| Course | HIM 422 Ethical and Legal Considerations in Health Information Management |
|---|---|
| Module | Module 8 |
| Paper type | undergraduate final project analyzing a health data breach end to end |
| Length | About 1,260 words, 7 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 422 Module 8
Final Project: One Email, 78.8 Million People, a Case Analysis of the Anthem Data Breach
[Student Name]
Southern New Hampshire University
HIM 422: Ethical and Legal Considerations in Health Information Management
Final Project
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Final Project: One Email, 78.8 Million People, a Case Analysis of the Anthem Data Breach
Executive Summary
In 2014 and early 2015, attackers who entered through a phishing message spent months inside Anthem's network and removed identifying data on 78.8 million people. Anthem detected the intrusion in January 2015 and disclosed it within days. The breach led to three public settlements totaling $170.5 million and left affected people with a lifelong risk of identity theft. Federal regulators traced the breach to missing or weak safeguards required by the HIPAA Security Rule. This analysis concludes that the most important failures were a lack of enterprise-wide risk analysis, broad standing access for privileged accounts and the retention of permanent identifiers without a current need, and it recommends changes in three phases.
What Happened
The intrusion started when an employee at an Anthem subsidiary opened a message crafted to look routine, giving attackers a way to run their own software inside the company. From that foothold they gathered login credentials belonging to staff with wide privileges and used them to query a data warehouse. The information removed included names, dates of birth, Social Security numbers, member numbers, home and email addresses and employment details. Investigators found no sign that diagnoses, claims or card numbers were taken.
The attack was caught by a person rather than a tool: a database administrator saw a query running under his own account that he had never launched. Anthem closed the access, brought in outside investigators and the FBI and made a public announcement on February 4, 2015. It then mailed letters, opened a call center and offered two years of identity protection. People insured by other Blue plans were affected too, because their claims had been processed through Anthem when they received care in its states.
Stakeholders
The people with the most at stake were the members and former members whose identifiers were taken, including those who had never chosen Anthem. Employer groups had to reassure their workforces. Anthem's security staff and the employees whose credentials were misused carried the response. Executives and the board answered for governance, regulators and attorneys general enforced federal and state law, law enforcement pursued the attackers and shareholders absorbed the financial exposure. Their interests often pulled in different directions: members wanted lasting protection, while the company wanted to limit cost and liability.
Impacts
Table 1 summarizes the verifiable financial consequences. The totals exclude investigation, notification, call center, monitoring and security costs, which Anthem did not itemize publicly.
Table 1. Public Settlements Arising From the Anthem Breach
| Settlement | Year | Amount | Notable terms |
|---|---|---|---|
| HHS Office for Civil Rights | 2018 | $16.0 million | Corrective action plan; largest HIPAA settlement to that date |
| Consumer class action | 2018 | $115.0 million | Credit monitoring, reimbursement, security commitments |
| State attorneys general | 2020 | $39.5 million | Security practice commitments |
| Total | $170.5 million |
Note. Compiled from public announcements and court records.
Harms Beyond the Settlements
Money measures only part of the damage. Jiang and Bai (2020) showed that many health data breaches expose identifiers that support financial fraud, and a Social Security number, once stolen, stays useful to criminals for life. Anthem's two years of monitoring therefore covered a small fraction of the risk it created. Romanosky et al. (2014) found that lawsuits after breaches became more likely when people suffered financial harm and less likely when companies offered monitoring; the scale of this breach overwhelmed the protective effect of the monitoring offer. Trust suffered among employers and other Blue plans, staff carried months of crisis work and the company operated under outside oversight for years.
Legal Analysis
Anthem, as a health plan, is a HIPAA covered entity. The Security Rule's requirements are flexible, scaled to an organization's size and risk, but they are not optional. Regulators concluded that Anthem lacked an enterprise-wide risk analysis, did not adequately review system activity, noticed the attackers far too late and did not limit access sufficiently. Each finding corresponds to a named Security Rule standard, and together they describe an organization that could not see its own risks. Anthem's prompt disclosure appears to have satisfied its notification duties, which shows that meeting one set of rules does not excuse another.
