HIM 530 Module 8 Workforce Culture Short Paper Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 530 Module 8 Workforce Culture Short Paper sample treats security as a matter of people and culture as well as technology. It is written for SNHU HIM 530 (HIM-530), where MS Health Information Management students consider how workforce behavior shapes information protection. At the composite 420-bed regional medical center in coastal North Carolina, 11% of staff clicked the last simulated phishing email, only 4% reported it and a coder who clicked a real phishing link waited two days to tell anyone because she feared discipline. The paper examines why busy staff click, why fear delays reporting, how to build a report-first culture with easy reporting, what role-based training release of information staff need against pretext callers and how leaders and measures can reward the behavior that limits harm.

CourseHIM 530 Information Protection & Security in HIM
ModuleModule 8
Paper typegraduate paper on security culture, phishing and incident reporting
LengthAbout 1,040 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 530 Module 8

1

Click, Then Call: Building a Security Culture Where Staff Report Mistakes at Osprey Point Health

[Student Name]

Southern New Hampshire University

HIM 530: Information Protection & Security in HIM

Module Eight Short Paper

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title names the behavior the culture should produce.
2

Click, Then Call: Building a Security Culture Where Staff Report Mistakes at Osprey Point Health

Last month, a remote coder at Osprey Point Health clicked a link in a message dressed up as a payroll notice and entered her password. She realized her mistake within minutes but waited two days to report it, worried she would be disciplined. In those two days, the attacker used her account to send phishing emails to 300 colleagues. Controls such as multifactor authentication, added under the risk management plan, now limit what a stolen password can do. But the two-day delay points to a problem no tool fixes: a culture in which people hide mistakes.

What this page is doingThe introduction shows how fear delayed reporting.
3

What the Delay Cost

The two days mattered. Of the 300 colleagues who received the attacker's messages from the coder's real account, 14 opened the link and 3 entered their own passwords before the security team blocked the sender. Investigators then had to review the mailboxes of all four compromised accounts for patient information and determine whether a breach had occurred. The review took about 60 staff hours and found one spreadsheet of release of information requests with patient names, which required a breach risk assessment. Had the coder reported within minutes, the security team estimates that the attacker's messages would have been stopped before any were sent.

What this page is doingThe cost of the reporting delay is quantified.
4

Why Busy People Click

Phishing works because it targets ordinary work habits. Among the health systems whose staff Gordon et al. (2019) tested with fake phishing messages, roughly one message in seven drew a click, with the likelihood of clicking falling as more campaigns were conducted. Jalali et al. (2020) studied hospital employees and found that knowing about phishing risk did not by itself keep people from clicking, and they pointed to the pressure of busy work as part of the explanation. For Osprey Point, this means that annual awareness training alone will not solve the problem. Staff who process hundreds of messages a day, many of them urgent, will sometimes click; the goal is to make clicks rarer and reports faster.

What this page is doingResearch explains why training alone does not stop clicks.
5

Why Fear Slows Reporting

The coder's delay reflects a culture problem. Edmondson (1999) found that teams in which members believed they could raise problems without being punished or embarrassed showed more learning behavior and performed better. In security, the most valuable learning behavior is reporting quickly. Every hour between a click and a report gives an attacker more time. Osprey Point's past practice of listing phishing clicks in employee evaluations taught staff that admitting a click was risky, which is the opposite of what the medical center needs.

What this page is doingPsychological safety research is applied to reporting.
6

A Report-First Culture

The new approach treats a prompt report as success, even after a click. Three changes support it. First, every email client will have a one-click button to report suspicious messages, which sends the message to the security team and removes it from the user's inbox. Second, the sanctions policy will be revised so that an employee who clicks and reports promptly faces no discipline; discipline is reserved for repeated disregard of training or for concealment. Third, the security team will thank reporters personally and publish anonymized monthly examples of phishing caught by staff, showing that reports make a difference.

What this page is doingChanges that reward prompt reporting are described.
7

Role-Based Training

Different roles face different threats. Release of information staff at Osprey Point receive phone calls from people claiming to be patients, attorneys or insurers, and some are attempts to obtain records under false pretenses. Their training will focus on identity verification: calling back through a number on file, requiring written authorizations for third parties and recognizing pressure tactics such as urgent demands from supposed executives. Coders will train on credential theft and on suspicious messages that appear to come from coding software vendors. Supervisors will learn how to respond when an employee reports a mistake, since a manager's first reaction shapes whether the next employee reports at all.

What this page is doingTraining is tailored to roles and threats.
8

Remote Staff and Home Settings

Most of Osprey Point's health information staff now work from home, where the usual cues of an office are missing. There is no colleague at the next desk to ask whether an email looks odd, and personal and work messages arrive on nearby devices. The culture plan therefore includes a staffed chat channel where anyone can ask the security team about a suspicious message and get an answer within minutes during business hours. Remote staff also receive short training on home risks, such as family members using work laptops and printing records at home, and the remote work policy's rules on private workspaces are reinforced in each team's monthly meeting.

What this page is doingCulture measures are adapted for remote staff.
9

Simulations Done Fairly

Phishing simulations will continue quarterly, since research suggests repeated exposure reduces clicking. They will be designed to teach rather than trap: realistic but not cruel, avoiding lures that exploit staff anxieties such as fake layoff notices or pandemic bonuses. Employees who click see a short explanation of the clues they missed, and those who click repeatedly receive brief one-on-one coaching rather than public identification.

