| Course | HCS 456 Risk Management (HCS/456) |
|---|---|
| Week | 2 |
| Paper type | Enterprise risk management paper |
| Length | about 1,068 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | BS in Health Administration |
| Updated | September 2026 |
Free sample paper for HCS 456 Week 2
From the Incident Log to the Boardroom: Replacing Claims-Driven Risk Management With Enterprise Risk Management at a Home Health and Hospice Agency
[Student Name]
University of Phoenix
HCS/456: Risk Management
Week 2 Assignment
[Instructor Name]
[Date]
The agency, its risk register and its figures are composites written for a model paper; frameworks and research come from the sources listed.
At the first board meeting after a composite home health and hospice agency hired its risk manager, a director asked a pointed question: why does the board hear about risk only after someone files a claim? The agency's risk program had been built around incident reports, insurance renewals and lawsuits. It handled losses competently but looked backward and saw only clinical and liability risks. This paper explains how the agency is replacing that approach with enterprise risk management and what changed.
Traditional Risk Management at the Agency
Before the change, the agency's risk activities were reactive and narrow. Staff reported injuries and patient incidents, the office manager filed them, the insurance broker renewed policies each year and the chief financial officer handled claims with defense counsel. No one looked at risks that did not produce incident reports, such as a referral source weakening or a key software vendor failing.
What Enterprise Risk Management Is
Enterprise risk management treats all significant risks as a connected portfolio, managed by leaders across the organization and overseen by the board, in light of the organization's strategy. The international risk management standard (International Organization for Standardization, 2018) describes the work in three layers: principles, such as integration and continual improvement; a framework in which leadership commits to managing risk as part of governance; and a process that sets scope and criteria, assesses risks, treats them, monitors and reviews them and records and reports the results. Risk in this view includes upside: a risk can also be an opportunity the organization is positioned to take.
A Model for Health Organizations
Etges et al. (2019) proposed an enterprise risk management model tailored to health organizations, combining identification of risks across processes, assessment of their likelihood and impact, prioritization and management, and emphasizing that clinical, operational and financial risks interact. Their model reinforced the agency's decision to use one register for all categories rather than separate lists kept by different departments.
Eight Categories
The agency's register uses eight categories. Clinical and patient safety: medication discrepancies after discharge and falls at home. Operational: staff scheduling, vehicle crashes and rural travel. Strategic: referral concentration and competition from hospital-owned agencies. Financial: payment changes and cash flow. Human capital: nurse turnover and workplace violence. Legal and regulatory: survey findings, hospice eligibility audits and billing compliance. Technology: the electronic record, mobile devices and cyberattacks. Hazard: winter storms and wildfire smoke.
Technology Risk as an Example of Breadth
Technology risk shows why breadth matters. Neprash et al. (2022) counted 374 ransomware attacks on health care delivery organizations from 2016 through 2021, with about four in ten causing electronic system downtime. For an agency whose nurses document every visit on tablets and whose schedules live in the cloud, such an attack would be an operational and clinical event, not only a technology problem.
Ranking and Owners
Owners rate every risk on two five-point scales, how likely and how damaging, and the pair of ratings sets its square on a heat map. Each has one executive owner. The four risks in the red zone were medication discrepancies after discharge, owned by the director of clinical services; nurse turnover, owned by the human resources director; a cyberattack on the electronic record, owned by the chief information officer; and referral concentration, owned by the chief executive.
The Risk Traditional Methods Missed
The register showed that 44% of the agency's referrals came from one regional hospital. The hospital's parent system had announced plans to open its own home health agency. No incident report or claim would ever have flagged this, yet losing those referrals would cut revenue by a third within two years. The largest risk on the register had never caused a single incident, which is exactly why the old program could not see it.
Responding to the Strategic Risk
The chief executive's response plan includes building referral relationships with two other hospitals and 30 physician practices, proposing a preferred-provider arrangement to the regional system based on the agency's readmission results and developing a palliative care service that the new competitor will not offer. The risk is reviewed at every board meeting.
Governance
The board's quality and compliance committee now oversees the register and reviews the heat map each quarter. The executive team reviews all red and orange risks monthly. The risk manager maintains the register, facilitates assessments and reports trends, but each executive owns the risks in his or her area.
Benefits
The agency expects fewer surprises, better use of limited money by funding the highest risks first, better conversations with insurers and a board that discusses risk before losses occur. Linking risk to strategy also helped the agency see opportunities, such as the palliative care service.
How the Register Changed Decisions
The register has already changed how money is spent. The capital budget had set aside funds to replace office furniture; the executive team moved part of that money to multifactor authentication and offline backups after the cyberattack risk landed in the red zone. The human resources director used the nurse turnover score to justify a retention bonus for nurses in their second year, the point at which most resignations occurred. And the insurance broker used the register to negotiate a lower premium for cyber coverage, because the agency could show the controls it had funded. Without a single ranked list, each request would have competed on its own for attention.
