| Course | HIM 530 Information Protection & Security in HIM |
|---|---|
| Module | Module 3 |
| Paper type | graduate milestone conducting a security risk analysis for a hospital |
| Length | About 1,000 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 530 Module 3
Final Project Milestone One: Where the Risk Lives, a Security Risk Analysis for Osprey Point Health
[Student Name]
Southern New Hampshire University
HIM 530: Information Protection & Security in HIM
Final Project Milestone One
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Final Project Milestone One: Where the Risk Lives, a Security Risk Analysis for Osprey Point Health
Osprey Point Health's last enterprise risk analysis was completed in 2021, before the medical center moved most health information staff to remote work, added 11 vendors and connected its infusion pumps to the network. The HIPAA Security Rule requires an accurate and thorough assessment of risks to electronic protected health information, and federal enforcement actions repeatedly cite its absence. This milestone updates the analysis and ranks the risks that the risk management plan in Milestone Two must address.
Scope and Method
The analysis covers all electronic patient information that Osprey Point creates, receives, maintains or transmits, wherever it resides: the record system, ancillary systems, medical devices, workstations, laptops, mobile devices, backups and systems operated by business associates. The method follows federal risk assessment guidance, which frames risk as a function of the likelihood that a threat exploits a vulnerability and the impact if it does (NIST, 2012). The team, including the information protection manager, the information security officer, a clinical engineer and a representative from each major department, gathered information through system inventories, interviews, a review of incident logs and a vendor survey.
Where Patient Data Live
The inventory found patient data in 46 systems. Most are expected, such as the record system, laboratory and pharmacy systems and the billing platform. Several were not on the 2021 list: a cloud-based transcription service, a text-messaging tool used by the transfer center, 212 networked infusion pumps and an imaging archive that stores 11 years of radiology images on a server whose operating system no longer receives security updates. The 38 business associates who hold patient data are also in scope, since a breach at a vendor is still a breach of Osprey Point's patients' information.
Threat Sources Considered
The team considered four kinds of threat sources. Criminal groups seeking ransom or data to sell are the most active against hospitals and favor phishing, stolen credentials and vendor connections. Insiders, whether curious, careless or malicious, already hold access and are harder to detect. Accidents, such as a record sent to the wrong fax number or a misconfigured cloud folder, cause many breaches without any bad intent. And environmental events, including hurricanes that regularly threaten the North Carolina coast, can take systems offline for days. Considering all four prevents the analysis from focusing only on dramatic cyberattacks while missing the everyday errors and storms that are just as likely to cause harm.
Rating Scales
Likelihood and impact are each rated on a five-point scale. Likelihood ranges from 1, rare, not expected within five years, to 5, almost certain, expected within the year. Impact ranges from 1, negligible, with no patient harm and minimal data exposure, to 5, severe, with disruption of patient care, exposure of large volumes of data or major regulatory consequences. Multiplying the two ratings yields a score as low as 1 or as high as 25; anything at 15 and above counts as high, 8 through 14 as moderate and the rest as low. Using defined scales lets others check the ratings and allows scores to be compared from year to year.
Risk Register
Table 1 lists the eight most significant risks identified.
Table 1. Security Risk Register
| Risk | Key vulnerability | Existing controls | Likelihood | Impact | Score |
|---|---|---|---|---|---|
| Compromise of unsupported imaging archive | No security updates; network reachable | Firewall rule; antivirus | 4 | 5 | 20 |
| Credential theft through phishing | 11% click rate; no MFA on email | Email filtering; annual training | 4 | 5 | 20 |
| Ransomware via vendor remote access | Shared vendor accounts; always-on connections | VPN; vendor agreements | 3 | 5 | 15 |
| Backups unusable when needed | No restore test in 14 months | Nightly backups on site | 3 | 5 | 15 |
| Insider snooping | Audit logs reviewed only after complaints | Role-based access; policy | 4 | 3 | 12 |
| Unpatched networked medical devices | Pumps on flat network | Vendor maintenance | 3 | 4 | 12 |
| Misdirected release of records | Manual matching at one site | Staff training | 3 | 3 | 9 |
| Loss of mobile device | Personal phones in transfer center | Encrypted laptops | 2 | 3 | 6 |
Note. Ratings by the risk analysis team; composite organization.
Why the Top Risks Rate High
The ratings rest on local facts and published evidence. Credential theft through phishing rates high because 11% of staff clicked the last simulated phishing email and email lacks multifactor authentication; Across the hospitals that Gordon et al. (2019) tested, staff clicked on simulated lures at a similar rate, so Osprey Point is typical rather than exceptional. Ransomware and backup risks rate high on impact because an attack could halt care. The national count by Neprash et al. (2022) showed ransomware against care delivery organizations increased sharply over six years and frequently disrupted care. The imaging archive and infusion pumps illustrate the problem that Argaw et al. (2020) describe in hospitals: legacy systems and connected medical devices that cannot easily be patched but still hold or reach patient data.
What Changed Since 2021
Comparing the new register with the 2021 analysis shows how risk moved. Remote work added home networks and personal spaces to the environment, although laptops are encrypted. Vendor connections nearly doubled. The imaging archive's operating system reached the end of support in 2023. And insider snooping, rated low in 2021, rose after two incidents last year showed that audit logs are not reviewed proactively. The change underlines why the risk analysis must be a recurring process rather than a one-time document.
