HIM 422 Module 4 Final Project Milestone Two Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 422 Module 4 Final Project Milestone Two sample measures what a major data breach cost, in dollars and in harms that no settlement repays. It is written for SNHU HIM 422 (HIM-422) and builds on the first milestone's summary, as BS Health Information Management coursework asks students to trace consequences before recommending fixes. The case remains the 2015 Anthem cyberattack, which exposed Social Security numbers and other identifiers for 78.8 million people. The milestone totals the public settlements with federal regulators, class action plaintiffs and state attorneys general, describes response and security costs, then turns to nonfinancial impacts on members, employer customers, staff and the organization's standing, drawing on research about what breached data enable, when breaches lead to lawsuits and how remediation affects health organizations.

CourseHIM 422 Ethical and Legal Considerations in Health Information Management
ModuleModule 4
Paper typeundergraduate milestone analyzing the impacts of a data breach
LengthAbout 1,040 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramBS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 422 Module 4

1

Final Project Milestone Two: What the Anthem Breach Cost, and What Money Could Not Repair

[Student Name]

Southern New Hampshire University

HIM 422: Ethical and Legal Considerations in Health Information Management

Final Project Milestone Two

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title separates measurable costs from harms that cannot be priced.
2

Final Project Milestone Two: What the Anthem Breach Cost, and What Money Could Not Repair

Milestone One described how attackers entered Anthem's network through a phishing email and left with identifying information on 78.8 million people. This milestone asks what followed. It separates financial impacts, which public records allow us to count at least in part, from nonfinancial impacts, which fall on people and relationships and are harder to measure but often last longer. Figures come from federal enforcement announcements, court records and press releases from state attorneys general.

What this page is doingThe introduction links to Milestone One and defines the two kinds of impact.
3

Regulatory Penalties

Federal enforcement came first. In October 2018, Anthem agreed with the Office for Civil Rights at HHS to pay $16 million and adopt a corrective action plan to settle potential HIPAA violations, then the largest HIPAA settlement in the agency's history. The agency's findings described failures that went to the heart of the Security Rule: no enterprise-wide risk analysis, inadequate review of information system activity, failure to identify and respond to the intrusion in time and insufficient controls to prevent unauthorized access. In 2020, a coalition of more than 40 state attorneys general reached a separate $39.5 million settlement with Anthem, which also required security commitments.

What this page is doingFederal and state enforcement outcomes are summarized with their findings.
4

Litigation

Consumers sued as well. Cases filed across the country were consolidated in federal court in California, and in 2018 the court approved a $115 million class settlement, at the time the largest ever for a data breach. The fund paid for additional credit monitoring, reimbursement of out-of-pocket losses and alternative cash payments for people who already had monitoring, and Anthem agreed to maintain specified security practices for several years.

Research helps explain why this case produced such a large settlement. Romanosky et al. (2014) examined data breach lawsuits and found that suits were more likely when breaches exposed more records and when individuals suffered financial harm, and less likely when the company offered free credit monitoring. Anthem did offer monitoring, but the scale of the breach and the exposure of Social Security numbers made litigation almost certain.

What this page is doingThe class action and the research on breach litigation are explained.
5

Response and Security Costs

Beyond penalties and settlements, Anthem paid for forensic investigation, legal counsel, notification letters to tens of millions of people, a dedicated call center, two years of identity protection services for everyone affected and later security improvements. Anthem did not publish a complete accounting of these costs, so this milestone does not estimate them. Table 1 summarizes the public figures that can be verified.

Table 1. Publicly Reported Financial Consequences of the Anthem Breach

ConsequenceYearAmount
HHS Office for Civil Rights resolution agreement2018$16,000,000
Consumer class action settlement2018$115,000,000
Multistate attorneys general settlement2020$39,500,000
Total public settlements$170,500,000
Investigation, notification, monitoring and security costs2015 onwardNot publicly itemized

Note. Compiled by the author from public announcements and court records.

