Saltar al contenido principal

Lamentablemente no somos totalmente compatibles con su navegador. Si tiene la opción, actualice a una versión más reciente o utilice Mozilla Firefox, Microsoft Edge, Google Chrome o Safari 14 o posterior. Si no puede y necesita ayuda, envíenos sus comentarios.

Elsevier
Publique con nosotros

A layered defense framework for assessment integrity

HESI’s exam security framework operates across four domains: the testing environment, access and identity controls, content protection, and pre- and post-exam online monitoring.

Multi-ethnic group of nursing students in class

The exam security threat landscape

The past decade has brought increasingly sophisticated threats to standardized assessments. Two patterns in particular stand out for their impact on exam integrity and score validity.

Organized content sharing Students increasingly use private messaging platforms, paid online services, social media, and more to circulate and purchase reconstructed or compromised exam questions and answers. The distributed and encrypted nature of these channels often makes detection and source identification difficult and take down notices only partially effective. Proxy and remote-assistance testing The shift toward remote assessment created opportunities for students to use secondary devices to photograph screens, receive coached answers in real time, or permit a third party to complete the exam on their behalf via remote desktop software.

The Swiss cheese model applied to assessment security

No single control is foolproof. A secure browser can be circumvented by a phone camera. A proctor can be distracted. An item can leak. The Swiss cheese model, borrowed from aviation and healthcare risk management, holds that layering multiple imperfect defenses ensures that the “holes” in any one layer are covered by the others.

compliance and security

HESI's security framework spans four domains, each reinforcing the others.

1. The testing environment

Elsevier Secure Browser (ESB) The Elsevier Secure Browser provides the primary technical control over the HESI test environment. It functions at the operating-system level, locking down browsers, and restricting what students can access or execute during an exam session.

Live proctoring Live proctoring is required for all HESI exams. Elsevier’s published best practices establish a structured proctoring protocol organized around three imperatives: control the room, control the machines, and close the loop.

2. Real-time access controls

Before an exam session begins, students must enter a virtual waiting room where a live proctor validates each student's identity and authorizes entry. Only after authorization is granted, a unique single-use access code is generated and delivered to that student — preventing unauthorized access even if login credentials are shared. Throughout the exam, proctors monitor a live dashboard that tracks student progress and flags unusual behavior in real time.

3. Content architecture: randomization and versioning

HESI reduces content exposure risk through several content controls:

  • Double-randomized exams where both the question order and answer-choices order are randomized independently for each test-taker

  • Parallel exams are available for nearly all HESI RN and PN exams, allowing for student exam retesting and rotation of versions across cohorts

  • Active content rotation replaces a substantial portion of exam items multiple times a year, reducing the likelihood that students encounter the same content across sittings.

  • A dedicated item pipeline continuously develops, pilots, and evaluates new content across all exam areas, keeping the item pool ahead of exposure risk.

4. Pre- and post-exam online monitoring

The HESI Test Security Team monitors the internet for unauthorized postings of, or claims about, HESI exam content. If and when content is identified, the team:

  • Initiates a formal investigation

  • Issues takedown notices to hosting platforms

  • Works with legal counsel and third-party vendors to pursue removal of unauthorized content

  • Adjusts exam content when the scope of exposure warrants action

New enhancements

  • Student Watermarking (now on every question)

  • Enhanced Content Rotation (40% of exit exam items, 3× per year)

  • Expanded Content Protection Team (daily monitoring, enforcement)

  • Proctor & Student Accountability (oaths, certification, conduct gate)

  • AI-Powered Item Creation (faster pipeline to stay ahead of leaks)

HESI Exam security steps

Frequently asked questions