What this page is doingPrinciples for fair simulations are set.
10

Leaders Set the Tone

Culture follows what leaders do. The chief executive and department directors will complete the same simulations and training as staff, and the chief information officer will describe at a town hall a time a phishing email nearly fooled her. When a leader reports a suspicious message, the security team will say so, with permission, in its monthly update. These signals tell staff that anyone can be fooled and that reporting is expected at every level.

What this page is doingLeadership modeling supports the culture.
11

Measuring Culture

Table 1 lists the measures, which value reporting as highly as avoiding clicks.

Table 1. Security Culture Measures

MeasureCurrentTarget in 12 months
Simulated phishing click rate11%5%
Simulated phishing report rate4%40%
Median time from real click to reportAbout 2 days (last incident)Under 30 minutes
Staff agreeing they can report mistakes without blame48%75%
Release of information calls failing verification that are escalatedNot tracked100% logged and escalated

Note. Measures and targets proposed by the author; composite data.

What this page is doingTable 1 sets culture measures and targets.
12

Conclusion

Osprey Point cannot train every click away, but it can make clicks rarer and reports immediate. Understanding why busy people click, removing the fear that delays reporting, making reporting easy, training by role, running fair simulations and having leaders model the behavior build a culture in which a mistake like the coder's is reported in minutes rather than days.

What this page is doingThe conclusion restates the goal of fast reporting.
13

References

Edmondson, A. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2), 350-383. https://doi.org/10.2307/2666999

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

Jalali, M. S., Bruckes, M., Westmattelmann, D., & Schewe, G. (2020). Why employees (still) click on phishing links: Investigation in hospitals. Journal of Medical Internet Research, 22(1), Article e16775. https://doi.org/10.2196/16775

What the HIM 530 Module 8 instructions ask for

The HIM 530 workforce culture paper looks at people as both the weakest and strongest part of information protection. Graduate length of four to five pages in APA 7, with research on human behavior and security, fits most sections. Begin with a concrete incident or data, such as phishing results, then explain why staff make security mistakes and why fear slows reporting. Propose a culture that rewards prompt reporting, with easy reporting tools and a sanctions policy that separates honest mistakes from concealment. Add training tailored to roles, including release of information threats such as pretext callers, principles for fair simulations, leadership modeling and measures that value reporting as well as avoiding mistakes.

How this HIM 530 Module 8 workforce culture short paper example is built

A remote coder at Osprey Point Health enters her password on a fake payroll page and waits two days to report it, while the attacker emails 300 colleagues. Gordon and colleagues and Jalali and colleagues explain why busy hospital staff click despite training, and Edmondson's work on psychological safety explains the delay. The paper introduces a one-click reporting button, no discipline for prompt reporters, role-based training for release of information staff facing pretext callers, fair quarterly simulations and leaders who share their own near misses. A measures table raises the report rate target from 4% to 40% in this HIM 530 paper. The two-day delay led to three more stolen passwords.

Where the HIM 530 Module 8 rubric puts the points

Workforce culture papers in HIM 530 are usually graded on understanding of human factors in security, use of research on phishing and reporting, a culture design that rewards the right behavior, role-based training, fair simulations, leadership involvement, meaningful measures and APA 7 mechanics. Papers that stand out recognize that punishing clicks can make organizations less safe by delaying reports and propose sanctions that distinguish mistakes from concealment. Graders reward measures such as report rate and time to report, which reveal culture better than click rates alone. Attention to health information roles, such as release of information staff, shows professional focus. Quantifying the cost of slow reporting persuades.

HIM 530 Module 8 help: the mistakes that cost points

HIM 530 culture papers slip when they rely on annual training alone, recommend punishing everyone who clicks, ignore role differences or measure only click rates. Some drafts also forget that supervisors' reactions determine whether staff report. If your course asks about another human factor, such as password sharing, workstation habits or social media, send the prompt so the paper addresses it. Include any phishing or survey data from your case, even rough numbers, and any recent incidents that were reported late. HIM 530 culture papers we write follow this order: incident, why people click, why fear slows reporting, a report-first design, role-based training, fair simulations, leadership, measures and conclusion. Share how many staff work remotely.

Get HIM 530 Module 8 written to your instructions

Send the HIM 530 Module 8 prompt and any phishing or survey results from your case. The paper will explain the human factors, design a report-first culture with easy tools and fair sanctions, tailor training by role, set simulation principles and define measures that value reporting, returned in 24 to 48 hours, with the first sample free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 530 papers and related MS Health Information Management samples

HIM 530 Module 8 questions, answered

Where can I find a free HIM 530 Module 8 Workforce Culture Short Paper sample?

The full HIM 530 Module 8 paper is on this page: phishing, role-based security training and a culture where staff report mistakes quickly.

Why do hospital employees click on phishing emails?

Phishing exploits routine work habits, and research suggests awareness alone does not prevent clicks when staff are busy.

Should employees be disciplined for clicking phishing links?

Punishing honest clicks can delay reporting; many organizations reserve discipline for concealment or repeated disregard of training.

What is a phishing report rate?

The share of recipients who report a simulated or real phishing email, a key sign of a healthy security culture.

What security training do release of information staff need?

Identity verification for callers and requesters, callbacks to numbers on file and recognition of pressure tactics used to obtain records.