HCIS 352 Week 4 Healthcare Information Operational Security Risks Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HCIS 352 Week 4 example identifies and ranks the operational security risks in a health care organization's daily technology use, and the paper appears after the facts table in APA 7 form. Week four of University of Phoenix HCIS 352, which the catalog lists as HCIS/352, shifts health IT and health administration students from building and maintaining systems to the day-to-day threats that can take them down or expose patient data. The sample examines a composite outpatient physical therapy group with 12 clinics that recently moved its scheduling, documentation and billing to cloud services. It describes eight operational risks found in a walk-through, from an exposed remote desktop connection and shared logins to unpatched exercise equipment tablets, rates each for likelihood and impact, and matches controls from federal cybersecurity practices for smaller health organizations. National ransomware data show why the top risks come first.

CourseHCIS 352 Foundations of it in the Health Care Environment (HCIS/352)
Week4
Paper typeOperational security risk assessment
Lengthabout 1,013 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Health Administration
UpdatedSeptember 2026

Free sample paper for HCIS 352 Week 4

1

Twelve Clinics, One Cloud and a Remote Desktop Left Open: The Operational Security Risks Facing an Outpatient Physical Therapy Group and How to Rank Them

[Student Name]

University of Phoenix

HCIS/352: Foundations of it in the Health Care Environment

Week 4 Assignment

[Instructor Name]

[Date]

The practice group, its incidents and its figures are composites written for a model paper; guidance and findings come from the sources listed.

What this part is doingThe title names the setting, its scale and the specific exposure that started the review, which grounds the risk list in a real situation.
2

Last spring, the IT contractor for a composite outpatient physical therapy group noticed thousands of failed login attempts on a remote desktop connection that someone had opened years ago for a vendor and never closed. No one had broken in, but the attempts showed that attackers had found the door. The group, with 12 clinics, 140 staff and about 1,800 visits a week, had recently moved scheduling, documentation and billing to cloud services and assumed that security was now the vendors' job. This paper describes the operational security risks a walk-through revealed, ranks them and recommends controls.

The Environment

Therapists document on laptops and tablets using a cloud-hosted therapy EHR. Front desks use shared workstations for scheduling and payments. Billing is outsourced to a company that logs into the EHR remotely. Each clinic has exercise equipment with attached tablets that track patients' exercises, and a network that also serves patient Wi-Fi. There is no IT department, only the contractor, available eight hours a week, and no one on staff owns security.

Eight Risks

Exposed remote access: the open remote desktop connection to an office server still holding old scanned records. Phishing: staff email accounts protected only by passwords. Shared logins: front desk staff at several clinics share one scheduling account. Unpatched devices: exercise equipment tablets running an outdated operating system, on the same network as clinic laptops. Lost or stolen laptops: therapists take laptops home, and two were stolen from cars last year, one without encryption. Vendor outage: if the cloud EHR goes down, clinics have no downtime procedures. Former employees: accounts are removed by email request, sometimes weeks late. Backups: the old office server's backups are stored on a drive attached to the same server.

Rating the Risks

Each risk was rated from 1 to 3 for likelihood and for impact, and the two ratings multiplied. Exposed remote access scored 9, likely and severe, because remote desktop is a common ransomware entry point and the server held patient records. Phishing scored 9 as well. Unencrypted laptops and shared logins scored 6. Former employee accounts and backups on the same server scored 6. Unpatched equipment tablets scored 4, and a vendor outage 4. The ranking changed the group's instinct, which had been to buy new antivirus software; the top risks were an open door and passwords without a second factor, both of which cost little to fix.

What this part is doingA simple, consistent rating turns a list into a priority order, which is the step most risk papers skip.
3

Why the Top Risks Come First

Neprash et al. (2022) counted 374 ransomware incidents at American hospitals, clinics and other care providers across six years ending in 2021, with yearly incidents more than doubling, and found that almost half disrupted care, most often through downtime, sometimes through canceled appointments. For a therapy group, a ransomware attack would mean days of canceled visits and lost revenue, along with notification of patients whose records were exposed.

Controls Matched to the Risks

A federal public-private effort known as the 405(d) program publishes Health Industry Cybersecurity Practices, including a technical volume for small organizations, whose recommended practices for smaller practices range from protecting email and endpoints to managing access, preventing data loss and training staff (U.S. Department of Health and Human Services, 2023). The group's controls follow that guidance. Exposed remote access: close it immediately, move remaining records to the cloud EHR and give the billing company access only through the EHR's own accounts with multifactor login. Phishing: turn on multifactor authentication for all email, add external-sender warnings and run quarterly phishing training. Shared logins: issue individual accounts and set screen locks. Laptops: encrypt every device and enroll all in remote management so they can be wiped. Former employees: link account removal to the payroll change form, with a same-day deadline. Backups: move backups off the server to an offline or immutable cloud copy.

The Lower-Ranked Risks

Equipment tablets will be moved to a separate network segment, since they cannot be patched quickly. For vendor outages, each clinic will print the next day's schedule and keep paper evaluation forms, and the group will review the vendor's uptime and incident history at contract renewal.

