| Course | HCIS 420 Information Systems Risk Management in Health Care (HCIS/420) |
|---|---|
| Week | 2 |
| Paper type | Regulatory requirements analysis |
| Length | about 1,066 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | BS in Health Administration |
| Updated | September 2026 |
Free sample paper for HCIS 420 Week 2
Required, Addressable and Often Misread: How a Regional Hospital Maps Its IT Controls to the HIPAA Security Rule, Federal Implementation Guidance and the National Cybersecurity Framework
[Student Name]
University of Phoenix
HCIS/420: Information Systems Risk Management in Health Care
Week 2 Assignment
[Instructor Name]
[Date]
The hospital, its controls and its gaps are composites written for a model paper; requirements come from the sources listed.
Last year's external audit of a composite 150-bed regional hospital found that several HIPAA Security Rule specifications marked addressable had been treated as optional and never considered. Automatic logoff was disabled on nursing workstations because nurses found it annoying; encryption was not used on backup tapes sent offsite. The finding showed a common misunderstanding of the rules. This paper explains the regulations and guidelines that govern health care IT security and maps the hospital's controls against them.
How the Security Rule Is Built
The HIPAA Security Rule protects electronic protected health information held or transmitted by covered entities and their business associates. It requires them (U.S. Department of Health and Human Services, 2022) to ensure the confidentiality, integrity and availability of that information, protect against reasonably anticipated threats and impermissible uses and ensure workforce compliance. The rule is organized into standards, each of which may have implementation specifications that explain how to meet it.
Security Rule and Privacy Rule
Staff at the hospital often used the two rules interchangeably, which confused the audit discussion. The Privacy Rule governs how protected health information in any form, paper, spoken or electronic, may be used and disclosed, and it gives patients rights over their records. The Security Rule is narrower: it applies only to electronic protected health information and sets the safeguards that keep it confidential, intact and available. A lost paper chart is a privacy problem; an unencrypted backup tape is a security problem that can become a privacy breach.
Required and Addressable
Implementation specifications are either required or addressable. Required specifications must be implemented. Addressable specifications must be assessed: if a specification is reasonable and appropriate for the organization, it must be implemented; if not, the organization must document why and implement an equivalent alternative measure if that is reasonable and appropriate (Marron, 2024). Addressable was written to give organizations flexibility in how they protect data, not permission to skip protection, which is exactly the distinction the hospital's audit exposed.
Administrative Safeguards
Administrative safeguards are the written policies and management procedures an organization uses to choose and run its security measures and to guide how its workforce behaves. They include the security management process, with required risk analysis, risk management, sanction policy and information system activity review; assigned security responsibility; workforce security; information access management; security awareness and training; security incident procedures; a contingency plan with required data backup, disaster recovery and emergency mode operation plans; periodic evaluation; and business associate contracts.
Physical Safeguards
Physical safeguards protect equipment and facilities. They include facility access controls, workstation use and workstation security, and device and media controls covering disposal, reuse, accountability and backup of hardware and media that hold electronic protected health information.
Technical Safeguards
Technical safeguards are the technology and related policies that protect data and control access. They include access control, with required unique user identification and emergency access procedures and addressable automatic logoff and encryption; audit controls; integrity controls; person or entity authentication; and transmission security, with addressable integrity controls and encryption.
Documentation Duties
The rule also requires written policies and procedures for each standard and records of the actions and assessments it demands, including the reasoning behind every addressable decision. That documentation must be retained six years, counted from the date it was created or was last in effect, and updated when the environment changes. The hospital's missing logoff decision was therefore two failures: a control not in place and no record explaining why.
Federal Implementation Guidance
Marron (2024), in the National Institute of Standards and Technology's special publication on implementing the Security Rule, explains each standard with key activities, sample questions organizations can ask themselves and links to cybersecurity resources, and places risk assessment and risk management at the center of compliance. The publication is guidance, not law, but it shows regulated organizations how to meet their obligations in practice.
The National Cybersecurity Framework
The National Institute of Standards and Technology (2024) Cybersecurity Framework 2.0 organizes cybersecurity outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is voluntary for most private health care organizations but gives them a common language for managing risk. The Security Rule tells the hospital what it must protect; the framework helps it organize how, and it covers areas, such as detection and recovery, in more detail than the rule.
Mapping the Hospital's Controls
The security officer mapped ten controls. Annual risk analysis: required by the security management process; supports Identify; last completed three years ago, a gap. Unique user accounts: required under access control; supports Protect; in place. Automatic logoff: addressable; supports Protect; disabled on nursing workstations without documented reasoning, a gap. Backup encryption: addressable; supports Protect and Recover; not used on offsite tapes, a gap. Audit log review: required through information system activity review and audit controls; supports Detect; logs collected but rarely reviewed, a gap. Security training: required; supports Protect; in place annually. Incident response plan: required; supports Respond; written but never tested, a gap. Contingency plan: required; supports Recover; backup exists, disaster recovery plan outdated, a gap. Business associate agreements: required; supports Govern; 12 of 90 vendors missing agreements, a gap. Device disposal: required under device and media controls; supports Protect; in place.
