| Course | HCIS 420 Information Systems Risk Management in Health Care (HCIS/420) |
|---|---|
| Week | 5 |
| Paper type | Risk management plan |
| Length | about 1,029 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | BS in Health Administration |
| Updated | September 2026 |
Free sample paper for HCIS 420 Week 5
Govern, Protect, Recover: A Comprehensive Information System Risk Management Plan for a 150-Bed Regional Hospital Built on the National Cybersecurity Framework
[Student Name]
University of Phoenix
HCIS/420: Information Systems Risk Management in Health Care
Week 5 Assignment
[Instructor Name]
[Date]
The hospital, its plan, budget and timeline are composites written for a model paper; frameworks and evidence come from the sources listed.
Over four weeks, a composite 150-bed regional hospital mapped its IT organization, compared its controls with federal requirements, identified ten information system risks and ranked them. The executive team now wants one document it can approve at a single meeting and that staff can follow for the next year. This paper is that plan. It is organized around the six functions of the national cybersecurity framework and ties every action to a ranked risk, an owner, a cost and a date.
Scope and Goals
The plan covers all systems that create, receive, store or transmit electronic protected health information, including hosted systems and connected medical devices. Its goals are to keep patient care running through cyber events, protect patient information, meet HIPAA Security Rule obligations and give the board clear evidence of progress.
Govern
The National Institute of Standards and Technology (2024) places governance at the center of its framework: setting strategy, expectations, roles and oversight for cybersecurity risk. Under this plan, the information security officer answers to the compliance and risk chief, while the CIO keeps an advisory link to the role. The executive team adopts a written risk appetite: the hospital will not accept risks rated very high and will accept moderate risks only with an executive signature. The security and privacy committee owns the register. Vendor oversight moves into governance, with business associate agreements required before any vendor receives access.
Identify
The asset inventory from Week 3 becomes a maintained record, updated when systems are bought or retired. The risk register is reviewed monthly and the full risk analysis yearly, following the federal risk assessment method (Joint Task Force Transformation Initiative, 2012).
Protect
Patching: critical patches within 30 days, with the 11 unsupported servers replaced or isolated within six months. Access: automatic logoff restored on nursing workstations with badge tap login so nurses return to their session in seconds. Multifactor authentication for email, remote access and payroll. Encryption: backups move to encrypted, immutable cloud storage, ending tape shipment. Training: annual security training plus quarterly phishing exercises, with extra coaching for staff who click.
Detect
Audit logs from the EHR feed a monitoring tool that flags unusual access, such as viewing records of employees, family members or well-known patients. The privacy officer reviews alerts weekly. A managed detection service monitors the network overnight and on weekends, replacing the gap left by a two-person security team.
Respond
The incident response plan is rewritten with roles, contact lists, decision rights and a clear authority to engage outside forensic help and legal counsel. A plan that has never been exercised is a guess, so the hospital will run two tabletop exercises a year, one of them with clinical leaders practicing the move to downtime procedures. Breach notification steps are built into the plan so the privacy officer can meet federal deadlines.
Recover
The disaster recovery plan is updated to restore the EHR, laboratory and pharmacy systems first, with recovery time targets of 24 hours for the EHR and 48 hours for revenue cycle. Backups are tested quarterly by restoring a sample system. Generator fuel contracts are extended to cover 96 hours for the data center, addressing the storm risk.
Risk Responses at a Glance
R1 ransomware: mitigate by replacing unsupported servers, immutable backups and detection; owner CIO; $420,000; six months. R5 unattended workstations: mitigate with badge tap login; owner chief nursing officer; $180,000; four months. R4 snooping: mitigate with access monitoring; owner privacy officer; $60,000 a year; three months. R8 incident handling: mitigate with a new plan and exercises; owner security officer; $25,000; three months. R6 vendors: transfer and mitigate through agreements and reviews; owner compliance officer; staff time; six months. R2 phishing: mitigate with multifactor login and training; owner CFO; $30,000; two months. R7 recovery: mitigate by updating and testing the plan; owner CIO; $50,000; nine months. R3 tapes: avoid by ending shipment; owner CIO; included in R1. R9 power: mitigate through fuel contracts; owner facilities director; $15,000. R10 pumps: accept residual risk with network separation; owner biomedical engineering director; $40,000.
Meeting the Security Rule
Each section maps to Security Rule standards: governance to assigned security responsibility and the security management process; Protect to access control, training and device controls; Detect to audit controls and activity review; Respond to incident procedures; Recover to the contingency plan. Federal implementation guidance links these standards to framework outcomes, which lets the hospital show compliance through the same plan it uses to manage risk (Marron, 2024).
People and Culture
Technology will not carry the plan alone. Department managers will discuss one security habit at each monthly staff meeting, drawn from real events at the hospital without naming anyone. Staff who report a suspicious email or a lost device will be thanked, not disciplined, so that reports arrive quickly. New employees will complete security training before receiving system access, and physicians will receive a short version during credentialing. The security officer will publish a brief quarterly note to all staff on what the program has fixed, so people see that their reports lead somewhere.