What this page is doingTable 1 totals verifiable financial consequences.
6

Impacts on Members

For members, the most serious impact is lasting exposure. Jiang and Bai (2020) analyzed the types of information compromised in health data breaches and found that many exposed Social Security numbers and other details that enable financial identity theft, not only medical information. A credit card number can be canceled; a Social Security number and birth date remain valid for life. Two years of monitoring, however well intended, ended long before the stolen data lost their value. Members also bore the time and worry of freezing credit, watching accounts and responding to phishing attempts that used their real details to seem legitimate.

What this page is doingMember harm is explained through the kind of data taken.
7

Impacts on Employers, Staff and Trust

Employer groups that bought Anthem coverage had to answer their employees' questions and decide whether to stay with the insurer, a decision that rests on trust in an organization they cannot inspect. Anthem's own staff faced months of crisis work, and employees whose credentials were used in the attack faced scrutiny for actions that attackers had engineered. Choi et al. (2019) found that after hospitals experienced breaches, the security changes that followed were associated with slower delivery of time-sensitive cardiac care, a reminder that remediation carries operational costs of its own. For an insurer, similar friction appears in stricter access controls and new verification steps that members, providers and employees must navigate.

What this page is doingImpacts on employers, staff and operations are described with research.
8

Impacts on Other Blue Plans

The breach also reached people who had never chosen Anthem. Anthem's notices went also to people insured by independent Blue plans elsewhere, because their claims had been routed through Anthem when they were treated in its territory. Their own insurers had to field calls, explain why a company they had no contract with had held their data and decide whether to offer additional protection. For those plans, the impact was a loss of control: their members' trust depended on another company's security, and the shared processing arrangement that made nationwide coverage convenient also made one company's failure everyone's problem.

What this page is doingThe paper identifies harm to plans that shared data with Anthem.
9

Reputation and Oversight

The breach attached Anthem's name to the largest health data breach then on record, a fact repeated in news coverage and in every later discussion of health care cybersecurity. The corrective action plan and settlement commitments placed Anthem's security practices under outside monitoring for years. In 2022 the company changed its corporate name to Elevance Health, although the Anthem brand remains on its health plans, so the breach's association with the name has not disappeared.

What this page is doingReputational and oversight impacts are identified.
10

What the Impacts Mean for Hospitals

Although Anthem is an insurer, its experience matters to hospital health information departments like the one where I work. The regulatory findings behind the $16 million settlement, especially the absence of an enterprise-wide risk analysis and weak monitoring of system activity, are the same findings that appear in enforcement actions against hospitals. The litigation research suggests that the size of a breach and the type of data exposed drive legal exposure more than the organization's intentions. And the remediation research shows that security changes made in a hurry after a breach can slow care. A hospital that invests before a breach avoids both the penalties and the rushed fixes.

What this page is doingThe paper draws lessons for hospital health information departments.
11

Weighing the Impacts

The public settlements total $170.5 million, a large sum that is nonetheless a small share of the company's annual revenue, and the full cost of response and remediation is larger but unknown. The nonfinancial impacts are more lasting. The people harmed most, members whose permanent identifiers were taken, received the least lasting protection. This imbalance between who pays and who is harmed is the ethical center of the case and the starting point for Milestone Three.

What this page is doingThe paper compares financial and nonfinancial impacts and sets up Milestone Three.
12

References

Choi, S. J., Johnson, M. E., & Lehmann, C. U. (2019). Data breach remediation efforts and their implications for hospital quality. Health Services Research, 54(5), 971-980. https://doi.org/10.1111/1475-6773.13203

Jiang, J. X., & Bai, G. (2020). Types of information compromised in breaches of protected health information. Annals of Internal Medicine, 172(2), 159-160. https://doi.org/10.7326/M19-1759

