Certified Professional in Patient Safety: four content domains with item counts, a separate 91-task axis, the eligibility routes, and the structural scope difference from CPHQ.

Ask about CPPS Certification: The Four Domains, Their Item Counts, and the 91-Task Second Axis

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

The Certified Professional in Patient Safety (CPPS) is awarded by the Certification Board for Professionals in Patient Safety (CBPPS), whose programme home is the Institute for Healthcare Improvement and whose examination is developed, administered and scored with PSI Services. Almost everything written about it online is exam-cram material or career-advice filler. This page is the opposite: it reproduces what CBPPS itself publishes — the examination content outline, the item count behind every domain, the eligibility language, the scoring model — and reads the blueprint for what it says a patient safety professional is expected to be able to do.

Two things in that blueprint are almost never restated correctly. First, the CPPS outline is two-dimensional: four content domains carrying published item counts, crossed with a separate, flat list of 91 task statements that the document deliberately does not map back to those domains. That is a different instrument design from the single-axis blueprint used by the CPHQ, whose seven content categories carry their task areas nested inside them. Second, the published eligibility requirement is an education-plus-healthcare-experience gate — it is not a requirement to have worked in patient safety, and it is not a clinical licence.

Which edition this page describes — read this first

Domain structure, item counts, fees and eligibility language change between exam editions and handbook revisions. Nothing below is stable across editions, and a figure that is correct today can be wrong at your next application. This page describes:

  • The CPPS Examination Content Outline, published September 2024, carrying a 2024 Certified Professional in Patient Safety copyright line and the footer ihi.org/cpps. This is the document linked from CBPPS’s own examination page as the outline the current exam covers.
  • The CPPS Candidate Handbook, November 2024, revision date 11/15/2024, published under a PSI Services copyright line.

Confirm every number below against the current candidate handbook and content outline before you apply. The handbook — not this page, not a review course, not any third-party summary — is the controlling document.

How the examination is constructed

From the November 2024 Candidate Handbook:

Element As published
Format Multiple choice, four options (A, B, C, D), computer-delivered
Total questions presented 120
Scored questions 100
Unscored pretest questions 20, dispersed through the exam and not marked in any way
Time limit 2.5 hours (150 minutes)
Breaks None permitted, at a test centre or under remote proctoring
Delivery PSI test centres (approximately 300 in the US, plus international) or live remote online proctoring
Cognitive mix Recall, application and analysis; the handbook states only a small percentage is recall, with the rest divided between application and analysis
Standard setting Criterion-referenced; minimum passing score set by the Angoff method, with statistical equating across forms
Guessing penalty None
Programme accreditation National Commission for Certifying Agencies (NCCA), the accrediting body of the Institute for Credentialing Excellence
Examination fee US $549 domestic; international candidates add $100

Three consequences follow directly from that table, and each changes how you should sit the exam.

One in six items does not count, and you cannot tell which. Twenty of the 120 items are unscored pretest items, dispersed and unmarked. There is no way to triage effort during the exam; every item has to be answered as though it counts, because from your seat it does.

150 minutes for 120 items is 75 seconds per item, with no break. That is a tighter per-item pace than the CPHQ allows, and the handbook explicitly forbids breaks in both delivery modes. Under live remote proctoring the handbook also permits no scratch paper at all — which matters, because the outline contains genuinely quantitative content (statistical process control, control charts, measure design) that many candidates are used to working out on paper.

The pass mark is a standard, not a rank. CBPPS scores criterion-referenced: there is no curve, and your result is compared against the criterion of acceptable practice for a qualified patient safety professional, not against other candidates. Note also what the handbook does not publish: unlike some certifying bodies it gives no scaled score range and no numeric passing score. It publishes the method (Angoff plus equating) and not the number. Any page quoting you a specific CPPS passing score is not quoting the handbook.

The four content domains and their item counts

The content outline publishes item counts rather than percentages. Because the exam scores exactly 100 items, each published count is simultaneously the item count and the percentage weight — an unusually clean blueprint to study against.

# Domain (as published) Scored items Share of the scored exam
1 Culture 20 20%
2 Systems Thinking, Human Factors Engineering, and Design 20 20%
3 Safety Risks and Responses 35 35%
4 Performance Measurement, Analysis, Improvement and Monitoring 25 25%
Total 100 100%

The counts are CBPPS’s; that they sum exactly to 100 is a useful check that you are reading a complete and current outline rather than a partial reproduction.

