HCIS 420 Week 3 Risk Identification and Management Planning Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HCIS 420 Week 3 example shows how a hospital identifies its information system risks and plans how it will manage them, with the complete paper in APA 7 form after the facts table. In University of Phoenix HCIS 420, catalog number HCIS/420, week three has health IT and health administration learners turn regulatory gaps into a structured list of risks with owners and a plan for handling them. The sample carries the composite 150-bed regional hospital forward from its control mapping. It builds an asset inventory, identifies threat sources and vulnerabilities using the federal risk assessment method, writes risk statements that link a threat, a weakness and a consequence, and records them in a risk register. It then sets out the management planning choices of accepting, avoiding, transferring or reducing each risk, names owners and defines how the register will be kept current.

CourseHCIS 420 Information Systems Risk Management in Health Care (HCIS/420)
Week3
Paper typeRisk identification and planning paper
Lengthabout 1,010 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Health Administration
UpdatedSeptember 2026

Free sample paper for HCIS 420 Week 3

1

From Seven Gaps to a Working Risk Register: Identifying Information System Risks and Planning How a Regional Hospital Will Manage Them

[Student Name]

University of Phoenix

HCIS/420: Information Systems Risk Management in Health Care

Week 3 Assignment

[Instructor Name]

[Date]

The hospital, its assets, threats and owners are composites written for a model paper; methods come from the sources listed.

What this part is doingThe title shows the paper's movement from the last assignment's gaps to this week's product, which keeps the course's thread visible.
2

The composite 150-bed regional hospital ended its regulatory mapping with seven gaps, from unencrypted backup tapes to untested incident plans. Gaps are useful, but they are not risks. A gap says a control is missing; a risk says what could happen because of it, how likely that is and how much it would hurt. This paper identifies the hospital's information system risks using a federal method, records them in a register and plans how each will be managed.

The Method

The hospital adopted the process described by the Joint Task Force Transformation Initiative (2012) in its guide for conducting risk assessments. The process asks assessors to identify threat sources and the events they could cause, identify vulnerabilities and predisposing conditions, determine likelihood and impact and then determine risk. Using a published method keeps assessors consistent and gives auditors a standard to check against. Federal guidance for the HIPAA Security Rule points covered entities to the same approach (Marron, 2024).

Starting With Assets

The team first listed what it must protect. The EHR holds records for 180,000 patients. The revenue cycle system holds billing and insurance data. The picture archive holds images. The laboratory and pharmacy systems support daily care. The interface engine connects them. Email and file shares hold everything staff attach and save. Biomedical devices, such as infusion pumps and monitors, connect to the network. Each asset was recorded with its owner, the data it holds and how long the hospital could run without it.

What this part is doingAssets come first because a risk is always a risk to something; without the inventory, threats float free of consequences.
3

Threat Sources and Events

The federal guide groups threat sources as adversarial, accidental, structural and environmental. For the hospital, adversarial threats include ransomware groups and fraud through phishing; accidental threats include staff errors such as sending records to the wrong recipient; structural threats include hardware and software failures; environmental threats include the spring storms that have twice cut power to the region.

Vulnerabilities

Vulnerabilities came from the Week 2 gaps and from new sources: a vulnerability scan found 42 servers missing critical patches, 11 of them on an operating system no longer supported by its maker. Incident reports showed three misdirected faxes and two lost badges in six months.

How the Team Found Risks

The security officer did not work alone. She interviewed the leaders of nursing, pharmacy, laboratory, imaging and finance, asking which systems they could not work without and for how long. She reviewed a year of incident reports and help desk tickets. The team ran a two-hour tabletop exercise in which a ransomware attack encrypted the EHR at 2 a.m., which surfaced questions no one could answer, such as who could authorize paying for outside forensic help.

Writing Risk Statements

Each risk was written in one form: because of a vulnerability, a threat source may cause an event, resulting in a consequence. Writing risks this way forces the team to name the weakness it can fix and the harm leadership cares about, which is what turns a worry into something a leader can decide on. For example: because audit logs are not reviewed, a staff member could view records of a celebrity patient without detection, resulting in a privacy breach, regulatory penalties and loss of trust.

The Risk Register

Ten risks entered the register. R1: ransomware through unpatched, unsupported servers, halting the EHR and care. R2: phishing leading to stolen credentials and fraudulent payroll changes. R3: loss of unencrypted backup tapes in transit, forcing breach notification. R4: undetected snooping in records because logs go unreviewed. R5: unauthorized access at unattended nursing workstations. R6: a vendor without a business associate agreement exposing data. R7: a failed recovery after a disaster because the plan is outdated. R8: a poorly handled incident because the response plan is untested. R9: a storm-related power loss outlasting generator fuel for the data center. R10: tampering with network-connected infusion pumps. Each row lists the asset, owner, current controls and planned response.