Breach Notification
If unsecured protected health information is breached, the HITECH Act's breach notification rule requires notice to affected individuals without unreasonable delay and within 60 days of discovery, a report to federal regulators at HHS and media notice in any state or jurisdiction where the breach reaches over 500 residents. Encryption that meets federal guidance can make data secured, which removes the notification duty if encrypted media are lost, a strong reason to encrypt backup tapes.
Gaps for the Risk Analysis
Seven of the ten controls showed gaps. Each becomes a starting point for Week 3's risk identification: an outdated risk analysis, disabled automatic logoff, unencrypted backups, unreviewed audit logs, an untested incident plan, an outdated disaster recovery plan and missing business associate agreements.
Conclusion
The HIPAA Security Rule sets required and addressable specifications across administrative, physical and technical safeguards; addressable does not mean optional. Federal guidance and the national framework help translate the rule into practice. Mapping the hospital's controls against both showed seven gaps, which the risk analysis will now examine.
References
Marron, J. A. (2024). Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A cybersecurity resource guide (NIST Special Publication 800-66 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-66r2
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
U.S. Department of Health and Human Services. (2022). Summary of the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
What the HCIS 420 Week 2 instructions ask
HCIS 420 Week 2 usually asks students to explain the regulations and guidelines that govern health care IT security. Prompts commonly cover the HIPAA Security Rule's administrative, physical and technical safeguards, required and addressable implementation specifications, breach notification under HITECH, and voluntary frameworks such as those from the National Institute of Standards and Technology. Some versions ask students to apply the requirements to an organization or compare regulatory and voluntary guidance. Expect about three pages with official sources. Strong papers state the requirements accurately, avoid common misreadings, show how voluntary frameworks help meet legal obligations and connect requirements to specific controls an organization has or lacks.
How this HCIS 420 Week 2 example is built
The paper begins with a finding from the hospital's last audit: several addressable specifications had been treated as optional and ignored. It then explains the rule's structure, the three categories of safeguards and what required and addressable mean, correcting the misreading. Each safeguard category is described with examples of standards and specifications. A section introduces federal implementation guidance, which maps the rule to cybersecurity activities, and the national framework's six functions. A mapping section takes ten of the hospital's controls and shows which rule standard and framework function each supports, marking gaps. Breach notification rules are summarized briefly, and the paper closes with the list of gaps that Week 3's risk identification will pick up.
HCIS 420 Week 2 grading rubric: where the points go
For this week, faculty generally emphasize accuracy about the regulations. Points go to a correct description of the Security Rule's structure, correct handling of required versus addressable specifications, correct placement of standards within the three safeguard categories and an accurate summary of breach notification. Explaining how voluntary frameworks relate to legal requirements earns credit, as does applying the rules to specific controls. Organization by safeguard category or by control helps. Style and references complete the grade. Papers that treat addressable specifications as optional, mix up the Privacy and Security Rules or list requirements without any application usually earn less than papers that map real controls to the rules.
HCIS 420 Week 2 help: mistakes to avoid
The most frequent error in HCIS 420 Week 2 is misunderstanding addressable specifications. Addressable does not mean optional: an organization must assess whether the specification is reasonable and appropriate, implement it if so, and if not, document why and adopt an equivalent measure when appropriate. Another error is mixing up safeguard categories; audit controls are technical, workforce training is administrative, device and media controls are physical. Students also cite frameworks as though they were law; explain that they are voluntary tools that help meet legal duties. Use official sources for requirements. Apply the rules to specific controls, since that is what the course builds toward. Finally, include breach notification, which is where many organizations meet the rules in practice.
Related HCIS 420 sample papers
Other HCIS 420 week samples
- HCIS 420 Week 1: Health Care IT Organization
- HCIS 420 Week 3: Risk Identification and Planning
- HCIS 420 Week 4: Information System Risk Analysis
- HCIS 420 Week 5: Comprehensive Risk Management Plan
More BS in Health Administration sample papers
- HCIS 318 Week 2: Health Care Roles
- HCIS 352 Week 2: Health IT Infrastructure
- HCS 120 Week 2: Speaking the Language of the Body
- HCS 131 Week 2: Communication Types and Preferences
HCIS 420 Week 2 questions, answered
What does HCIS/420 Week 2 usually ask for?
Many sections ask students to explain the regulations and guidelines for health care IT security, such as the HIPAA Security Rule's safeguards, required and addressable specifications, breach notification and NIST frameworks.
Where can I find a free HCIS 420 Week 2 sample paper?
The paper above maps a hospital's controls to the HIPAA Security Rule and the NIST framework and can be read free, with margin notes. A first paper written around your own organization costs nothing.
Are addressable HIPAA specifications optional?
No; the organization must assess each one, implement it if reasonable and appropriate, and otherwise document why and implement an equivalent alternative measure if reasonable and appropriate.
What are the three categories of HIPAA security safeguards?
Administrative (risk analysis, workforce training, contingency planning), physical (locked facilities, workstation placement, disposal and reuse of media) and technical (unique logins, audit logs, protection of data in transit).
Is the NIST Cybersecurity Framework required for hospitals?
It is voluntary for most private health care organizations, but it offers a structured way to manage cybersecurity risk and helps organizations meet HIPAA Security Rule obligations.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HCIS 420 week samples · All courses