HIM 560 Module 3 Final Project Milestone One Example

Reviewed by Delia Ravenscroft, MSN, RN

This HIM 560 Module 3 Final Project Milestone One sample takes stock of the technology a hospital already runs before anyone proposes a change. It is written for SNHU HIM 560 (HIM-560), where MS Health Information Management students open their capstone with an honest picture of the systems in place today. At the composite 220-bed hospital with four rural clinics on the Texas Gulf Coast, the director inventories eight systems and the network and backup arrangements beneath them, interviews staff who use them and rates each against six criteria: vendor support, fit with workflow, security, resilience, interoperability and cost. The assessment finds the greatest risks in places few people look, a server room below flood level, backups stored beside the servers and an interface engine no longer supported, and ranks them for the requirements milestone that follows.

CourseHIM 560 HIM Informatics and Technology Infrastructure
ModuleModule 3
Paper typegraduate milestone assessing a hospital's current technology infrastructure
LengthAbout 1,020 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Health Information Management
UpdatedOctober 2026

Free sample paper for HIM 560 Module 3

1

Final Project Milestone One: What We Run Today. A Current-State Infrastructure Assessment of Pelican Shoals Health

[Student Name]

Southern New Hampshire University

HIM 560: HIM Informatics and Technology Infrastructure

Final Project Milestone One

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title signals an inventory of the present before any proposal.
2

Final Project Milestone One: What We Run Today. A Current-State Infrastructure Assessment of Pelican Shoals Health

Pelican Shoals Health must replace its document imaging system within eighteen months, when the vendor ends support, and leaders have asked whether the hospital should use the occasion to rethink its wider technology. That question cannot be answered well without a clear view of what exists now. This milestone inventories the hospital's health information systems and the infrastructure beneath them, explains how they were assessed, rates each against six criteria and ranks the gaps that the next milestone's requirements must address.

What this page is doingThe introduction explains why the assessment comes first.
3

Scope and Methods

The assessment covers systems that create, store or move patient information used by the health information department, together with the servers, network and backup arrangements that support them. Clinical systems such as pharmacy and radiology are included only where they feed the record through interfaces.

Three methods were used. Contracts, support notices and the IT asset list provided vendor and version information. Twelve interviews, with coders, release-of-information staff, clinic managers, nurses and the two IT analysts, explored how each system fits daily work. A walk-through of the server room, network closets and backup process checked what the documents said. Sittig and Singh (2010) argue that health IT must be judged across technical and social dimensions, so interviews carried as much weight as the asset list.

What this page is doingScope and methods combine documents, interviews and observation.
4

The Inventory

Table 1 summarizes the systems and supporting infrastructure found, with the rating assigned to each. Ratings of good, fair or poor reflect the six criteria described below.

Table 1. Current Systems and Infrastructure with Overall Ratings

ComponentDescriptionMain concernRating
Inpatient recordMid-market vendor, hosted in the hospital's basement server roomPhysical location and aging serversFair
Clinic recordDifferent vendor, hosted by that vendorNo electronic link to the hospitalFair
Document imagingOn-site system, support ends in eighteen monthsEnd of support; slow retrievalPoor
Coding encoderVendor-hosted web applicationNone significantGood
Release of informationOutsourced vendor portalManual uploads from imagingFair
Interface engine42 point-to-point interfaces; version no longer supportedNo vendor fixes; one analyst knows itPoor
Network to clinicsOne leased circuit per clinic, no backup pathClinic outage if a circuit failsFair
BackupsNightly to disk in the server room; weekly copy to a site 3 miles inlandBackups share the servers' flood riskPoor

Note. Prepared by the author from the asset list, contracts, interviews and a site walk-through.

What this page is doingTable 1 inventories and rates each component.
5

Assessment Criteria

Each component was rated on six criteria. Vendor support asked whether security fixes and help are still available. Workflow fit asked whether staff can do their work without workarounds. Security asked whether access controls, patching and monitoring meet current practice. Resilience asked how quickly the component could recover from failure or disaster. Interoperability asked whether it can exchange data using current standards. Cost asked what it takes to keep it running, including staff time. A component rated poor on either vendor support or resilience was rated poor overall, because those failures can stop work entirely.

What this page is doingCriteria are defined before findings.
6

Findings: Resilience

The most serious findings concern resilience. The server room sits in the basement of the original building and took on water during a hurricane six years ago; the room has since gained a pump but not a new location. Nightly backups are written to disks in the same room, and only a weekly copy leaves the building, so a flood could destroy both servers and up to six days of backups. The NIST contingency planning guide recommends that organizations set recovery objectives through a business impact analysis and keep backups at a location not exposed to the same threats (Swanson et al., 2010). Neither step has been taken. Ransomware makes the gap more pressing: Neprash et al. (2022) counted ransomware incidents at hospitals, clinics and other care providers and found the yearly number more than twice as high in 2021 as in 2016, with care frequently interrupted, and disk backups on the same network can be encrypted along with the systems they protect.

What this page is doingResilience gaps are identified with recognized guidance.
7

Findings: Support and Interfaces

Two systems are near or past the end of vendor support. The imaging system's support ends in eighteen months, after which security fixes stop. Its retrieval is also slow: release-of-information staff reported waiting up to a minute for large charts and printing records to upload them manually to the outsourced portal. The interface engine's version is already unsupported, and only one analyst understands its configuration. When the dictation interface failed last spring, recovery depended on that analyst being reachable. Forty-two point-to-point interfaces also mean forty-two places where a change in one system can break another.

