| Course | HIM 200 Introduction to Health Information Technology |
|---|---|
| Module | Module 6 |
| Paper type | undergraduate paper on health information privacy, security and breaches |
| Length | About 1,070 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 200 Module 6
Three Hours in the Wrong Hands: Privacy, Security and a Phishing Incident at Brennan County
[Student Name]
Southern New Hampshire University
HIM 200: Introduction to Health Information Technology
Module Six Short Paper
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Three Hours in the Wrong Hands: Privacy, Security and a Phishing Incident at Brennan County
Last spring, a scheduler at Brennan County Medical Center opened a message dressed up as a note from hospital payroll, asking staff to confirm direct deposit details. The scheduler clicked the link and entered a password. For about three hours, until the information technology team noticed unusual activity, an outsider could read the scheduler's email, which contained appointment lists for 212 patients. This paper uses that incident to explain the rules that protect health information, the national threat picture and the safeguards that reduce risk.
Privacy and Security Are Different
HIPAA's Privacy Rule sets the terms for when a hospital may share a patient's information and with whom, and it lets patients view, copy and ask to correct their own records. It applies whether information is on paper, spoken or electronic. The Security Rule, by contrast, covers only data held electronically, and it obliges hospitals and other covered organizations to guard their confidentiality, integrity and availability through administrative, physical and technical safeguards. The phishing incident was a security failure that created a possible privacy breach.
The Three Kinds of Safeguards
Administrative safeguards include risk analysis, security training, access policies and incident response plans. Physical safeguards protect facilities and devices, such as locked server rooms and workstation placement. Technical safeguards include unique user logins, audit logs, encryption and automatic logoff. The Security Rule allows flexibility based on an organization's size and risks, but it requires a documented risk analysis, which Brennan County had last updated four years before the incident.
Was It a Breach?
When protected information that was not encrypted reaches someone who should not have it, federal rules make Brennan County prove the event harmless or else tell the patients. The assessment asks four questions: how sensitive and identifiable the data were, what kind of person or group received them, whether anyone truly opened or took the data and how well the hospital contained the damage. Brennan County's forensic review could not rule out that the attacker viewed the appointment lists, which included names, dates and visit types. The privacy officer concluded notification was required.
What Notification Required
Because fewer than 500 people were affected, Brennan County had to mail a letter to each of the 212 patients promptly, and in no case later than two months after learning of the incident, and add the event to the yearly small-breach log it files with federal regulators. Larger incidents, those touching at least 500 people in one state, bring extra duties: local news outlets must be told, the federal report cannot wait for year end and the incident appears on a public federal list. Each letter described the phishing email, listed the appointment details exposed and offered a phone line for questions.
The National Picture
Brennan County's incident was small by national standards. McCoy and Perlis (2018) examined breaches reported to federal regulators from 2010 through 2017 and counted 2,149 breaches affecting about 176 million records, with hacking and information technology incidents growing as a share over time. Kruse et al. (2017) reviewed cybersecurity threats in healthcare and concluded that the sector lags others in protecting data, with outdated systems and limited security investment among the vulnerabilities.
Ransomware
The most disruptive threat is ransomware, which encrypts systems until a payment is made. Neprash et al. (2022) counted yearly ransomware hits on American hospitals and clinics rising from 43 to 91 between 2016 and 2021, and the 374 attacks over that period exposed the information of nearly 42 million patients. Harm can spread beyond the target. Dameff et al. (2023) studied two emergency departments near a health system hit by a month-long attack and found that they saw higher patient volumes, including more stroke-related cases, as patients were diverted to them.
People Are the Front Door
Most attacks begin with a person. Gordon et al. (2019) analyzed simulated phishing campaigns at six U.S. health care institutions and found that about one in seven emails was clicked, while repeated campaigns were associated with lower click rates. Brennan County ran its first simulation after the incident: 17% of staff clicked. The finding reinforced that training is not a one-time event but a routine that must be repeated.
Privacy Threats From Inside
Not every privacy failure comes from outside. Employees sometimes look at records they have no job reason to see, such as a neighbor's or a coworker's chart. The Privacy Rule's minimum necessary standard limits access to what each role requires, and audit logs record every chart opened. Brennan County's HIM department reviews a random sample of access logs monthly and investigates alerts when staff open charts of patients with the same last name or address.
Layered Safeguards for Brennan County
No single safeguard stops every attack, so protection must be layered. Table 1 lists the steps the hospital adopted or planned after the incident.
Table 1. Safeguards Adopted After the Incident
| Safeguard type | Measure | Purpose |
|---|---|---|
| Technical | Multifactor authentication for email and remote access | Stolen password alone no longer opens account |
| Technical | External email banner and link scanning | Warn staff about outside messages |
| Administrative | Quarterly phishing simulations with brief training | Build habits; measure progress |
| Administrative | Updated risk analysis and incident response plan | Meet Security Rule; speed response |
| Administrative | Stop emailing patient lists; use secure scheduling reports | Reduce data exposed in mailboxes |
| Physical | Offline backups stored separately | Restore systems after ransomware |
Note. Measures approved by the hospital's security committee.
The HIM Role
HIM professionals sit at the center of privacy work. At Brennan County, the privacy officer is the HIM director, who led the breach risk assessment and notification letters. HIM staff apply the minimum necessary standard in release of information, verify requesters' identity and authority, conduct access audits and educate staff on privacy. They also maintain the accounting of disclosures that patients may request.
