HCS 468 Week 3 Health Privacy and Security Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HCS 468 Week 3 example treats health privacy and security as a management task, walking through the security risk analysis a clinical laboratory owes under HIPAA and the safeguards its leaders funded afterward. Readers get the finished APA 7 paper beneath the facts table. In University of Phoenix HCS 468 the third week narrows from regulation in general to the rules that protect patient information, and HCS/468 health administration students are asked to explain privacy and security requirements, identify risks and recommend protections. The setting is the same composite laboratory used earlier in the course: 11 draw sites with self-service check-in kiosks, drivers carrying tablets between physician offices and a billing office that nearly wired money to a criminal. The paper separates the Privacy Rule from the Security Rule, uses national data on ransomware to show why the threat is real and ranks risks by likelihood and impact.

CourseHCS 468 Regulatory and Compliance within the Health Care Industry (HCS/468)
Week3
Paper typePrivacy and security risk analysis
Lengthabout 1,162 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Health Administration
UpdatedSeptember 2026

Free sample paper for HCS 468 Week 3

1

Couriers, Kiosks and a Phishing Email: A HIPAA Security Risk Analysis for an Independent Clinical Laboratory and the Safeguards Its Leaders Chose

[Student Name]

University of Phoenix

HCS/468: Regulatory and Compliance within the Health Care Industry

Week 3 Assignment

[Instructor Name]

[Date]

The laboratory, its systems and its incidents are composites written for a model paper; legal requirements and attack data come from the sources listed.

What this part is doingThe title names three ordinary sources of risk before the legal term, signaling that the analysis will start from the organization, not the regulation.
2

On a Thursday afternoon, the billing supervisor at a composite independent clinical laboratory received an email that appeared to come from the chief financial officer. It asked her to update the bank account for a reagent supplier before a payment that evening and to keep the change quiet because of an audit. She noticed that the reply address differed by one letter and called the chief financial officer, who had sent nothing. The laboratory lost no money, but leadership asked the compliance officer for a full review of how its patient information and systems are protected. This paper presents that review.

Privacy and Security Are Different Duties

Under the Privacy Rule, the laboratory decides who may see a patient's information and for what purpose, whether that information sits on a paper requisition, in a phone call or on a screen; the same rule lets patients inspect and copy what the laboratory holds about them. The Security Rule is narrower in one way and deeper in another (U.S. Department of Health and Human Services, n.d.). It covers only information held or sent electronically, but it obliges the laboratory to protect that information with three kinds of safeguards, administrative, physical and technical, so that it stays confidential, accurate and available when clinicians need it. The Breach Notification Rule then requires notice to patients, the government and sometimes the media when unsecured information is compromised.

What this part is doingPrivacy, security and breach notification are separated in the first section, which is the distinction graders check before anything else.
3

Why the Threat Has Grown

Neprash et al. (2022) built a database of publicly reported ransomware incidents in care delivery and found 374 of them over six years ending in 2021, which between them exposed the health data of close to 42 million people. Incidents per year rose from 43 in the first year studied to 91 in the last. In 166 of the incidents, patient care itself was interrupted, usually because clinical systems went dark, and over time the attackers increasingly hit large organizations with many sites and were less often resolved by restoring data from backups.

What a Risk Analysis Requires

The Security Rule does not list one set of required technologies. It asks each organization to assess its own risks and choose reasonable and appropriate safeguards. Guidance from the Office for Civil Rights (2010) describes the expected steps: define the scope, identify where electronic information is created, received, kept and sent, identify threats and vulnerabilities, assess current controls, determine likelihood and impact, assign risk levels, document the results and update the analysis periodically. A laboratory that bought excellent software but never wrote down its risks would still be out of compliance, because the analysis itself is the requirement.

The Laboratory's Information Assets

The review found electronic information in more places than leaders expected. The laboratory information system holds every order and result. An interface engine sends results to physician offices and the patient app. Billing software stores insurance and payment data. At each draw site, a check-in kiosk scans insurance cards and photo identification. Twenty-six drivers carry tablets that display pickup lists with patient names. Staff email, shared network drives and a cloud backup complete the picture.

Threats and Scores

The compliance officer and the information technology manager scored six threats from one to five for likelihood and for impact, multiplying the two for a risk score.

What this part is doingA simple likelihood-times-impact score lets a nontechnical reader see why four risks were funded first and two were deferred.
4

Phishing that leads to stolen passwords or payment fraud: likelihood 5, impact 4, score 20.

Ransomware on the laboratory information system: likelihood 3, impact 5, score 15.

A lost or stolen courier tablet: likelihood 4, impact 3, score 12.

A kiosk screen or scanner exposing another patient's data: likelihood 4, impact 3, score 12.

Accounts of former employees left active: likelihood 3, impact 3, score 9.

Faxed results sent to the wrong office: likelihood 2, impact 3, score 6.

Safeguard One: Phishing

Administrative and technical safeguards were combined. All staff will complete short training with monthly simulated phishing emails, and anyone who clicks receives a two-minute follow-up lesson rather than discipline. Multifactor authentication will be required for email and remote access. Any request to change payment details must be confirmed by phone using a number already on file, the rule that saved the laboratory in the Thursday incident.

Safeguard Two: Ransomware

The laboratory information system and billing software will be backed up daily to storage that cannot be altered from the main network, and restoration will be tested every quarter. The laboratory will also write a downtime procedure so testing can continue on paper requisitions and phone results for critical values if systems are down, since a laboratory that cannot report a critical potassium is a patient safety problem, not only a data problem.

