HIM 530 Module 9 Final Project Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 530 Module 9 Final Project sample proposes a complete information protection program, joining the risk analysis, risk management plan and incident response plan from earlier milestones with access monitoring, vendor oversight and workforce culture. It is written for SNHU HIM 530 (HIM-530), and it models the finished program MS Health Information Management students present as their closing deliverable. The composite 420-bed regional medical center in coastal North Carolina had an outdated risk analysis, an unsupported imaging archive, snooping found only by complaint and an untested response plan. The program sets purpose and scope, establishes governance, describes six connected components, lays out a twelve-month roadmap and first-year budget, defines a board dashboard and names the risks to the program itself, citing research and federal guidance.

CourseHIM 530 Information Protection & Security in HIM
ModuleModule 9
Paper typegraduate final project proposing a complete information protection program
LengthAbout 1,080 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedSeptember 2026

Free sample paper for HIM 530 Module 9

1

Final Project: Protecting Patients' Information as One Program, an Information Protection Proposal for Osprey Point Health

[Student Name]

Southern New Hampshire University

HIM 530: Information Protection & Security in HIM

Final Project

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title emphasizes a single, connected program.
2

Final Project: Protecting Patients' Information as One Program, an Information Protection Proposal for Osprey Point Health

Executive Summary

Osprey Point Health protects patient information through a collection of separate efforts: an information technology security team, a privacy office, a release of information unit and annual training. Each works, but none sees the whole. This proposal combines them into one information protection program governed by a steering committee and built on six components: annual risk analysis, risk management, access monitoring, vendor oversight, incident response and a report-first workforce culture. First-year cost is about $552,000, most of it for replacing an unsupported imaging archive and adding multifactor authentication. Leadership is asked to approve the program, its budget and a quarterly dashboard to the board.

What this page is doingThe executive summary states the problem, program, cost and request.
3

Purpose and Scope

The program exists to keep patient information private, accurate and available when needed, so that patients can trust Osprey Point and care can continue when systems fail. Its scope covers all patient information in any form, paper or electronic, held by the medical center or its business associates, and all workforce members, including remote staff, students and contractors.

What this page is doingPurpose and scope are defined.
4

Governance

The NIST framework's newest function, Govern, places strategy, roles, policy and oversight above all other security activities (NIST, 2024). Jalali and Kaiser (2018) found in their study of hospital cybersecurity that organizational factors, such as leadership attention and coordination between departments, shaped security as much as technology. The program therefore starts with governance: an information protection steering committee whose chair is the chief information officer and whose members are the privacy officer, information security officer, health information director, compliance officer, a physician leader and a nursing leader. The committee owns the risk register, approves major controls and accepted risks and reports to the board's audit committee every quarter.

What this page is doingGovernance is established with supporting guidance and research.
5

Six Components

Each component draws on earlier work. Annual risk analysis, following federal guidance, keeps the register current and is repeated after major changes. Risk management assigns each significant risk a response, owner, cost and date, beginning with isolating and then retiring the imaging archive and requiring multifactor authentication. Access monitoring combines rules and analytics to find snooping before patients do, since Jiang and Bai (2019) found that many breaches start inside organizations. Vendor oversight tiers 38 business associates, scales due diligence to risk and plans for the failure of critical vendors. Incident response assigns roles, severity levels and notice deadlines and is exercised twice a year, with regional partners informed early because, as Dameff et al. (2023) showed, one hospital's ransomware outage spills into neighboring emergency departments. Workforce culture rewards prompt reporting, trains by role and runs fair phishing simulations, which Gordon et al. (2019) linked to fewer clicks over repeated campaigns.

What this page is doingThe six components are summarized with evidence.
6

How the Components Connect

The components feed each other. Incidents and monitoring alerts update the risk register. The register sets priorities for risk management and vendor oversight. Culture determines how quickly incidents are reported, which affects how much damage response must contain. Post-incident reviews change training, controls and contracts. Treating these as one cycle under one committee is the core change the program makes.

What this page is doingThe program is described as one connected cycle.
7

What Changes for Staff

For most employees, the program will be visible in a few concrete ways. Everyone will log in to email and remote systems with a second factor. A report button will appear in every email client, and reporting a suspicious message will earn thanks rather than suspicion. Staff who open sensitive records will occasionally be asked to state a reason. Health information staff will see new verification steps for callers and standard record sets for requests. Supervisors will receive short monthly summaries of their teams' training and phishing results, framed as coaching information rather than scorecards. Explaining these changes before they arrive, and why each one matters, will do more for adoption than any policy memo.

What this page is doingThe program's visible effects on staff are described.
8

Links to Health Information Management

Several parts of the program sit naturally with the health information department. Release of information verification, minimum necessary record sets, audit of record access, the return of downtime paper records after recovery and breach risk assessments all draw on health information expertise. Placing the privacy officer and the health information director on the steering committee ensures that protection is judged by its effect on the record and on patients' rights, not only by technical measures such as patch levels or firewall rules.

What this page is doingHIM's role in the program is made explicit.
9

Twelve-Month Roadmap

Table 1 sequences the program's first year.

Table 1. Twelve-Month Roadmap

QuarterKey actions
1Charter steering committee; isolate imaging archive; begin multifactor authentication; one-click phishing reporting; revise sanctions policy
2Complete multifactor rollout; immutable backups with first restore test; vendor tiering and Tier 1 reassessments; rule-based access alerts
3Vendor remote access controls; medical device network segment; access analytics pilot; first tabletop exercise under new plan
4Complete archive migration; second clearinghouse live; annual risk analysis update; program review and report to the board

Note. Roadmap prepared by the author with the steering committee.

