| Course | HIM 530 Information Protection & Security in HIM |
|---|---|
| Module | Module 8 |
| Paper type | graduate paper on security culture, phishing and incident reporting |
| Length | About 1,040 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 530 Module 8
Click, Then Call: Building a Security Culture Where Staff Report Mistakes at Osprey Point Health
[Student Name]
Southern New Hampshire University
HIM 530: Information Protection & Security in HIM
Module Eight Short Paper
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Click, Then Call: Building a Security Culture Where Staff Report Mistakes at Osprey Point Health
Last month, a remote coder at Osprey Point Health clicked a link in a message dressed up as a payroll notice and entered her password. She realized her mistake within minutes but waited two days to report it, worried she would be disciplined. In those two days, the attacker used her account to send phishing emails to 300 colleagues. Controls such as multifactor authentication, added under the risk management plan, now limit what a stolen password can do. But the two-day delay points to a problem no tool fixes: a culture in which people hide mistakes.
What the Delay Cost
The two days mattered. Of the 300 colleagues who received the attacker's messages from the coder's real account, 14 opened the link and 3 entered their own passwords before the security team blocked the sender. Investigators then had to review the mailboxes of all four compromised accounts for patient information and determine whether a breach had occurred. The review took about 60 staff hours and found one spreadsheet of release of information requests with patient names, which required a breach risk assessment. Had the coder reported within minutes, the security team estimates that the attacker's messages would have been stopped before any were sent.
Why Busy People Click
Phishing works because it targets ordinary work habits. Among the health systems whose staff Gordon et al. (2019) tested with fake phishing messages, roughly one message in seven drew a click, with the likelihood of clicking falling as more campaigns were conducted. Jalali et al. (2020) studied hospital employees and found that knowing about phishing risk did not by itself keep people from clicking, and they pointed to the pressure of busy work as part of the explanation. For Osprey Point, this means that annual awareness training alone will not solve the problem. Staff who process hundreds of messages a day, many of them urgent, will sometimes click; the goal is to make clicks rarer and reports faster.
Why Fear Slows Reporting
The coder's delay reflects a culture problem. Edmondson (1999) found that teams in which members believed they could raise problems without being punished or embarrassed showed more learning behavior and performed better. In security, the most valuable learning behavior is reporting quickly. Every hour between a click and a report gives an attacker more time. Osprey Point's past practice of listing phishing clicks in employee evaluations taught staff that admitting a click was risky, which is the opposite of what the medical center needs.
A Report-First Culture
The new approach treats a prompt report as success, even after a click. Three changes support it. First, every email client will have a one-click button to report suspicious messages, which sends the message to the security team and removes it from the user's inbox. Second, the sanctions policy will be revised so that an employee who clicks and reports promptly faces no discipline; discipline is reserved for repeated disregard of training or for concealment. Third, the security team will thank reporters personally and publish anonymized monthly examples of phishing caught by staff, showing that reports make a difference.
Role-Based Training
Different roles face different threats. Release of information staff at Osprey Point receive phone calls from people claiming to be patients, attorneys or insurers, and some are attempts to obtain records under false pretenses. Their training will focus on identity verification: calling back through a number on file, requiring written authorizations for third parties and recognizing pressure tactics such as urgent demands from supposed executives. Coders will train on credential theft and on suspicious messages that appear to come from coding software vendors. Supervisors will learn how to respond when an employee reports a mistake, since a manager's first reaction shapes whether the next employee reports at all.
Remote Staff and Home Settings
Most of Osprey Point's health information staff now work from home, where the usual cues of an office are missing. There is no colleague at the next desk to ask whether an email looks odd, and personal and work messages arrive on nearby devices. The culture plan therefore includes a staffed chat channel where anyone can ask the security team about a suspicious message and get an answer within minutes during business hours. Remote staff also receive short training on home risks, such as family members using work laptops and printing records at home, and the remote work policy's rules on private workspaces are reinforced in each team's monthly meeting.
Simulations Done Fairly
Phishing simulations will continue quarterly, since research suggests repeated exposure reduces clicking. They will be designed to teach rather than trap: realistic but not cruel, avoiding lures that exploit staff anxieties such as fake layoff notices or pandemic bonuses. Employees who click see a short explanation of the clues they missed, and those who click repeatedly receive brief one-on-one coaching rather than public identification.
Leaders Set the Tone
Culture follows what leaders do. The chief executive and department directors will complete the same simulations and training as staff, and the chief information officer will describe at a town hall a time a phishing email nearly fooled her. When a leader reports a suspicious message, the security team will say so, with permission, in its monthly update. These signals tell staff that anyone can be fooled and that reporting is expected at every level.
Measuring Culture
Table 1 lists the measures, which value reporting as highly as avoiding clicks.
Table 1. Security Culture Measures
| Measure | Current | Target in 12 months |
|---|---|---|
| Simulated phishing click rate | 11% | 5% |
| Simulated phishing report rate | 4% | 40% |
| Median time from real click to report | About 2 days (last incident) | Under 30 minutes |
| Staff agreeing they can report mistakes without blame | 48% | 75% |
| Release of information calls failing verification that are escalated | Not tracked | 100% logged and escalated |
Note. Measures and targets proposed by the author; composite data.
