HIM 530 Module 7 Final Project Milestone Three Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 530 Module 7 Final Project Milestone Three sample plans how a hospital responds when a security incident happens anyway, from the first alert to the last required notice. It is written for SNHU HIM 530 (HIM-530) as the third stage of an information protection program for MS Health Information Management students. The composite 420-bed regional medical center in coastal North Carolina had an incident response plan that had never been exercised. The milestone sets up a response team with roles, defines severity levels, lays out steps from detection through recovery and review in line with NIST's 2025 incident response guidance, explains how care continues during an outage, maps communication, walks through the breach risk assessment and federal and state notice deadlines and reports lessons from a ransomware tabletop exercise, citing research on ransomware's spillover and on post-breach remediation.

CourseHIM 530 Information Protection & Security in HIM
ModuleModule 7
Paper typegraduate milestone planning incident response and breach notification
LengthAbout 1,020 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 530 Module 7

1

Final Project Milestone Three: When Prevention Fails, an Incident Response and Breach Notification Plan for Osprey Point Health

[Student Name]

Southern New Hampshire University

HIM 530: Information Protection & Security in HIM

Final Project Milestone Three

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title states the premise of incident planning.
2

Final Project Milestone Three: When Prevention Fails, an Incident Response and Breach Notification Plan for Osprey Point Health

Milestone Two lowered Osprey Point Health's highest risks, but no set of controls prevents every incident. What matters then is how quickly the medical center detects the problem, limits the damage, keeps caring for patients and meets its legal duties. Osprey Point's existing plan, written in 2020, lists phone numbers but has never been tested. This milestone replaces it with a plan built around roles, severity, clear steps, communication and breach notification, and tests it with a tabletop exercise.

What this page is doingThe introduction explains why incident planning follows risk management.
3

The Response Team

The incident response team has a core group and an extended group. The core group includes the information security officer as incident commander, the privacy officer, the chief information officer, the health information director and a clinical operations leader. The extended group joins as needed: legal counsel, communications, human resources, facilities, the cyber insurance carrier's breach coach and outside forensic investigators on retainer. Each role has a named primary and backup, since incidents do not wait for business hours. Contact details for every role are kept in a printed binder and on a phone app that works when hospital systems are down, since a plan stored only on the network is useless during ransomware. The binder is checked and reprinted every quarter.

What this page is doingTeam roles are defined with backups.
4

Severity Levels

Table 1 defines four severity levels, which determine who is called and how fast.

Table 1. Incident Severity Levels

LevelDefinitionExamplesResponse
1 LowLimited, contained, no patient data affectedBlocked phishing email; lost encrypted laptopHandled by security team; logged
2 ModeratePossible exposure of limited patient dataMisdirected record; one account compromisedPrivacy officer engaged within 24 hours
3 HighConfirmed exposure of patient data or disruption of a clinical systemInsider snooping case; vendor breach noticeCore team convened within 4 hours
4 CriticalWidespread disruption of care or large-scale data compromiseRansomware across systemsFull team immediately; downtime procedures; executive notification

Note. Levels defined by the author with the security committee.

What this page is doingTable 1 sets severity levels and responses.
5

Steps From Detection to Review

NIST's 2025 incident response guidance places response within the broader Cybersecurity Framework, treating preparation, detection, response and recovery as parts of continuous risk management rather than a separate emergency activity (Nelson et al., 2025). Osprey Point's plan follows that structure. Detection and analysis confirm whether an event is an incident and assign severity. Containment limits spread, for example by isolating infected systems or disabling a compromised account, while preserving evidence. Eradication removes the cause, and recovery restores systems from verified clean backups, starting with those that support patient care. Within a month of closing an incident, a review records successes, failures and needed changes, and its actions feed back into the risk register.

What this page is doingResponse steps align with current NIST guidance.
6

Keeping Care Going

A critical incident is a clinical event. When the record system is unavailable, units switch to downtime procedures: printed downtime reports of current patients and medications, paper documentation and manual ordering and results processes. If the emergency department cannot work safely, it can ask regional dispatch to send ambulances elsewhere. In the attack studied by Dameff et al. (2023), a single system's ransomware outage pushed up volumes, waits and ambulance arrivals at neighboring emergency departments, so the plan includes notifying regional hospitals and the emergency medical services coordinator early in any Level 4 incident. The health information department will manage the return of downtime paper records to the electronic record after recovery.

What this page is doingClinical continuity and regional notification are planned.
7

Who Is Told What, and When

Communication follows the severity level. For a Level 3 or 4 incident, the incident commander informs the chief executive officer within one hour, the board chair the same day and staff through clear, regular updates that tell them what to do. The cyber insurer must be notified promptly under the policy, and law enforcement, usually the FBI for ransomware, is contacted early. Communications staff prepare holding statements for media and patients, reviewed by legal counsel, and a single spokesperson speaks for the hospital.

What this page is doingInternal and external communication is mapped.
8

Breach Assessment and Notification

Any incident involving patient data triggers a breach risk assessment. Under HIPAA, an improper use or disclosure counts as a breach unless a documented review of four factors shows compromise to be unlikely. The review weighs the type and volume of data exposed, who obtained or used it, whether anyone actually saw or took it and what has been done to reduce the harm. The kind of data matters: Jiang and Bai (2020) found that many breaches exposed identifiers that enable financial fraud, which raises the harm to patients. When notice is required, patients must hear from Osprey Point promptly and never later than 60 days after the breach came to light; notify federal regulators within 60 days if 500 or more people are affected, or in an annual log if fewer; notify prominent media if more than 500 residents of a state are affected; and meet North Carolina's breach law, which also requires notice to the state attorney general's office.

