| Course | HIM 530 Information Protection & Security in HIM |
|---|---|
| Module | Module 5 |
| Paper type | graduate milestone planning responses to analyzed security risks |
| Length | About 1,040 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 530 Module 5
Final Project Milestone Two: From Register to Response, a Risk Management Plan for Osprey Point Health
[Student Name]
Southern New Hampshire University
HIM 530: Information Protection & Security in HIM
Final Project Milestone Two
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Final Project Milestone Two: From Register to Response, a Risk Management Plan for Osprey Point Health
Milestone One produced a risk register for Osprey Point Health with eight significant risks scored from 6 to 20. A register without a plan is only a list of worries. Under the Security Rule, a hospital must put in place measures that bring risks down to a reasonable and appropriate level, and this milestone sets out how Osprey Point will do that: which response each risk receives, which controls will be implemented, who owns them, what they cost, when they will be done and how much risk remains afterward.
Four Ways to Respond to Risk
Every risk can be handled in one of four ways. Mitigation reduces likelihood or impact through controls. Transfer shifts part of the consequence to another party, such as through cyber insurance or contract terms with a vendor. Avoidance removes the activity that creates the risk, such as retiring a system. Acceptance means leaders knowingly tolerate a risk, usually a low one, and document why. Most of Osprey Point's risks call for mitigation, but the plan uses avoidance for the imaging archive over time and acceptance for the lowest-rated risk.
The Plan by Risk
Table 1 summarizes the response for each risk, with its owner, cost, completion date and expected residual score.
Table 1. Risk Management Plan
| Risk (score) | Response and key controls | Owner | Cost | Due | Residual score |
|---|---|---|---|---|---|
| Unsupported imaging archive (20) | Mitigate now by isolating it on its own network segment with no internet access; avoid long term by migrating images to the supported archive | Chief information officer | $180,000 | Isolation 30 days; migration 9 months | 8 |
| Phishing credential theft (20) | Multifactor authentication for email and remote access; quarterly phishing simulations with targeted training | Information security officer | $65,000 | 90 days | 8 |
| Vendor remote access ransomware (15) | Named vendor accounts; access enabled only when requested; session recording | Information security officer | $40,000 | 120 days | 6 |
| Unusable backups (15) | Immutable offsite backup copy; quarterly restore tests of critical systems | Infrastructure manager | $55,000 | 90 days | 6 |
| Insider snooping (12) | Rule-based alerts, analytics pilot, break-the-glass prompts | Privacy officer | $38,000 | 6 months | 6 |
| Unpatched medical devices (12) | Separate device network segment; device inventory with patch status | Clinical engineering | $60,000 | 9 months | 6 |
| Misdirected releases (9) | Two-identifier match; second check for legal releases | Release of information lead | $5,000 | 60 days | 4 |
| Mobile device loss (6) | Accept; transfer center to use hospital devices at next refresh | Privacy officer | None now | Accepted with review in 12 months | 6 |
Note. Plan prepared by the author with the security committee; costs are estimates.
The Reasoning Behind the Top Responses
The imaging archive cannot be patched, so the only fast mitigation is to limit who and what can reach it; isolation cuts likelihood sharply within a month, while migration removes the risk entirely. Argaw et al. (2020) describe legacy systems like this as a characteristic weakness of hospital security, often left in place because replacing them competes with clinical priorities. For phishing, multifactor authentication matters more than training, because it stops a stolen password from being enough, but training still helps. Gordon et al. (2019) found that the odds of clicking a simulated phishing email fell as employees received more simulation campaigns, which supports quarterly exercises rather than one annual course.
Backups deserve priority because they determine how quickly care can resume after ransomware. Year over year, the ransomware incidents cataloged by Neprash et al. (2022) kept rising, and a large share of them interrupted patient care. The effects reach beyond the victim: Dameff et al. (2023) found that when one health system suffered a ransomware attack, neighboring emergency departments saw more patients, longer waits and more ambulance arrivals. Osprey Point is the only large hospital for its coastal region, so a long outage would strain every surrounding facility.
Risks the Plan Could Create
Controls can create new problems, and the plan anticipates three. Isolating the imaging archive could slow radiologists who compare new images with old ones, so the network change will be tested with the radiology department on a weekend and a fast-path request process will exist for urgent retrievals. Multifactor authentication could lock out night staff who forget their phones, so the help desk will offer a temporary code process verified through a supervisor. And restricting vendor access could delay repairs to critical equipment, so vendors will be able to request emergency access by phone with a documented callback. Planning for these side effects reduces the chance that frustrated staff will work around the new controls.
Documenting Acceptance
The lowest risk, loss of a personal mobile phone used in the transfer center, scored 6. Replacing those phones immediately would cost more than the risk justifies, since messages are brief and the phones use screen locks. The chief information officer and privacy officer signed a risk acceptance stating the rationale, the conditions under which it would be revisited and a plan to issue hospital devices at the next hardware refresh. Documented acceptance is itself a control: it proves the risk was considered rather than ignored.
Budget and Sequencing
The plan's first-year cost is about $443,000, of which the archive migration is the largest item. The sequence follows the scores and speed of effect: archive isolation, multifactor authentication, backups and vendor access controls in the first four months, then insider monitoring, device segmentation and archive migration. Cyber insurance renewal next spring provides a second reason to act quickly, since insurers increasingly require multifactor authentication and tested backups as conditions of coverage.
