| Course | HCIS 420 Information Systems Risk Management in Health Care (HCIS/420) |
|---|---|
| Week | 4 |
| Paper type | Risk analysis paper |
| Length | about 1,007 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | BS in Health Administration |
| Updated | September 2026 |
Free sample paper for HCIS 420 Week 4
Scoring Ten Risks: A Likelihood and Impact Analysis of a Regional Hospital's Information System Risks and What the Scores Tell Leadership
[Student Name]
University of Phoenix
HCIS/420: Information Systems Risk Management in Health Care
Week 4 Assignment
[Instructor Name]
[Date]
The hospital, its risks, ratings and costs are composites written for a model paper; methods and findings come from the sources listed.
The security and privacy committee of a composite 150-bed regional hospital now holds a register of ten information system risks, each with an owner and a planned response. It cannot fund all responses this year. The chair asked a direct question: which risks are worst? This paper answers by analyzing each risk's likelihood and impact on defined scales, ranking them and explaining how much confidence the ranking deserves.
Choosing a Method
Quantitative analysis would express each risk in expected dollars lost per year, but the hospital lacks reliable data on how often most events occur. Purely qualitative labels, such as high and low, are fast but vague. The team chose a semi-quantitative approach, which the federal risk assessment guide describes as using defined bins or scales, such as 1 to 5, that carry clear meanings (Joint Task Force Transformation Initiative, 2012).
Federal regulators do not prescribe a single method, only that the analysis be accurate and thorough and cover all electronic protected health information the organization holds (U.S. Department of Health and Human Services, Office for Civil Rights, 2010).
Likelihood Scale
Level 1, rare: not expected in the next five years. Level 2, unlikely: could happen once in five years. Level 3, possible: once in two or three years. Level 4, likely: about once a year. Level 5, almost certain: several times a year. Assessors rated inherent likelihood given current controls, not ideal ones.
Impact Scale
Level 1, minimal: no effect on care, under $10,000. Level 2, minor: brief inconvenience, under $100,000. Level 3, moderate: delays to care for hours, reportable breach under 500 people or up to $1 million. Level 4, major: diversion or canceled procedures for a day or more, breach of over 500 people or up to $5 million. Level 5, severe: patient harm or multiday loss of core systems, over $5 million. The highest applicable category sets the level.
Rating the Risks
R1 ransomware through unsupported servers: likelihood 4, impact 5, score 20. R2 phishing and payroll fraud: likelihood 5, impact 2, score 10. R3 loss of unencrypted tapes: likelihood 2, impact 4, score 8. R4 undetected record snooping: likelihood 4, impact 3, score 12. R5 access at unattended workstations: likelihood 4, impact 3, score 12. R6 vendor exposure without an agreement: likelihood 3, impact 4, score 12. R7 failed disaster recovery: likelihood 2, impact 5, score 10. R8 poorly handled incident: likelihood 3, impact 4, score 12. R9 extended power loss: likelihood 2, impact 4, score 8. R10 infusion pump tampering: likelihood 1, impact 5, score 5.
Reasons Behind Key Ratings
R1's likelihood is 4 because 11 servers run an unsupported operating system and health care is a frequent ransomware target. R2's impact is only 2 because payroll changes above a threshold already need a second approval. R10's likelihood is 1 because tampering requires network access and specialized knowledge, although its impact would be severe.
The Heat Map
Scores of 15 to 25 fall in the very high band, 10 to 14 high, 5 to 9 moderate and 1 to 4 low. One risk, R1, is very high. Six are high: R2, R4, R5, R6, R7 and R8. Three are moderate: R3, R9 and R10. None is low, which is expected for a first analysis in a hospital that has not assessed risk in three years.
Testing the Top Rating With Evidence
The ransomware rating deserved a check against outside data. Neprash et al. (2022) identified 374 ransomware attacks against American care delivery organizations from 2016 to 2021, with the annual number more than doubling over the period and nearly half of attacks disrupting care delivery. The evidence supports rating ransomware as both likely and severe for a hospital of this size, and it shows that the consequence is measured in delayed care, not only in data.
Financial Exposure for the Top Risks
For R1, the finance office estimated a five-day EHR outage at $2.4 million in lost revenue, recovery costs and overtime, before any regulatory penalties. For R4, a snooping breach affecting a few hundred records would cost about $150,000 in investigation, notification and legal review. For R6, a vendor breach affecting 20,000 patients could cost $1.5 million. These figures are rough, but they show leadership that the largest spending should go to R1.
Residual Risk
The committee also estimated residual risk after planned responses. Patching and replacing the 11 unsupported servers, plus immutable backups, would lower R1's likelihood to 2 and its score to 10. Restoring automatic logoff with badge tap login would lower R5 to 6. The difference between inherent and residual scores helps justify each response's cost.
