HIM 530 Module 5 Final Project Milestone Two Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 530 Module 5 Final Project Milestone Two sample turns a security risk analysis into a risk management plan, the second step the HIPAA Security Rule requires. It is written for SNHU HIM 530 (HIM-530), and it continues the staged information protection program for MS Health Information Management students. The composite 420-bed regional medical center in coastal North Carolina ranked eight risks, led by an unsupported imaging archive and phishing-driven credential theft at 20 of 25. The plan explains the four ways to respond to risk, assigns each risk a response with specific controls, an owner, a cost, a timeline and an expected residual score, documents the acceptance of the lowest risk, sets a budget and describes how the security committee will track progress, citing research on phishing, ransomware, legacy devices and the spillover effects of attacks.

CourseHIM 530 Information Protection & Security in HIM
ModuleModule 5
Paper typegraduate milestone planning responses to analyzed security risks
LengthAbout 1,040 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 530 Module 5

1

Final Project Milestone Two: From Register to Response, a Risk Management Plan for Osprey Point Health

[Student Name]

Southern New Hampshire University

HIM 530: Information Protection & Security in HIM

Final Project Milestone Two

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title marks the move from analysis to action.
2

Final Project Milestone Two: From Register to Response, a Risk Management Plan for Osprey Point Health

Milestone One produced a risk register for Osprey Point Health with eight significant risks scored from 6 to 20. A register without a plan is only a list of worries. Under the Security Rule, a hospital must put in place measures that bring risks down to a reasonable and appropriate level, and this milestone sets out how Osprey Point will do that: which response each risk receives, which controls will be implemented, who owns them, what they cost, when they will be done and how much risk remains afterward.

What this page is doingThe introduction links analysis to required risk management.
3

Four Ways to Respond to Risk

Every risk can be handled in one of four ways. Mitigation reduces likelihood or impact through controls. Transfer shifts part of the consequence to another party, such as through cyber insurance or contract terms with a vendor. Avoidance removes the activity that creates the risk, such as retiring a system. Acceptance means leaders knowingly tolerate a risk, usually a low one, and document why. Most of Osprey Point's risks call for mitigation, but the plan uses avoidance for the imaging archive over time and acceptance for the lowest-rated risk.

What this page is doingThe four risk responses are defined.
4

The Plan by Risk

Table 1 summarizes the response for each risk, with its owner, cost, completion date and expected residual score.

Table 1. Risk Management Plan

Risk (score)Response and key controlsOwnerCostDueResidual score
Unsupported imaging archive (20)Mitigate now by isolating it on its own network segment with no internet access; avoid long term by migrating images to the supported archiveChief information officer$180,000Isolation 30 days; migration 9 months8
Phishing credential theft (20)Multifactor authentication for email and remote access; quarterly phishing simulations with targeted trainingInformation security officer$65,00090 days8
Vendor remote access ransomware (15)Named vendor accounts; access enabled only when requested; session recordingInformation security officer$40,000120 days6
Unusable backups (15)Immutable offsite backup copy; quarterly restore tests of critical systemsInfrastructure manager$55,00090 days6
Insider snooping (12)Rule-based alerts, analytics pilot, break-the-glass promptsPrivacy officer$38,0006 months6
Unpatched medical devices (12)Separate device network segment; device inventory with patch statusClinical engineering$60,0009 months6
Misdirected releases (9)Two-identifier match; second check for legal releasesRelease of information lead$5,00060 days4
Mobile device loss (6)Accept; transfer center to use hospital devices at next refreshPrivacy officerNone nowAccepted with review in 12 months6

Note. Plan prepared by the author with the security committee; costs are estimates.

What this page is doingTable 1 sets the response for each risk.
5

The Reasoning Behind the Top Responses

The imaging archive cannot be patched, so the only fast mitigation is to limit who and what can reach it; isolation cuts likelihood sharply within a month, while migration removes the risk entirely. Argaw et al. (2020) describe legacy systems like this as a characteristic weakness of hospital security, often left in place because replacing them competes with clinical priorities. For phishing, multifactor authentication matters more than training, because it stops a stolen password from being enough, but training still helps. Gordon et al. (2019) found that the odds of clicking a simulated phishing email fell as employees received more simulation campaigns, which supports quarterly exercises rather than one annual course.

Backups deserve priority because they determine how quickly care can resume after ransomware. Year over year, the ransomware incidents cataloged by Neprash et al. (2022) kept rising, and a large share of them interrupted patient care. The effects reach beyond the victim: Dameff et al. (2023) found that when one health system suffered a ransomware attack, neighboring emergency departments saw more patients, longer waits and more ambulance arrivals. Osprey Point is the only large hospital for its coastal region, so a long outage would strain every surrounding facility.

What this page is doingTop responses are justified with research.
6

Risks the Plan Could Create

Controls can create new problems, and the plan anticipates three. Isolating the imaging archive could slow radiologists who compare new images with old ones, so the network change will be tested with the radiology department on a weekend and a fast-path request process will exist for urgent retrievals. Multifactor authentication could lock out night staff who forget their phones, so the help desk will offer a temporary code process verified through a supervisor. And restricting vendor access could delay repairs to critical equipment, so vendors will be able to request emergency access by phone with a documented callback. Planning for these side effects reduces the chance that frustrated staff will work around the new controls.

