IHP 355 Module 3 Privacy Short Paper Example

Reviewed by Delia Ravenscroft, MSN, RN

This IHP 355 Module 3 Privacy Short Paper sample shows how a compliance office turns two privacy incidents into a stronger HIPAA program. It is written for SNHU IHP 355 (IHP-355), part of the BS Healthcare Administration curriculum. At a composite hospital, an unencrypted laptop with patient spreadsheets was stolen from a car, and an access audit found six employees had opened a local celebrity's record without reason. Annas explains that the HIPAA Privacy Rule gave patients rights to see and amend their records and limited how their information may be used and shared. Liu and colleagues found that most reported breaches involved theft or loss, often of laptops and portable devices, with hacking rising. Kruse and colleagues reviewed security techniques and found encryption, access control and audit among the most common. The paper recommends safeguards, owners and measures.

CourseIHP 355 Healthcare Regulatory Compliance and Accreditation
ModuleModule 3
Paper typeshort paper on HIPAA privacy and security compliance
LengthAbout 1,020 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramBS Healthcare Administration
UpdatedSeptember 2026

Free sample paper for IHP 355 Module 3

1

A Stolen Laptop and a Curious Click: Strengthening HIPAA Compliance at a Community Hospital

[Student Name]

Southern New Hampshire University

IHP 355: Healthcare Regulatory Compliance and Accreditation

Module Three Short Paper

[Instructor Name]

[Date]

What this page is doingThe title names the two incidents that prompted the review.
2

A Stolen Laptop and a Curious Click: Strengthening HIPAA Compliance at a Community Hospital

In one month, Riverbend's compliance office faced two privacy problems. A manager's laptop, holding spreadsheets with names, dates of birth and diagnoses for about 1,900 patients, was stolen from a parked car. A password guarded the machine, yet nothing on its drive was encrypted. Two weeks later, a routine access audit found that six employees had opened the electronic record of a local television anchor admitted for surgery, none of whom were involved in her care. This paper explains what the HIPAA Privacy and Security Rules require, what research shows about how health information is lost and what safeguards the hospital should adopt.

What this page is doingThe introduction presents two incidents that frame the paper.
3

What the Privacy Rule Requires

Congress's 1996 HIPAA statute told the federal health department to write privacy standards, and the Privacy Rule took effect for most covered entities in 2003. Annas (2003) described what the rule changed. Patients could now review and copy their own records, to request corrections, to receive a notice of privacy practices and to get an accounting of certain disclosures. Hospitals, health plans and clearinghouses may share patient information to deliver care, get paid and run the organization, while nearly everything else needs the patient's written permission, and uses must generally be limited to the minimum necessary. Annas also noted the rule's complexity and gaps, including its reliance on organizations to police their own workforce.

What this page is doingThe rule's patient rights and limits are summarized from the source.
4

The Security Rule and Breach Notification

The Security Rule adds requirements for electronic protected health information, organized into administrative, physical and technical safeguards, such as risk analysis, workforce training, facility access controls, access management and audit controls. Later amendments under the HITECH Act strengthened enforcement and required notification of patients, the federal government and, for larger breaches, the media when unsecured information is breached. Information that is properly encrypted is generally not considered unsecured, which is why the missing encryption on Riverbend's laptop turned a theft into a reportable breach.

What this page is doingSecurity safeguards and breach notification are explained, linking encryption to the incident.
5

Where Breaches Happen

Liu et al. (2015) analyzed breaches affecting 500 or more people that were reported to the federal government over several years. Theft was the most common cause, and laptops and other portable devices were frequently involved, along with paper records. Breaches caused by hacking and other information technology incidents were less common but growing, and a small number of large breaches accounted for most of the records affected. The findings suggest that many breaches result from ordinary lapses, such as leaving an unencrypted device in a car, rather than sophisticated attacks.

Riverbend's laptop theft fits the most common pattern exactly.