Limits of the Analysis
The ratings are informed judgments, not measurements. Two raters gave R8 different impacts until they agreed on a definition. Likelihood for rare events, such as R10, is especially uncertain. The team will record the reason for each rating so that next year's analysis can learn from what actually happened.
Presenting the Results
The committee asked for results it could read in five minutes. The security officer prepared a one-page heat map, a table of the ten risks with scores and owners and three sentences on the top risk. Trustees on the audit committee received the same page. Keeping the format stable from quarter to quarter will let leaders see whether scores fall as responses are completed, which is the evidence the board had asked for when it first raised the question of who owns information risk.
Ranked Priorities
First, R1. Second, the four risks scoring 12, ordered by cost to fix: R5, R4, R8 and R6. Then R2 and R7, and then the moderate risks. This ranking goes to Week 5's risk management plan.
Conclusion
Defined scales turned ten risks into a ranked list the committee can fund in order. Ransomware through unsupported servers stands above all others on both evidence and cost, while several moderate risks can wait for later cycles with monitoring in place.
References
Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
U.S. Department of Health and Human Services, Office for Civil Rights. (2010). Guidance on risk analysis requirements under the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
What the HCIS 420 Week 4 instructions ask
HCIS 420 Week 4 typically asks students to analyze the information system risks they identified for a health care organization. Prompts may cover qualitative, quantitative and semi-quantitative analysis, likelihood and impact scales, risk matrices or heat maps, financial estimates, residual risk and how the analysis informs priorities. Some sections ask students to analyze risks from their earlier work; others supply a case. Three or so pages with recognized methods is typical. Strong papers define their scales so that ratings mean something, apply them consistently, support key ratings with evidence, consider both patient care and financial impact and explain the uncertainty in the numbers.
How this HCIS 420 Week 4 example is built
The sample begins with the hospital's security and privacy committee asking which of ten risks to fund first. It explains the choice of a semi-quantitative method and defines five likelihood levels and five impact levels in the hospital's own terms, with impact covering patient safety, operations, finances and regulation. Each risk is then rated with a sentence of reasoning. A heat map groups the risks into very high, high, moderate and low bands. The ransomware rating is checked against national data on attacks against care providers and their disruption of care. A rough cost estimate for the top three risks follows, then a section on uncertainty, and the ranked list closes the paper for use in Week 5's plan.
HCIS 420 Week 4 grading rubric: where the points go
For this week, rubrics usually reward a defensible method applied with care. Faculty look for defined scales, consistent ratings with reasons, a clear ranking or matrix, attention to patient safety as well as financial impact and evidence behind the most important ratings. Discussing the limits of the analysis and residual risk earns credit. A heat map or table helps graders see the results. Style and sources count for the remainder. Papers that assign numbers without defining them, rate every risk high or leave out how an outage would affect patients usually earn less than papers whose ratings a reader could reproduce from the definitions given.
HCIS 420 Week 4 help: mistakes to avoid
The most common weakness in HCIS 420 Week 4 is undefined scales. Rating a risk 4 means nothing unless the paper says what 4 means for likelihood and for impact. Define levels in terms the organization uses, such as hours of EHR downtime or dollars lost. Another error is rating every risk high, which makes the analysis useless for choosing; spread the ratings honestly. Students also forget patient harm, which is the defining impact in health care. Support major ratings with evidence, such as industry incident data. Acknowledge that the numbers are estimates with uncertainty. Separate inherent risk from residual risk after current controls. Finally, end with a ranked list, since the purpose of analysis is to decide what comes first.
Related HCIS 420 sample papers
Other HCIS 420 week samples
- HCIS 420 Week 1: Health Care IT Organization
- HCIS 420 Week 2: Health Care IT Regulations
- HCIS 420 Week 3: Risk Identification and Planning
- HCIS 420 Week 5: Comprehensive Risk Management Plan
More BS in Health Administration sample papers
- HCIS 318 Week 4: Personal Health Data and Ethics
- HCIS 352 Week 4: Operational Security Risks
- HCS 120 Week 4: Patient Health Data and Technology
- HCS 131 Week 4: Teamwork and Collaboration
HCIS 420 Week 4 questions, answered
What does HCIS/420 Week 4 usually ask for?
Many sections ask students to analyze health care information system risks by rating likelihood and impact, ranking them, estimating costs and explaining how the analysis sets priorities.
Where can I find a free HCIS 420 Week 4 sample paper?
This page has one: a risk analysis of ten hospital risks with defined scales and a heat map, plus margin notes. For your own risks, a first custom analysis is free.
What is a semi-quantitative risk analysis?
An approach that uses defined numeric scales or bins, such as 1 to 5 or 0 to 100, to represent likelihood and impact, combining the consistency of numbers with judgment where precise data are lacking.
What is a risk heat map?
A grid that plots risks by likelihood and impact, usually colored from low to very high, to show at a glance which risks need attention first.
What is residual risk?
The risk that remains after current or planned controls are in place, which leadership must either accept or reduce further.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HCIS 420 week samples · All courses