Budget and Timeline
The first-year cost is about $820,000, including $60,000 in recurring monitoring. Months one to three: governance changes, multifactor login, access monitoring and the new incident plan. Months four to six: server replacement, badge tap login and cloud backups. Months seven to twelve: disaster recovery testing, the second tabletop exercise and the annual risk analysis.
Measures for the Board
The audit committee will see, each quarter: share of critical patches installed inside the 30-day target, number of unsupported systems, phishing click rate, alerts reviewed within a week, days since the last successful restore test and the count of very high and high risks.
Review
The plan is reviewed yearly and after any major incident, merger or new core system, and the risk register monthly.
Conclusion
Built on four weeks of structure, regulation, identification and analysis, this plan gives the hospital a governed, funded and measured program. It addresses its worst risk first, prepares for attacks that succeed and lets the board see whether risk is actually falling.
References
Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1
Marron, J. A. (2024). Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A cybersecurity resource guide (NIST Special Publication 800-66 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-66r2
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
What the HCIS 420 Week 5 instructions ask
HCIS 420 Week 5 generally asks students to develop a comprehensive risk management plan for a health care organization's information systems. Prompts may ask for the plan's scope and goals, governance and roles, risk responses and controls, incident response and contingency planning, training, monitoring, budget, timeline and how the plan meets regulatory requirements. Many sections expect students to draw on the organization and risks developed in earlier weeks. Plans often run four or five pages. Strong plans follow a recognized framework, tie each control to a ranked risk, give owners and deadlines, include response and recovery rather than only prevention and define how progress will be measured and reported.
How this HCIS 420 Week 5 example is built
The sample begins with the executive team's request for a plan it can approve in one meeting. It states the plan's scope, goals and governance, with the security officer's new reporting line and the risk appetite statement. The body follows the framework's six functions. Govern covers roles, policy and vendor oversight. Identify covers the asset inventory and the risk register. Protect covers patching, access, encryption and training. Detect covers log review and monitoring. Respond covers the incident plan and exercises. Recover covers backups and disaster recovery. A table assigns the ten ranked risks their responses, owners, costs and deadlines. A timeline, board measures and an annual review cycle close the plan.
HCIS 420 Week 5 grading rubric: where the points go
The final plan is usually graded as a whole. Faculty look for a complete, coherent plan: governance and roles, controls tied to analyzed risks, incident response and recovery, training, budget, timeline, measures and regulatory alignment. Use of a recognized framework as the organizing structure earns credit. Plans that carry forward earlier weeks' work consistently show mastery of the course. Clear tables and headings help graders follow. Writing mechanics and references complete the grade. Plans that list security products without linking them to risks, stop at prevention with no detection or recovery or leave out who is accountable and by when usually earn less than plans a hospital could actually adopt.
HCIS 420 Week 5 help: mistakes to avoid
A frequent HCIS 420 Week 5 problem is a list of good security practices written in place of a plan. A plan ties each action to a ranked risk, names an owner, sets a date and states a cost. Another error is covering prevention only; attacks will sometimes succeed, so detection, response and recovery need equal attention. Students also forget governance, yet the plan needs an approver, a risk appetite and a reporting line. Carry forward the organization, risks and scores from earlier weeks rather than starting over. Use a framework to organize the plan. Include training, since people cause and catch many incidents. Finally, define a few measures leadership will see, and state when the plan itself will be reviewed.
Related HCIS 420 sample papers
Other HCIS 420 week samples
- HCIS 420 Week 1: Health Care IT Organization
- HCIS 420 Week 2: Health Care IT Regulations
- HCIS 420 Week 3: Risk Identification and Planning
- HCIS 420 Week 4: Information System Risk Analysis
More BS in Health Administration sample papers
- HCIS 318 Week 5: Technology and Communication Methods
- HCIS 352 Week 5: Health Information Data Compliance
- HCS 120 Week 5: Why Compliance Matters in Health Care
- HCS 131 Week 5: Customer Service and Perception
HCIS 420 Week 5 questions, answered
What does HCIS/420 Week 5 usually ask for?
Many sections ask students to develop a comprehensive risk management plan for a health care organization's information systems, covering governance, controls, incident response, recovery, training, budget, timeline and measures.
Where can I find a free HCIS 420 Week 5 sample paper?
The hospital risk management plan above is free to read, organized by the NIST framework functions with margin notes. A first custom plan for your organization is also offered at no charge.
What are the six functions of the NIST Cybersecurity Framework 2.0?
Govern, Identify, Protect, Detect, Respond and Recover, which together describe the outcomes an organization needs to manage cybersecurity risk.
What should a health care risk management plan include?
Scope and governance, a risk register with responses and owners, protective controls, detection, incident response, contingency and recovery plans, training, budget, timeline and measures reported to leadership.
How often should a hospital review its risk management plan?
At least annually and whenever major changes occur, such as a new system, merger or significant incident, with the risk register reviewed more often, for example monthly.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HCIS 420 week samples · All courses