HIM 530 Module 3 Final Project Milestone One Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 530 Module 3 Final Project Milestone One sample carries out a security risk analysis, the step the HIPAA Security Rule requires before any safeguard can be chosen sensibly. It is written for SNHU HIM 530 (HIM-530), where the final project builds an information protection program for MS Health Information Management students in stages. The composite 420-bed regional medical center in coastal North Carolina has not updated its enterprise risk analysis since 2021. The milestone defines scope and method using federal risk assessment guidance, inventories where electronic patient data live, identifies threats, vulnerabilities and existing controls, sets five-point likelihood and impact scales and presents a register of eight risks scored and ranked, with research on ransomware, phishing and medical device security supporting the ratings.

CourseHIM 530 Information Protection & Security in HIM
ModuleModule 3
Paper typegraduate milestone conducting a security risk analysis for a hospital
LengthAbout 1,000 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 530 Module 3

1

Final Project Milestone One: Where the Risk Lives, a Security Risk Analysis for Osprey Point Health

[Student Name]

Southern New Hampshire University

HIM 530: Information Protection & Security in HIM

Final Project Milestone One

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title frames the analysis as locating risk.
2

Final Project Milestone One: Where the Risk Lives, a Security Risk Analysis for Osprey Point Health

Osprey Point Health's last enterprise risk analysis was completed in 2021, before the medical center moved most health information staff to remote work, added 11 vendors and connected its infusion pumps to the network. The HIPAA Security Rule requires an accurate and thorough assessment of risks to electronic protected health information, and federal enforcement actions repeatedly cite its absence. This milestone updates the analysis and ranks the risks that the risk management plan in Milestone Two must address.

What this page is doingThe introduction explains why the analysis is needed now.
3

Scope and Method

The analysis covers all electronic patient information that Osprey Point creates, receives, maintains or transmits, wherever it resides: the record system, ancillary systems, medical devices, workstations, laptops, mobile devices, backups and systems operated by business associates. The method follows federal risk assessment guidance, which frames risk as a function of the likelihood that a threat exploits a vulnerability and the impact if it does (NIST, 2012). The team, including the information protection manager, the information security officer, a clinical engineer and a representative from each major department, gathered information through system inventories, interviews, a review of incident logs and a vendor survey.

What this page is doingScope and method are defined with federal guidance.
4

Where Patient Data Live

The inventory found patient data in 46 systems. Most are expected, such as the record system, laboratory and pharmacy systems and the billing platform. Several were not on the 2021 list: a cloud-based transcription service, a text-messaging tool used by the transfer center, 212 networked infusion pumps and an imaging archive that stores 11 years of radiology images on a server whose operating system no longer receives security updates. The 38 business associates who hold patient data are also in scope, since a breach at a vendor is still a breach of Osprey Point's patients' information.

What this page is doingThe data inventory reveals new locations since 2021.
5

Threat Sources Considered

The team considered four kinds of threat sources. Criminal groups seeking ransom or data to sell are the most active against hospitals and favor phishing, stolen credentials and vendor connections. Insiders, whether curious, careless or malicious, already hold access and are harder to detect. Accidents, such as a record sent to the wrong fax number or a misconfigured cloud folder, cause many breaches without any bad intent. And environmental events, including hurricanes that regularly threaten the North Carolina coast, can take systems offline for days. Considering all four prevents the analysis from focusing only on dramatic cyberattacks while missing the everyday errors and storms that are just as likely to cause harm.

What this page is doingThreat sources beyond hackers are considered.
6

Rating Scales

Likelihood and impact are each rated on a five-point scale. Likelihood ranges from 1, rare, not expected within five years, to 5, almost certain, expected within the year. Impact ranges from 1, negligible, with no patient harm and minimal data exposure, to 5, severe, with disruption of patient care, exposure of large volumes of data or major regulatory consequences. Multiplying the two ratings yields a score as low as 1 or as high as 25; anything at 15 and above counts as high, 8 through 14 as moderate and the rest as low. Using defined scales lets others check the ratings and allows scores to be compared from year to year.

What this page is doingRating scales and thresholds are defined.
7

Risk Register

Table 1 lists the eight most significant risks identified.

Table 1. Security Risk Register

RiskKey vulnerabilityExisting controlsLikelihoodImpactScore
Compromise of unsupported imaging archiveNo security updates; network reachableFirewall rule; antivirus4520
Credential theft through phishing11% click rate; no MFA on emailEmail filtering; annual training4520
Ransomware via vendor remote accessShared vendor accounts; always-on connectionsVPN; vendor agreements3515
Backups unusable when neededNo restore test in 14 monthsNightly backups on site3515
Insider snoopingAudit logs reviewed only after complaintsRole-based access; policy4312
Unpatched networked medical devicesPumps on flat networkVendor maintenance3412
Misdirected release of recordsManual matching at one siteStaff training339
Loss of mobile devicePersonal phones in transfer centerEncrypted laptops236

Note. Ratings by the risk analysis team; composite organization.