What this page is doingResearch on reported breaches shows the laptop theft is typical.
6

Snooping as a Privacy Violation

The celebrity record access is a different kind of problem. Employees looking at records out of curiosity violate the minimum necessary standard and the hospital's policies even if no information leaves the building. These incidents are often discovered only through audits, and they damage trust when patients learn of them. Because the Privacy Rule depends on organizations to control their workforce, as Annas noted, the hospital's response must combine technical monitoring with clear consequences applied consistently.

What this page is doingSnooping is explained as a workforce compliance issue.
7

What Security Techniques Work

Kruse et al. (2017) systematically reviewed techniques used to secure electronic health records. The most frequently reported were encryption of data at rest and in transit, authentication methods such as strong passwords and two-factor login, role-based access control that limits what each user can see and audit trails that record who viewed which records. The authors emphasized combining administrative, physical and technical safeguards rather than relying on any single measure, and they noted that staff behavior remains a major source of risk.

What this page is doingA review of security techniques identifies the main safeguards.
8

Recommendations

Riverbend should adopt six measures. First, require full-disk encryption on every laptop and portable device that can hold patient data, enforced by information technology before a device connects to the network. Second, stop storing patient spreadsheets on local drives, moving them to secure shared storage. Third, expand automated access monitoring so the system flags unusual access, such as views of high-profile patients or of coworkers' records, for daily review. Fourth, apply a consistent sanctions policy for snooping, from retraining for a first minor event to termination for serious or repeated ones. Fifth, refresh privacy training with real, de-identified examples. Sixth, complete the breach notifications required for the laptop incident on time and document the risk assessment.

Table 1. Safeguards, Owners and Measures

SafeguardOwnerMeasure
Full-disk encryption on portable devicesInformation technologyPercent of devices encrypted
No patient data on local drivesInformation technology; department headsLocal-drive scans with findings
Automated access monitoringPrivacy officerFlags reviewed within 24 hours
Consistent sanctions for snoopingHuman resources; privacy officerSanctions applied per policy
Refreshed training with real examplesCompliance officeCompletion rate; quiz results

Note. Measures are reviewed quarterly by the compliance committee.

What this page is doingSix recommendations respond to the two incidents and the research.
9

Responding to the Laptop Breach

Because the laptop was not encrypted, the theft counts as a reportable breach unless the hospital's written risk review shows a low probability that the data were compromised, which is unlikely for a stolen device. With about 1,900 people affected, the hospital must notify each person without unreasonable delay and no later than sixty days after discovery, explaining what happened, what information was involved and what steps they can take. It must also report the breach to the federal government; because fewer than 500 people were affected, that report can be made in the annual log rather than immediately, and media notice is not required. The compliance office should offer a call line for worried patients and document every step, since regulators judge organizations partly on how they respond.

What this page is doingBreach notification steps are applied to the incident's facts.
10

Balancing Privacy and Care

Safeguards must not block care. Encryption and login steps add time, and overly strict access controls can prevent clinicians from seeing information they need in an emergency. The hospital should keep a documented break-the-glass process that lets clinicians override restrictions with a stated reason, which is then audited. Involving clinicians in designing access rules will reduce workarounds that create new risks.

What this page is doingThe need to balance protection with access to care is addressed.
11

Conclusion

The laptop theft and the celebrity chart views were both predictable: research shows that lost devices and inappropriate access are common sources of privacy violations. Encryption, access monitoring, consistent sanctions and practical training address both, and measuring each safeguard will show whether the program is working.