Romanosky, S., Hoffman, D. A., & Acquisti, A. (2014). Empirical analysis of data breach litigation. Journal of Empirical Legal Studies, 11(1), 74-104. https://doi.org/10.1111/jels.12035

What the HIM 422 Module 4 instructions ask for

HIM 422 Final Project Milestone Two usually asks you to analyze the impacts of the breach you summarized in Milestone One, both financial and nonfinancial. A paper of three to five pages in APA 7 that uses credible sources, including enforcement announcements, court records and scholarly research, fits most versions. Identify penalties, settlements and response costs with dates and amounts, and say clearly when a figure is not public rather than inventing one. Then explain nonfinancial impacts on each major stakeholder group, such as patients or members, employers, staff and the organization's reputation and oversight. End by weighing the two kinds of impact against each other and connecting them to the recommendations you will write next.

How this HIM 422 Module 4 final project milestone two example is built

The milestone totals $170.5 million in public settlements from the Anthem breach: $16 million with the HHS Office for Civil Rights, a $115 million class action and $39.5 million with more than 40 state attorneys general, noting that response costs were never itemized. Romanosky and colleagues explain why a breach this size was sure to be litigated. Jiang and Bai show why exposed Social Security numbers create lifelong risk that two years of monitoring cannot cover, and Choi and colleagues show remediation's own costs. Employer trust, staff strain, the 2022 name change and years of oversight complete the picture before the impacts are weighed. Separate sections cover other Blue plans and the lessons hospitals can draw.

Where the HIM 422 Module 4 rubric puts the points

Impact milestones in HIM 422 tend to be graded on accurate financial figures with sources, thorough analysis of nonfinancial impacts across stakeholders, clear organization, use of research and APA 7 mechanics. Top papers separate verified amounts from unknown costs, explain the regulatory findings behind a penalty and connect impacts to the specific kind of data exposed. Graders also reward writers who notice imbalances, such as who pays and who is harmed, because those observations lead naturally into ethical recommendations. A table of verified figures makes the financial section easy to check and shows careful handling of sources, which the rubric often rewards directly. Clear headings for each stakeholder group help as well.

HIM 422 Module 4 help: the mistakes that cost points

Impact papers lose points when they list only fines, invent cost estimates without sources, treat all stakeholders as one group or skip the harms that cannot be priced. Papers also slip when the regulators' reasons for a penalty go unexplained. If your breach differs, such as a hospital ransomware attack that disrupted care or an insider who viewed celebrity records, send the case details with your Milestone One so the analysis carries forward accurately. Include any feedback from your instructor as well. A custom milestone can follow the same structure of penalties, litigation, response costs, stakeholder harms and a closing comparison used for this Anthem case.

Get HIM 422 Module 4 written to your instructions

Share the HIM 422 Milestone Two guidelines and your Milestone One summary. The milestone will total verified penalties and settlements, flag costs that are not public, analyze nonfinancial harms for each stakeholder and weigh the two, sent back within 24 to 48 hours with your first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 422 papers and related BS Health Information Management samples

HIM 422 Module 4 questions, answered

Where can I find a free HIM 422 Module 4 Final Project Milestone Two sample?

The complete HIM 422 Module 4 milestone is on this page: the Anthem breach's $170.5 million in settlements and the harms that carry no price.

How much did the Anthem breach cost in settlements?

Public settlements total $170.5 million: $16 million with HHS, a $115 million class action and $39.5 million with state attorneys general.

Why was the Anthem HIPAA settlement so large?

Regulators cited failures including no enterprise-wide risk analysis, weak activity review, slow detection and inadequate access controls, across 78.8 million records.

What nonfinancial impacts does a breach have?

Lasting identity theft risk, time and stress for affected people, lost trust among customers, strain on staff, reputational damage and years of oversight.

Why is a stolen Social Security number worse than a stolen card number?

A card can be canceled, but a Social Security number stays valid for life, so the risk continues long after monitoring ends.