What this page is doingTable 1 presents the risk register.
8

Why the Top Risks Rate High

The ratings rest on local facts and published evidence. Credential theft through phishing rates high because 11% of staff clicked the last simulated phishing email and email lacks multifactor authentication; Across the hospitals that Gordon et al. (2019) tested, staff clicked on simulated lures at a similar rate, so Osprey Point is typical rather than exceptional. Ransomware and backup risks rate high on impact because an attack could halt care. The national count by Neprash et al. (2022) showed ransomware against care delivery organizations increased sharply over six years and frequently disrupted care. The imaging archive and infusion pumps illustrate the problem that Argaw et al. (2020) describe in hospitals: legacy systems and connected medical devices that cannot easily be patched but still hold or reach patient data.

What this page is doingTop ratings are explained with local evidence and research.
9

What Changed Since 2021

Comparing the new register with the 2021 analysis shows how risk moved. Remote work added home networks and personal spaces to the environment, although laptops are encrypted. Vendor connections nearly doubled. The imaging archive's operating system reached the end of support in 2023. And insider snooping, rated low in 2021, rose after two incidents last year showed that audit logs are not reviewed proactively. The change underlines why the risk analysis must be a recurring process rather than a one-time document.

What this page is doingChanges since the last analysis are identified.
10

Limitations

Ratings involve judgment, even with defined scales, and the team may underestimate risks in systems it knows less well, such as vendor-operated platforms. The vendor survey received responses from 29 of 38 business associates, so some vendor risks may be missing. The analysis will be repeated annually and after any major change.

What this page is doingLimitations are acknowledged.
11

Conclusion

Osprey Point's updated analysis identifies two high risks that share a score of 20, the unsupported imaging archive and credential theft through phishing, followed by vendor remote access and untested backups at 15. These four will be the first priorities for the risk management plan in Milestone Two, with the moderate risks, led by insider snooping and unpatched devices, scheduled close behind.

What this page is doingThe conclusion names priorities for Milestone Two.
12

References

Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J.-M., O'Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20, Article 146. https://doi.org/10.1186/s12911-020-01161-7

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

What the HIM 530 Module 3 instructions ask for

HIM 530 Final Project Milestone One is a security risk analysis for your case organization. Plan roughly four to six graduate pages in APA 7, including a risk register and federal guidance alongside research. Define the scope so that it includes every place electronic patient information is created, stored or sent, including devices and vendors. Describe your method and who participated. Set explicit likelihood and impact scales and a scoring rule, then build a register listing each risk with its vulnerability, existing controls and rating. Explain why the highest risks rate high, using local facts and published evidence, note how risks have changed since any earlier analysis and acknowledge where your ratings rest on judgment. Consider every type of threat source.

How this HIM 530 Module 3 final project milestone one example is built

Osprey Point Health updates a risk analysis last done in 2021. Scope covers 46 systems, 212 networked infusion pumps and 38 business associates, and the method follows NIST's risk assessment guidance. Five-point likelihood and impact scales produce scores up to 25. The register ranks an unsupported imaging archive and phishing-driven credential theft at 20, vendor remote access and untested backups at 15 and insider snooping and unpatched devices at 12. Gordon and colleagues, Neprash and colleagues and Argaw and colleagues support the top ratings, and a comparison with 2021 shows risk moving with remote work and new vendors in this HIM 530 milestone. Threat sources include insiders, accidents and hurricanes.

Where the HIM 530 Module 3 rubric puts the points

Risk analysis milestones in HIM 530 are usually graded on complete scope, a defined and repeatable method, explicit rating scales, a well-organized risk register, ratings supported by evidence, attention to vendors and medical devices, recognition of change over time, honest limitations and APA 7 mechanics. Graduate analyses that stand out find data in unexpected places, such as messaging tools or legacy archives, and explain ratings rather than simply stating them. Graders reward scales precise enough that another team could reproduce the scores. Identifying clear priorities for the next milestone shows that the analysis is a working tool, not a compliance exercise. Considering accidents and weather adds realism.

HIM 530 Module 3 help: the mistakes that cost points

HIM 530 risk analyses slip when scope covers only the main record system, when likelihood and impact are rated without defined scales, when vendors and devices are ignored or when the register lists threats without vulnerabilities and existing controls. Some drafts also jump to solutions before finishing the analysis. If your case organization is a clinic, a health plan or a business associate rather than a hospital, send the case so the scope and risks fit. Include any inventory, incident history or phishing results you have. HIM 530 risk analyses we write follow this order: need, scope and method, data inventory, scales, register, rationale, change over time, limitations and priorities.

Get HIM 530 Module 3 written to your instructions

Send the HIM 530 Milestone One guidelines and details about your case organization's systems and vendors. The analysis will define scope and method, inventory where patient data live, set rating scales, build a scored risk register and explain the top ratings with evidence, returned in 24 to 48 hours with the first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 530 papers and related MS Health Information Management samples

HIM 530 Module 3 questions, answered

Where can I find a free HIM 530 Module 3 Final Project Milestone One sample?

The complete HIM 530 Module 3 milestone is here: a hospital security risk analysis with scope, method, likelihood and impact scales and a ranked risk register.

Is a security risk analysis required under HIPAA?

Yes. The Security Rule requires an accurate and thorough assessment of risks to electronic protected health information.

How is risk scored in a security risk analysis?

Commonly by rating likelihood and impact on defined scales and combining them, such as multiplying two five-point ratings.

What should a risk register include?

Each risk, its key vulnerability, existing controls, likelihood, impact and overall score.

How often should a risk analysis be updated?

Regularly, at least annually in many organizations, and after major changes such as new systems, vendors or ways of working.