The distribution is the finding. Safety Risks and Responses alone is 35 items. Add Performance Measurement, Analysis, Improvement and Monitoring and the two operational domains are 60 of 100 scored items. Culture — the domain most people assume dominates a patient safety credential, and the one most review material leads with — is 20. Domain 3 is also the only domain subdivided into four sub-areas (A to D) rather than two or three, which is consistent with its weight.

A study plan weighted by intuition about what “patient safety” means as a subject will be badly mis-weighted against the actual blueprint. The exam is built around identifying risk, recognising harm, and measuring whether a response worked.

What sits inside each domain

1. Culture — 20 items

Two sub-areas. Culture of Safety: organisation culture (the outline names just, non-hierarchical and psychological safety as examples); organisational infrastructure and requirements; safety climate and healthy work environment; communication and collaboration; learning culture; event response. Leadership and Outreach: at organisational, community/group, and individual/team levels.

Note that “event response” is filed under Culture, not under Safety Risks and Responses. That placement is deliberate and it is the exam’s view of the subject: how an organisation responds to an individual event is a cultural property before it is a procedural one, which is exactly the premise of a just culture algorithm.

2. Systems Thinking, Human Factors Engineering, and Design — 20 items

Three sub-areas. Systems Thinking: systems thinking models and frameworks — the outline names SEIPS as a model example and Safety I & II and High Reliability as framework examples; system complexity; systems approaches and principles. Human Factors Engineering: cognitive bias; system constraints and barriers; human factors and ergonomics; human capacity. Design: usability and functionality; workflow; resources including supplies and cost/benefit; technology, equipment and environment.

Those three named frameworks are the only models the entire outline commits to by name, and they should be taken literally. SEIPS, the Safety-I/Safety-II distinction and high reliability theory are the vocabulary the item writers were working from. The design sub-area also runs directly parallel to the regulatory-side treatment of the same discipline in FDA’s human factors and usability engineering guidance, which is where the same principles become a device submission requirement.

3. Safety Risks and Responses — 35 items

The largest domain, and the only one with four sub-areas.

A. Risk Assessment: escalations, reporting systems and communication methodologies; severity of incident; process and data analysis; transitions of care; environmental hazards; settings and care location; work environment and psychological safety; sociodemographic and population-specific stratification and assessment.

B. Risk and Harm Recognition: diagnosis; medication management and use process; interventions, surgery, diagnostic and therapeutic procedures; patient deterioration; health care acquired conditions and infections; inequities (sociodemographic, population, condition-specific and workforce); physical and non-physical violence and incivility; over- and under-treatment and omissions; emergency preparedness.

C. Barriers to Safety: human and financial resources; supplies and shortages; technological factors including interoperability; inequities in care (access, language, technology, health literacy); care fragmentation and transitions; extra-organizational challenges such as pandemics, regulations and policies.

D. Patient and Workplace Safety Responses: protocols and checklists; safety systems (the outline names rapid response, proactive, environmental and EHR); risk management; peer and team support including safety huddles, debriefings and de-escalation; communication and resolution programs.

Two entries in that list are worth pausing on. “Health care acquired conditions and infections” is the point where the patient safety officer’s remit overlaps the infection preventionist’s, and the surveillance definitions are shared. And “severity of incident” plus “escalations and reporting systems” is where the examinable content meets a real regulatory obligation: what constitutes a sentinel event and what must be escalated is defined externally, not by the organisation.

4. Performance Measurement, Analysis, Improvement and Monitoring — 25 items

Three sub-areas. Measurement: process mapping; process, outcome and balance measurement design; data collection and analysis; data visualization. Review and Analysis: analysis tools; analysis and review process for risks, events and hazards; approaches to proactive and reactive review; barriers to review and analysis. Improvement and Sustainability: improvement models; design, selection and implementation; communication and education; evaluation of event and process response; hierarchy of hazard reduction; change management; monitoring change.

“Balance measures” appearing beside process and outcome measures tells you which improvement tradition the blueprint sits in — the Model for Improvement and the PDSA cycle, where a balancing measure is a formal part of the measure set rather than an afterthought. And the hierarchy of hazard reduction is the single most testable concept in this domain, because it produces a defensible right answer: given a set of proposed corrective actions, the strongest is the one that removes reliance on individual vigilance.