What this page is doingThe conclusion links incidents, evidence and safeguards.
12

References

Annas, G. J. (2003). HIPAA regulations: A new era of medical-record privacy? New England Journal of Medicine, 348(15), 1486-1490. https://doi.org/10.1056/NEJMlim035027

Kruse, C. S., Smith, B., Vanderlinden, H., & Nealand, A. (2017). Security techniques for the electronic health records. Journal of Medical Systems, 41(8), Article 127. https://doi.org/10.1007/s10916-017-0778-4

Liu, V., Musen, M. A., & Chou, T. (2015). Data breaches of protected health information in the United States. JAMA, 313(14), 1471-1473. https://doi.org/10.1001/jama.2015.2252

What the IHP 355 Module 3 instructions ask for

The IHP 355 privacy assignment usually asks you to explain HIPAA's privacy and security requirements and apply them to a scenario, such as a breach, an access complaint or a policy review. Expect two to four pages in APA 7 with a few scholarly sources. Explain what the Privacy Rule and Security Rule require in plain terms, attribute each to the right authority and apply them to the facts. Use research on how breaches occur and which safeguards work, then recommend specific administrative, physical and technical measures with owners. Address breach notification if the scenario involves a loss of data, and remember to balance privacy with clinicians' need to access information. IHP 355 graders notice clean headings in IHP 355 papers.

How this IHP 355 Module 3 privacy short paper example is built

This paper responds to a composite hospital's stolen unencrypted laptop holding data on about 1,900 patients and to six employees who viewed a celebrity's record. Annas explains the Privacy Rule's patient rights and limits on use, and the paper adds Security Rule safeguards and breach notification, noting that encryption would have changed the outcome. Liu and colleagues show theft of portable devices is the most common breach cause, and Kruse and colleagues identify encryption, access control and audits as key techniques. Six recommendations, a table of owners and measures and a break-the-glass process that protects access to care complete it. IHP 355 students can reuse this structure for IHP 355 work. IHP 355 claims here trace to cited IHP 355 sources.

Where the IHP 355 Module 3 rubric puts the points

Privacy papers in IHP 355 are typically graded on accurate explanation of HIPAA requirements, correct application to the scenario, use of research on breaches and safeguards, practical recommendations across administrative, physical and technical categories, attention to breach notification where relevant, scholarly support and APA 7. Strong papers attribute requirements correctly, explain why encryption matters for breach status and assign owners and measures. Papers lose points when they describe HIPAA vaguely, recommend only more training or ignore the need for clinicians to access information during care. Consistent sanctions for snooping are often expected in the recommendations. IHP 355 marks favor careful formatting across IHP 355 sections. IHP 355 citations keep every IHP 355 argument credible.

IHP 355 Module 3 help: the mistakes that cost points

In IHP 355, privacy papers frequently lose points for confusing the Privacy and Security Rules, for missing breach notification duties, for recommendations without owners and for relying on training alone. Another common gap is treating snooping as harmless because no data left the building. Explain requirements accurately, apply them to the facts, use evidence on breaches and safeguards, assign owners and measures and balance privacy with care. If your scenario involves a specific breach size or state privacy law, add those details to your IHP 355 notes and the paper will address them. Add breach size and dates if known. IHP 355 drafts start well from a IHP 355 outline. IHP 355 feedback already received guides IHP 355 revisions.

Get IHP 355 Module 3 written to your instructions

Send the IHP 355 privacy prompt and the scenario you are analyzing. The paper will explain HIPAA's privacy and security requirements accurately, apply them to the facts, use research on breaches and safeguards and recommend measures with owners, within 24 to 48 hours, free the first time. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More IHP 355 papers and related BS Healthcare Administration samples

IHP 355 Module 3 questions, answered

Where can I find a free IHP 355 Module 3 Privacy Short Paper sample?

Read the whole paper here: a stolen laptop and inappropriate record access analyzed under HIPAA, with research on breaches and recommended safeguards.

What rights does the HIPAA Privacy Rule give patients?

Rights to see and copy their records, request corrections, receive a notice of privacy practices and get an accounting of certain disclosures.

What causes most health data breaches?

Research on reported breaches found theft and loss, often of laptops and portable devices, were most common, with hacking rising.

Why does encryption matter under HIPAA?

Properly encrypted data is generally not considered unsecured, so a lost encrypted device usually does not trigger breach notification.

Is looking at a coworker's or celebrity's chart a HIPAA violation?

Yes, viewing records without a work-related need violates the minimum necessary standard and hospital policy, even if nothing is shared.