HCIS 420 Week 4 Risk Analysis Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HCIS 420 Week 4 example carries out a risk analysis, rating a hospital's information system risks for likelihood and impact and ranking them for action, and the APA 7 paper itself follows. Analysis is the task in week four of University of Phoenix HCIS 420 (HCIS/420 in the course catalog), which trains health IT and health administration learners to judge which risks deserve attention first. The sample scores the ten risks in the register built for the composite 150-bed regional hospital. It defines five-level likelihood and impact scales, following the semi-quantitative approach in the federal risk assessment guide, and explains what each level means for this hospital. It then rates each risk, shows the resulting heat map, tests one rating with national ransomware evidence, estimates financial exposure for the top risks and states the limits of the scores before handing the ranking to the planning week.

CourseHCIS 420 Information Systems Risk Management in Health Care (HCIS/420)
Week4
Paper typeRisk analysis paper
Lengthabout 1,007 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Health Administration
UpdatedSeptember 2026

Free sample paper for HCIS 420 Week 4

1

Scoring Ten Risks: A Likelihood and Impact Analysis of a Regional Hospital's Information System Risks and What the Scores Tell Leadership

[Student Name]

University of Phoenix

HCIS/420: Information Systems Risk Management in Health Care

Week 4 Assignment

[Instructor Name]

[Date]

The hospital, its risks, ratings and costs are composites written for a model paper; methods and findings come from the sources listed.

What this part is doingThe title promises scores and their meaning for leadership, which is what an analysis must deliver.
2

The security and privacy committee of a composite 150-bed regional hospital now holds a register of ten information system risks, each with an owner and a planned response. It cannot fund all responses this year. The chair asked a direct question: which risks are worst? This paper answers by analyzing each risk's likelihood and impact on defined scales, ranking them and explaining how much confidence the ranking deserves.

Choosing a Method

Quantitative analysis would express each risk in expected dollars lost per year, but the hospital lacks reliable data on how often most events occur. Purely qualitative labels, such as high and low, are fast but vague. The team chose a semi-quantitative approach, which the federal risk assessment guide describes as using defined bins or scales, such as 1 to 5, that carry clear meanings (Joint Task Force Transformation Initiative, 2012).

Federal regulators do not prescribe a single method, only that the analysis be accurate and thorough and cover all electronic protected health information the organization holds (U.S. Department of Health and Human Services, Office for Civil Rights, 2010).

Likelihood Scale

Level 1, rare: not expected in the next five years. Level 2, unlikely: could happen once in five years. Level 3, possible: once in two or three years. Level 4, likely: about once a year. Level 5, almost certain: several times a year. Assessors rated inherent likelihood given current controls, not ideal ones.

Impact Scale

Level 1, minimal: no effect on care, under $10,000. Level 2, minor: brief inconvenience, under $100,000. Level 3, moderate: delays to care for hours, reportable breach under 500 people or up to $1 million. Level 4, major: diversion or canceled procedures for a day or more, breach of over 500 people or up to $5 million. Level 5, severe: patient harm or multiday loss of core systems, over $5 million. The highest applicable category sets the level.

What this part is doingEach impact level names effects on patients, operations and money, so raters with different backgrounds can agree on a number.
3

Rating the Risks

R1 ransomware through unsupported servers: likelihood 4, impact 5, score 20. R2 phishing and payroll fraud: likelihood 5, impact 2, score 10. R3 loss of unencrypted tapes: likelihood 2, impact 4, score 8. R4 undetected record snooping: likelihood 4, impact 3, score 12. R5 access at unattended workstations: likelihood 4, impact 3, score 12. R6 vendor exposure without an agreement: likelihood 3, impact 4, score 12. R7 failed disaster recovery: likelihood 2, impact 5, score 10. R8 poorly handled incident: likelihood 3, impact 4, score 12. R9 extended power loss: likelihood 2, impact 4, score 8. R10 infusion pump tampering: likelihood 1, impact 5, score 5.

Reasons Behind Key Ratings

R1's likelihood is 4 because 11 servers run an unsupported operating system and health care is a frequent ransomware target. R2's impact is only 2 because payroll changes above a threshold already need a second approval. R10's likelihood is 1 because tampering requires network access and specialized knowledge, although its impact would be severe.

The Heat Map

Scores of 15 to 25 fall in the very high band, 10 to 14 high, 5 to 9 moderate and 1 to 4 low. One risk, R1, is very high. Six are high: R2, R4, R5, R6, R7 and R8. Three are moderate: R3, R9 and R10. None is low, which is expected for a first analysis in a hospital that has not assessed risk in three years.

Testing the Top Rating With Evidence

The ransomware rating deserved a check against outside data. Neprash et al. (2022) identified 374 ransomware attacks against American care delivery organizations from 2016 to 2021, with the annual number more than doubling over the period and nearly half of attacks disrupting care delivery. The evidence supports rating ransomware as both likely and severe for a hospital of this size, and it shows that the consequence is measured in delayed care, not only in data.

