HIM 422 Module 6 Final Project Milestone Three Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 422 Module 6 Final Project Milestone Three sample moves from what happened and what it cost to what an organization owed and should now do. It is written for SNHU HIM 422 (HIM-422), where the third milestone asks BS Health Information Management learners to weigh the legal and ethical dimensions of a breach and recommend a response. The case is still the 2015 Anthem cyberattack that exposed identifiers for 78.8 million people. The milestone ties the federal regulators' findings to specific Security Rule duties, considers negligence and state law, then examines the case through the ethical principles of nonmaleficence, justice, fidelity and transparency, including why former members' Social Security numbers were still stored. It closes with ten recommendations, each with an owner and timeline, supported by research on phishing, cybersecurity practice and the costs of rushed remediation.

CourseHIM 422 Ethical and Legal Considerations in Health Information Management
ModuleModule 6
Paper typeundergraduate milestone on the ethics, law and recommended response to a breach
LengthAbout 1,040 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramBS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 422 Module 6

1

Final Project Milestone Three: What Anthem Owed, and What Should Change

[Student Name]

Southern New Hampshire University

HIM 422: Ethical and Legal Considerations in Health Information Management

Final Project Milestone Three

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title pairs the obligations with the recommended changes.
2

Final Project Milestone Three: What Anthem Owed, and What Should Change

Earlier milestones showed that a single phishing message opened the door to Anthem's systems, that the intruders roamed unnoticed for months and that they carried off identifiers for 78.8 million people, and that the consequences included $170.5 million in public settlements and lasting harm to members. This milestone asks two further questions. What did the law and professional ethics require of Anthem? And what should Anthem, or any organization holding similar data, change? Legal considerations come first, then ethical ones, then recommendations.

What this page is doingThe introduction states the milestone's two questions.
3

Legal Considerations: The Security Rule

The federal findings map directly onto the HIPAA Security Rule. The rule makes an accurate and thorough risk analysis the foundation of every other safeguard, and regulators found that Anthem had not conducted one across the enterprise. The rule expects covered entities to review records of system activity such as logins and queries, and regulators found that review insufficient. It requires procedures to identify and respond to security incidents, and the attack ran for months before anyone noticed. It also requires technical controls that limit access to those who need it, and regulators found those controls inadequate. None of these duties requires perfect security. Each requires a reasonable, documented process, and the findings suggest that process was missing where it mattered most.

What this page is doingThe federal findings are matched to Security Rule duties.
4

Legal Considerations: Negligence and State Law

The class action rested largely on negligence: a duty to protect members' data, a breach of that duty through inadequate security, and harm caused by the breach. Proving harm is often the hardest element in breach cases, because courts have disagreed about whether the risk of future identity theft is itself an injury. The exposure of Social Security numbers made harm easier to argue here. State laws added obligations of their own, including breach notification deadlines and consumer protection statutes, which is why more than 40 attorneys general could pursue a separate settlement. McCoy and Perlis (2018) showed that large hacking incidents at health plans came to dominate the number of breached records, which suggests regulators and courts were learning from this case how to treat the next one.

What this page is doingNegligence and state law are explained as additional layers.
5

Ethical Considerations

Law sets a floor; ethics asks what the organization owed the people whose data it held. Four principles help. Nonmaleficence, the duty to avoid harm, asks whether Anthem took reasonable steps to prevent a foreseeable injury; the regulatory findings suggest it did not. Justice asks how burdens are distributed, and the Module 4 analysis showed that members, especially those whose permanent identifiers were taken, bore lasting risk while receiving two years of protection. Fidelity concerns keeping faith with people who trusted the organization, including members of other Blue plans who never chose Anthem at all. Transparency is where Anthem acted best: it disclosed the attack publicly within about a week of discovering it and cooperated with law enforcement.

The AHIMA Code of Ethics asks health information professionals to protect the confidentiality and security of health information and to advocate for appropriate uses of it. For Anthem's information governance staff, that obligation raises a hard question: why was a data warehouse holding Social Security numbers for former members at all? Reports at the time noted that the data were not encrypted at rest, and Anthem responded that encryption would not have stopped attackers who used valid administrator credentials. Both points can be true. The deeper problem is that data kept without a current purpose can only create risk.

What this page is doingFour ethical principles and the professional code are applied.
6

Recommendations

Kruse et al. (2017) concluded that health care has lagged other industries in cybersecurity while holding especially valuable data, so the recommendations aim to close specific gaps rather than add general awareness. Table 1 lists ten recommendations, each linked to a finding, an owner and a timeline.

Table 1. Recommendations With Owners and Timelines

RecommendationFinding addressedOwnerTimeline
Enterprise-wide risk analysis, repeated each yearNo enterprise risk analysisChief information security officer90 days, then annually
Multifactor authentication for all remote and privileged accessStolen credentials reusedInformation technology security6 months
Privileged access management with just-in-time rightsBroad standing accessInformation technology security9 months
Automated review of unusual queries and data volumesWeak activity reviewSecurity operations center6 months
Purge or archive former members' identifiers under a retention scheduleData kept without purposeInformation governance12 months
Replace Social Security numbers with internal identifiers; tokenize where keptPermanent identifiers exposedInformation governance and IT18 months
Encrypt data at rest in warehousesUnencrypted stored dataInformation technology security12 months
Recurring phishing simulations with targeted trainingPhishing entry pointSecurity awareness teamQuarterly
Longer identity protection for anyone whose Social Security number is exposedShort protection for lifelong riskPrivacy officePolicy within 90 days
Board-level cybersecurity committee with quarterly metricsGovernance gapsBoard of directorsNext board cycle

Note. Recommendations developed by the author from the findings in Milestones One and Two.