Safeguard Three: Courier Tablets

Tablets will be encrypted, locked by a code after two minutes, and enrolled in management software that can erase them remotely. Pickup lists will show order numbers and office names instead of patient names wherever possible. Encryption matters legally as well as practically: under the breach rule, loss of properly encrypted data is generally not a reportable breach.

Safeguard Four: Kiosks

Kiosk screens will clear after 30 seconds of inactivity, privacy filters will be installed, and scanned identification images will be sent to the registration system and deleted from the kiosk. Front desk staff will check each kiosk at opening and closing.

Deferred Risks

Account removal for departing staff will be tied to the human resources termination checklist, an inexpensive process change. Faxed results will be phased out as more offices receive electronic results, with fax numbers verified twice a year until then.

Who Owns Each Safeguard

Each safeguard has one named owner. The information technology manager owns multifactor authentication, backups and tablet management. The billing manager owns the payment change procedure and reports every attempted fraud to the compliance officer. Site supervisors own the kiosk checks and sign a monthly log. Human resources owns account removal and sends a list of departures to information technology every Friday. The compliance officer owns training, the phishing simulations and the annual update of the analysis, and she reports progress to the compliance committee each quarter. Naming owners matters because security programs usually fail in the gaps between departments, where everyone assumes someone else is watching.

Keeping It Current

The risk analysis will be updated every year and whenever the laboratory adds a system, a site or a vendor with access to patient data. Business associate agreements with the courier software vendor and the cloud backup provider were reviewed and found current.

Conclusion

The near miss in the billing office showed that the laboratory's greatest weakness was not a missing technology but an untested assumption that staff would recognize fraud. A documented risk analysis turned a vague worry into six ranked risks, and the safeguards leaders funded address the four most serious with a mix of training, process and technology. Repeating the analysis each year keeps the protection as current as the threats.

5

References

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

Office for Civil Rights. (2010). Guidance on risk analysis requirements under the HIPAA Security Rule. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html

U.S. Department of Health and Human Services. (n.d.). Summary of the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

What the HCS 468 Week 3 instructions ask

HCS 468 Week 3 usually centers on protecting patient information. Depending on the section, the assignment may ask you to explain the HIPAA Privacy, Security and Breach Notification Rules, describe the administrative, physical and technical safeguards the Security Rule requires, identify threats to patient information and recommend ways to reduce them. Some sections ask for an analysis of a real breach; others ask students to assess an organization they know. A paper of two to four pages with current sources is common. Strong papers distinguish privacy from security, explain that a documented risk analysis is required rather than optional, tie each safeguard to a specific risk and show how staff behavior and technology work together.

How this HCS 468 Week 3 example is built

The paper begins with a near miss: an email that looked like it came from the laboratory's chief financial officer asked the billing office to change a vendor's bank account. From there it explains what the Privacy and Security Rules each cover, why ransomware has become the leading threat to health care operations and what a security risk analysis must include. The analysis lists the laboratory's information assets, from the laboratory information system to the courier tablets, and scores six threats by likelihood and impact in a table. Leaders funded safeguards for the four highest risks: phishing, lost devices, kiosk exposure and ransomware. The paper closes with training, testing and a schedule for repeating the analysis.

HCS 468 Week 3 grading rubric: where the points go

Instructors typically weigh accuracy about the law first: the difference between privacy and security, the three safeguard categories and the breach notification duty. Credit then goes to a realistic assessment of risks in a specific organization and to safeguards matched to those risks. Current evidence about threats, such as data on attacks or enforcement actions, strengthens the paper. Grading also considers whether the plan includes people and processes, not only technology, and whether it can be sustained. The rest of the grade covers organization, clarity and citation style. Submissions that list every safeguard the rule mentions without prioritizing, or that describe encryption and passwords without any link to the organization's actual risks, rarely reach the top band.

HCS 468 Week 3 help: mistakes to avoid

A common slip in HCS 468 Week 3 is writing about HIPAA as if it were a single rule. Explain that the Privacy Rule governs uses and disclosures of all protected health information, the Security Rule protects electronic information and the Breach Notification Rule sets duties after an incident. Another mistake is describing safeguards in the abstract. Start with the organization's assets and threats, rank them and then choose safeguards. Remember that the risk analysis must be documented and repeated. Include human factors; most attacks start with an email. Do not promise that any measure makes a breach impossible. Use a government source for legal requirements and a recent study for threat data. Finally, name who owns each safeguard and when it will be checked.

Related HCS 468 sample papers

Other HCS 468 week samples

More BS in Health Administration sample papers

HCS 468 Week 3 questions, answered

What does HCS/468 Week 3 usually ask for?

Many sections ask students to explain health information privacy and security requirements, especially HIPAA, identify risks to patient information in an organization and recommend safeguards.

Where can I find a free HCS 468 Week 3 sample paper?

The laboratory security risk analysis above is open to read, including its scored risk table and short side notes on each choice. Tell us your organization and assignment, and your first custom paper is free.

What is the difference between the HIPAA Privacy Rule and Security Rule?

The Privacy Rule sets standards for using and disclosing protected health information in any form; the Security Rule requires safeguards to protect electronic protected health information.

What are the three types of safeguards in the Security Rule?

Administrative ones cover policies, risk analysis and workforce training; physical ones protect buildings, workstations and devices; technical ones include unique logins, audit logs, encryption and protection of data in transit.

Is a risk analysis required under HIPAA?

Yes. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information and to review it periodically.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.