15.4 IT Strategic Plans and Departmental Objectives
Key Takeaways
- Task A.4 is develop and implement an IT strategic plan and departmental objectives that align with and support organizational strategies and goals.
- The IT plan is a translation layer and cascade—not a substitute for the organizational plan and not a project list with a new cover.
- Departmental objectives need owners, measures, and a quoted organizational aim. Uptime-only or “complete the upgrade” objectives fail the cascade.
- The portfolio (run / grow / transform; keep, kill, combine) is how the plan is implemented; capacity is a strategic constraint.
- An EHR upgrade may sit in the portfolio as a program if it enables a named capability the aim needs. The upgrade is still not the strategy.
15.4 IT Strategic Plans and Departmental Objectives
Quick Answer: Domain 4 task A.4 is develop and implement an IT strategic plan and departmental objectives that align with and support organizational strategies and goals. The IT plan is a cascade, not a second government. An EHR upgrade may be a portfolio program. It is still not the strategy.
A.1 contributed to the organizational plan. A.2 read the environment. A.3 forecast capacity, skills, and data against business needs. A.4 is where HIT writes its multi-year plan and this year’s departmental objectives so the rest of the organization can see how information and systems will support the aims—and what will not be done.
Cascade, do not compete
The IT strategic plan is a translation layer:
Organizational aim → IT strategic theme that quotes the aim → departmental objective with owner and measure → portfolio item → benefit residual
If you cannot walk that chain backward from a project to a numbered organizational goal, the item does not belong in the plan as “strategic.” It may still belong as run-the-business (keep the lights on, replace end-of-life, meet a binding regulation). Honesty about run versus grow versus transform is part of A.4, not a branding exercise.
| IT-plan element | What “good” looks like | What fails A.4 |
|---|---|---|
| Principles | Single enterprise identity; EHR as system of record unless a governed exception; cloud and security patterns already decided | A new principle invented to justify last week’s purchase |
| Current state versus aims | Gaps against organizational aims and the A.3 forecast | Gaps against a vendor roadmap or a conference demo |
| Multi-year themes | “Instrument and improve board access KPI” quoting aim 2.3 | “Digital transformation” with no aim ID |
| Departmental objectives | Owner, date window, measure, quoted aim | “Complete the EHR upgrade”; “achieve 99.9% uptime” as the only objective |
| Portfolio | Run / grow / transform; keep, kill, combine; capacity envelope | A project list in priority-number cosplay |
| Implementation cadence | Quarterly cascade review with operations owners | A slide filed after the retreat |
The organizational plan remains the parent. If operations amends an aim, the IT plan amends. If HIT wants work that is absent from the parent, that is an A.1 governance request—not a stealth line in the IT appendix.
Departmental objectives are not slogans
A.4 names departmental objectives for a reason. Themes without yearly, owned objectives are posters.
Good (access aim 2.3): “By Q3, ambulatory operations owns a weekly new-patient-wait measure from scheduling plus EHR, with a published match rule and residual, and HIT will deliver the feed and the dual-search registration change the A.3 forecast named.”
Good (harm aim 1.1): “By Q4, close the scan-compliance gap on two high-risk units to the rate quality already specified, with nursing as owner and HIT supplying device reliability and exception workflow.”
Bad: “Complete the EHR upgrade.” That is a milestone, not an objective that supports an organizational goal.
Bad: “Achieve 99.9% uptime.” Reliability can be a run objective. It cannot be the only departmental expression of a strategy about access, harm, or equity.
Bad: “Become a digital workplace.” No owner, no measure, no aim.
Write objectives that operations can recognize as their aim with HIT as the enabling department. If the only audience who understands the objective is the technical steering group, you have not cascaded—you have translated the strategy into jargon and called it alignment.
Objectives should absorb the A.3 forecast: the skills you will hire or contract, the identity work, the site network, the BAA load. An objective that assumes infinite analyst capacity is a wish list with a date.
Portfolio is how you implement the plan
“Develop and implement” is official language. Implementation of an IT strategic plan is not a go-live. It is running a portfolio against the cascade:
- Intake starts with the organizational objective identifier and the A.2 environment note (who will veto, which driver is live).
- Prioritize against written aims and against capacity. A yes is a no to something else; show the displacement.
- Classify run (keep current services safe and supported), grow (scale a current aim), transform (new capability the plan named).
- Review quarterly: keep, kill, combine, or send back to strategy governance.
- Name benefit owners in operations. HIT can own a feed; it cannot own wait time.
An EHR upgrade belongs here as a program when the plan can name the capability the aim needs—new ambulatory site support the current version cannot carry, a safety requirement, a certification date, a security debt that blocks the risk appetite the board already set. The upgrade still does not become the strategy, the theme, or the only departmental objective. If the upgrade exists only to “stay current,” it is run-the-business capital, and it must compete honestly with other run items.
Cloud migrations, data platforms, and “AI” follow the same rule. They enter the portfolio when A.3 linked them to a business need and A.1 still has a parent aim. Otherwise they are sidecar government.
Implement means refresh, not laminate
A plan that cannot change is decoration. Implementation includes:
- An annual refresh after the organizational plan moves
- Quarterly portfolio reviews with finance, quality, and clinical operations—not only HIT
- A public list of what was killed and why (capacity, environment, or lost parent aim)
- Departmental huddles that track objectives, not only tickets
- Architecture and security as constraints that protect the plan, not as a veto theater that never appears until design
HIMSS does not publish a required CPHIMS IT-plan template, theme count, or scoring sheet. Use the organization’s governance. The exam tests whether the plan supports organizational strategies and goals, whether objectives are real, and whether you can tell a project from a strategy.
Scenarios and exam traps
Scenario. The CIO publishes a three-year “digital strategic plan” that never cites the board’s access, harm, or clinic aims. Send it back to A.1. A.4 cannot start from a blank parent. Themes must quote organizational strategies and goals.
Scenario. Departmental objectives are “complete the EHR upgrade” and “99.9% uptime.” Rewrite. If the upgrade enables closed-loop meds on the harm aim, say that, with nursing as owner and a scan-compliance measure. Keep uptime as a run objective, not as the strategy costume.
Scenario. The portfolio has 40 “P1” projects. That is not implementation. Force keep/kill/combine against the capacity the A.3 forecast already said was binding. Show what a new yes displaces.
Scenario. After the retreat, the IT plan is laminated and filed. Nine months later a merger environment (A.2) changes the access aim. Implementation means a refresh and a kill list—not loyalty to last year’s slide.
Watch these traps:
- Writing an IT plan that competes with, rather than supports, the organizational plan.
- Treating an EHR upgrade as the strategy, the theme, or the only objective.
- Objectives with no owner, no measure, and no quoted aim.
- A numbered project list offered as a portfolio.
- Filing the plan and skipping quarterly keep/kill/combine.
- Inventing a HIMSS-required CPHIMS plan template or score.
A CIO publishes a three-year digital strategic plan that never cites the board’s access, harm, or clinic aims. What does task A.4 require?
Which departmental objective best implements an IT strategic plan that supports a written harm-reduction aim?
Where does an EHR upgrade belong in a professional A.4 IT strategic plan?