What this page is doingTable 1 sequences the first year.
10

First-Year Budget

Spending in year one comes to about $552,000: $443,000 for the risk management controls, including $180,000 for archive migration and $38,000 for access monitoring tools; $45,000 for a half-time vendor risk analyst; $30,000 for phishing simulation and training; $24,000 for tabletop facilitation and forensic retainer; and $10,000 for printed downtime materials and contact binders. Several items, such as multifactor authentication and tested backups, are also likely to be required by the cyber insurer at renewal, which offsets part of their cost.

What this page is doingThe first-year budget is itemized.
11

Board Dashboard

Each quarter, board members will see a single page of eight measures: number of high risks and their trend; share of risk management items completed on time; multifactor authentication coverage; share of snooping cases found by monitoring rather than complaint; Tier 1 vendors reassessed on schedule; days since the last successful restore test; phishing report rate; and incidents by severity with notice deadlines met. Each measure has a target and a named owner.

What this page is doingA board dashboard with owners and targets is defined.
12

Risks to the Program

The program itself faces risks. Budget pressure could delay archive migration, leaving isolation as a longer-term fix; the committee will accept that explicitly if it occurs. Staff turnover in the small security team could stall work, so key procedures are documented and cross-trained. And attention may fade after the first year, which the quarterly board dashboard is designed to prevent.

What this page is doingThree threats to the program's own success are paired with responses.
13

Conclusion

Osprey Point's patients are protected today by capable people working in separate lanes. Bringing them together under one governance structure, with six connected components, a sequenced roadmap, a realistic budget and a quarterly report card for the board, would turn information protection from a set of tasks into a program that learns and improves.

What this page is doingThe conclusion restates the program's value.
14

References

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), Article e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

Jalali, M. S., & Kaiser, J. P. (2018). Cybersecurity in hospitals: A systematic, organizational perspective. Journal of Medical Internet Research, 20(5), Article e10059. https://doi.org/10.2196/10059

Jiang, J. X., & Bai, G. (2019). Evaluation of causes of protected health information breaches. JAMA Internal Medicine, 179(2), 265-267. https://doi.org/10.1001/jamainternmed.2018.5295

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29

What the HIM 530 Module 9 instructions ask for

The HIM 530 final project asks you to propose a complete information protection program that brings together your risk analysis, risk management plan and incident response plan. Plan on 1,500 words or more in APA 7 with tables and current research and federal guidance. Open with an executive summary stating the problem, the program, its cost and the decisions you need. Define purpose and scope, set up governance with clear roles and reporting, describe each component and how the components connect, sequence the work over a year, itemize the budget and define a dashboard with owners and targets. Name risks to the program itself, and revise milestone material rather than repeating it word for word.

How this HIM 530 Module 9 final project example is built

Osprey Point Health's program proposal opens with an executive summary: separate security efforts combined into one program costing about $552,000 in its first year. A steering committee reports to the board's audit committee, grounded in NIST's Govern function and Jalali and Kaiser's organizational findings. Six components, from annual risk analysis to a report-first culture, draw on Jiang and Bai, Dameff and colleagues and Gordon and colleagues. A quarterly roadmap, an itemized budget, an eight-measure board dashboard with owners and three risks to the program complete this HIM 530 final project, which ends by describing a program that learns from every incident. Sections explain what changes for staff and where health information expertise leads.

Where the HIM 530 Module 9 rubric puts the points

Final projects in HIM 530 tend to be graded on a clear executive summary, defined purpose and scope, effective governance, complete and connected components, a realistic roadmap and budget, meaningful measures with owners, awareness of program risks, integration of earlier milestones and APA 7 mechanics. Programs that stand out show how components feed one another and give leaders a small set of measures they can act on. Graders reward budgets tied to specific risks and governance that reaches the board. Evidence of revision, rather than pasted milestones, shows the work has become a coherent proposal a real organization could adopt. Explaining changes for staff aids adoption.

HIM 530 Module 9 help: the mistakes that cost points

HIM 530 final projects slip when they list security activities without governance, repeat milestones without integrating them, omit costs or measures or ignore people and vendors. Some drafts also forget to tell leaders what decisions are needed. If your case organization is a clinic, health plan or business associate, or if your milestones reached different conclusions, send all your milestones and feedback so the program reflects your own analysis. Mention any budget ceiling you were given and the committees your case organization already has. HIM 530 programs we write follow this order: summary, purpose and scope, governance, components, connections, roadmap, budget, dashboard, program risks and conclusion. Include your department's role.

Get HIM 530 Module 9 written to your instructions

Send the HIM 530 final project guidelines along with your milestones and instructor feedback. The proposal will open with an executive summary, set governance, integrate six connected components, sequence a year of work, itemize costs and define a board dashboard and program risks, delivered in 24 to 48 hours with the first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 530 papers and related MS Health Information Management samples

HIM 530 Module 9 questions, answered

Where can I find a free HIM 530 Module 9 Final Project sample?

This page carries the complete HIM 530 Module 9 project: an information protection program with governance, six components, a roadmap, budget and board dashboard.

What is an information protection program?

A governed set of connected activities, such as risk analysis, controls, monitoring, vendor oversight, incident response and training, that protect patient information.

Who should govern a hospital's information protection program?

A steering committee with security, privacy, health information, compliance and clinical leaders, reporting regularly to the board.

What measures should a board see about information protection?

A short dashboard covering high risks, control completion, authentication coverage, proactive detection, vendor reviews, restore tests, phishing reporting and incidents.

How should an information protection budget be justified?

By tying each cost to a specific risk from the risk analysis and showing the expected reduction in residual risk.