Limitations
Ratings involve judgment, even with defined scales, and the team may underestimate risks in systems it knows less well, such as vendor-operated platforms. The vendor survey received responses from 29 of 38 business associates, so some vendor risks may be missing. The analysis will be repeated annually and after any major change.
Conclusion
Osprey Point's updated analysis identifies two high risks that share a score of 20, the unsupported imaging archive and credential theft through phishing, followed by vendor remote access and untested backups at 15. These four will be the first priorities for the risk management plan in Milestone Two, with the moderate risks, led by insider snooping and unpatched devices, scheduled close behind.
References
Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J.-M., O'Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20, Article 146. https://doi.org/10.1186/s12911-020-01161-7
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
What the HIM 530 Module 3 instructions ask for
HIM 530 Final Project Milestone One is a security risk analysis for your case organization. Plan roughly four to six graduate pages in APA 7, including a risk register and federal guidance alongside research. Define the scope so that it includes every place electronic patient information is created, stored or sent, including devices and vendors. Describe your method and who participated. Set explicit likelihood and impact scales and a scoring rule, then build a register listing each risk with its vulnerability, existing controls and rating. Explain why the highest risks rate high, using local facts and published evidence, note how risks have changed since any earlier analysis and acknowledge where your ratings rest on judgment. Consider every type of threat source.
How this HIM 530 Module 3 final project milestone one example is built
Osprey Point Health updates a risk analysis last done in 2021. Scope covers 46 systems, 212 networked infusion pumps and 38 business associates, and the method follows NIST's risk assessment guidance. Five-point likelihood and impact scales produce scores up to 25. The register ranks an unsupported imaging archive and phishing-driven credential theft at 20, vendor remote access and untested backups at 15 and insider snooping and unpatched devices at 12. Gordon and colleagues, Neprash and colleagues and Argaw and colleagues support the top ratings, and a comparison with 2021 shows risk moving with remote work and new vendors in this HIM 530 milestone. Threat sources include insiders, accidents and hurricanes.
Where the HIM 530 Module 3 rubric puts the points
Risk analysis milestones in HIM 530 are usually graded on complete scope, a defined and repeatable method, explicit rating scales, a well-organized risk register, ratings supported by evidence, attention to vendors and medical devices, recognition of change over time, honest limitations and APA 7 mechanics. Graduate analyses that stand out find data in unexpected places, such as messaging tools or legacy archives, and explain ratings rather than simply stating them. Graders reward scales precise enough that another team could reproduce the scores. Identifying clear priorities for the next milestone shows that the analysis is a working tool, not a compliance exercise. Considering accidents and weather adds realism.
HIM 530 Module 3 help: the mistakes that cost points
HIM 530 risk analyses slip when scope covers only the main record system, when likelihood and impact are rated without defined scales, when vendors and devices are ignored or when the register lists threats without vulnerabilities and existing controls. Some drafts also jump to solutions before finishing the analysis. If your case organization is a clinic, a health plan or a business associate rather than a hospital, send the case so the scope and risks fit. Include any inventory, incident history or phishing results you have. HIM 530 risk analyses we write follow this order: need, scope and method, data inventory, scales, register, rationale, change over time, limitations and priorities.
Get HIM 530 Module 3 written to your instructions
Send the HIM 530 Milestone One guidelines and details about your case organization's systems and vendors. The analysis will define scope and method, inventory where patient data live, set rating scales, build a scored risk register and explain the top ratings with evidence, returned in 24 to 48 hours with the first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 530 papers and related MS Health Information Management samples
- HIM 530 Module 1 Discussion: Privacy, Security and Confidentiality in HIM Practice
- HIM 530 Module 2 Frameworks Short Paper: The HIPAA Security Rule Beside the NIST Framework
- HIM 530 Module 4 Access Monitoring Short Paper: Insider Snooping and Audit Log Review
- HIM 530 Module 5 Final Project Milestone Two: A Risk Management Plan
- HIM 530 Module 6 Third-Party Risk Short Paper: Business Associates and Vendor Oversight
- HIM 530 Module 7 Final Project Milestone Three: Incident Response and Breach Notification
- HIM 530 Module 8 Workforce Culture Short Paper: Phishing, Awareness and Reporting Without Fear
- HIM 530 Module 9 Final Project: The Information Protection Program
- HIM 530 Module 10 Reflection: What Protecting Information Taught the Writer
- HIM 520 Module 2 Human Resources Short Paper: Recruiting and Keeping Coders in a Merged Department
- HIM 510 Module 1 Discussion: Professional Identity and the Roles of HIM Leaders
- HIM 500 Module 3 Final Project Milestone One: History, Standards and a Process for Evaluating New Health IT
- HIM 360 Module 8 Discussion: ICD-11 and the Future of Classification
HIM 530 Module 3 questions, answered
Where can I find a free HIM 530 Module 3 Final Project Milestone One sample?
The complete HIM 530 Module 3 milestone is here: a hospital security risk analysis with scope, method, likelihood and impact scales and a ranked risk register.
Is a security risk analysis required under HIPAA?
Yes. The Security Rule requires an accurate and thorough assessment of risks to electronic protected health information.
How is risk scored in a security risk analysis?
Commonly by rating likelihood and impact on defined scales and combining them, such as multiplying two five-point ratings.
What should a risk register include?
Each risk, its key vulnerability, existing controls, likelihood, impact and overall score.
How often should a risk analysis be updated?
Regularly, at least annually in many organizations, and after major changes such as new systems, vendors or ways of working.