What this page is doingSupport and interface risks are described.
8

Findings: Workflow and Exchange

Interviews showed that most workarounds involve moving information between systems. Health information staff scan about 120 faxed pages a day from the clinics. Nurses print clinic notes for admitted patients. Coders open three applications to code one chart. Clinic managers described a single circuit outage last year that left one clinic without its record for most of a day, with appointments continued on paper. These workarounds cost staff time and create chances for error, and they point to interoperability and network redundancy as the areas where improvement would be felt most directly. Staff also described informal fixes that no document records, such as a coder who keeps a personal spreadsheet of charts awaiting late reports and a clinic manager who photographs the day's schedule each morning in case the circuit fails. These habits show where people have stopped trusting the systems.

What this page is doingInterview findings reveal workarounds.
9

Ranked Gaps

The gaps are ranked by their risk to patients and operations. First, backups and servers share a flood-prone location, and no recovery objectives exist. Second, the interface engine is unsupported and depends on one person. Third, document imaging will lose support within eighteen months. Fourth, the clinics cannot exchange data electronically with the hospital. Fifth, each clinic depends on a single network circuit. The encoder and the clinic record hosting are adequate for now.

What this page is doingGaps are ranked for the next milestone.
10

Conclusion

Leaders asked about document imaging, but the assessment shows that the hospital's largest risks lie in where its systems and backups are kept and in an interface engine few understand. The requirements milestone will therefore treat imaging replacement as one part of a wider set of needs that includes recovery, integration and clinic connectivity.

What this page is doingThe conclusion reframes the project's scope.
11

References

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

Sittig, D. F., & Singh, H. (2010). A new sociotechnical model for studying health information technology in complex adaptive healthcare systems. Quality and Safety in Health Care, 19(Suppl. 3), i68-i74. https://doi.org/10.1136/qshc.2010.042085

Swanson, M., Bowen, P., Phillips, A. W., Gallup, D., & Lynes, D. (2010). Contingency planning guide for federal information systems (NIST Special Publication 800-34, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-34r1

What the HIM 560 Module 3 instructions ask for

Milestone One of the HIM 560 final project asks for a current-state assessment of your organization's technology infrastructure, or of the course case. Four to six pages in APA 7, drawing on scholarly and government sources, is the usual scope. Define the scope, explain how you gathered information, such as documents, interviews and observation, and inventory the systems, interfaces, network and backup arrangements involved. Set clear criteria before rating anything, such as vendor support, workflow fit, security, resilience, interoperability and cost, and rate each component against them, ideally in a table. Report the most important findings with evidence and rank the gaps so the next milestone knows which needs to address first.

How this HIM 560 Module 3 final project milestone one example is built

Pelican Shoals Health's director inventories eight components, from an inpatient record in a basement server room to 42 interfaces on an unsupported engine, and rates each after twelve interviews and a walk-through. The worst findings concern resilience: backups share the servers' flood risk, no recovery objectives exist and the NIST contingency guide by Swanson and colleagues recommends both. Neprash and colleagues' ransomware trends add urgency, while Sittig and Singh's model justifies weighting interviews. Workarounds include scanning 120 faxed pages a day and coders opening three applications. The HIM 560 milestone ranks five gaps and widens the project beyond imaging to recovery, integration and clinic connectivity.

Where the HIM 560 Module 3 rubric puts the points

HIM 560 current-state milestones tend to be graded on a clearly defined scope, sound information-gathering methods, a complete inventory, explicit criteria applied consistently, findings supported by evidence and gaps ranked by risk, along with APA 7 citations. Strong assessments go beyond an asset list to include how people actually use the systems and where workarounds occur. Graders reward attention to infrastructure that is easy to overlook, such as backups, network paths and interface engines, because these often carry the greatest risk. An assessment that changes how leaders frame the project, rather than confirming their first assumption, shows real analytical value. Recording informal workarounds adds depth that an asset list cannot.

HIM 560 Module 3 help: the mistakes that cost points

Current-state milestones in HIM 560 lose points for listing systems without rating them, skipping interviews, using criteria that are never defined or proposing solutions before the assessment is finished. Some drafts also ignore backups and network infrastructure entirely, even though those are often where the largest risks sit. If your case is different, such as a physician practice, a long-term care organization or a system after a merger, send the guidelines and any details you have and the assessment will fit that setting. A rough list of your systems and vendors helps even if incomplete. HIM 560 milestones we write define scope, gather evidence three ways, rate components on stated criteria and rank the gaps by risk to patients and operations.

Get HIM 560 Module 3 written to your instructions

Send the HIM 560 Milestone One guidelines and whatever you know about your organization's systems, vendors, network and backups. The assessment will define scope and methods, inventory and rate each component against stated criteria, report evidence-based findings and rank the gaps for your requirements milestone, ready in 24 to 48 hours, free on a first request. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More HIM 560 papers and related MS Health Information Management samples

HIM 560 Module 3 questions, answered

Where can I find a free HIM 560 Module 3 Milestone One sample?

The whole HIM 560 Milestone One assessment appears here: a current-state assessment of a hospital's systems, network, interfaces and backups, rated against six criteria.

What is a current-state technology assessment?

A structured review of existing systems and infrastructure, how they are used and how well they meet defined criteria before changes are planned.

Why include interviews in an infrastructure assessment?

Documents show what systems exist; interviews show how people actually use them and where workarounds and risks occur.

What is a business impact analysis?

A step in contingency planning that identifies critical processes and sets how quickly each must be restored and how much data loss is acceptable.

Why are backups stored in the same building a risk?

A flood, fire or ransomware attack that damages the servers can destroy or encrypt the backups at the same time.