What this part is doingOnly the top-rated risk is tested against outside evidence, since that is where an error in the rating would matter most.
4

Financial Exposure for the Top Risks

For R1, the finance office estimated a five-day EHR outage at $2.4 million in lost revenue, recovery costs and overtime, before any regulatory penalties. For R4, a snooping breach affecting a few hundred records would cost about $150,000 in investigation, notification and legal review. For R6, a vendor breach affecting 20,000 patients could cost $1.5 million. These figures are rough, but they show leadership that the largest spending should go to R1.

Residual Risk

The committee also estimated residual risk after planned responses. Patching and replacing the 11 unsupported servers, plus immutable backups, would lower R1's likelihood to 2 and its score to 10. Restoring automatic logoff with badge tap login would lower R5 to 6. The difference between inherent and residual scores helps justify each response's cost.

Limits of the Analysis

The ratings are informed judgments, not measurements. Two raters gave R8 different impacts until they agreed on a definition. Likelihood for rare events, such as R10, is especially uncertain. The team will record the reason for each rating so that next year's analysis can learn from what actually happened.

Presenting the Results

The committee asked for results it could read in five minutes. The security officer prepared a one-page heat map, a table of the ten risks with scores and owners and three sentences on the top risk. Trustees on the audit committee received the same page. Keeping the format stable from quarter to quarter will let leaders see whether scores fall as responses are completed, which is the evidence the board had asked for when it first raised the question of who owns information risk.

Ranked Priorities

First, R1. Second, the four risks scoring 12, ordered by cost to fix: R5, R4, R8 and R6. Then R2 and R7, and then the moderate risks. This ranking goes to Week 5's risk management plan.

Conclusion

Defined scales turned ten risks into a ranked list the committee can fund in order. Ransomware through unsupported servers stands above all others on both evidence and cost, while several moderate risks can wait for later cycles with monitoring in place.

5

References

Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

U.S. Department of Health and Human Services, Office for Civil Rights. (2010). Guidance on risk analysis requirements under the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html

What the HCIS 420 Week 4 instructions ask

HCIS 420 Week 4 typically asks students to analyze the information system risks they identified for a health care organization. Prompts may cover qualitative, quantitative and semi-quantitative analysis, likelihood and impact scales, risk matrices or heat maps, financial estimates, residual risk and how the analysis informs priorities. Some sections ask students to analyze risks from their earlier work; others supply a case. Three or so pages with recognized methods is typical. Strong papers define their scales so that ratings mean something, apply them consistently, support key ratings with evidence, consider both patient care and financial impact and explain the uncertainty in the numbers.

How this HCIS 420 Week 4 example is built

The sample begins with the hospital's security and privacy committee asking which of ten risks to fund first. It explains the choice of a semi-quantitative method and defines five likelihood levels and five impact levels in the hospital's own terms, with impact covering patient safety, operations, finances and regulation. Each risk is then rated with a sentence of reasoning. A heat map groups the risks into very high, high, moderate and low bands. The ransomware rating is checked against national data on attacks against care providers and their disruption of care. A rough cost estimate for the top three risks follows, then a section on uncertainty, and the ranked list closes the paper for use in Week 5's plan.

HCIS 420 Week 4 grading rubric: where the points go

For this week, rubrics usually reward a defensible method applied with care. Faculty look for defined scales, consistent ratings with reasons, a clear ranking or matrix, attention to patient safety as well as financial impact and evidence behind the most important ratings. Discussing the limits of the analysis and residual risk earns credit. A heat map or table helps graders see the results. Style and sources count for the remainder. Papers that assign numbers without defining them, rate every risk high or leave out how an outage would affect patients usually earn less than papers whose ratings a reader could reproduce from the definitions given.

HCIS 420 Week 4 help: mistakes to avoid

The most common weakness in HCIS 420 Week 4 is undefined scales. Rating a risk 4 means nothing unless the paper says what 4 means for likelihood and for impact. Define levels in terms the organization uses, such as hours of EHR downtime or dollars lost. Another error is rating every risk high, which makes the analysis useless for choosing; spread the ratings honestly. Students also forget patient harm, which is the defining impact in health care. Support major ratings with evidence, such as industry incident data. Acknowledge that the numbers are estimates with uncertainty. Separate inherent risk from residual risk after current controls. Finally, end with a ranked list, since the purpose of analysis is to decide what comes first.

Related HCIS 420 sample papers

Other HCIS 420 week samples

More BS in Health Administration sample papers

HCIS 420 Week 4 questions, answered

What does HCIS/420 Week 4 usually ask for?

Many sections ask students to analyze health care information system risks by rating likelihood and impact, ranking them, estimating costs and explaining how the analysis sets priorities.

Where can I find a free HCIS 420 Week 4 sample paper?

This page has one: a risk analysis of ten hospital risks with defined scales and a heat map, plus margin notes. For your own risks, a first custom analysis is free.

What is a semi-quantitative risk analysis?

An approach that uses defined numeric scales or bins, such as 1 to 5 or 0 to 100, to represent likelihood and impact, combining the consistency of numbers with judgment where precise data are lacking.

What is a risk heat map?

A grid that plots risks by likelihood and impact, usually colored from low to very high, to show at a glance which risks need attention first.

What is residual risk?

The risk that remains after current or planned controls are in place, which leadership must either accept or reduce further.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.