What this page is doingTable 1 links each recommendation to a finding, owner and timeline.
7

Why These Recommendations

Several recommendations rest directly on evidence. Gordon et al. (2019) found that about one in seven simulated phishing emails at health care institutions was clicked, and that the likelihood of clicking fell with repeated campaigns, which supports recurring simulations rather than a single annual training module. Multifactor authentication and privileged access management address the fact that stolen credentials, not broken encryption, gave the attackers their reach. Data minimization addresses the ethical problem at its root: information that no longer exists cannot be stolen. Longer identity protection answers the justice concern by matching the protection to the length of the risk.

What this page is doingThe recommendations are justified with evidence and ethics.
8

Implementing Without New Harm

Security changes can create their own problems. Choi et al. (2019) found that hospitals that had experienced breaches saw slower delivery of time-sensitive heart attack care in the following years, which the authors linked to new security procedures. For an insurer, rushed controls can delay claims, lock out providers or frustrate members. The recommendations are therefore phased over 18 months, tested with the staff who use the systems and paired with measures of their effect on service as well as on security.

What this page is doingThe paper plans to avoid harm from the fixes themselves.
9

Conclusion

Anthem's legal failures were failures of process: no enterprise risk analysis, weak monitoring, slow detection and broad access. Its ethical failures ran deeper, leaving lifelong risk with the people least able to control it and holding data no longer needed. The ten recommendations address both, and the final project will bring the summary, impacts and these recommendations together into one case analysis.

What this page is doingThe conclusion summarizes the legal and ethical analysis and previews the final project.
10

References

Choi, S. J., Johnson, M. E., & Lehmann, C. U. (2019). Data breach remediation efforts and their implications for hospital quality. Health Services Research, 54(5), 971-980. https://doi.org/10.1111/1475-6773.13203

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10. https://doi.org/10.3233/THC-161263

McCoy, T. H., Jr., & Perlis, R. H. (2018). Temporal trends and characteristics of reportable health data breaches, 2010-2017. JAMA, 320(12), 1282-1284. https://doi.org/10.1001/jama.2018.9222

What the HIM 422 Module 6 instructions ask for

HIM 422 Final Project Milestone Three usually asks you to analyze the legal and ethical considerations of the breach you have been studying and to recommend changes. Most versions expect three to five pages in APA 7 with credible sources and at least one table or organized list. Connect each legal consideration to a specific rule, such as a Security Rule requirement, a negligence element or a state law, and explain whether the organization met it. Then apply ethical principles or a professional code separately, so the grader can see where law and ethics diverge. Finish with specific recommendations that name an owner and a timeline, and explain the evidence or reasoning behind each one.

How this HIM 422 Module 6 final project milestone three example is built

The milestone matches the federal findings against Anthem to Security Rule duties, from enterprise risk analysis to activity review, incident response and access control. Negligence and state law add layers, and McCoy and Perlis show how large plan breaches reshaped enforcement. Nonmaleficence, justice, fidelity and transparency frame the ethics, with the AHIMA Code of Ethics raising why former members' Social Security numbers were still stored. Ten recommendations follow in a table with owners and timelines, supported by Kruse and colleagues and by Gordon and colleagues on repeated phishing simulations, while Choi and colleagues shape a phased rollout that avoids new harm to members and providers. The conclusion previews the final case analysis.

Where the HIM 422 Module 6 rubric puts the points

Recommendation milestones in HIM 422 are commonly graded on accurate legal analysis tied to specific requirements, thoughtful ethical reasoning kept distinct from legal compliance, recommendations that respond to identified failures, feasibility, use of sources and APA 7 mechanics. Top papers credit what the organization did well, such as prompt disclosure, alongside its failures, and they connect each recommendation to evidence. Graders reward owners and timelines because they show the writer understands implementation. Anticipating the side effects of security changes, such as slower service, demonstrates the balanced judgment expected of health information leaders who must protect data without obstructing care. Owners named by role, not by person, keep the plan realistic.

HIM 422 Module 6 help: the mistakes that cost points

Recommendation papers lose points when they list generic advice such as training staff, merge ethics into law, overlook what the organization did right or skip owners and timelines. Another frequent gap is recommending technology without linking it to a finding, such as encryption for a breach caused by stolen credentials. If your breach involved a hospital, an insider or ransomware, send the case and your earlier milestones so the recommendations fit those facts and your instructor's feedback carries forward. A custom milestone can use the same sequence of legal rules, ethical principles, a recommendations table with owners and timelines, evidence and an implementation caution.

Get HIM 422 Module 6 written to your instructions

Forward the HIM 422 Milestone Three guidelines along with your first two milestones. The paper will tie each legal issue to its rule, apply ethical principles separately, credit what went right and give specific recommendations with owners and timelines, in 24 to 48 hours with the first one free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 422 papers and related BS Health Information Management samples

HIM 422 Module 6 questions, answered

Where can I find a free HIM 422 Module 6 Final Project Milestone Three sample?

This page holds the entire HIM 422 Module 6 milestone: the Anthem breach's legal duties and ethical failures, with ten recommendations and owners.

What Security Rule failures did regulators find at Anthem?

No enterprise-wide risk analysis, insufficient review of system activity, failure to detect and respond to the intrusion and inadequate access controls.

Which ethical principles apply to a data breach?

Nonmaleficence, justice, fidelity and transparency are useful lenses, along with the AHIMA Code of Ethics for health information professionals.

Why is data minimization an ethical recommendation?

Information kept without a current purpose creates risk without benefit, and data that no longer exist cannot be stolen.

What makes a breach recommendation strong?

It responds to a specific finding, names an owner and timeline and is supported by evidence or clear reasoning.