What this part is doingLower-ranked risks still receive responses, but cheaper ones, which shows judgment about limited resources.
4

People as the Last Line

Several of the eight risks are really habits: sharing a login to save time, leaving a laptop in a car, clicking a convincing email. Controls help, but staff behavior decides how well they work. The group's clinic managers will spend five minutes of each monthly staff meeting on one security habit, using real examples from the walk-through without naming anyone, and front desk staff will be told plainly that reporting a suspicious email or a lost device quickly is never a disciplinary matter. A group this size cannot afford a security team, but it can build a culture in which people notice problems and speak up.

Meeting the Rules

Under the HIPAA Security Rule, covered entities must assess and manage risks to electronic protected health information using administrative, physical and technical safeguards (U.S. Department of Health and Human Services, 2022). The walk-through and ratings form the start of the group's documented risk analysis, which it had never completed.

Costs

Multifactor authentication is included in the group's email subscription. Device management and encryption cost about $6 per device per month. Network segmentation for 12 clinics costs about $9,000 once. Training costs about $2,000 a year. Additional contractor hours for the first quarter cost about $12,000.

Ninety-Day Action List

Week 1: close remote desktop access and enable multifactor email login. Month 1: encrypt all laptops, create individual accounts and move backups. Month 2: segment equipment tablets and link account removal to payroll. Month 3: write downtime procedures, run the first phishing exercise and repeat the walk-through to confirm each fix.

Conclusion

Moving to the cloud did not move the group's security risks away. An exposed remote connection, weak email protection, shared logins, unencrypted laptops and poor account and backup practices were the real threats. Rating them showed that the most dangerous risks were also among the cheapest to fix.

5

References

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

U.S. Department of Health and Human Services. (2022). Summary of the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

U.S. Department of Health and Human Services. (2023). Health industry cybersecurity practices: Managing threats and protecting patients (2023 ed.). 405(d) Program. https://405d.hhs.gov/public/navigation/hicp

What the HCIS 352 Week 4 instructions ask

HCIS 352 Week 4 generally asks students to identify operational security risks to health care information systems and recommend ways to reduce them. Prompts may cover threats such as ransomware, phishing, insider misuse, lost or stolen devices, vendor and cloud failures, unpatched systems and physical security, along with their likely impact on patient care and data. Some sections provide a scenario; others ask students to consider a type of organization. A paper of around three pages with credible sources is usual. Strong answers identify risks specific to the setting, rate them in a consistent way, choose controls matched to the most serious ones and remember that small organizations have limited budgets and staff.

How this HCIS 352 Week 4 example is built

The sample opens with a near miss: an attacker's scan of the group's exposed remote desktop connection, caught only by chance. It then describes the group's technology after its move to the cloud and the walk-through that produced a list of eight risks. Each risk is described in terms of what could happen and how it would affect patients or operations. A simple three-by-three rating of likelihood and impact ranks the risks. Controls come from federal health care cybersecurity practices for small and medium organizations, matched to each high-ranked risk. National data on ransomware attacks and their disruption of care justify the ranking. A short section on costs and a 90-day action list close the paper.

HCIS 352 Week 4 grading rubric: where the points go

For this week, rubrics usually emphasize the quality of risk identification and the logic linking risks to controls. Faculty look for risks specific to the organization, consistent ratings, controls that address the highest risks first and use of recognized security guidance for health care. Awareness of how incidents would affect patient care, not only data, earns credit. Practical recommendations sized to the organization's resources are valued. Organized structure, such as a ranked list followed by controls, helps. Accurate references complete the grade. Papers that list every conceivable threat without ranking, or that recommend expensive tools unsuited to a small organization, usually earn less than papers with a clear, prioritized plan.

HCIS 352 Week 4 help: mistakes to avoid

A common mistake in HCIS 352 Week 4 is producing a long list of threats copied from a security website with no connection to the organization. Walk through the setting and find its specific weaknesses. Another is treating all risks as equal; rate them and act on the worst first. Students also think only of hackers, when shared passwords, lost tablets and vendor outages cause many incidents. Consider how each risk affects patient care and scheduling, not only data. Match controls to risks, and prefer inexpensive, high-value measures such as multifactor authentication for a small group. Cite health-care-specific guidance. Finally, include a short action timeline, since a risk list without deadlines rarely changes anything.

Related HCIS 352 sample papers

Other HCIS 352 week samples

More BS in Health Administration sample papers

HCIS 352 Week 4 questions, answered

What does HCIS/352 Week 4 usually ask for?

Many sections ask students to identify operational security risks to health care information systems, such as ransomware, phishing, insider misuse and device loss, and recommend controls.

Where can I find a free HCIS 352 Week 4 sample paper?

The physical therapy group's security risk assessment above is free to read, with margin notes on how each risk was rated. A first custom assessment for your own scenario costs nothing.

What is an exposed remote desktop connection?

A remote access service reachable directly from the internet, which attackers scan for and try to break into with stolen or guessed passwords, making it a common entry point for ransomware.

How should a small practice rank security risks?

By rating each risk's likelihood and impact on a simple scale, then addressing the highest combined scores first with controls that fit the practice's budget.

What security measures give small health organizations the most value?

Recommended practices for smaller organizations emphasize email protection, multifactor authentication, regular patching, backups kept offline, access management and staff training.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.