What this page is doingPossible side effects of the controls are anticipated.
7

Documenting Acceptance

The lowest risk, loss of a personal mobile phone used in the transfer center, scored 6. Replacing those phones immediately would cost more than the risk justifies, since messages are brief and the phones use screen locks. The chief information officer and privacy officer signed a risk acceptance stating the rationale, the conditions under which it would be revisited and a plan to issue hospital devices at the next hardware refresh. Documented acceptance is itself a control: it proves the risk was considered rather than ignored.

What this page is doingA documented risk acceptance is explained.
8

Budget and Sequencing

The plan's first-year cost is about $443,000, of which the archive migration is the largest item. The sequence follows the scores and speed of effect: archive isolation, multifactor authentication, backups and vendor access controls in the first four months, then insider monitoring, device segmentation and archive migration. Cyber insurance renewal next spring provides a second reason to act quickly, since insurers increasingly require multifactor authentication and tested backups as conditions of coverage.

What this page is doingBudget and sequencing are set out.
9

Governance and Tracking

The security steering committee will track each item monthly and report residual risk to the board each quarter. When an item is complete, the owner will provide evidence, such as a report showing multifactor enrollment above 98% or a successful restore test, and the risk score will be updated in the register. If an item misses two target dates, the committee chair takes it directly to the hospital's president.

What this page is doingGovernance and evidence-based tracking are defined.
10

Conclusion

This plan gives each of Osprey Point's eight risks a documented response, owner, cost, date and expected residual score, bringing the highest risks from 20 to 8 within the year. It uses mitigation where controls work quickly, avoidance where a system cannot be made safe and acceptance where cost outweighs risk. Milestone Three will plan for the incidents that controls cannot prevent.

What this page is doingThe conclusion summarizes and points to incident response.
11

References

Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J.-M., O'Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20, Article 146. https://doi.org/10.1186/s12911-020-01161-7

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

What the HIM 530 Module 5 instructions ask for

In the second HIM 530 milestone, the risk register becomes an action plan. Four to six graduate pages in APA 7 with a plan table and supporting research fit most versions. Explain the four risk responses, then give every significant risk a response with specific controls, an accountable owner, an estimated cost, a completion date and an expected residual score. Justify the most important choices with evidence rather than vendor claims, document any risk you accept and why, set a budget and a sequence that deals with the highest risks first and describe how progress will be tracked with evidence and reported to leaders. Keep every score consistent with your Milestone One analysis. Plan for side effects of controls.

How this HIM 530 Module 5 final project milestone two example is built

Osprey Point Health's plan answers eight risks from the Milestone One register. The unsupported imaging archive is isolated within 30 days and migrated within nine months, a legacy problem Argaw and colleagues describe. Multifactor authentication and quarterly phishing simulations, supported by Gordon and colleagues, address credential theft. Immutable backups with restore tests respond to ransomware risks shown by Neprash and colleagues and Dameff and colleagues. A table gives each risk an owner, cost, date and residual score, the lowest risk is formally accepted and a $443,000 budget and monthly tracking with evidence complete this HIM 530 milestone. Side effects of new controls, such as locked-out night staff, are planned for.

Where the HIM 530 Module 5 rubric puts the points

Risk management milestones in HIM 530 are commonly graded on consistency with the risk analysis, appropriate response types, specific controls matched to each risk, clear ownership, realistic costs and timelines, residual risk estimates, documented acceptance, governance and APA 7 mechanics. Graduate plans that stand out prioritize by both score and speed of effect and explain why a control fits a risk, such as multifactor authentication for stolen passwords. Graders reward documented acceptance of low risks, since it shows judgment rather than an attempt to eliminate everything. Evidence-based tracking, such as restore test reports, shows that completion will be real. Anticipating side effects of controls earns credit.

HIM 530 Module 5 help: the mistakes that cost points

HIM 530 risk management plans slip when they list controls without linking them to risks, omit owners or dates, recommend expensive tools for low risks or pretend every risk can be eliminated. Some drafts also forget residual risk or how completion will be verified. If your case organization's risks differ, such as a clinic relying on a cloud record vendor or a business associate processing claims, send your Milestone One so the plan follows your register. Mention any budget limits and who in your case approves security spending. HIM 530 plans we write follow this order: purpose, response types, plan table, reasoning for top responses, acceptance, budget and sequence, governance and conclusion.

Get HIM 530 Module 5 written to your instructions

Send the HIM 530 Milestone Two guidelines with your risk analysis. The plan will explain the four responses, assign each risk specific controls, an owner, a cost, a date and a residual score, justify key choices with evidence, document acceptance and set a budget and tracking, delivered in 24 to 48 hours, free for a first request. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 530 papers and related MS Health Information Management samples

HIM 530 Module 5 questions, answered

Where can I find a free HIM 530 Module 5 Final Project Milestone Two sample?

The full HIM 530 Module 5 milestone is on this page: a security risk management plan with responses, owners, costs, timelines and residual risk for eight risks.

What are the four ways to respond to a security risk?

Mitigate it with controls, transfer part of it through insurance or contracts, avoid it by removing the activity or accept it knowingly with documentation.

What is residual risk?

The risk that remains after controls are in place, estimated with the same likelihood and impact scales used in the analysis.

Why prioritize multifactor authentication over training for phishing?

Multifactor authentication stops a stolen password from being enough to log in, while training reduces but does not eliminate clicks.

Why document accepted risks?

Documentation shows that leaders considered the risk and chose to tolerate it for stated reasons, which regulators and auditors expect.