Civil law added a second front. The consolidated class action claimed that Anthem owed members a duty of reasonable care, breached it and caused harm. State attorneys general used consumer protection and breach laws. The case illustrates a pattern described by McCoy and Perlis (2018), who found that hacking incidents at health plans had come to account for most of the health records exposed in reported breaches, drawing enforcement attention toward the largest data holders.
Ethical Analysis
Ethically, the case turns on responsibility for risk that others cannot control. Members could not inspect Anthem's security, choose what it stored or decide how long it kept their data, so the duty to avoid harm rested entirely with Anthem. The distribution of harm was unjust: the lifelong burden fell on individuals while the organization's obligations ended with settlements and a monitoring period. Keeping identifiers of former members raises a question of stewardship that the AHIMA Code of Ethics addresses directly, since health information professionals are expected to protect information and to advocate for its appropriate use. Anthem deserves credit for its candor. It announced the breach quickly and cooperated with investigators, which respected members' right to know and allowed them to protect themselves sooner.
Recommendations
The recommendations fall into three phases. In the first 90 days, the organization should complete an enterprise-wide risk analysis, require multifactor authentication for every privileged and remote account and set alerts for unusual query volumes against sensitive tables. Within the first year, it should remove standing administrator rights in favor of time-limited access, encrypt stored data in warehouses, adopt a retention schedule that deletes or archives former members' identifiers and begin recurring phishing simulations. Gordon et al. (2019) found that staff at health care institutions clicked about one simulated phishing message in seven and that repeated campaigns lowered the odds of clicking. Within eighteen months, it should replace Social Security numbers with internal identifiers, extend identity protection for anyone whose number is exposed to match the length of the risk and establish a board committee that receives security metrics every quarter.
Changes should be tested with the people who use the systems. Choi et al. (2019) found that security measures adopted after hospital breaches were associated with slower emergency cardiac care, a warning that controls introduced in haste can create new harm.
Lessons for Health Information Management
For a hospital health information department such as mine, three lessons stand out. First, the Security Rule's risk analysis is not paperwork; it is the only way to know where sensitive data live and who can reach them. Second, retention schedules are security tools, because data destroyed on schedule cannot be stolen. Third, breach history is shifting. Liu et al. (2015) found that most breaches reported from 2010 through 2013 involved stolen devices and paper, but the largest losses since then have come from network intrusions, so a department's safeguards must move from locked cabinets to access controls and monitoring.
Conclusion
The Anthem breach began with one message and ended with 78.8 million people carrying a lasting risk they did not choose. Regulators, courts and states imposed $170.5 million in settlements, yet the most durable harm fell on individuals. The analysis shows that the breach was made possible by gaps in risk analysis, access control and data stewardship that the law already required organizations to address. Closing those gaps, in phases and with care for the people who use the systems, is the clearest lesson for any organization entrusted with health information.
References
Choi, S. J., Johnson, M. E., & Lehmann, C. U. (2019). Data breach remediation efforts and their implications for hospital quality. Health Services Research, 54(5), 971-980. https://doi.org/10.1111/1475-6773.13203
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Jiang, J. X., & Bai, G. (2020). Types of information compromised in breaches of protected health information. Annals of Internal Medicine, 172(2), 159-160. https://doi.org/10.7326/M19-1759
Liu, V., Musen, M. A., & Chou, T. (2015). Data breaches of protected health information in the United States. JAMA, 313(14), 1471-1473. https://doi.org/10.1001/jama.2015.2252
McCoy, T. H., Jr., & Perlis, R. H. (2018). Temporal trends and characteristics of reportable health data breaches, 2010-2017. JAMA, 320(12), 1282-1284. https://doi.org/10.1001/jama.2018.9222
Romanosky, S., Hoffman, D. A., & Acquisti, A. (2014). Empirical analysis of data breach litigation. Journal of Empirical Legal Studies, 11(1), 74-104. https://doi.org/10.1111/jels.12035
What the HIM 422 Module 8 instructions ask for
For the HIM 422 final project, the milestone drafts become a single, complete analysis of one health data breach. Plan roughly 1,500 to 2,000 words in APA 7 with tables and at least five credible sources, including scholarly research and public enforcement records. Open with an executive summary, then describe what happened, who was affected, the financial and nonfinancial impacts, the legal requirements involved and the ethical issues. Finish with prioritized recommendations and the lessons for health information management. Revise rather than paste: rewrite each milestone to reflect instructor feedback, remove repetition and make sure every figure and date matches across sections before you submit the final version.