What this part is doingThe register's rows are kept short and parallel, which is how real registers stay readable for executives.
4

Choosing Responses

Four responses are available. Mitigate: most risks, such as R1, R4 and R5, will be reduced with patching, log review and restored logoff settings. Transfer: part of R1's financial impact is transferred through cyber insurance, and R6 through business associate agreements that assign responsibilities. Avoid: R3 will be avoided entirely by ending physical tape shipment and moving to encrypted cloud backup. Accept: the team proposed accepting a small residual risk that some old biomedical devices cannot be patched, with network separation in place, subject to executive approval.

Risks Outside the Hospital's Walls

Several risks sit with partners. The EHR vendor hosts production data, the billing clearinghouse processes claims and the managed service company watches the network overnight. The team asked each for its latest independent security assessment and incident history, and it added a question about vendor access to every future contract review. A partner's weakness becomes the hospital's risk the moment that partner can reach patient data, so vendor risks stay in the same register rather than a separate file no one reads.

Owners

Owners are the leaders who bear the consequence, not always IT. The chief nursing officer owns R5. The chief financial officer owns R2. The privacy officer owns R4. The CIO owns R1, R3, R7 and R9. The director of biomedical engineering owns R10.

Keeping the Register Current

The security and privacy committee will review the register monthly, add risks from new systems and incidents and close risks when responses are complete. The full risk analysis will be repeated yearly and whenever a major system changes, in keeping with the national framework's view of risk identification as continuous work rather than a single project (National Institute of Standards and Technology, 2024). Week 4's analysis will score each risk so the committee can order its work.

Conclusion

By moving from gaps to assets, threats, vulnerabilities and precise risk statements, the hospital built a register of ten owned risks, each with a chosen response. Following a published method and involving clinical and business leaders made the list specific enough to act on.

5

References

Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1

Marron, J. A. (2024). Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A cybersecurity resource guide (NIST Special Publication 800-66 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-66r2

National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

What the HCIS 420 Week 3 instructions ask

HCIS 420 Week 3 commonly asks students to identify risks to a health care organization's information systems and describe how the organization will plan to manage them. Prompts may cover asset identification, threats and vulnerabilities, methods for gathering risk information, risk statements, risk registers, risk owners and the choice among accepting, avoiding, transferring and mitigating risk. Some sections ask students to apply these steps to an organization from earlier weeks. Around three pages with recognized frameworks is typical. Strong papers follow a named method, write risks precisely enough to act on, involve people outside IT in finding them and give every risk an owner and a planned response.

How this HCIS 420 Week 3 example is built

The sample starts where Week 2 ended, with seven control gaps, and explains that gaps are not yet risks. It describes the federal risk assessment process and uses its terms: threat sources, threat events, vulnerabilities, likelihood and impact. An asset inventory lists the hospital's key systems and the data each holds. Methods for identifying risks follow: interviews with department leaders, vulnerability scans, a review of incident reports and a tabletop exercise. The paper then writes ten risk statements in a standard form and places them in a register with columns for owner and response. The management planning section explains the four response options with hospital examples, and the paper closes with the review cycle for the register.

HCIS 420 Week 3 grading rubric: where the points go

The risk identification week tends to reward method and precision. Faculty look for a recognized approach to identifying risks, a clear inventory of assets, threats and vulnerabilities, risk statements that connect cause and consequence and a register that assigns ownership. Explaining the range of risk responses, with fitting examples, earns credit. Involving clinical and business leaders in finding risks shows understanding that risk is not only technical. A table or register helps. APA style and sources carry the remainder. Papers that list generic threats such as hackers and viruses without tying them to specific systems and weaknesses, or that assume every risk must be eliminated, usually score lower than papers with owned, specific risks.

HCIS 420 Week 3 help: mistakes to avoid

Many HCIS 420 Week 3 papers lose points by confusing a gap, a threat and a risk. A gap is a missing control; a threat is something that could exploit a weakness; a risk is the chance and consequence of that happening to a specific asset. Write risk statements that say all three. Another error is identifying risks from the IT department alone; clinical leaders know which downtime would hurt patients. Students also forget that not every risk must be reduced; some are accepted, transferred through contracts or insurance or avoided by retiring a system. Give each risk an owner outside IT when the business owns the consequence. Use a named framework. Finally, plan how the register stays current, since risks change monthly.

Related HCIS 420 sample papers

Other HCIS 420 week samples

More BS in Health Administration sample papers

HCIS 420 Week 3 questions, answered

What does HCIS/420 Week 3 usually ask for?

Many sections ask students to identify information system risks in a health care organization and plan how they will be managed, including assets, threats, vulnerabilities, risk registers, owners and responses.

Where can I find a free HCIS 420 Week 3 sample paper?

There is one on this page: a regional hospital risk register built from its control gaps, with notes in the margin. A risk paper built on your own organization is free as a first order.

What is a risk register?

A document that lists an organization's identified risks, typically with a description, owner, likelihood, impact, planned response and status, and is updated as risks change.

What are the four ways to respond to a risk?

Accept it, avoid it by stopping the risky activity, transfer or share it through contracts or insurance, or mitigate it with controls that lower its likelihood or impact.

What is the difference between a threat and a vulnerability?

A threat is a circumstance or event, such as ransomware, that could cause harm; a vulnerability is a weakness, such as an unpatched server, that a threat could exploit.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.