Measuring Security Culture
Three measures will show whether safeguards are working: the phishing simulation click rate, targeted to fall below 5% within a year; the share of staff completing annual privacy and security training; and the number of confirmed inappropriate access cases found in audits. Reporting these to the board keeps security visible as a patient safety issue.
Conclusion
A single click exposed 212 patients' appointment details at Brennan County, a small incident beside the huge breaches and ransomware attacks reported nationally. The HIPAA rules define what must be protected and when patients must be told, but protection depends on layered safeguards, repeated training and vigilant HIM oversight of access and disclosure.
References
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10. https://doi.org/10.3233/THC-161263
McCoy, T. H., & Perlis, R. H. (2018). Temporal trends and characteristics of reportable health data breaches, 2010-2017. JAMA, 320(12), 1282-1284. https://doi.org/10.1001/jama.2018.9222
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
What the HIM 200 Module 6 instructions ask for
In HIM 200's privacy and security module, students usually explain how federal rules protect health information, what threats organizations face and which safeguards reduce risk. A paper near 1,200 words, backed by four journal studies or more in APA 7, fits most versions. Keep the Privacy, Security and Breach Notification Rules distinct and accurate, and apply them to a specific incident or scenario. Use research to describe current threats, recommend layered safeguards across administrative, physical and technical categories and explain where HIM fits. HIM 200 graders notice clean headings in HIM 200 papers. HIM 200 names and dates need checking before HIM 200 submission. HIM 200 prompts vary by term, so recheck HIM 200 directions.
How this HIM 200 Module 6 privacy and security short paper example is built
A scheduler's phishing click exposes 212 patients' appointment details for three hours. The paper distinguishes the Privacy and Security Rules, explains three kinds of safeguards and applies the four-factor breach risk assessment and notification requirements. McCoy and Perlis's breach counts, Kruse and colleagues' review, Neprash and colleagues' ransomware trends and Dameff and colleagues' regional effects describe the threat, while Gordon and colleagues' phishing data explain the human factor. A safeguards table, the HIM role and security measures follow. HIM 200 students can reuse this structure for HIM 200 work. HIM 200 claims here trace to cited HIM 200 sources. HIM 200 readers can adapt each section to HIM 200 data.
Where the HIM 200 Module 6 rubric puts the points
Privacy and security papers in HIM 200 are commonly assessed on accurate description of HIPAA rules, correct application to a scenario, use of research on threats, completeness of safeguards, attention to HIM responsibilities and APA 7 mechanics. The best papers apply the breach risk assessment step by step, cite specific figures on breaches and phishing and recommend safeguards in all three categories. Measurable targets, such as a lower phishing click rate, show that the writer understands security as an ongoing program. HIM 200 marks favor careful formatting across HIM 200 sections. HIM 200 citations keep every HIM 200 argument credible. HIM 200 instructors weigh evidence heavily in HIM 200 grading.
HIM 200 Module 6 help: the mistakes that cost points
Privacy papers lose points when they treat the Privacy and Security Rules as the same, misstate notification deadlines, describe threats vaguely or recommend only technology. Another common gap is ignoring insider access and HIM audits. Keep the rules distinct, apply them to a case, use current research, layer safeguards and define HIM's role. If your prompt focuses on a specific topic, such as substance use disorder records or patient right of access, send it with your HIM 200 notes so the paper covers it. HIM 200 drafts start well from a HIM 200 outline. HIM 200 feedback already received guides HIM 200 revisions. HIM 200 rubrics posted in Brightspace clarify HIM 200 expectations.
Get HIM 200 Module 6 written to your instructions
Forward the HIM 200 Module 6 instructions with a short description of your incident or case. Expect a paper that lays out the HIPAA rules correctly, apply the breach risk assessment, describe current threats with research and recommend layered safeguards with HIM's role, within 24 to 48 hours, free the first time. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 200 papers and related BS Health Information Management samples
- HIM 200 Module 1 Discussion: Why Health Information Technology Matters: From Paper to Digital
- HIM 200 Module 2 EHR Adoption Short Paper: How the HITECH Act Drove Electronic Record Adoption
- HIM 200 Module 3 Interoperability Short Paper: Health Information Exchange, FHIR and Information Blocking
- HIM 200 Module 4 Project One: Evaluating a Hospital's Patient Portal
- HIM 200 Module 5 Usability and Safety Short Paper: When Record Design Contributes to Harm
HIM 200 Module 6 questions, answered
Where can I find a free HIM 200 Module 6 Privacy and Security Short Paper sample?
Read the complete HIM 200 Module 6 paper on this page: a phishing incident used to explain HIPAA rules, breach trends and layered safeguards.
What is the difference between the HIPAA Privacy and Security Rules?
The Privacy Rule governs use and disclosure of health information in any form; the Security Rule protects electronic information with safeguards.
When must a HIPAA breach be reported?
Affected individuals must be notified within 60 days of discovery; breaches of 500 or more also require media notice and prompt federal reporting.
How common are phishing clicks in healthcare?
Gordon and colleagues found about one in seven simulated phishing emails clicked at six health care institutions.
What does HIM do in privacy protection?
Applies minimum necessary in release of information, verifies requesters, audits access, maintains disclosure accounting and educates staff.