What this page is doingThe four-factor assessment and notice deadlines are explained.
9

Testing the Plan

The plan was tested in a three-hour tabletop exercise simulating ransomware that encrypts the record system on a Friday night. Three gaps emerged: the downtime reports had not printed since a system upgrade, no one knew how to reach the forensic firm after hours and communications staff lacked approved templates for patients. Each became an action item with an owner and date. Choi et al. (2019) found that security changes made after hospital breaches were associated with slower delivery of urgent cardiac care, a reminder that recovery plans should be tested with clinicians so that new safeguards do not create new harm.

What this page is doingTabletop findings are reported with research on remediation effects.
10

Conclusion

Osprey Point's new plan assigns roles with backups, grades incidents by severity, follows current NIST guidance from detection through review, keeps care going and meets every notice deadline. A tabletop exercise already found three gaps that would have hurt in a real attack. The plan will be exercised twice a year and reviewed after every Level 3 or 4 incident, and it becomes part of the full information protection program in the final project. Each exercise will rotate the scenario, from an insider case to a vendor breach, so the team practices more than one kind of bad day.

What this page is doingThe conclusion summarizes and links to the final project.
11

References

Choi, S. J., Johnson, M. E., & Lehmann, C. U. (2019). Data breach remediation efforts and their implications for hospital quality. Health Services Research, 54(5), 971-980. https://doi.org/10.1111/1475-6773.13203

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270

Jiang, J. X., & Bai, G. (2020). Types of information compromised in breaches of protected health information. Annals of Internal Medicine, 172(2), 159-160. https://doi.org/10.7326/M19-1759

Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST Special Publication 800-61, Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3

What the HIM 530 Module 7 instructions ask for

The third HIM 530 milestone covers the bad day: how your case organization responds to a security incident and satisfies breach notice rules. Most HIM 530 sections expect four to six graduate pages in APA 7, a severity table and current federal guidance alongside research. Define the response team with backups, set severity levels and describe steps from detection through containment, eradication, recovery and post-incident review. Explain how clinical care continues during an outage and how communication flows inside and outside the organization. Walk through the breach risk assessment and every notice deadline that applies, including state law, and test the plan with a tabletop exercise whose findings become action items. Keep a copy of the plan offline.

How this HIM 530 Module 7 final project milestone three example is built

Osprey Point Health replaces an untested 2020 plan. A core team with named backups, four severity levels in a table and steps aligned with Nelson and colleagues' 2025 NIST profile structure the response. Downtime procedures and early notice to neighboring hospitals reflect Dameff and colleagues' findings on ransomware spillover. Communication runs from the chief executive to the FBI and the insurer. The four-factor breach assessment, Jiang and Bai's evidence on exposed identifiers and every federal and North Carolina deadline follow. A Friday-night ransomware tabletop exposes three gaps, and Choi and colleagues' research shapes testing with clinicians in this HIM 530 milestone. A printed contact binder backs up the digital plan.

Where the HIM 530 Module 7 rubric puts the points

Incident response milestones in HIM 530 are commonly graded on a clearly defined team, useful severity levels, complete response phases aligned with current guidance, attention to clinical continuity, a communication plan, accurate breach assessment and notification requirements including state law, testing and APA 7 mechanics. The strongest graduate plans treat a major incident as a clinical event as well as a technical one and include neighboring facilities in their thinking. Graders reward accurate deadlines and the four-factor assessment stated correctly. A tabletop exercise that uncovers real gaps, converted into owned action items, shows the plan is a working document rather than a binder on a shelf.

HIM 530 Module 7 help: the mistakes that cost points

HIM 530 incident response milestones slip when they stop at detection, ignore how patients will be cared for during an outage, misstate breach deadlines, forget state law or never test the plan. Some drafts also list contacts without roles or backups. If your case organization is in another state, or is a clinic, health plan or business associate, send the case so the plan applies the right notice rules and scale. Include any past incident reports. HIM 530 plans we write follow this order: purpose, team, severity levels, response steps, clinical continuity, communication, breach assessment and notification, testing and conclusion. Mention your state's breach law if you know it.

Get HIM 530 Module 7 written to your instructions

Send the HIM 530 Milestone Three guidelines with your earlier milestones and your case organization's state. The plan will define the team and severity levels, set response steps from detection to review, keep care going, map communication, apply the breach assessment and every notice deadline and report a tabletop test, finished in 24 to 48 hours, first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 530 papers and related MS Health Information Management samples

HIM 530 Module 7 questions, answered

Where can I find a free HIM 530 Module 7 Final Project Milestone Three sample?

This page holds the complete HIM 530 Module 7 milestone: an incident response and breach notification plan with roles, severity levels, deadlines and a tabletop test.

What are the phases of incident response?

Preparation, detection and analysis, containment, eradication, recovery and post-incident review, now framed by NIST within overall cybersecurity risk management.

What is the deadline for telling patients about a HIPAA breach?

Patients must be told promptly, and in every case within 60 calendar days of the date the breach was discovered.

Which factors decide whether an incident is a reportable HIPAA breach?

The type and amount of data, who obtained or used it, whether it was actually seen or taken and how well the risk was reduced afterward.

What is a tabletop exercise?

A discussion-based rehearsal in which the response team walks through a simulated incident to find gaps in the plan.