Conclusion
Osprey Point cannot train every click away, but it can make clicks rarer and reports immediate. Understanding why busy people click, removing the fear that delays reporting, making reporting easy, training by role, running fair simulations and having leaders model the behavior build a culture in which a mistake like the coder's is reported in minutes rather than days.
References
Edmondson, A. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2), 350-383. https://doi.org/10.2307/2666999
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Jalali, M. S., Bruckes, M., Westmattelmann, D., & Schewe, G. (2020). Why employees (still) click on phishing links: Investigation in hospitals. Journal of Medical Internet Research, 22(1), Article e16775. https://doi.org/10.2196/16775
What the HIM 530 Module 8 instructions ask for
The HIM 530 workforce culture paper looks at people as both the weakest and strongest part of information protection. Graduate length of four to five pages in APA 7, with research on human behavior and security, fits most sections. Begin with a concrete incident or data, such as phishing results, then explain why staff make security mistakes and why fear slows reporting. Propose a culture that rewards prompt reporting, with easy reporting tools and a sanctions policy that separates honest mistakes from concealment. Add training tailored to roles, including release of information threats such as pretext callers, principles for fair simulations, leadership modeling and measures that value reporting as well as avoiding mistakes.
How this HIM 530 Module 8 workforce culture short paper example is built
A remote coder at Osprey Point Health enters her password on a fake payroll page and waits two days to report it, while the attacker emails 300 colleagues. Gordon and colleagues and Jalali and colleagues explain why busy hospital staff click despite training, and Edmondson's work on psychological safety explains the delay. The paper introduces a one-click reporting button, no discipline for prompt reporters, role-based training for release of information staff facing pretext callers, fair quarterly simulations and leaders who share their own near misses. A measures table raises the report rate target from 4% to 40% in this HIM 530 paper. The two-day delay led to three more stolen passwords.
Where the HIM 530 Module 8 rubric puts the points
Workforce culture papers in HIM 530 are usually graded on understanding of human factors in security, use of research on phishing and reporting, a culture design that rewards the right behavior, role-based training, fair simulations, leadership involvement, meaningful measures and APA 7 mechanics. Papers that stand out recognize that punishing clicks can make organizations less safe by delaying reports and propose sanctions that distinguish mistakes from concealment. Graders reward measures such as report rate and time to report, which reveal culture better than click rates alone. Attention to health information roles, such as release of information staff, shows professional focus. Quantifying the cost of slow reporting persuades.
HIM 530 Module 8 help: the mistakes that cost points
HIM 530 culture papers slip when they rely on annual training alone, recommend punishing everyone who clicks, ignore role differences or measure only click rates. Some drafts also forget that supervisors' reactions determine whether staff report. If your course asks about another human factor, such as password sharing, workstation habits or social media, send the prompt so the paper addresses it. Include any phishing or survey data from your case, even rough numbers, and any recent incidents that were reported late. HIM 530 culture papers we write follow this order: incident, why people click, why fear slows reporting, a report-first design, role-based training, fair simulations, leadership, measures and conclusion. Share how many staff work remotely.
Get HIM 530 Module 8 written to your instructions
Send the HIM 530 Module 8 prompt and any phishing or survey results from your case. The paper will explain the human factors, design a report-first culture with easy tools and fair sanctions, tailor training by role, set simulation principles and define measures that value reporting, returned in 24 to 48 hours, with the first sample free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 530 papers and related MS Health Information Management samples
- HIM 530 Module 1 Discussion: Privacy, Security and Confidentiality in HIM Practice
- HIM 530 Module 2 Frameworks Short Paper: The HIPAA Security Rule Beside the NIST Framework
- HIM 530 Module 3 Final Project Milestone One: A Security Risk Analysis for the Medical Center
- HIM 530 Module 4 Access Monitoring Short Paper: Insider Snooping and Audit Log Review
- HIM 530 Module 5 Final Project Milestone Two: A Risk Management Plan
- HIM 530 Module 6 Third-Party Risk Short Paper: Business Associates and Vendor Oversight
- HIM 530 Module 7 Final Project Milestone Three: Incident Response and Breach Notification
- HIM 530 Module 9 Final Project: The Information Protection Program
- HIM 530 Module 10 Reflection: What Protecting Information Taught the Writer
- HIM 520 Module 8 Policy Short Paper: Revising the Remote Work Policy
- HIM 500 Module 1 Discussion: What Informatics Is and Why HIM Leaders Need It
- HIM 510 Module 7 Final Project Milestone Three: Procedures That Carry Out the Policy
- HIM 440 Module 5 Final Project Milestone Two: A Process Improvement Plan for Unbilled Accounts
HIM 530 Module 8 questions, answered
Where can I find a free HIM 530 Module 8 Workforce Culture Short Paper sample?
The full HIM 530 Module 8 paper is on this page: phishing, role-based security training and a culture where staff report mistakes quickly.
Why do hospital employees click on phishing emails?
Phishing exploits routine work habits, and research suggests awareness alone does not prevent clicks when staff are busy.
Should employees be disciplined for clicking phishing links?
Punishing honest clicks can delay reporting; many organizations reserve discipline for concealment or repeated disregard of training.
What is a phishing report rate?
The share of recipients who report a simulated or real phishing email, a key sign of a healthy security culture.
What security training do release of information staff need?
Identity verification for callers and requesters, callbacks to numbers on file and recognition of pressure tactics used to obtain records.