| Course | HIM 422 Ethical and Legal Considerations in Health Information Management |
|---|---|
| Module | Module 6 |
| Paper type | undergraduate milestone on the ethics, law and recommended response to a breach |
| Length | About 1,040 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 422 Module 6
Final Project Milestone Three: What Anthem Owed, and What Should Change
[Student Name]
Southern New Hampshire University
HIM 422: Ethical and Legal Considerations in Health Information Management
Final Project Milestone Three
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Final Project Milestone Three: What Anthem Owed, and What Should Change
Earlier milestones showed that a single phishing message opened the door to Anthem's systems, that the intruders roamed unnoticed for months and that they carried off identifiers for 78.8 million people, and that the consequences included $170.5 million in public settlements and lasting harm to members. This milestone asks two further questions. What did the law and professional ethics require of Anthem? And what should Anthem, or any organization holding similar data, change? Legal considerations come first, then ethical ones, then recommendations.
Legal Considerations: The Security Rule
The federal findings map directly onto the HIPAA Security Rule. The rule makes an accurate and thorough risk analysis the foundation of every other safeguard, and regulators found that Anthem had not conducted one across the enterprise. The rule expects covered entities to review records of system activity such as logins and queries, and regulators found that review insufficient. It requires procedures to identify and respond to security incidents, and the attack ran for months before anyone noticed. It also requires technical controls that limit access to those who need it, and regulators found those controls inadequate. None of these duties requires perfect security. Each requires a reasonable, documented process, and the findings suggest that process was missing where it mattered most.
Legal Considerations: Negligence and State Law
The class action rested largely on negligence: a duty to protect members' data, a breach of that duty through inadequate security, and harm caused by the breach. Proving harm is often the hardest element in breach cases, because courts have disagreed about whether the risk of future identity theft is itself an injury. The exposure of Social Security numbers made harm easier to argue here. State laws added obligations of their own, including breach notification deadlines and consumer protection statutes, which is why more than 40 attorneys general could pursue a separate settlement. McCoy and Perlis (2018) showed that large hacking incidents at health plans came to dominate the number of breached records, which suggests regulators and courts were learning from this case how to treat the next one.
Ethical Considerations
Law sets a floor; ethics asks what the organization owed the people whose data it held. Four principles help. Nonmaleficence, the duty to avoid harm, asks whether Anthem took reasonable steps to prevent a foreseeable injury; the regulatory findings suggest it did not. Justice asks how burdens are distributed, and the Module 4 analysis showed that members, especially those whose permanent identifiers were taken, bore lasting risk while receiving two years of protection. Fidelity concerns keeping faith with people who trusted the organization, including members of other Blue plans who never chose Anthem at all. Transparency is where Anthem acted best: it disclosed the attack publicly within about a week of discovering it and cooperated with law enforcement.
The AHIMA Code of Ethics asks health information professionals to protect the confidentiality and security of health information and to advocate for appropriate uses of it. For Anthem's information governance staff, that obligation raises a hard question: why was a data warehouse holding Social Security numbers for former members at all? Reports at the time noted that the data were not encrypted at rest, and Anthem responded that encryption would not have stopped attackers who used valid administrator credentials. Both points can be true. The deeper problem is that data kept without a current purpose can only create risk.
Recommendations
Kruse et al. (2017) concluded that health care has lagged other industries in cybersecurity while holding especially valuable data, so the recommendations aim to close specific gaps rather than add general awareness. Table 1 lists ten recommendations, each linked to a finding, an owner and a timeline.
Table 1. Recommendations With Owners and Timelines
| Recommendation | Finding addressed | Owner | Timeline |
|---|---|---|---|
| Enterprise-wide risk analysis, repeated each year | No enterprise risk analysis | Chief information security officer | 90 days, then annually |
| Multifactor authentication for all remote and privileged access | Stolen credentials reused | Information technology security | 6 months |
| Privileged access management with just-in-time rights | Broad standing access | Information technology security | 9 months |
| Automated review of unusual queries and data volumes | Weak activity review | Security operations center | 6 months |
| Purge or archive former members' identifiers under a retention schedule | Data kept without purpose | Information governance | 12 months |
| Replace Social Security numbers with internal identifiers; tokenize where kept | Permanent identifiers exposed | Information governance and IT | 18 months |
| Encrypt data at rest in warehouses | Unencrypted stored data | Information technology security | 12 months |
| Recurring phishing simulations with targeted training | Phishing entry point | Security awareness team | Quarterly |
| Longer identity protection for anyone whose Social Security number is exposed | Short protection for lifelong risk | Privacy office | Policy within 90 days |
| Board-level cybersecurity committee with quarterly metrics | Governance gaps | Board of directors | Next board cycle |
Note. Recommendations developed by the author from the findings in Milestones One and Two.
Why These Recommendations
Several recommendations rest directly on evidence. Gordon et al. (2019) found that about one in seven simulated phishing emails at health care institutions was clicked, and that the likelihood of clicking fell with repeated campaigns, which supports recurring simulations rather than a single annual training module. Multifactor authentication and privileged access management address the fact that stolen credentials, not broken encryption, gave the attackers their reach. Data minimization addresses the ethical problem at its root: information that no longer exists cannot be stolen. Longer identity protection answers the justice concern by matching the protection to the length of the risk.
Implementing Without New Harm
Security changes can create their own problems. Choi et al. (2019) found that hospitals that had experienced breaches saw slower delivery of time-sensitive heart attack care in the following years, which the authors linked to new security procedures. For an insurer, rushed controls can delay claims, lock out providers or frustrate members. The recommendations are therefore phased over 18 months, tested with the staff who use the systems and paired with measures of their effect on service as well as on security.
