13.3 Implementation: Scope, Schedule, Budget, and Quality

Key Takeaways

  • Task C.4 is implementation under four constraints: scope, schedule, budget, and quality. You can trade among them; you cannot pretend a slipped date has no effect on testing or harm.
  • Quality is not leftover polish. Integrated testing, downtime rehearsal, identity, and medication-safety checks are the quality bar. Cutting them to hit a banner date is a C.4 fail.
  • Cutover strategy (big bang, phased, pilot, parallel, staggered by unit) is chosen for clinical risk and recoverability, not only for consultant cost.
  • Go-live is a mode of care: command center, extra staffing, reduced discretionary volume when needed, stop-the-line authority, and a back-out trigger written before first login.
  • Scope creep is a change, not a favor. Adding a module mid-build re-baselines schedule, budget, or quality—or it is refused.
Last updated: August 2026

13.3 Implementation: Scope, Schedule, Budget, and Quality

Quick Answer: Task C.4 is implementation while managing scope, schedule, budget, and quality. Those four move together. A printed go-live date that forces you to skip integrated testing is not “on time.” It is a quality failure with a calendar. Choose cutover for clinical risk, and treat go-live as a mode of care with a command center and a back-out.

Selection (C.1) and change/training design (C.2–C.3) do not finish the job. C.4 is the period when build, conversion, testing, training, and first productive use either stay inside the charter or silently become a different project. Classic project language called this the triple constraint (scope, time, cost). Healthcare implementation adds quality as a first-class constraint because a cheap, on-time, in-scope system that drops allergies is a failed implementation.

CPHIMS practice questionsPractice questions with detailed explanations

Four constraints, not three plus leftover polish

Write all four on the charter and on every status slide.

ConstraintWhat it means in HIT implementationTypical pressureIllegal-feeling but common “save”
ScopeIn/out list: sites, modules, interfaces, data converted, roles live on day one“Just add oncology,” “just add the other hospital”Silent expansion with the same date and staff
ScheduleMilestone dates: integrated test, training complete, dress rehearsal, cutoverBoard-promised date, contract penalty, fiscal yearCompress testing into the last weekend
BudgetCapital plus implementation services, overtime, backfill, devices, interfacesContingency already spentUnpaid superusers and deferred interfaces
QualitySafety, identity, downtime, conversion completeness, competency, defect bar“Good enough for Friday”Skip integrated, regression, or downtime drill

Rules the exam rewards:

  • If scope grows, re-baseline schedule, budget, or quality targets—or refuse the growth. “Just add it” is a C.2 change and a C.4 scope event.
  • If schedule is immovable (a data-center exit, a legal sunset), shrink scope or add budget (staff, dual running). Do not shrink quality on medication, identity, or downtime.
  • If budget is cut, name what leaves the release. Hidden cuts become production defects.
  • Quality gates are dates that can slip the go-live: failed integrated test, failed dress rehearsal, incomplete conversion audit, untrained night shift. A gate that cannot fail is decoration.

Crashing adds resources to shorten duration (more analysts, extra test cycles). Fast-tracking overlaps phases that were sequential (training while a few defects remain). Both raise risk. Fast-tracking a medication-safety defect into production is not clever scheduling.

Cutover strategies

Cutover is how you switch from the old way to the new way. The strategy is a clinical and operational design, not a vendor preference.

StrategyWhat happensWhen it can be honestTypical failure
Big bangMost users and sites switch in one windowSmall, tightly coupled system; interfaces cannot be split; organization can staff a true command centerEntire enterprise learns together with no rollback island
Phased / modularModules or functions go live over time (results, then orders, then BCMA)Dependencies allow a safe sequence; each phase has its own test and supportHalf-old, half-new workflow that drops orders
Staggered by unit or siteOne hospital, one service line, or one unit firstYou can staff elbow support and learn; interfaces and identity still work for the mixed state“Pilot” that is actually the busiest ED on a Monday
PilotA bounded population with kill criteriaExplicit success metrics and a stop rulePilot with no authority to stop
ParallelOld and new run together for a defined periodThroughput allows dual documentation or dual claims; reconciliation is staffedDual documentation until staff collapse; nobody compares the two

Choose by clinical coupling and recoverability. A laboratory analyzer that must share one patient identity with the EHR may force a tighter window. A consumer portal increment can phase. “Big bang is cheaper because we only pay consultants once” is a budget argument, not a safety argument. Write the back-out trigger (what defect or harm rate returns you to paper or the prior system) before first login.