The second axis: 91 tasks the outline does not map to domains

After the four domains, the content outline carries a separately headed section: “Secondary Classifications — Tasks”, a numbered list of 91 task statements. This is the structural feature that most distinguishes the CPPS blueprint, and it is routinely reproduced as though it were just more domain detail. It is not.

The list is flat and independent. No task is nested under a domain, and the document publishes no cross-walk between the two axes. Every item on the exam is classified on both — a content domain and a task — but because CBPPS publishes counts only for the domain axis, you cannot infer how many items test any individual task. Task 40 (“Perform root cause analysis”) could be one item or five; the outline does not say, and anyone telling you otherwise is guessing.

The practical reading: the domain counts tell you where to spend study time. The task list tells you what form the questions take. The tasks are written almost entirely in doing verbs — perform, evaluate, apply, differentiate, identify, monitor, advocate, facilitate — which is consistent with the handbook’s statement that most questions are job-related and test application and analysis rather than recall of facts.

The tasks that name a specific, procedurally-defined body of work

Most of the 91 tasks are stated generally. A minority name a specific named method or artefact, and those are the ones with a determinate right answer, which makes them the most likely to be examinable at the analysis level:

Task (as published, abbreviated) What it corresponds to in practice
15. Identify and apply principles of a fair and just culture The decision procedure that separates the individual from the event
67. Differentiate between unintended human error and behavioral choices as they apply to safety The same procedure stated as its operative test — this is a just culture algorithm question in all but name
40. Perform root cause analysis (RCA) Retrospective analysis of a serious event
41. Perform apparent cause analysis The lighter-weight, lower-severity counterpart — a genuinely distinct method that most review material omits entirely
37. Perform activities to identify gaps and risks (e.g., FMEA, walk-arounds) Prospective analysis, before an event occurs
42. Use a risk-based prioritization to rank severity hazards, risk, and events Severity and probability scoring, the gate that decides which events get an RCA at all
44. Identify the strongest interventions for effective and sustained improvement The hierarchy of hazard reduction, applied to a real corrective action list
45. Evaluate the degree to which proposed solutions match root causes The most common real-world RCA failure: a corrective action that does not address the cause it was written for
35. Promote compliance with requirements related to reporting serious occurrences and reportable events External reporting obligations, including sentinel event review and state reporting
58. Analyze safety data using statistical techniques (e.g., statistical process control) Control charts; distinguishing signal from noise
62. Use structure, process, outcome, and balancing measures to evaluate system performance Measure-set design
65. Identify normalized deviance (e.g., drift) in processes and systems Recognising that a workaround has become the standard method
66. Recognize rule violations as an indicator of potential system design or performance flaws The systems reading of a violation, rather than the disciplinary one
54. Recognize cybersecurity threats to patient safety A comparatively recent addition to a patient safety blueprint, and one worth noting
3–8. Identify, use, interpret and disseminate validated safety culture/climate surveys Six of the first eight tasks concern survey instruments, their interpretation and the dissemination of results

That last row is a weighting signal in itself. Tasks 3 through 8, plus task 2 and task 1, put the first eight entries of the list almost entirely on safety culture measurement — which, read against a 20-item Culture domain, suggests the Culture items are more measurement-shaped than rhetoric-shaped.

Two of these tasks touch a legal boundary the blueprint does not itself explain. Tasks 40, 41, 45 and 46 describe performing and sharing the findings of event analyses; what may be said, to whom, and under what protection is determined by the patient safety organization work-product privilege rather than by the analysis method. And task 46 (“share findings and action items from safety reviews with appropriate parties”) is the point at which the quality department’s event review and the clinician-facing morbidity and mortality conference become two different disclosure channels with two different protections.

Workforce harm is examinable content, not context

Task 2 of the outline reads: “Address patient and workforce safety through a unified strategy to eliminate harm.” That framing is carried consistently through the rest of the document, and it is the clearest scope difference between this credential and a general healthcare quality one.

Counting the published task list — this arithmetic is performed here and is not published by CBPPS — at least eight of the 91 tasks concern harm to the workforce rather than to patients: task 2 (unified strategy), 21 (advocate for a healthy work environment), 22 (assess workforce safety and plan to prevent physical, non-physical and psychological harm), 23 (contributing factors to harm for patients, care partners and visitors), 24 (de-escalation training), 38 (support for staff affected by safety-related adverse events), 78 (occupational health hazards affecting the workforce), and 86 (a systems approach to disruptive workplace behaviors). On the domain axis, workforce harm appears again in 3.A.7 (work environment and psychological safety), 3.B.6 (workforce inequities) and 3.B.7 (physical and non-physical violence and incivility).