Challenges
The change has costs. Executives must spend time on risk assessments, scoring is partly subjective and staff accustomed to thinking of risk management as paperwork must learn to see it as part of their jobs. Data on some risks, such as referral trends, had to be built from scratch.
First-Year Steps
The first year includes training executives on the register, completing a full assessment of all eight categories, adding the heat map to board materials and testing response plans for the four red-zone risks, including a tabletop exercise on a cyberattack.
Conclusion
The agency's traditional program handled claims and incidents but could not see risks that had not yet hurt anyone. Enterprise risk management puts every category of risk in one register, ties each to strategy and an owner and brings the portfolio to the board. The referral concentration risk, invisible to the old approach, shows why the change matters.
References
Etges, A. P. B. d. S., de Souza, J. S., Kliemann Neto, F. J., & Felix, E. A. (2019). A proposed enterprise risk management model for health organizations. Journal of Risk Research, 22(4), 513-531. https://doi.org/10.1080/13669877.2017.1422780
International Organization for Standardization. (2018). Risk management: Guidelines (ISO Standard No. 31000:2018).
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
What the HCS 456 Week 2 instructions ask
In HCS 456 Week 2 the usual deliverable is a paper, often capped near 1,400 words, on enterprise risk management in health care. Students define enterprise risk management, compare it with traditional risk management, describe its components or framework and explain how it applies to a health care organization, sometimes one they know. Prompts may ask about the categories of risk, the role of leadership and the board, and the benefits and challenges of adopting the approach. Strong papers explain that enterprise risk management treats risks as a connected portfolio tied to strategy, name risk categories beyond patient safety, show how risks are ranked and owned and give an example of a risk the traditional approach would miss.
How this HCS 456 Week 2 example is built
The paper opens with the agency's first board meeting after hiring a risk manager, where directors asked why they heard about risk only after a claim. It describes the agency's traditional program: incident reports, insurance and claims. It then defines enterprise risk management using a framework that links risk to strategy and performance, and a model developed for health organizations. The agency's new register sorts risks into eight categories, each with an owner, and a heat map ranks them by likelihood and impact. The paper walks through one strategic risk, 44% of referrals coming from one hospital. It closes with governance, benefits, challenges and first-year steps.
HCS 456 Week 2 grading rubric: where the points go
The enterprise risk management paper is typically graded on accurate definitions, a clear comparison with traditional risk management and meaningful application. Instructors look for the core ideas: risk viewed across the whole organization, linked to strategy, owned by named leaders and overseen by the board. Points go to describing a framework or process, naming risk categories beyond clinical and liability risk and using an example from a real or composite organization. Discussing benefits and challenges of adoption shows balance. Credible sources should support the discussion. Staying inside the word limit and citing correctly in APA account for the last points, and papers describing enterprise risk management as a larger incident reporting system usually miss the central point.
HCS 456 Week 2 help: mistakes to avoid
The most common misunderstanding in HCS 456 Week 2 is treating enterprise risk management as traditional risk management with more categories. The difference is purpose: it links risk to strategy and treats risks as a connected portfolio managed by leaders and overseen by the board. Say this directly. Another gap is listing categories without showing how risks are ranked and owned; include a register or heat map. Students also forget that some risks are opportunities, since the approach considers upside as well. Use a concrete example of a risk the old approach would miss, such as dependence on one payer or referral source. Keep within the word count. Finally, address challenges, such as culture and data.
Related HCS 456 sample papers
Other HCS 456 week samples
- HCS 456 Week 1: The Risk Manager's Role and Skills
- HCS 456 Week 3: Regulations and Risk Factors
- HCS 456 Week 4: Risk Tools and Decision Making
- HCS 456 Week 5: Risk Management Plan
More BS in Health Administration sample papers
- HCS 451 Week 2: Quality Improvement in Health Care
- HCS 455 Week 2: The Legislative Process and Its Influencers
- HCS 457 Week 2: Measuring Health Status
- HCS 465 Week 2: Sampling and Data Collection
HCS 456 Week 2 questions, answered
What does HCS/456 Week 2 usually ask for?
Most versions want a paper of roughly four or five double-spaced pages defining enterprise risk management, comparing it with traditional risk management and applying it to a health care organization.
Where can I find a free HCS 456 Week 2 sample paper?
Our enterprise risk management paper for a home health agency is printed above in full; there is no charge to read it, and short notes beside the text point out the register and heat map. A first paper built on your own organization can be written free.
What is the difference between enterprise and traditional risk management?
Traditional risk management focuses on clinical and liability losses after they occur; enterprise risk management looks at all categories of risk across the organization, links them to strategy and is overseen by leadership and the board.
What are the categories of enterprise risk in health care?
Commonly clinical and patient safety, operational, strategic, financial, human capital, legal and regulatory, technology and hazard risks.
What is a risk heat map?
A chart that plots risks by likelihood and impact, often colored from green to red, so leaders can see which risks need attention first.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HCS 456 week samples · All courses