Conversion is part of cutover: what historical data moves, what is archived, who audits a sample of allergies, meds, and problems, and what clinicians do when a migrated allergy is missing at 02:00. An un-audited conversion is a quality fail regardless of the strategy name.

Clinical safety during go-live

Go-live is a designed mode of care, closer to Chapter 12’s downtime thinking than to a software release party.

  1. Command center with clinical and technical authority in the same room (or a linked virtual room), not a help desk that pages an analyst at home.
  2. Stop-the-line. A named pair can halt a unit, freeze a function, or trigger back-out. Hierarchy that cannot stop a crashing BCMA is not a command structure.
  3. Staffing. Extra clinicians, superusers, and registrars. Reduce elective volume if the risk model says so. Do not run a full OR board on a first-ever EHR with half the usual nurses.
  4. Safety huddles. Frequent, short, and fed by tickets and unit reports—not only by green server dashboards.
  5. Known degraded modes. Which functions stay on paper, which orders are verbal-then-backload, how two identifiers still work.
  6. Communication that does not depend on the system you just turned off (overhead, radios, mass notification).
  7. Hypercare window with 24×7 coverage sized to the clinical day, then a written step-down—not a sudden “good luck.”

Harm during go-live is a quality signal, not noise to be trained through. A cluster of wrong-patient or missed-allergy events is a gate: fix, back out, or reduce scope. Celebrating “we are live” while the ED is on full paper is not C.4 success.

How to read a C.4 stem

  1. Name which constraint is being protected (usually the date or the champion’s extra module).
  2. Name which constraint is being silently sacrificed (usually quality or night-shift staffing).
  3. Prefer the answer that re-baselines in public or refuses the unsafe trade.
  4. If the stem is about cutover, pick the strategy that matches coupling and recoverability, not the cheapest consultant invoice.
  5. If the stem is about go-live chaos, pick command, stop-the-line, and back-out—not more banners.
Loading diagram...
C.4: an immovable date that eats the quality gate is not on-time delivery

Scenarios and exam traps

Scenario — testing as the slack. Integrated testing is still red on allergy and ADT. The banner is already printed. Sponsors say “train harder and go live; we will fix in hypercare.” C.4 says the quality gate failed. Slip the date or shrink scope (delay a non-safety module). Training cannot close a failed integrated path.

Scenario — free module. Mid-build, the CMO wants an extra oncology module “while the consultants are here.” Same date, same budget, same testers. That is scope creep. Open a change: extend time, add money, or put oncology in a later phase. Adding it silently steals quality from the original release.

Scenario — cheap big bang. A system with six hospitals and uneven interface readiness schedules one Friday cutover because the vendor discount expires. Several sites have not finished conversion audits. Stagger or pilot the ready site; do not buy a discount with six simultaneous first nights.

Scenario — go-live as an install. There is no command center, no stop-the-line, and the OR board is full. Tickets pile up in a general queue. Implementation quality includes the care model for the weekend, not only the code.

Watch these traps:

  1. Treating quality as optional polish after scope, time, and cost are locked.
  2. Cutting integrated, regression, or downtime tests to protect a banner.
  3. Silent scope growth.
  4. Choosing cutover only by consultant cost.
  5. Parallel operations with no one reconciling the two records.
  6. No back-out trigger, so “live” means “stuck.”
  7. Calling first login success while harm clusters are open.

Task C.4 is honest constraint management plus a clinically staffed cutover. Section 13.4 is what happens after the banners come down: operate, upgrade, and read the tickets as data.

Test Your Knowledge

Integrated testing is still failing allergy and ADT paths. The go-live banner is printed. Sponsors want to “train harder and fix in hypercare.” What is the CPHIMS-correct C.4 response?

A
B
C
D
Test Your Knowledge

A six-hospital system wants one Friday big-bang cutover because the vendor’s consultant discount expires. Two hospitals have not finished conversion audits. How should cutover be chosen?

A
B
C
D
Test Your Knowledge

Mid-build, the CMO asks to add an oncology module “while the consultants are on site,” keeping the same date, testers, and budget. What failed?

A
B
C
D