How this HIM 422 Module 8 final project example is built
The final project on the 2015 Anthem breach opens with an executive summary naming three core failures. It retells the attack and the administrator who spotted it, maps stakeholders and their conflicting interests and presents $170.5 million in public settlements in a table. Jiang and Bai and Romanosky and colleagues explain harms and litigation, McCoy and Perlis frame enforcement trends and the legal and ethical analyses stay separate. Recommendations fall into 90-day, one-year and eighteen-month phases, supported by Gordon and colleagues on phishing and tempered by Choi and colleagues. Liu and colleagues anchor lessons for hospital health information departments before a short conclusion that returns to the single email where the case began.
Where the HIM 422 Module 8 rubric puts the points
Final projects in HIM 422 are commonly graded on a clear executive summary, an accurate and complete case description, thorough stakeholder and impact analysis, correct legal analysis tied to specific requirements, ethical reasoning that goes beyond compliance, feasible and prioritized recommendations, integration of milestone feedback and APA 7 mechanics. The strongest projects read as one argument rather than stitched-together milestones, credit what the organization did well and end with lessons that apply to the writer's own field. Graders notice when numbers and dates stay consistent across sections, and they reward recommendations placed on a realistic timeline rather than listed all at once. Tables that summarize money and settlements keep long sections readable.
HIM 422 Module 8 help: the mistakes that cost points
Marks slip when the three milestones sit side by side with repeated sections, when instructor feedback is ignored, when figures change between sections or when recommendations have no priority or timeline. Another frequent gap is an executive summary that describes the paper instead of stating its conclusions. If your breach is different, send your three milestones and the feedback you received, so the final version corrects earlier issues and keeps your own case facts. Include the final rubric if your course posts one, along with any required headings or template. A custom project follows the same structure shown here: summary, case, stakeholders, impacts, law, ethics, phased recommendations and lessons.
Get HIM 422 Module 8 written to your instructions
Send the HIM 422 final project guidelines with your three milestones and any instructor feedback. The finished analysis will open with an executive summary, keep facts consistent, separate law from ethics and give phased recommendations with lessons for your field, back within 24 to 48 hours, the first request at no cost. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 422 papers and related BS Health Information Management samples
- HIM 422 Module 1 Discussion: The Legal System, Tort Law and a Records Subpoena
- HIM 422 Module 2 Final Project Milestone One: The Anthem Breach Summarized, With Stakeholders
- HIM 422 Module 3 Journal: Consent and Health Record Policies
- HIM 422 Module 4 Final Project Milestone Two: Financial and Nonfinancial Impacts of the Anthem Breach
- HIM 422 Module 5 Journal: Workplace Law, Incident Reports and Governance
- HIM 422 Module 6 Final Project Milestone Three: Ethical and Legal Considerations and Recommendations
- HIM 422 Module 7 Journal: The Ethical Release of Patient Information
- HIM 360 Module 4 Project One: A Mortality and Severity Coding Review
- HIM 400 Module 1 Discussion: Why Health Technology Projects Fail
- HIM 350 Module 4 Project One: A Communication Technology Audit of a Behavioral Health Agency
- HIM 200 Module 7 Project Two: A Plan to Improve Portal Use and Record Exchange
HIM 422 Module 8 questions, answered
Where can I find a free HIM 422 Module 8 Final Project sample?
The full HIM 422 Module 8 project is here: a complete Anthem breach case analysis covering facts, impacts, law, ethics and phased recommendations.
How should the final project differ from the milestones?
It should read as one revised argument with an executive summary, consistent figures and changes based on instructor feedback, not pasted milestones.
What should an executive summary of a breach analysis include?
The event, its scale, the main findings and the analysis's central conclusion, stated briefly enough to read in a minute.
Why phase breach recommendations?
Phasing puts urgent fixes first, spreads cost and allows testing with users so new controls do not disrupt service or care.
What lessons does the Anthem breach hold for hospitals?
Risk analysis must be real, retention schedules reduce what can be stolen and safeguards must focus on network access as well as physical records.