Governance and Tracking
The security steering committee will track each item monthly and report residual risk to the board each quarter. When an item is complete, the owner will provide evidence, such as a report showing multifactor enrollment above 98% or a successful restore test, and the risk score will be updated in the register. If an item misses two target dates, the committee chair takes it directly to the hospital's president.
Conclusion
This plan gives each of Osprey Point's eight risks a documented response, owner, cost, date and expected residual score, bringing the highest risks from 20 to 8 within the year. It uses mitigation where controls work quickly, avoidance where a system cannot be made safe and acceptance where cost outweighs risk. Milestone Three will plan for the incidents that controls cannot prevent.
References
Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J.-M., O'Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20, Article 146. https://doi.org/10.1186/s12911-020-01161-7
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
What the HIM 530 Module 5 instructions ask for
In the second HIM 530 milestone, the risk register becomes an action plan. Four to six graduate pages in APA 7 with a plan table and supporting research fit most versions. Explain the four risk responses, then give every significant risk a response with specific controls, an accountable owner, an estimated cost, a completion date and an expected residual score. Justify the most important choices with evidence rather than vendor claims, document any risk you accept and why, set a budget and a sequence that deals with the highest risks first and describe how progress will be tracked with evidence and reported to leaders. Keep every score consistent with your Milestone One analysis. Plan for side effects of controls.
How this HIM 530 Module 5 final project milestone two example is built
Osprey Point Health's plan answers eight risks from the Milestone One register. The unsupported imaging archive is isolated within 30 days and migrated within nine months, a legacy problem Argaw and colleagues describe. Multifactor authentication and quarterly phishing simulations, supported by Gordon and colleagues, address credential theft. Immutable backups with restore tests respond to ransomware risks shown by Neprash and colleagues and Dameff and colleagues. A table gives each risk an owner, cost, date and residual score, the lowest risk is formally accepted and a $443,000 budget and monthly tracking with evidence complete this HIM 530 milestone. Side effects of new controls, such as locked-out night staff, are planned for.
Where the HIM 530 Module 5 rubric puts the points
Risk management milestones in HIM 530 are commonly graded on consistency with the risk analysis, appropriate response types, specific controls matched to each risk, clear ownership, realistic costs and timelines, residual risk estimates, documented acceptance, governance and APA 7 mechanics. Graduate plans that stand out prioritize by both score and speed of effect and explain why a control fits a risk, such as multifactor authentication for stolen passwords. Graders reward documented acceptance of low risks, since it shows judgment rather than an attempt to eliminate everything. Evidence-based tracking, such as restore test reports, shows that completion will be real. Anticipating side effects of controls earns credit.
HIM 530 Module 5 help: the mistakes that cost points
HIM 530 risk management plans slip when they list controls without linking them to risks, omit owners or dates, recommend expensive tools for low risks or pretend every risk can be eliminated. Some drafts also forget residual risk or how completion will be verified. If your case organization's risks differ, such as a clinic relying on a cloud record vendor or a business associate processing claims, send your Milestone One so the plan follows your register. Mention any budget limits and who in your case approves security spending. HIM 530 plans we write follow this order: purpose, response types, plan table, reasoning for top responses, acceptance, budget and sequence, governance and conclusion.
Get HIM 530 Module 5 written to your instructions
Send the HIM 530 Milestone Two guidelines with your risk analysis. The plan will explain the four responses, assign each risk specific controls, an owner, a cost, a date and a residual score, justify key choices with evidence, document acceptance and set a budget and tracking, delivered in 24 to 48 hours, free for a first request. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 530 papers and related MS Health Information Management samples
- HIM 530 Module 1 Discussion: Privacy, Security and Confidentiality in HIM Practice
- HIM 530 Module 2 Frameworks Short Paper: The HIPAA Security Rule Beside the NIST Framework
- HIM 530 Module 3 Final Project Milestone One: A Security Risk Analysis for the Medical Center
- HIM 530 Module 4 Access Monitoring Short Paper: Insider Snooping and Audit Log Review
- HIM 510 Module 9 Final Project: The Policy Package and a Professional Identity Statement
- HIM 500 Module 7 Final Project Milestone Three: Technology Recommendations for the Hospital
- HIM 520 Module 6 Ethics Short Paper: A Physician's Request to Change a Note After an Adverse Event
- HIM 440 Module 8 Discussion: Leading a Department Through Change
HIM 530 Module 5 questions, answered
Where can I find a free HIM 530 Module 5 Final Project Milestone Two sample?
The full HIM 530 Module 5 milestone is on this page: a security risk management plan with responses, owners, costs, timelines and residual risk for eight risks.
What are the four ways to respond to a security risk?
Mitigate it with controls, transfer part of it through insurance or contracts, avoid it by removing the activity or accept it knowingly with documentation.
What is residual risk?
The risk that remains after controls are in place, estimated with the same likelihood and impact scales used in the analysis.
Why prioritize multifactor authentication over training for phishing?
Multifactor authentication stops a stolen password from being enough to log in, while training reduces but does not eliminate clicks.
Why document accepted risks?
Documentation shows that leaders considered the risk and chose to tolerate it for stated reasons, which regulators and auditors expect.