Conclusion
Anthem's legal failures were failures of process: no enterprise risk analysis, weak monitoring, slow detection and broad access. Its ethical failures ran deeper, leaving lifelong risk with the people least able to control it and holding data no longer needed. The ten recommendations address both, and the final project will bring the summary, impacts and these recommendations together into one case analysis.
References
Choi, S. J., Johnson, M. E., & Lehmann, C. U. (2019). Data breach remediation efforts and their implications for hospital quality. Health Services Research, 54(5), 971-980. https://doi.org/10.1111/1475-6773.13203
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10. https://doi.org/10.3233/THC-161263
McCoy, T. H., Jr., & Perlis, R. H. (2018). Temporal trends and characteristics of reportable health data breaches, 2010-2017. JAMA, 320(12), 1282-1284. https://doi.org/10.1001/jama.2018.9222
What the HIM 422 Module 6 instructions ask for
HIM 422 Final Project Milestone Three usually asks you to analyze the legal and ethical considerations of the breach you have been studying and to recommend changes. Most versions expect three to five pages in APA 7 with credible sources and at least one table or organized list. Connect each legal consideration to a specific rule, such as a Security Rule requirement, a negligence element or a state law, and explain whether the organization met it. Then apply ethical principles or a professional code separately, so the grader can see where law and ethics diverge. Finish with specific recommendations that name an owner and a timeline, and explain the evidence or reasoning behind each one.
How this HIM 422 Module 6 final project milestone three example is built
The milestone matches the federal findings against Anthem to Security Rule duties, from enterprise risk analysis to activity review, incident response and access control. Negligence and state law add layers, and McCoy and Perlis show how large plan breaches reshaped enforcement. Nonmaleficence, justice, fidelity and transparency frame the ethics, with the AHIMA Code of Ethics raising why former members' Social Security numbers were still stored. Ten recommendations follow in a table with owners and timelines, supported by Kruse and colleagues and by Gordon and colleagues on repeated phishing simulations, while Choi and colleagues shape a phased rollout that avoids new harm to members and providers. The conclusion previews the final case analysis.
Where the HIM 422 Module 6 rubric puts the points
Recommendation milestones in HIM 422 are commonly graded on accurate legal analysis tied to specific requirements, thoughtful ethical reasoning kept distinct from legal compliance, recommendations that respond to identified failures, feasibility, use of sources and APA 7 mechanics. Top papers credit what the organization did well, such as prompt disclosure, alongside its failures, and they connect each recommendation to evidence. Graders reward owners and timelines because they show the writer understands implementation. Anticipating the side effects of security changes, such as slower service, demonstrates the balanced judgment expected of health information leaders who must protect data without obstructing care. Owners named by role, not by person, keep the plan realistic.
HIM 422 Module 6 help: the mistakes that cost points
Recommendation papers lose points when they list generic advice such as training staff, merge ethics into law, overlook what the organization did right or skip owners and timelines. Another frequent gap is recommending technology without linking it to a finding, such as encryption for a breach caused by stolen credentials. If your breach involved a hospital, an insider or ransomware, send the case and your earlier milestones so the recommendations fit those facts and your instructor's feedback carries forward. A custom milestone can use the same sequence of legal rules, ethical principles, a recommendations table with owners and timelines, evidence and an implementation caution.
Get HIM 422 Module 6 written to your instructions
Forward the HIM 422 Milestone Three guidelines along with your first two milestones. The paper will tie each legal issue to its rule, apply ethical principles separately, credit what went right and give specific recommendations with owners and timelines, in 24 to 48 hours with the first one free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 422 papers and related BS Health Information Management samples
- HIM 422 Module 1 Discussion: The Legal System, Tort Law and a Records Subpoena
- HIM 422 Module 2 Final Project Milestone One: The Anthem Breach Summarized, With Stakeholders
- HIM 422 Module 3 Journal: Consent and Health Record Policies
- HIM 422 Module 4 Final Project Milestone Two: Financial and Nonfinancial Impacts of the Anthem Breach
- HIM 422 Module 5 Journal: Workplace Law, Incident Reports and Governance
- HIM 350 Module 5 Patient Communication Short Paper: Reminders, Portals, Health Literacy and Access
- HIM 220 Module 4 Project One: A Data Dictionary for a Readmission Dashboard
- HIM 200 Module 3 Interoperability Short Paper: Health Information Exchange, FHIR and Information Blocking
- HIM 360 Module 2 Complex Diagnosis Short Paper: Neoplasms, Poisonings, Adverse Effects and Underdosing
HIM 422 Module 6 questions, answered
Where can I find a free HIM 422 Module 6 Final Project Milestone Three sample?
This page holds the entire HIM 422 Module 6 milestone: the Anthem breach's legal duties and ethical failures, with ten recommendations and owners.
What Security Rule failures did regulators find at Anthem?
No enterprise-wide risk analysis, insufficient review of system activity, failure to detect and respond to the intrusion and inadequate access controls.
Which ethical principles apply to a data breach?
Nonmaleficence, justice, fidelity and transparency are useful lenses, along with the AHIMA Code of Ethics for health information professionals.
Why is data minimization an ethical recommendation?
Information kept without a current purpose creates risk without benefit, and data that no longer exist cannot be stolen.
What makes a breach recommendation strong?
It responds to a specific finding, names an owner and timeline and is supported by evidence or clear reasoning.