Two practical implications. First, a candidate preparing only on patient-harm content is under-preparing for roughly a tenth of the task axis. Second, this is the credential that treats workplace violence prevention, second-victim support and psychological safety as core examinable competence — which is why a safety officer whose remit includes workforce harm will find the CPPS blueprint fits the job better than a quality blueprint does.

Eligibility: what CBPPS actually requires, and what it does not

The published requirement has two parts. A candidate must have patient safety practices as an integral component of current or future professional responsibilities, and must meet one of two education-plus-experience routes:

Route Education Experience
A Baccalaureate degree or higher 3 years in a health care setting, or with a provider of services to the health care industry — explicitly including time spent in clinical rotations and residency programmes
B Associate degree or equivalent 5 years in a health care setting, or with a provider of services to the health care industry — including time spent in clinical rotations

Read that experience wording carefully, because it is widely misreported. The requirement is experience in a health care setting. It is not three years of patient safety experience, and it is not three years in a patient safety role. A pharmacist, a clinical engineer, a health IT analyst or a vendor-side quality specialist accrues qualifying experience simply by working; the patient-safety condition is carried entirely by the separate “integral component of current or future professional responsibilities” clause — and that clause explicitly admits future responsibilities, so someone moving into a safety role rather than already holding one is eligible on the face of the requirement.

Three further points the published requirement makes plain:

  • No clinical licence is required. CBPPS names non-clinical health care workers and executives among expected candidates, and the eligibility routes reference degrees, not licensure.
  • Residency and clinical rotations count toward the experience requirement. This is stated in the requirement itself, not a concession — it materially shortens the route for a physician candidate.
  • Eligibility is attested, then audited. CBPPS randomly audits a limited number of applications each year, and selected candidates must produce documentation of their education and experience. There is no verification step for everyone else at application time, which is precisely why the attestation is worth reading accurately before you make it.

On retakes, the handbook is specific: a 30-day wait between attempts, a maximum of three attempts in a one-year period, and a one-year wait after a third failure. Each attempt requires a new application and the full fee.

CPPS or CPHQ: the scope difference, stated structurally

This is the comparison most safety officers are actually making, and it is better settled on blueprint structure than on prestige. The CPHQ’s own examination structure — its seven content categories, their item counts, and the competency-framework domain that has no examinable category — is treated in full in the CPHQ certification guide. What follows is only the contrast.

Dimension CPPS CPHQ
Certifying body Certification Board for Professionals in Patient Safety (CBPPS); programme home at IHI Healthcare Quality Certification Commission, the certifying arm of NAHQ
Blueprint axes Two — 4 content domains crossed with 91 unmapped tasks One — 7 content categories with task areas nested inside them
Items presented / scored 120 / 100 140 / 125
Time 150 minutes (75 seconds per presented item) 3 hours (77 seconds per presented item)
Published passing score Method published (Angoff plus equating); no scaled range or pass number published Scaled 200–800, passing score 600
Experience prerequisite Yes — baccalaureate plus 3 years, or associate plus 5 years, of health care experience See the CPHQ guide; the frequently-quoted “2 years” line is item-difficulty calibration, not a prerequisite
Recertification 3-year cycle, 45 CE hours, or retest Different cycle and CE model — see the CPHQ guide
Centre of gravity Risk identification, harm recognition, event analysis and response; workforce harm treated as core content Improvement method and health data analytics; regulatory and accreditation is the smallest category

The honest way to read that table: these are not competing general credentials at different quality levels. They are differently-scoped instruments.

The CPPS blueprint spends 35 of 100 items on identifying, recognising and responding to risk and harm, and treats workforce harm as examinable content. The CPHQ blueprint spends its two largest categories on performance and process improvement and on health data analytics, with patient safety as one category among seven. If your daily work is event intake, severity triage, RCA and FMEA facilitation, disclosure and workforce-harm prevention, the CPPS blueprint is a description of your job. If your daily work is improvement project portfolios, measure development, dashboards, statistical analysis and QAPI documentation, the CPHQ blueprint is.

Two practical notes rather than advice. Many practitioners hold both, and the CPPS handbook’s own certificant testimonials show post-nominals combining CPPS with CPHQ, CPHRM and CPXP. And there is now a third, narrower CBPPS credential — the Certified Professional in Human Factors in Healthcare (CPHFH) — which carves out the human factors territory that sits inside CPPS domain 2.

Recertification

Published in the November 2024 handbook:

  • Cycle: 3 years.
  • Requirement: 45 continuing education hours in total, or successful retest.
  • What counts: the handbook states that all CE following the CPPS content outline is accepted, and names education programmes, self-study, CPPS item writing, and academic coursework among the options.
  • Recertification application fee: $225, with an additional international fee.

Item writing counting toward recertification is worth noting: it means a certificant can maintain the credential partly by contributing to the instrument that awards it, which is the normal mechanism by which an NCCA-accredited exam keeps its item bank current with practice. There is a separate CPPS Recertification Handbook; the candidate handbook is not the controlling document for renewal.

What the published outline does not tell you

Stated plainly, because the gaps matter as much as the content:

  • No task-level item counts. The 91 tasks carry no weights. Any claimed distribution across them is invention.
  • No published numeric passing score and no scaled score range. The handbook publishes the standard-setting method only.
  • No published pass rate. CBPPS states that because review-course participation is self-selected, it does not report comparative pass rates.
  • No sub-area item counts. Within domain 3’s 35 items, nothing indicates how the four sub-areas divide them.
  • The resource list is background, not a syllabus. CBPPS describes it as material that was referred to and served as background during exam development, and states plainly that it does not endorse preparation resources and that the optional practice exam is a diagnostic tool rather than a study guide.

Frequently asked questions

Do I need to already work in patient safety to sit the CPPS?

No. The published eligibility requires that patient safety practices be an integral component of your current or future professional responsibilities, plus a degree and general health care experience — a baccalaureate plus 3 years, or an associate degree plus 5 years. The experience does not have to be patient safety experience.

How many questions are on the CPPS exam and how long is it?

120 questions presented, of which 100 are scored and 20 are unmarked pretest items, in 150 minutes with no breaks.

What is the CPPS passing score?

CBPPS does not publish one. The handbook publishes the method — a criterion-referenced standard set by the Angoff method, with equating across forms — and no scaled range or cut score. Treat any specific number you see quoted as unsourced.

What are the four CPPS domains and their weights?

Culture (20 items), Systems Thinking / Human Factors Engineering / Design (20), Safety Risks and Responses (35), and Performance Measurement, Analysis, Improvement and Monitoring (25). Because exactly 100 items are scored, those counts are also the percentage weights.

Is CPPS harder than CPHQ?

They are not on a common scale, so the question has no answer. Both are criterion-referenced against their own standard of minimally acceptable practice in different scopes. The useful question is which blueprint describes your job — see the comparison table above and the CPHQ certification guide.

Does CPPS require a clinical licence?

No. The eligibility routes reference degrees and health care experience, and CBPPS names non-clinical health care workers and executives among the expected candidate population.

How is the CPPS credential maintained?

A 3-year recertification cycle requiring 45 CE hours that follow the CPPS content outline, or a successful retest. CPPS item writing is among the accepted CE activities.

What happens if I fail?

A 30-day wait before retesting, a maximum of three attempts in a one-year period, and a one-year wait after a third unsuccessful attempt. Each attempt requires a new application and the full fee.

Where this sits

The CPPS blueprint is, read carefully, a published description of what a patient safety professional is expected to be able to do — which makes it useful well beyond exam preparation. Several of the tasks it names are treated in full elsewhere on this site: the just culture algorithm behind tasks 15 and 67, the sentinel event definitions behind escalation and external reporting, the PSO work-product privilege that governs what an event analysis can say and where, the morbidity and mortality conference as the clinician-facing counterpart to quality-department review, the National Patient Safety Goals a surveyor will judge safety activity against, and the Model for Improvement that supplies domain 4’s measure vocabulary. The wider map is on the patient safety pillar.

Sources

  • CBPPS, CPPS Examination Content Outline, published September 2024 (© 2024 Certified Professional in Patient Safety) — linked from ihi.org/learn/certifications/cpps/examination.
  • CBPPS / PSI Services, Certified Professional in Patient Safety Candidate Handbook, November 2024, rev. 11/15/2024.
  • IHI, CPPS programme overview and CPPS examination pages, retrieved 26 August 2026.

Every figure above is reproduced from those two documents as published on the retrieval date, except the two places where arithmetic performed here is labelled as such (the percentage column, which is trivially equal to the item counts, and the count of workforce-related tasks). Editions change; verify against the current handbook before applying.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.